At a Glance
Before the details, the commitments that matter most:- Bot-free capture, on your device. Runa does not send a bot to join your meeting. The app captures audio from your microphone and, where you enable it, your computer’s system audio — which includes other participants’ voices. That audio is uploaded securely to produce your transcript, and you control how long it is kept (Settings → Data & privacy).
- Nobody trains AI models on your content. Our cloud, model, and speech-to-text providers are contractually prohibited from using your content to train their models, and Runa does not train its own models on it either.
- Google data is used only to run the features you turned on. What Runa reads from Google Calendar, Gmail, Google Drive, and your Google contacts is used only to provide and improve features you can see in the app — never for advertising, never to train AI models, never sold. See Google User Data.
- We do not sell your personal data, and we do not “share” it for cross-context behavioral advertising as those terms are defined under California law.
- Connected apps read live, and writes need your approval. You choose which apps Runa can reach. Runa reads them at the moment a feature runs and does not copy their contents into its search index or cross-meeting memory. Anything that changes a connected app is shown to you first and executes only when you approve it.
- We create voiceprints to label who said what — and you control them. Voice recognition is optional, voiceprints are treated as biometric identifiers under some laws, and we publish a Biometric Data Retention & Destruction Schedule. If you record or name other people, see your responsibilities in Recording, Transcription, and Consent.
- AI outputs are reviewed by a human — you. Runa does not make solely automated decisions that produce legal or similarly significant effects about you.
- You can delete your data and account at any time. Settings → Profile → Delete Account. We delete or anonymize within 30 days, subject to legal retention.
1. Scope of This Policy
This Policy covers the personal data Runa handles as a business. Where we handle data on an organization’s behalf, that organization is in charge of it. Runa Labs Inc. is a Delaware corporation. This Policy applies to personal data we collect when you visit joinruna.com, install or use the Runa application, connect a third-party service to Runa, contact us, or receive communications from us. It does not apply to third-party services we do not control — including any service you connect to Runa, which has its own privacy policy — or to personal data we process on behalf of an enterprise customer under a Data Processing Agreement (“DPA”). In that case the customer is the controller, Runa is the processor, and you should direct privacy requests to your organization first. If we cannot act on a request because we are a processor, we will tell you and, where reasonable, refer you to the controller. “Personal data” means information that identifies, relates to, or could reasonably be linked with a particular individual. “De-identified data” means data processed so that it can no longer reasonably be linked to anyone.2. Information We Collect
We collect what you give us, what the Services generate from your meetings, and what your device and usage tell us. The table below lists the categories of personal data we collect, and may have collected in the 12 months preceding the date of this Policy. The third parties named in the last column are described in How We Share Your Information.Sensitive Personal Information
Some of what we collect qualifies as sensitive personal information under California and analogous state laws:- Account credentials — your Runa password and the access tokens you authorize. Stored encrypted, used only to authenticate you.
- Contents of communications where Runa is not the intended recipient — meeting invites on a calendar you connect and, where you enable the relevant connector, messages in a connected mailbox or chat workspace, notes in connected CRM and project tools, and the contents of files you hand Runa. Read only within the permissions you grant, only to provide features you enabled, and only when the feature runs.
- Biometric information, in the form of voiceprints. This is the only special category we collect intentionally.
Where It Comes From
We collect personal data directly from you (when you create an account, configure the app, or contact us); automatically from your use of the Services (telemetry, diagnostic logs, cookies, IP-based location); from services you connect (calendars, work tools, and identity providers you set up yourself at Settings → Connectors); and, for business-to-business outreach, fraud prevention, and security, from vendors and public sources. Attendees who are not Runa users may also appear in calendar metadata and transcripts — see Meeting Attendees Who Aren’t Runa Users.Children’s Data
The Services are not directed to children, and we do not knowingly collect personal data from anyone under 16. If we learn that we have, we will delete it as quickly as possible. If you believe a child under 16 has provided us personal data, contact admin@joinruna.com.3. How We Use Your Information
To run the Services you asked for, keep them secure, bill you, and improve them. We use personal data to:- Provide the Services — create and manage your account, detect meetings on your connected calendar, capture audio, produce transcripts, and generate summaries, action items, decisions, and cross-meeting memory.
