Skip to main content
Runlane
Home
Resources
AboutRunbooksBlog
PricingContact
Open app
Home
Resources
AboutRunbooksBlog
PricingContact

Last updated: September 8, 2026

Privacy Policy

This policy explains how Runlane collects, uses, discloses, and protects personal information.

1. Scope

This Privacy Policy applies when you visit Runlane's websites, use our applications or APIs, participate in a preview program, or otherwise interact with us (collectively, the "Services"). "Runlane", "we", "us", and "our" refer to the provider of the Services.

This policy applies globally. Additional rights may apply based on where you live. If you do not agree with this policy, do not use the Services.

2. Our Role

Runlane is the controller of personal information used to operate our website, manage accounts, secure the Services, communicate with users, and administer our business.

Organizations use Runlane to manage their own work. For personal information contained in workspace content ("Customer Content"), the Organization generally determines why and how that information is processed. Runlane processes it on the Organization's behalf as a processor or service provider. If your request concerns Customer Content controlled by an Organization, contact that Organization first. We will assist it as required by law.

3. Information We Collect

We may collect the following categories of information:

  • Account information: name, email address, profile details, authentication records, account identifiers, Organization and workspace membership, roles, invitations, and preferences.
  • Customer Content: projects, tasks, Runbooks, project memory, table data, comments, uploaded files, prompts, instructions, messages, agent inputs, outputs, generated artifacts, and other content you choose to process through the Services.
  • Agent operations data: agent configuration, enabled skills, run status, schedules, events, approvals, rejections, retries, logs, usage records, budgets, limits, generated files, and audit history.
  • Credentials and integration data: credential names, environment variable names, encrypted credential values, OAuth tokens, connected account identifiers, provider scopes, connection status, and data retrieved from services you connect.
  • Device, network, and log information: IP address, browser and device type, operating system, request details, timestamps, diagnostic data, errors, security events, and approximate location derived from IP address.
  • Analytics information: interactions with the Services, pages and features used, navigation events, and session information when optional analytics is enabled.
  • Communications: support requests, privacy requests, feedback, survey responses, and other messages you send us.

You may choose not to provide certain information, but some Services may not work without it. Customer Content may include personal information about other people. You are responsible for providing required notices and obtaining appropriate rights or consents before submitting it.

4. How We Collect Information

We collect information:

  • directly from you when you create an account, configure a workspace, contact us, or submit content;
  • from your Organization and its administrators or other authorized users;
  • automatically when you use the Services;
  • from identity providers when you sign in through them; and
  • from third-party services you connect or direct an agent to access, subject to the permissions you grant.

5. How We Use Information

We use personal information to:

  • provide, operate, maintain, and support the Services;
  • authenticate users and enforce Organization, workspace, project, and agent permissions;
  • perform agent runs, scheduled work, connected-service actions, and human review workflows;
  • store files and artifacts, maintain run history, and provide audit records;
  • measure usage, apply limits and budgets, and administer preview entitlements;
  • monitor performance, troubleshoot errors, prevent abuse, and protect the Services and users;
  • communicate about accounts, security, service changes, support, and requested updates;
  • understand and improve how the Services work;
  • enforce our Terms of Service and protect legal rights; and
  • comply with applicable law, court orders, and valid government requests.

To understand and improve the Services, we use analytics information, usage records, diagnostic data, and feedback. We do not use Customer Content for general product improvement unless you or your Organization authorizes that use. We may process Customer Content as needed to provide requested support or troubleshoot the Services.

6. Legal Bases

Where applicable law requires a legal basis, we rely on:

  • Contract: processing needed to provide the Services you or your Organization requested.
  • Legitimate interests: securing, supporting, analyzing, and improving the Services; communicating with users; preventing abuse; and protecting our rights, where those interests are not overridden by your rights.
  • Legal obligations: processing needed to comply with law and lawful requests.
  • Consent: processing for which you expressly provide consent. You may withdraw consent at any time without affecting earlier processing.

7. AI Processing and Model Training

When you use an AI feature, relevant Customer Content may be sent to AI model providers and infrastructure providers to generate a response or perform the requested Agent Action. The information sent depends on your instructions, selected files, enabled skills, connected services, and agent configuration.

Runlane does not use Customer Content to train AI models operated by Runlane. Model providers process Customer Content under the terms and settings applicable to the selected model and provider route. Some routes support zero-data retention, but we do not guarantee zero-data retention for every model.

Zero-data retention means the model provider does not retain prompts and outputs after processing. Providers of models or routes without zero-data retention may retain prompts and outputs for limited periods under their terms, including for safety, abuse prevention, or service operation. The model selected by you or your Organization therefore affects provider retention. We may use aggregated or de-identified service information that cannot reasonably identify you or your Organization to understand and improve the Services.

AI outputs and Agent Actions are subject to human direction and review. Runlane does not use personal information to make solely automated decisions about individuals that produce legal or similarly significant effects. Your Organization is responsible for decisions it makes using the Services.

8. Credentials and Connected Services

The Services may store Secrets and OAuth tokens so authorized agents can access connected services during a run. Secret plaintext is encrypted and is not returned through the browser after creation or update. Browser interfaces expose only limited credential and connection metadata.

When you connect a third-party service, we receive and process information allowed by the permissions you grant. Agent Actions may also send information to that service. The third party handles information under its own privacy policy when acting independently of Runlane. You can disconnect a service to stop future access, but this does not delete information already processed.

The use of raw or derived user data received from Google Workspace APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

9. Cookies, Local Storage, and Analytics

We use cookies and similar technologies needed for authentication, security, preferences, and core functionality. The application may also store interface preferences and temporary form or session state in local or session storage.

