
Privacy policy
Last updated: May 2026
Privacy Policy
Last updated: August 25, 2026
Runa Labs Inc. ("Runa," "we," "us") provides AI meeting intelligence for the agent-era company. This Privacy Policy explains what personal data we collect, how we use and share it, the choices you have, and the rights you can exercise. By using the Services, you accept the practices described below.
Your use of Runa is at all times subject to our Terms of Service, which incorporates this Privacy Policy. Undefined terms have the meanings given in the Terms.
At a Glance
Before the details, the commitments that matter most:
Bot-free capture, on your device. Runa does not send a bot to join your meeting. The app captures audio from your microphone and, where you enable it, your computer's system audio — which includes other participants' voices. That audio is uploaded securely to produce your transcript, and you control how long it is kept (Settings → Data & privacy).
Nobody trains AI models on your content. Our cloud, model, and speech-to-text providers are contractually prohibited from using your content to train their models, and Runa does not train its own models on it either.
Google data is used only to run the features you turned on. What Runa reads from Google Calendar, Gmail, Google Drive, and your Google contacts is used only to provide and improve features you can see in the app — never for advertising, never to train AI models, never sold. See Google User Data.
We do not sell your personal data, and we do not "share" it for cross-context behavioral advertising as those terms are defined under California law.
Connected apps read live, and writes need your approval. You choose which apps Runa can reach. Runa reads them at the moment a feature runs and does not copy their contents into its search index or cross-meeting memory. Anything that changes a connected app is shown to you first and executes only when you approve it.
We create voiceprints to label who said what — and you control them. Voice recognition is optional, voiceprints are treated as biometric identifiers under some laws, and we publish a Biometric Data Retention & Destruction Schedule. If you record or name other people, see your responsibilities in Recording, Transcription, and Consent.
AI outputs are reviewed by a human — you. Runa does not make solely automated decisions that produce legal or similarly significant effects about you.
You can delete your data and account at any time. Settings → Profile → Delete Account. We delete or anonymize within 30 days, subject to legal retention.
1. Scope of This Policy
This Policy covers the personal data Runa handles as a business. Where we handle data on an organization's behalf, that organization is in charge of it.
Runa Labs Inc. is a Delaware corporation. This Policy applies to personal data we collect when you visit joinruna.com, install or use the Runa application, connect a third-party service to Runa, contact us, or receive communications from us.
It does not apply to third-party services we do not control — including any service you connect to Runa, which has its own privacy policy — or to personal data we process on behalf of an enterprise customer under a Data Processing Agreement ("DPA"). In that case the customer is the controller, Runa is the processor, and you should direct privacy requests to your organization first. If we cannot act on a request because we are a processor, we will tell you and, where reasonable, refer you to the controller.
"Personal data" means information that identifies, relates to, or could reasonably be linked with a particular individual. "De-identified data" means data processed so that it can no longer reasonably be linked to anyone.
2. Information We Collect
We collect what you give us, what the Services generate from your meetings, and what your device and usage tell us.
The table below lists the categories of personal data we collect, and may have collected in the 12 months preceding the date of this Policy. The third parties named in the last column are described in How We Share Your Information.