- Power search, answers, and agent features — search across your meetings, detect conflicts, suggest follow-ups, and draft messages or prepare updates in connected systems for your approval.
- Personalize and support — tailor the Services to your preferences and usage, answer your questions, diagnose problems, and improve reliability.
- Bill and administer accounts — process subscriptions, charges, and refunds through our payment processor, and send transactional notices about your account, security, and billing. These are required for the Services and are not subject to marketing opt-out.
- Communicate — send newsletters, product updates, and announcements, which you can unsubscribe from at any time.
- Secure and comply — prevent, detect, and investigate fraud, abuse, and security incidents; enforce our Terms; and comply with law, legal process, and lawful requests from public authorities.
- Operate the business — internal analytics and planning, and corporate transactions such as financing, merger, or sale of assets.
- Research and improve — measure quality, diagnose failures, and evaluate the models behind Runa’s features. Third-party AI providers are never permitted to train on your personal data, and Runa does not train its own models on it: the datasets our features are evaluated against are fabricated, not drawn from customer content. If we ever introduce internal training on de-identified data, we will tell you before it begins and give you a way to opt out — and data received through Google APIs is permanently excluded from it, as described in Google User Data.
4. Recording, Transcription, and Consent
Recording laws vary. You are responsible for the consents your meetings require; Runa gives you the controls to honor them. Runa captures your microphone and, where you enable it, your computer’s system audio — which includes the voices of other participants — and may create voiceprints of participants you name. Recording or transcribing a conversation, and creating a voiceprint of someone, may require notice to or consent from some or all participants:- Recording and wiretap laws. Some U.S. states — including California, Connecticut, Delaware, Florida, Illinois, Maryland, Massachusetts, Montana, New Hampshire, Oregon, Pennsylvania, and Washington — generally require all-party consent to record a private conversation. Others require only one party. Many countries have their own rules.
- Biometric privacy laws. Illinois (BIPA), Texas (CUBI), Washington, and the GDPR generally require notice and consent before an individual’s voiceprint is created.
5. Voice Recognition and Biometric Data
Runa creates voiceprints so it can label who said what. The feature is optional, you can delete them, and we publish a destruction schedule. To label speakers and recognize the same person across meetings, Runa creates voice profiles (“voiceprints”) — numeric summaries of voice characteristics. These are treated as biometric identifiers under BIPA, CUBI, and Washington law, and as special-category biometric data under the GDPR. How they are created. Your own voiceprint is created only if you choose to set up voice recognition, from a short enrollment recording you make in the app. Voiceprints of other people are created when you label a speaker in a transcript so Runa can recognize them later; the people you name may include individuals who are not Runa users. Where voice data lives. Raw enrollment recordings and voice-matching samples stay on your device. A single aggregate profile per person — one numeric summary — is stored on Runa’s servers, encrypted at rest and scoped to your account, so labeling is consistent across your devices. How it is used. Only to label who is speaking and recognize them in your future meetings. We never use voice data for advertising, never sell or otherwise profit from it, and never use it to train foundation models. Sharing. If voice-signature sharing is enabled for your workspace, your own profile — and only your own, never anyone else’s — may be published to organizations you belong to, so colleagues’ copies of Runa can suggest you as a speaker. A published signature includes your name, email, and profile, and is only ever a suggestion a colleague must confirm. Organization-wide sharing of your own profile is on by default and you can turn it off in Settings, which deletes the published copy immediately. Sharing with individual contacts is off by default. Your choices, and your responsibilities. You can decline enrollment, decline to name speakers, delete any person’s voice profile, disable sharing, and delete your account at any time. Where you enroll or name another person, you are responsible for the notice and written consent that biometric privacy laws require before their voiceprint is created. Retention and destruction. We retain and destroy voice data under our published Biometric Data Retention & Destruction Schedule. In summary: unconfirmed samples on your device expire automatically; a person’s profile is destroyed when you delete them from speaker memory, delete the source meeting, or delete your account; and turning off sharing deletes any published copy immediately. To ask what voice data we hold about you, or to have it deleted, contact admin@joinruna.com.6. AI Processing and Automated Decisions