We use analytics to understand feature use and service performance, diagnose problems, and improve the user experience. We use marketing measurement to help us understand the effectiveness of our marketing campaigns. The data we collect may include page and feature usage, navigation events, session information, and associated account, device, browser, and network information.

The optional analytics and marketing cookies are enabled by default. You can change these preferences at any time using the controls below.

You can control cookies through your browser, but blocking essential storage may prevent parts of the Services from working.

10. How We Disclose Information

We may disclose information to:

  • Your Organization: administrators and authorized workspace members according to their roles and permissions.
  • Service providers and subprocessors: providers supporting cloud hosting, databases, object storage, authentication, AI processing, background jobs, email, analytics, security, error monitoring, and customer support.
  • Connected services: third-party services you connect or direct an agent to use.
  • Professional advisers: lawyers, auditors, insurers, and other advisers where reasonably necessary and subject to confidentiality obligations.
  • Authorities and other parties: where reasonably necessary to comply with law, respond to valid legal process, investigate fraud or abuse, enforce our agreements, or protect rights, safety, and security.
  • Transaction parties: participants in a proposed or completed merger, financing, reorganization, acquisition, or sale of assets, subject to appropriate confidentiality and data-protection safeguards.

We require service providers to process personal information only for authorized purposes and to protect it appropriately. We do not disclose Customer Content to third parties for their own marketing.

11. International Data Transfers

Runlane and our service providers may process information in Australia, the United States, and other countries where we or they operate. Those countries may have privacy laws different from those where you live.

Information processed in another country may be subject to that country's laws and lawful access requests. You may contact us for information about where your personal information may be processed.

12. Data Security

We use technical and organizational measures designed to protect personal information. These include encryption in transit, encryption of Secrets and OAuth tokens at rest, tenant and role-based access controls, scoped credential access, audit records, and monitoring for service and security events.

No method of transmission or storage is completely secure. You are responsible for protecting your account, limiting the credentials and permissions you grant, and promptly reporting suspected misuse by email.

13. Data Retention and Deletion

We retain personal information and Customer Content for as long as reasonably needed to provide and secure the Services, maintain required business and audit records, comply with law, resolve disputes, and enforce our agreements. Retention periods vary by data type, purpose, service configuration, and legal requirements.

Closing an individual account does not delete Customer Content controlled by an Organization. An active Organization may retain information it needs to administer its records.

When information is no longer needed, we delete or anonymise it where reasonably practicable. Deletion timing varies by data type and system, and residual copies may remain in backups until those backups expire through ordinary rotation. We may retain limited information where required by law, needed to resolve a dispute, or necessary to prevent fraud or protect security, and will use it only for that purpose.

De-identified information that cannot reasonably be linked to an individual or Organization may be retained. Data sent to a connected third-party service is subject to that service's retention practices.

14. Your Privacy Rights

Depending on where you live and subject to legal exceptions, you may have the right to:

  • access or obtain a copy of your personal information;
  • correct inaccurate or incomplete personal information;
  • delete or erase personal information;
  • restrict or object to processing;
  • receive portable personal information you provided to us;
  • withdraw consent where processing is based on consent;
  • opt out of direct marketing, sale, sharing, or targeted advertising;
  • appeal a refusal of a request where applicable; and
  • complain to a privacy or data-protection regulator.

Runlane does not sell personal information. You can turn off optional cookies from this page, and we will not discriminate against you for exercising a privacy right.

To exercise a right, send us an email . Describe your request and the account or Organization involved. We may verify your identity and authority before responding. An authorized agent may submit a request where permitted by law, but we may require proof of authority.

We will review privacy complaints, may ask for information needed to investigate, and aim to respond within a reasonable period. If your request concerns Customer Content controlled by your Organization, we may refer the request to that Organization.

If you are not satisfied with our response, you may contact an applicable regulator. This may include the Office of the Australian Information Commissioner in Australia; the Federal Trade Commission, your state attorney general, or an applicable state privacy regulator in the United States; your local supervisory authority in the European Economic Area; or the Information Commissioner's Office in the United Kingdom.

15. Marketing Communications

We may send service announcements, security alerts, and account messages needed to operate the Services. You cannot opt out of these while maintaining an active account.

Where we send optional marketing, you can unsubscribe using the link in the message or by contacting us. We may retain a limited suppression record so we can honour your choice.

16. Children

The Services are for business users aged 18 or older. We do not knowingly collect personal information directly from anyone under 18. If you believe a person under 18 provided personal information to us, contact us so we can investigate and delete it where appropriate.

17. Third-Party Links

The Services may link to websites or services Runlane does not control. Their privacy practices are governed by their own policies, and this Privacy Policy does not apply to them.

18. Changes to This Policy

We may update this Privacy Policy from time to time. We will update the date above and take reasonable steps to notify you before material changes take effect. We will request consent where required by law.

19. Contact

Questions, complaints, and privacy requests may be sent by email or by post .

Runlane

Hand off the work that keeps coming back, without losing sight of what's important.

Runbooks

  • Marketing
  • Support
  • Sales
  • HR
  • Finance
  • Operations
  • Growth

Product

  • Home
  • Pricing
  • Sign in

Company

  • About
  • Blog
  • Contact

Legal

  • Terms
  • Privacy
RUNLANE

© 2026 Runlane™. All rights reserved.

We use cookies to optimize your experience.

Cookie preferences

We use different types of cookies to optimize your experience. You may choose which types of cookies to allow and can change your preferences at any time.