CategoryExamplesCategories of Third PartiesProfile or Contact DataName, username, email address, profile photo, phone number if providedService Providers; Parties You AuthorizePayment DataCard brand, last 4 digits, billing address and email. Full card numbers are held by our payment processor (Stripe, Inc.), not by RunaService ProvidersDevice and Usage DataIP address and approximate location, device and operating system details, application version, audio device identifiers, pages and features used, session duration, performance and crash dataService ProvidersProfessional DataJob title, role, employer, company domain, professional websiteService Providers; Parties You AuthorizeCalendar and Meeting MetadataMeeting titles, descriptions, times, attendees, organizer, location, and recurrence, for calendars you connectService Providers; Parties You AuthorizeRecordings and TranscriptsAudio captured by the Runa app from your microphone and, where you enable it, your system audio, and the transcripts generated from itService Providers (cloud storage, speech-to-text, AI models); Parties You AuthorizeVoice and Biometric DataVoiceprints — numeric representations of voice characteristics, treated as biometric identifiers under some laws — used to label and recognize speakers. See Voice Recognition and Biometric DataService Providers; Parties You AuthorizeMeeting MemorySummaries, notes, action items, decisions, entities, topics, embeddings, and cross-meeting context Runa generates from your transcriptsService Providers; Parties You AuthorizeAgent Action DataAgent-suggested actions, your approvals or rejections, the resulting outputs, and audit logs of agent activityService Providers; Parties You AuthorizeWorkspace and Sharing DataWhat you share with teammates, and the permissions, comments, and reactions attached to itService Providers; Parties You Authorize (including teammates)Integration DataData Runa reads from — and, where you grant it, writes to — an app you connect, within the permissions you grant. See Connected AppsService Providers; Parties You AuthorizeCommunications with RunaSupport tickets, sales inquiries, survey responses, feedback, and anything you volunteer in themService ProvidersInferencesInferences drawn from the above to power features such as topic clustering, open-loop detection, and suggested follow-ups. Not used for advertising and not soldService Providers
Sensitive Personal Information
Some of what we collect qualifies as sensitive personal information under California and analogous state laws:
Account credentials — your Runa password and the access tokens you authorize. Stored encrypted, used only to authenticate you.
Contents of communications where Runa is not the intended recipient — meeting invites on a calendar you connect and, where you enable the relevant connector, messages in a connected mailbox or chat workspace, notes in connected CRM and project tools, and the contents of files you hand Runa. Read only within the permissions you grant, only to provide features you enabled, and only when the feature runs.
Biometric information, in the form of voiceprints. This is the only special category we collect intentionally.
Precise geolocation is not collected; we use approximate IP-based location only. Racial or ethnic origin, religious beliefs, union membership, genetic data, health, sex life, sexual orientation, and immigration status are not intentionally collected. Such information may incidentally appear in a transcript if a participant discusses it; we do not analyze transcripts to infer these characteristics and do not use them for any secondary purpose.
We use sensitive personal information only for purposes permitted under California Civil Code § 1798.121 and analogous laws — to provide the Services you request, ensure security, prevent fraud, and comply with law. Other than using voiceprints to label speakers, we do not use it to infer characteristics about you. You can limit our use of it — see Your Rights and Choices.
Where It Comes From
We collect personal data directly from you (when you create an account, configure the app, or contact us); automatically from your use of the Services (telemetry, diagnostic logs, cookies, IP-based location); from services you connect (calendars, work tools, and identity providers you set up yourself at Settings → Connectors); and, for business-to-business outreach, fraud prevention, and security, from vendors and public sources.
Attendees who are not Runa users may also appear in calendar metadata and transcripts — see Meeting Attendees Who Aren't Runa Users.
Children's Data
The Services are not directed to children, and we do not knowingly collect personal data from anyone under 16. If we learn that we have, we will delete it as quickly as possible. If you believe a child under 16 has provided us personal data, contact admin@joinruna.com.
3. How We Use Your Information
To run the Services you asked for, keep them secure, bill you, and improve them.
We use personal data to:
Provide the Services — create and manage your account, detect meetings on your connected calendar, capture audio, produce transcripts, and generate summaries, action items, decisions, and cross-meeting memory.
Power search, answers, and agent features — search across your meetings, detect conflicts, suggest follow-ups, and draft messages or prepare updates in connected systems for your approval.
Personalize and support — tailor the Services to your preferences and usage, answer your questions, diagnose problems, and improve reliability.
Bill and administer accounts — process subscriptions, charges, and refunds through our payment processor, and send transactional notices about your account, security, and billing. These are required for the Services and are not subject to marketing opt-out.
Communicate — send newsletters, product updates, and announcements, which you can unsubscribe from at any time.
Secure and comply — prevent, detect, and investigate fraud, abuse, and security incidents; enforce our Terms; and comply with law, legal process, and lawful requests from public authorities.