AI generates your transcripts, summaries, and drafts. No provider trains on your content, and nothing decides anything about you on its own. Runa uses AI to transcribe audio; to generate summaries, action items, decisions, and structured notes; to build the embeddings behind cross-meeting memory and search; to flag potential conflicts between statements across meetings; and to read a connected app live in order to ground an answer, a brief, or a draft. We rely on third-party providers for this — Google Cloud (Vertex AI) for generative AI, Cloudflare Workers AI for embeddings, and AssemblyAI, Deepgram, and ElevenLabs for speech-to-text. Where a feature searches the public web, your query and relevant context are sent to Google Search; web search is on by default for cross-meeting chat and in-meeting questions, off by default for automated routines, and can be turned off. Our agreements with all of these providers prohibit them from using your content to train their own models, and inputs are processed under enterprise terms with no retention or short-window retention for abuse monitoring only. Providers may change over time; our current subprocessor list is available on request. Automated decision-making. Runa does not make solely automated decisions that produce legal or similarly significant effects about you. AI outputs are presented for your review, and you can edit, override, or discard them. Where Runa executes an action in a connected system, that action results from your approval. You have the right to obtain human review of any AI output and to challenge it — contact admin@joinruna.com. Transparency and the EU AI Act. Runa identifies AI-generated content as such in the application, and will provide additional disclosures where the EU AI Act or other law requires. Runa is designed as a general-purpose AI application, not a high-risk AI system under Annex III, and we do not market it for evaluating employees. If you intend a use that could be high-risk, you are responsible for compliance and must not present AI outputs as authoritative decisions without human review.7. Connected Apps
You choose which apps Runa can reach. It reads them live rather than copying them, and nothing gets written without your approval. You can connect third-party services to Runa using OAuth, and you set up and remove every connection yourself at Settings → Connectors. Runa requests only the permissions a connector needs and accesses data only within what you grant. The connectors available change over time and can depend on your plan and on the third party’s own review; Settings → Connectors always shows what is available to you and what you have connected. Today they fall into three groups:- Calendars (Google and Microsoft) — read-only. Runa detects your meetings, reads event and attendee details, and resolves names and profile photos for the people you meet. It cannot create, change, or delete anything on your calendar. Calendar credentials are stored on your device rather than on Runa’s servers.
- Work tools — mail, CRM, project and issue tracking, knowledge bases, file storage, time tracking, and team chat. Most can read; several can also write, always subject to your approval.
- AI assistants — Runa’s Model Context Protocol (“MCP”) connector lets an assistant you authorize, such as ChatGPT or Claude, read from Runa. This direction is read-only: an assistant connected this way cannot change anything in Runa or in an app you connected to Runa. Access is decided by the scopes you consented to and re-checked on every call, is bounded by what you can already see in Runa, retains nothing extra, and is filtered and audited. Review or revoke each assistant at Settings → Connectors.
Four points worth stating plainly:
- Runa never sends email on its own initiative. Everything Runa composes is created as a draft in your own mailbox and waits there. A message leaves only when you click Send yourself. No automated routine and no background job can reach a send path, and Runa’s chat can only propose a message.
- Google Drive is read-only and per-file. Runa cannot create, edit, move, share, or delete anything in your Drive, and cannot list, search, or open the files you did not pick. We deliberately do not request access to every file your account can open.
