Skip to content

Privacy Policy

Last updated:

1. What this policy covers

This policy describes what personal data Runlane (runlane.run) collects, why, and what your choices are. It applies to the web app, the Telegram bot, and the MCP server. Contact: [email protected].

2. Data we collect

We collect only what the Service needs to work:

  • Account data: your Telegram ID, username, display name, and avatar; email address if you sign in with GitHub/Google or add one in your profile.
  • Content: boards, tasks, comments, wiki pages, files, voice notes, and photos you (or agents acting under your account) put on the Service.
  • Payment metadata: order ID, package, amount, and payment status. We never receive or store card numbers — the payment provider handles them.
  • Technical data: session cookies, your language and theme preferences, and product analytics events (pages visited, features used) tied to a pseudonymous ID.

3. How we use data

  • To provide the Service: store and sync your boards, authenticate you, deliver realtime updates and notifications.
  • To run AI features you invoke: the relevant content (e.g. a voice note or board tasks) is sent to our AI model providers for processing. AI providers process it to return a result; we do not sell your content or use it to train models.
  • To process payments and credit your balance.
  • To send transactional email (e.g. address confirmation) if you have added an email.
  • To understand product usage via analytics and improve the Service.

4. Cookies

We use cookies for signing you in (session), remembering your language and theme, and product analytics. We do not use advertising cookies.

5. Processors and sharing

We do not sell personal data. We share data only with processors needed to run the Service:

  • Hosting and infrastructure (application hosting, database, file storage).
  • Telegram — when you use the bot or Telegram sign-in.
  • Realtime delivery provider — for live board updates.
  • AI model providers (via OpenRouter) — only the content required for the AI action you invoke.
  • Payment provider — to process top-ups.
  • Email delivery provider — to send transactional email.
  • Product analytics provider — pseudonymous usage events.

6. Retention

We keep your data while your account is active. When your account is deleted, personal data and content are removed within 30 days, except records we must keep for legal or accounting reasons (e.g. payment records).

7. Your rights

You can access and update profile data in the app. To request a copy of your data, correct it, or delete your account and data, write to [email protected]. We respond within 30 days.

8. Security

Data is transmitted over TLS and stored with access restricted to what operating the Service requires. No system is perfectly secure; if a breach affecting your data occurs, we will notify you without undue delay.

9. Children

The Service is not directed at children under 16, and we do not knowingly collect their data.

10. Changes

We may update this policy; the current version with its "last updated" date always lives at this page. Material changes will be announced in the product or by email.