Privacy Policy
Effective July 21, 2026 · Runnel collects little, and reads less.
1. Who we are
Runnel (app.runnel.link) is operated by an individual based in Bulgaria, in the European Union. For anything in this policy, write to privacy@runnel.link.
2. What we collect, and why
Account data. Your email address, and one or more ways to sign in: a password (stored as a hash), a Google or GitHub identity (we receive your name and email from the provider), or a passkey (we store only its public key). We use these to sign you in and to send you account email: address verification and password reset. We send no marketing email.
Link data. Link destinations are end-to-end encrypted in your browser. We store ciphertext we cannot decrypt. The plaintext destination passes through our servers at two moments: when you create a link, for safety checks against threat blocklists, and at each open of a proxied link, to stream the content. A third exists only if you create it: connect an AI app and tick "Allow reading destinations", and each of that app's requests decrypts your destinations to answer it, under a grant you can revoke at any time. In every case the destination is processed in memory and never written to storage or logs.
Access metadata. For each link open we record the IP address, user agent, country, bytes served, and time. We use this to enforce quotas, to investigate abuse, and to show you the coarsened access history of your own links, and for nothing else.
Billing data. Paid plans are sold through Stripe, which acts as the merchant of record. Stripe holds your card and billing details. We store only your plan and a Stripe customer reference. We never see your card number.
3. What we never do
We do not sell your data. We show no ads, run no third-party analytics, and set no tracking cookies.
If you own a link, you can see coarsened access data for it: outcome, time, country, and browser family. Raw connection data (IP address, full user agent) is never shown in the product.
4. Cookies
Runnel sets only the cookies it needs to sign you in and keep you signed in. None of them track you.
5. Who processes data for us
- Cloudflare hosts Runnel and carries all traffic.
- Resend delivers account email.
- Stripe handles payments, as merchant of record.
- Google and GitHub authenticate you only if you choose to sign in with them.
Each processes data solely to provide its service to us.
6. Retention and deletion
We keep your data while your account exists. You can delete your account yourself: Security → Delete account emails you a confirmation link, and confirming erases your account and its data immediately and permanently. Our payment processor (Stripe) retains its own transaction records as required for legal and tax purposes.
7. Your rights
Under the GDPR you can ask us for a copy of your data, correct it, delete it, or export it. Write to privacy@runnel.link. You can also complain to a supervisory authority. Ours is Bulgaria's Commission for Personal Data Protection (cpdp.bg).
8. Changes
We may update this policy. We will announce material changes on the dashboard, and this page always shows the effective date.