- Every connector acts as the account you connected, so that service’s own permissions apply unchanged — Runa cannot see anything there that you cannot. Several are narrower still: Drive is limited to files you pick, Notion to pages you select, HubSpot to the object types it is granted. Slack is mixed — reading and posting happen as the Runa app in your workspace, while message search runs as the account of the person who connected it, and so can reach channels and direct messages Runa was never invited to.
- Google data is held to stricter rules than anything else here. Runa’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google User Data states that commitment in full, and it controls over anything else in this Policy.
Connected data is read live, not indexed
When you ask a question or a feature runs, Runa calls the connected app with your stored credential, uses the result, and discards it. Data read from a connected app is not added to Runa’s search index, not turned into embeddings, and not incorporated into cross-meeting memory. Attaching a source to a Runa folder records a pointer to it, not a copy. What Runa does store is limited to:- The connection itself — the encrypted credential and non-content metadata such as the account name, granted permissions, and status.
- Anything you asked Runa to prepare — a draft, a proposed CRM update, a proposed task — held while it awaits approval and afterwards as a record of what you approved.
- Derived content a feature produces — most notably a pre-meeting brief that may summarize recent correspondence with attendees. The brief is stored with the meeting; the underlying messages are not.
- A ledger of writes — what was sent where, when, by whom, and the outcome, so an interrupted request can never silently repeat an action.
Writes require your approval
Every action that changes something in a connected app is shown to you first and executes only when you approve it. In Runa’s chat the review card is the action; the model has no tool that writes without one. Two narrow exceptions exist only if you configure an automated routine yourself, and both are limited to destinations you chose: a routine can email its result to your own Runa account address, and can post its result to the Slack channel you configured for it. A routine may also create a draft in your connected mailbox where you set that as its delivery, and may prepare a folder-note edit for your review. Beyond these, routines cannot write to connected apps at all. You can pause, disable, or delete any routine and review what each run did.Credentials, disconnecting, and deletion
Server-side credentials are envelope-encrypted before they are written to the database — each record encrypted with its own key, and that key encrypted under a master key held in a separate system. Credentials are never returned to the client, never written to logs, and never shared between connectors. You can disconnect any app at Settings → Connectors, and revoke Runa’s access from the connected service’s own settings at any time. When you disconnect, Runa stops using the connection and asks the third party to revoke the credential where that provider offers a revocation endpoint; where none exists, deleting the stored credential is the revocation. Because connected content is never ingested, disconnecting leaves no copies of your mail, files, messages, or records in Runa’s index or memory — only the material listed above, which is deleted with the meeting or record it belongs to, or when you delete your account. Deleting your account deletes and, where supported, revokes the credential for every connected app. You are responsible for ensuring you are permitted to grant Runa the access you grant — particularly where a connector reads content of which Runa is not the intended recipient.8. Google User Data
Runa uses Google user data only to provide and improve the features you can see in the app. Nothing else — no advertising, no model training, no sale. When you connect a Google service, Runa receives Google user data. We use it only to provide and improve user-facing features that are prominent in the Runa application, and for no other purpose. This section controls over anything else in this Policy where the two could be read differently.What we access, and the feature each one exists for
Signing in asks for the basic profile and nothing else. Every other permission above is requested only at the moment you turn on the feature that needs it, and only from you.
Limited Use
Runa’s use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:- We use Google user data only to provide or improve user-facing features that are prominent in Runa’s interface — the features in the table above. We do not use it for any other purpose, and we do not use it to build features you have not enabled.
- We do not use Google user data — or anything derived from it — to develop, improve, or train generalized or non-personalized AI or machine-learning models, whether ours or anyone else’s. We hold our AI providers to the same rule: where a provider’s terms already bar training on customer content we rely on that, and where a provider offers a training opt-out we set it — per request where the API supports one, at the account level where it does not. Google user data is also excluded from any internal use of de-identified data described in How We Use Your Information.