Operate the business — internal analytics and planning, and corporate transactions such as financing, merger, or sale of assets.
Research and improve — measure quality, diagnose failures, and evaluate the models behind Runa's features. Third-party AI providers are never permitted to train on your personal data, and Runa does not train its own models on it: the datasets our features are evaluated against are fabricated, not drawn from customer content. If we ever introduce internal training on de-identified data, we will tell you before it begins and give you a way to opt out — and data received through Google APIs is permanently excluded from it, as described in Google User Data.
Data we receive through Google APIs is held to a narrower standard than the rest of this list: it is used only to provide and improve the user-facing features described in Google User Data, and never for advertising, marketing, internal analytics and planning, or model development.
In the EEA, UK, and Switzerland, our lawful bases for each of these purposes are set out in Your Rights and Choices.
We will not collect new categories of personal data, or use what we have for materially different and incompatible purposes, without notice and, where required, your consent.
4. Recording, Transcription, and Consent
Recording laws vary. You are responsible for the consents your meetings require; Runa gives you the controls to honor them.
Runa captures your microphone and, where you enable it, your computer's system audio — which includes the voices of other participants — and may create voiceprints of participants you name. Recording or transcribing a conversation, and creating a voiceprint of someone, may require notice to or consent from some or all participants:
Recording and wiretap laws. Some U.S. states — including California, Connecticut, Delaware, Florida, Illinois, Maryland, Massachusetts, Montana, New Hampshire, Oregon, Pennsylvania, and Washington — generally require all-party consent to record a private conversation. Others require only one party. Many countries have their own rules.
Biometric privacy laws. Illinois (BIPA), Texas (CUBI), Washington, and the GDPR generally require notice and consent before an individual's voiceprint is created.
You are responsible for complying with these laws when you use Runa — obtaining any required consents before capturing audio, providing required notices at the start of a meeting, obtaining written consent from anyone whose voiceprint you cause to be created, and honoring requests from participants to stop capture or delete a transcript or voiceprint. Accepting this Policy or the Terms yourself does not provide consent on another person's behalf.
Runa supports you in this by showing a clear indicator when capture is active, letting you pause or stop capture at any time, letting you delete a meeting or transcript, and providing a process for any participant — including non-users — to request access, correction, or deletion.
If you deploy Runa to a workforce, you are responsible for establishing a lawful basis and for any required employee notices or works-council consultations.
5. Voice Recognition and Biometric Data
Runa creates voiceprints so it can label who said what. The feature is optional, you can delete them, and we publish a destruction schedule.
To label speakers and recognize the same person across meetings, Runa creates voice profiles ("voiceprints") — numeric summaries of voice characteristics. These are treated as biometric identifiers under BIPA, CUBI, and Washington law, and as special-category biometric data under the GDPR.
How they are created. Your own voiceprint is created only if you choose to set up voice recognition, from a short enrollment recording you make in the app. Voiceprints of other people are created when you label a speaker in a transcript so Runa can recognize them later; the people you name may include individuals who are not Runa users.
Where voice data lives. Raw enrollment recordings and voice-matching samples stay on your device. A single aggregate profile per person — one numeric summary — is stored on Runa's servers, encrypted at rest and scoped to your account, so labeling is consistent across your devices.
How it is used. Only to label who is speaking and recognize them in your future meetings. We never use voice data for advertising, never sell or otherwise profit from it, and never use it to train foundation models.
Sharing. If voice-signature sharing is enabled for your workspace, your own profile — and only your own, never anyone else's — may be published to organizations you belong to, so colleagues' copies of Runa can suggest you as a speaker. A published signature includes your name, email, and profile, and is only ever a suggestion a colleague must confirm. Organization-wide sharing of your own profile is on by default and you can turn it off in Settings, which deletes the published copy immediately. Sharing with individual contacts is off by default.
Your choices, and your responsibilities. You can decline enrollment, decline to name speakers, delete any person's voice profile, disable sharing, and delete your account at any time. Where you enroll or name another person, you are responsible for the notice and written consent that biometric privacy laws require before their voiceprint is created.