- We serve no advertising of any kind, and we never use Google user data for advertising, ad targeting, ad measurement, or profiling.
- We do not sell Google user data, and we do not “share” it for cross-context behavioral advertising as those terms are defined under California law.
- We transfer Google user data only where necessary to provide or improve the features above — to the service providers that operate them for us, under contracts barring any other use — to comply with applicable law, or as part of a merger, acquisition, or sale of assets, and in that last case only after giving you notice and obtaining your explicit consent.
- No one at Runa reads your Google user data except with your affirmative agreement for the specific messages concerned, where necessary for security purposes such as investigating abuse or a reported vulnerability, to comply with applicable law, or where the data has been aggregated and anonymized and is used for internal operations.
How long we keep it, and how to end it
Gmail and Drive content is read at the moment a feature runs and then discarded. It is not copied into Runa’s search index, not turned into embeddings, and not added to cross-meeting memory. What persists is only what you asked Runa to produce — a draft awaiting your Send, a stored pre-meeting brief, the record of a write you approved — and each is deleted with the meeting or record it belongs to, or when you delete your account. Calendar details are treated differently, and we want to be precise about it. When you record a meeting, the event it came from — title, time, location, organiser, and the attendee list including email addresses — is stored as part of that meeting’s record and is deleted with it. That same summary is converted into a numeric embedding so the meeting is findable by search; the provider that performs that conversion is contractually barred from training on it or retaining it. Runa also keeps a rolling mirror of your upcoming week so features can see your schedule without holding a live connection open. Disconnecting your calendar deletes that mirror immediately, and deleting your account deletes all of it. You can disconnect Gmail and Google Drive at Settings → Connectors, and Google Calendar at Settings → Calendars. Disconnecting stops all access, asks Google to revoke the credential, and deletes the data derived from that connection. You can also revoke Runa’s access directly from your Google Account permissions page. Deleting your Runa account revokes every Google connection and deletes the stored credentials.9. Meeting Attendees Who Aren’t Runa Users
If you appear in someone’s Runa meeting, you have rights here too. When a Runa user records a meeting, attendees who are not Runa users may appear in calendar metadata and in the transcript — their name, email address from the invite, what they said, and, where the user names them, a voiceprint used to label them. To help the user prepare and recall, Runa may also generate a short professional profile of an attendee and locate a public profile photo. Our lawful basis is generally the legitimate interest of the Runa user, and Runa’s interest in providing the Service they requested, balanced against the non-user’s rights. Voice data is treated differently: because a voiceprint is biometric data, we do not rely on legitimate interest for it — the user who enrolls or names a non-user is responsible for obtaining that person’s consent first. We do not use non-user personal data for our own marketing, to build profiles for our own purposes, or for anything other than providing the Services to the user who recorded the meeting. If you are a meeting attendee and want to access, correct, or delete your personal data, or object to its processing, contact admin@joinruna.com with details of the meeting — date, time, organizer, your role — so we can find the record. Because we usually hold that data as part of a meeting record controlled by our user, we may need to refer you to them or their organization, or coordinate with them, to give effect to your request. We respond within the timelines applicable law requires.10. How We Share Your Information
With the vendors who run the Services, with the people and tools you choose, and where the law requires. Never with advertisers. We do not sell personal data, and we do not “share” it for cross-context behavioral advertising as those terms are defined under California law. We disclose it only as follows. Service providers and subprocessors. We engage vendors that process personal data on our behalf under written contracts limiting their use to providing services to us: cloud infrastructure and generative AI (Google Cloud Platform, Cloudflare), speech-to-text (AssemblyAI, Deepgram, ElevenLabs), web search (Google), payments (Stripe), identity providers for sign-in, email delivery, product analytics, error monitoring, support tooling, and security and fraud prevention. We require each to process data only as instructed, keep it confidential, secure it appropriately, comply with data protection law, permit audits, and sign Standard Contractual Clauses or an equivalent mechanism for international transfers. Our current subprocessor list is available at admin@joinruna.com; enterprise customers also receive it and notice of new subprocessors under their DPA. Parties you authorize. Teammates and workspace members you share a meeting, note, or output with; apps you connect; assistants you connect through MCP; organizations through which you access Runa, such as your employer on an enterprise plan; and anyone you choose to share Runa content with externally. Where organization features are enabled, a person or company Runa creates from your meetings — and the notes and facts attached to them — is by default visible to your organization so teammates who know them can see it; this is opt-out, and once you un-share an item it stays un-shared. Where you make a meeting visible to your organization or share it with a teammate, its content may surface to them through cross-meeting chat and search, and theirs to you; meetings you keep private are not shared this way. If you create a public share link for a meeting, anyone with that link can view it — attendees, summary, action items, and full transcript — and chat with it anonymously, without signing in, until you revoke the link. Organizational email disclosure. If you used an email address provisioned by an organization to create a personal account that organization does not manage, that organization may request, and we will disclose, the email address associated with your account. We will not transfer your other account information or its contents without your consent. Legal, safety, and compliance. We may disclose personal data where we believe in good faith it is necessary to comply with law, legal process, or a lawful request from a public authority; to enforce our Terms; to investigate fraud or security issues; or to protect the rights, property, or safety of Runa, our users, or others. Where lawful, we will notify the affected individual before disclosing personal data in response to a government request. Corporate transactions. In a financing, reorganization, merger, acquisition, or sale of assets, personal data may transfer to the counterparty or successor, subject to this Policy or a comparable one. We will give notice before personal data becomes subject to a different policy. Data received through Google APIs transfers in such a transaction only after we give you notice and obtain your explicit consent. Aggregated and de-identified data. We may share data that does not identify anyone for any lawful business purpose. We will not attempt to re-identify it, will not allow anyone else to, and commit to maintaining it as de-identified consistent with CCPA § 1798.140(m). Data received through Google APIs is excluded: we do not aggregate, de-identify, or share it for any purpose beyond providing and improving the features described in Google User Data.11. Cookies, Analytics, and Marketing
Essential, functional, and analytics cookies only. No advertising networks. Our Site and Services use cookies and similar technologies — pixel tags, web beacons, and scripts — in three kinds: essential (needed to authenticate you and deliver features you requested), functional (remembering your choices and settings), and performance/analytical (understanding how the Services are used so we can improve them). You can block or delete cookies through your browser settings, though doing so may affect functionality. We use product analytics and error-monitoring providers, which process data on our behalf and are prohibited from using it for their own purposes. We do not engage in cross-context behavioral advertising and do not allow advertising networks to collect personal data on the Site or in the Services. We do not respond to browser “Do Not Track” signals, but we honor Global Privacy Control signals where required by law. Under California Civil Code §§ 1798.83–1798.84, we do not knowingly disclose personal data to third parties for their direct-marketing purposes, and we do not offer financial incentives in exchange for the collection or sale of personal data. You can opt out of marketing emails using the unsubscribe link in any of them, or by contacting us. Opting out does not affect transactional messages, which are required for the Services.12. Security
Encrypted in transit and at rest, hosted in the U.S., with least-privilege access. We protect personal data with physical, technical, organizational, and administrative measures appropriate to its sensitivity. The Services run on Google Cloud Platform in the United States, with meeting audio stored on Cloudflare R2; certain AI inference may run on a provider’s global multi-region endpoint. Personal data is encrypted in transit using TLS 1.2 or higher and at rest using AES-256 with keys managed by our cloud providers. Certain sensitive data — including documents you upload and stored credentials for connected tools — is additionally encrypted by Runa at the application layer, using keys held separately from the data. Our program also includes network isolation, least-privilege access controls with multi-factor authentication for administrative access, audit logging, vulnerability management and periodic third-party penetration testing, hardened secrets management, backup and disaster recovery with restore testing, vendor security review, and personnel security including confidentiality obligations and training. If we become aware of a security incident affecting your personal data, we will notify you and the applicable authorities as required by law. Notifications to enterprise customers are governed by their DPA. You can help by using a strong, unique password, enabling multi-factor authentication, limiting access to your devices, and reviewing carefully what you share through connected services and what you approve from agent features. No method of transmitting or storing data is completely secure, and we cannot guarantee absolute security.13. Data Retention and Deletion
We keep data as long as we need it to serve you, and delete it when you tell us to. We retain personal data only as long as necessary to provide the Services and fulfill the purposes in this Policy, unless a longer period is required or permitted by law. The criteria we apply are the purpose of the processing, the sensitivity of the data, our legal obligations, and your reasonable expectations.