Retention and destruction. We retain and destroy voice data under our published Biometric Data Retention & Destruction Schedule. In summary: unconfirmed samples on your device expire automatically; a person's profile is destroyed when you delete them from speaker memory, delete the source meeting, or delete your account; and turning off sharing deletes any published copy immediately.
To ask what voice data we hold about you, or to have it deleted, contact admin@joinruna.com.
6. AI Processing and Automated Decisions
AI generates your transcripts, summaries, and drafts. No provider trains on your content, and nothing decides anything about you on its own.
Runa uses AI to transcribe audio; to generate summaries, action items, decisions, and structured notes; to build the embeddings behind cross-meeting memory and search; to flag potential conflicts between statements across meetings; and to read a connected app live in order to ground an answer, a brief, or a draft.
We rely on third-party providers for this — Google Cloud (Vertex AI) for generative AI, Cloudflare Workers AI for embeddings, and AssemblyAI, Deepgram, and ElevenLabs for speech-to-text. Where a feature searches the public web, your query and relevant context are sent to Google Search; web search is on by default for cross-meeting chat and in-meeting questions, off by default for automated routines, and can be turned off. Our agreements with all of these providers prohibit them from using your content to train their own models, and inputs are processed under enterprise terms with no retention or short-window retention for abuse monitoring only. Providers may change over time; our current subprocessor list is available on request.
Automated decision-making. Runa does not make solely automated decisions that produce legal or similarly significant effects about you. AI outputs are presented for your review, and you can edit, override, or discard them. Where Runa executes an action in a connected system, that action results from your approval. You have the right to obtain human review of any AI output and to challenge it — contact admin@joinruna.com.
Transparency and the EU AI Act. Runa identifies AI-generated content as such in the application, and will provide additional disclosures where the EU AI Act or other law requires. Runa is designed as a general-purpose AI application, not a high-risk AI system under Annex III, and we do not market it for evaluating employees. If you intend a use that could be high-risk, you are responsible for compliance and must not present AI outputs as authoritative decisions without human review.
7. Connected Apps
You choose which apps Runa can reach. It reads them live rather than copying them, and nothing gets written without your approval.
You can connect third-party services to Runa using OAuth, and you set up and remove every connection yourself at Settings → Connectors. Runa requests only the permissions a connector needs and accesses data only within what you grant. The connectors available change over time and can depend on your plan and on the third party's own review; Settings → Connectors always shows what is available to you and what you have connected.
Today they fall into three groups:
Calendars (Google and Microsoft) — read-only. Runa detects your meetings, reads event and attendee details, and resolves names and profile photos for the people you meet. It cannot create, change, or delete anything on your calendar. Calendar credentials are stored on your device rather than on Runa's servers.
Work tools — mail, CRM, project and issue tracking, knowledge bases, file storage, time tracking, and team chat. Most can read; several can also write, always subject to your approval.
AI assistants — Runa's Model Context Protocol ("MCP") connector lets an assistant you authorize, such as ChatGPT or Claude, read from Runa. This direction is read-only: an assistant connected this way cannot change anything in Runa or in an app you connected to Runa. Access is decided by the scopes you consented to and re-checked on every call, is bounded by what you can already see in Runa, retains nothing extra, and is filtered and audited. Review or revoke each assistant at Settings → Connectors.
Work toolWhat Runa can readWhat Runa can writeSalesforceAccounts, contacts, opportunities, and fields the connected user can already seeUpdate an opportunity, create a contact, log a meeting, add a noteHubSpotContacts, companies, deals, owners, and the portal's property schema; tickets and custom objects where the portal grants themCreate or update a record, add a note, create a task, log an activitySlackChannels the Runa app can see, messages in a channel you attach to a Runa folder, messages that mention Runa, direct messages you send it — plus message search that runs under the account of the person who connected SlackPost a message in a channel you selectedGmail and Microsoft OutlookYour mail, searched and read to give context for a brief, an answer, or a follow-upCreate a draft; send it when you click Send; create an event on your own calendarBasecampProjects, to-dos, assignments, messages, Campfire lines, people, and schedulesCreate a to-do list or to-do, complete a to-do, post a message, add a commentLinearTeams, projects, cycles, issues, and comments in the workspace you authorizedCreate or update an issue, add a commentNotionPages, databases, comments, and people — only within what you select on Notion's authorization screenCreate or update a page, add a commentGoogle DriveOnly the files and folders you hand Runa in Google's picker when you connect, and what is inside a folder you pickedNothing. Read-only end to endHarvestProjects and tasks assigned to you, and your own recent and running time entriesLog time, start or stop a timer, update an entry's notes
Four points worth stating plainly:
Runa never sends email on its own initiative. Everything Runa composes is created as a draft in your own mailbox and waits there. A message leaves only when you click Send yourself. No automated routine and no background job can reach a send path, and Runa's chat can only propose a message.
Google Drive is read-only and per-file. Runa cannot create, edit, move, share, or delete anything in your Drive, and cannot list, search, or open the files you did not pick. We deliberately do not request access to every file your account can open.
Every connector acts as the account you connected, so that service's own permissions apply unchanged — Runa cannot see anything there that you cannot. Several are narrower still: Drive is limited to files you pick, Notion to pages you select, HubSpot to the object types it is granted. Slack is mixed — reading and posting happen as the Runa app in your workspace, while message search runs as the account of the person who connected it, and so can reach channels and direct messages Runa was never invited to.
Google data is held to stricter rules than anything else here. Runa's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google User Data states that commitment in full, and it controls over anything else in this Policy.
Connected data is read live, not indexed
When you ask a question or a feature runs, Runa calls the connected app with your stored credential, uses the result, and discards it. Data read from a connected app is not added to Runa's search index, not turned into embeddings, and not incorporated into cross-meeting memory. Attaching a source to a Runa folder records a pointer to it, not a copy. What Runa does store is limited to:
The connection itself — the encrypted credential and non-content metadata such as the account name, granted permissions, and status.
Anything you asked Runa to prepare — a draft, a proposed CRM update, a proposed task — held while it awaits approval and afterwards as a record of what you approved.
Derived content a feature produces — most notably a pre-meeting brief that may summarize recent correspondence with attendees. The brief is stored with the meeting; the underlying messages are not.
A ledger of writes — what was sent where, when, by whom, and the outcome, so an interrupted request can never silently repeat an action.
Content read from a connected app is sent to our AI providers to produce the answer or draft you asked for, on the same no-training terms that apply to everything else.
Writes require your approval
Every action that changes something in a connected app is shown to you first and executes only when you approve it. In Runa's chat the review card is the action; the model has no tool that writes without one.
Two narrow exceptions exist only if you configure an automated routine yourself, and both are limited to destinations you chose: a routine can email its result to your own Runa account address, and can post its result to the Slack channel you configured for it. A routine may also create a draft in your connected mailbox where you set that as its delivery, and may prepare a folder-note edit for your review. Beyond these, routines cannot write to connected apps at all. You can pause, disable, or delete any routine and review what each run did.
Credentials, disconnecting, and deletion
Server-side credentials are envelope-encrypted before they are written to the database — each record encrypted with its own key, and that key encrypted under a master key held in a separate system. Credentials are never returned to the client, never written to logs, and never shared between connectors.
You can disconnect any app at Settings → Connectors, and revoke Runa's access from the connected service's own settings at any time. When you disconnect, Runa stops using the connection and asks the third party to revoke the credential where that provider offers a revocation endpoint; where none exists, deleting the stored credential is the revocation. Because connected content is never ingested, disconnecting leaves no copies of your mail, files, messages, or records in Runa's index or memory — only the material listed above, which is deleted with the meeting or record it belongs to, or when you delete your account. Deleting your account deletes and, where supported, revokes the credential for every connected app.
You are responsible for ensuring you are permitted to grant Runa the access you grant — particularly where a connector reads content of which Runa is not the intended recipient.