When you delete your account we delete or anonymize your personal data within 30 days, except where retention is required by law or necessary to assert or defend legal claims. Backups expire on a rolling basis under our backup retention schedule.
14. Your Rights and Choices
Controls in the app, plus the rights your local law gives you. We will not discriminate against you for exercising them.In the application
Delete a meeting from the meeting itself; delete your account at Settings → Profile → Delete Account; manage connected apps — including every Google connection — at Settings → Connectors; set how long audio, transcripts, and notes are kept at Settings → Data & privacy; pause or stop capture at any time during a meeting; unsubscribe from marketing email; and manage cookies in your browser. You can also revoke Runa’s access to your Google account at any time from your Google Account permissions page.U.S. state privacy rights
If you are a resident of California, Nevada, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Iowa, Delaware, New Hampshire, New Jersey, Minnesota, Maryland, Rhode Island, Indiana, Kentucky, or Tennessee, you may have the right to know what personal data we collect, the sources, the purposes, and the categories of third parties we disclose it to; to access and receive a portable copy; to correct inaccurate data; to delete data, subject to permitted exceptions; to opt out of sale, sharing, targeted advertising, and certain profiling; and to limit the use of sensitive personal information. Your specific rights depend on your state’s law, and you may have a right to appeal our decision on a request. We do not sell or share personal data, do not engage in targeted advertising, and do not profile in a way that produces legal or similarly significant effects. We honor Global Privacy Control and other recognized universal opt-out signals where required. For California residents, the disclosures in Information We Collect, How We Use Your Information, and How We Share Your Information cover the 12 months preceding this Policy; in that period we sold or shared no personal data, and we disclosed the categories listed there to the recipients described there for business purposes. Illinois (BIPA), Texas (CUBI), and Washington biometric laws. Runa creates and stores voiceprints treated as biometric identifiers under these laws. We maintain a publicly available written Biometric Data Retention & Destruction Schedule; we do not sell, lease, trade, or otherwise profit from biometric data; we use and disclose voice data only to provide the speaker-labeling features described above and to the providers that store it for us; and voice recognition is optional and deletable at any time. These laws generally require an individual’s informed written consent before their voiceprint is created — where you enroll, name, or recognize another person through Runa, obtaining that consent is your responsibility. Washington My Health My Data Act. We do not knowingly collect consumer health data. If it incidentally appears in a transcript, we treat it under the safeguards in this Policy and do not use it for any secondary purpose.EEA, UK, and Swiss rights
If you are in the EEA, UK, Switzerland, Liechtenstein, Norway, or Iceland, this section applies; if you are in Brazil, read references to the GDPR as the analogous provisions of the LGPD. Runa Labs Inc. is the controller of personal data processed through the direct Services. Where Runa acts as a processor for an enterprise customer, that customer is the controller. We will appoint EU and UK representatives under Article 27 where required; contact details are available at admin@joinruna.com. Our lawful bases under Article 6 are performance of a contract (to provide the Services — most categories of data in Information We Collect depend on this, and withholding them may make parts of the Services unavailable); legitimate interests (to operate, secure, and improve the Services, prevent fraud, market to business contacts, complete corporate transactions, and create de-identified data — you can object to this basis, and none of these bases are applied to data received through Google APIs beyond operating, securing, and improving the features you connected it for); consent (for optional features such as voice recognition and certain marketing, withdrawable at any time); legal obligation; and, rarely, vital interests. We intentionally process one special category of data under Article 9: the voiceprints described above. Our basis is your explicit consent under Article 9(2)(a), given by enabling voice recognition and withdrawable by disabling the feature and deleting the affected profiles. Where you create a voiceprint of another person, obtaining their explicit consent is your responsibility. Other special categories may only incidentally appear in a transcript; we do not seek out, infer, or use them. You have the right to access your personal data and obtain a copy; rectify it (note that transcripts cannot be modified after creation, though you can edit the summaries and notes generated from them); erase it; restrict processing; object to processing based on legitimate interests, absolutely so for direct marketing; port your data in a machine-readable format; withdraw consent; not be subject to solely automated decisions with legal or similarly significant effects; and lodge a complaint with your supervisory authority — the EDPB list for the EU, the ICO in the UK, and the FDPIC in Switzerland. For non-user attendees, personal data is collected from the organizer’s calendar and from audio captured by the Runa user, as described in Meeting Attendees Who Aren’t Runa Users.How to submit a request
Email admin@joinruna.com with the subject line “Privacy Request: [nature of request],” including enough information for us to verify your identity and find the records — typically your name, the email address associated with your account or the meeting, what you are asking for, and any relevant dates. You may also use the in-product controls above. We verify identity proportionately to the sensitivity of the data and the risk of unauthorized access, and will not use verification information for any other purpose. If we cannot verify you, we will say so and explain what we need. You may use an authorized agent, in which case we require written permission from you and verification of your identity with us directly, unless the agent holds a valid power of attorney. We respond within the timelines applicable law requires — typically 45 days for U.S. state requests, extendable by 45 days, and 30 days under the GDPR, extendable by 60 for complex requests. If we deny a request in whole or in part, you may appeal by replying with the subject line “Privacy Appeal,” and we will respond within 60 days or the period the law requires; if we deny the appeal we will explain why and tell you how to contact your supervisory authority or attorney general. If we hold your personal data on behalf of an enterprise customer, direct your request to that customer. If you send it to us, we will refer you to them where reasonable and notify them of your request.15. International Data Transfers
We operate from the United States and use approved transfer mechanisms to get data there. The Services are hosted and operated in the United States. By using them, you acknowledge that personal data is transferred to, stored, and processed in the United States and may be processed in other countries where Runa or its subprocessors operate, whose laws may differ from those where you live. Where required, we rely on lawful transfer mechanisms — the European Commission’s Standard Contractual Clauses for transfers from the EEA, the UK International Data Transfer Addendum for the UK, and the Swiss-recognized SCCs for Switzerland — together with supplementary technical, organizational, and contractual safeguards. Where the EU–U.S., UK, and Swiss data privacy frameworks apply, we may rely on the relevant adequacy decisions and self-certifications. A copy of the mechanism applicable to your data is available on request.16. Changes to This Policy
We will tell you when something material changes. We may update this Policy from time to time; the “Last updated” date at the top reflects the current version. We will notify you of material changes by posting the updated Policy at this URL, emailing the address associated with your account, or providing notice in the Runa application. If you continue using the Services after an update takes effect, you agree to it. If you do not agree, stop using the Services and exercise your rights as described above.17. Contact Us
Questions about this Policy or our privacy practices: Runa Labs Inc.Attn: Privacy
Email: admin@joinruna.com EEA, UK, and Swiss residents may also lodge a complaint with their local supervisory authority. Contact details for our EU/UK Article 27 representative are available on request.