8. Google User Data
Runa uses Google user data only to provide and improve the features you can see in the app. Nothing else — no advertising, no model training, no sale.
When you connect a Google service, Runa receives Google user data. We use it only to provide and improve user-facing features that are prominent in the Runa application, and for no other purpose. This section controls over anything else in this Policy where the two could be read differently.
What we access, and the feature each one exists for
Google dataThe user-facing feature it powersYour Google account's basic profile — name, email address, profile pictureSigning you in and identifying your account. This is all "Continue with Google" asks forGoogle Calendar, read-onlyDetecting your meetings so Runa can offer to record them, showing your upcoming schedule, and attaching a meeting's title, time, and attendees to its transcript and notes. The calendar connection cannot create, change, or delete anythingGoogle Contacts and your Workspace directory, read-onlyResolving the name, role, and profile photo of the people in your meetings, so attendee lists and speaker labels show a person instead of an email addressGmail — read, and create draftsSearching and reading your mail to ground a pre-meeting brief, a follow-up, or an answer you asked for, and composing a reply as a draft in your own mailbox. Runa never sends mail: a message leaves only when you press Send yourselfCalendar events you own — create and updatePutting an event on your calendar from a proposal you approved on a confirmation card. Runa never notifies attendees; you send the invite from Google Calendar. Nothing is created without your approvalGoogle Drive — read-only, and only files you pickReading the specific files and folders you hand Runa in Google's own picker, so they can inform an answer or a brief. Runa cannot list, search, or open anything you did not pick, and cannot create, edit, move, share, or delete anything in your Drive
Signing in asks for the basic profile and nothing else. Every other permission above is requested only at the moment you turn on the feature that needs it, and only from you.
Limited Use
Runa's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically:
We use Google user data only to provide or improve user-facing features that are prominent in Runa's interface — the features in the table above. We do not use it for any other purpose, and we do not use it to build features you have not enabled.
We do not use Google user data — or anything derived from it — to develop, improve, or train generalized or non-personalized AI or machine-learning models, whether ours or anyone else's. Our AI providers are contractually prohibited from training on it, and it is excluded from any internal use of de-identified data described in How We Use Your Information.
We serve no advertising of any kind, and we never use Google user data for advertising, ad targeting, ad measurement, or profiling.
We do not sell Google user data, and we do not "share" it for cross-context behavioral advertising as those terms are defined under California law.
We transfer Google user data only where necessary to provide or improve the features above — to the service providers that operate them for us, under contracts barring any other use — to comply with applicable law, or as part of a merger, acquisition, or sale of assets, and in that last case only after giving you notice and obtaining your explicit consent.
No one at Runa reads your Google user data except with your affirmative agreement for the specific messages concerned, where necessary for security purposes such as investigating abuse or a reported vulnerability, to comply with applicable law, or where the data has been aggregated and anonymized and is used for internal operations.
How long we keep it, and how to end it
Gmail and Drive content is read at the moment a feature runs and then discarded. It is not copied into Runa's search index, not turned into embeddings, and not added to cross-meeting memory. What persists is only what you asked Runa to produce — a draft awaiting your Send, a stored pre-meeting brief, the record of a write you approved — and each is deleted with the meeting or record it belongs to, or when you delete your account. Calendar and contact details are kept as part of the meeting record they describe and are deleted with it.
You can disconnect any Google service at Settings → Connectors, which stops all access and asks Google to revoke the credential. You can also revoke Runa's access directly from your Google Account permissions page. Deleting your Runa account revokes every Google connection and deletes the stored credentials.
9. Meeting Attendees Who Aren't Runa Users
If you appear in someone's Runa meeting, you have rights here too.
When a Runa user records a meeting, attendees who are not Runa users may appear in calendar metadata and in the transcript — their name, email address from the invite, what they said, and, where the user names them, a voiceprint used to label them. To help the user prepare and recall, Runa may also generate a short professional profile of an attendee and locate a public profile photo.
Our lawful basis is generally the legitimate interest of the Runa user, and Runa's interest in providing the Service they requested, balanced against the non-user's rights. Voice data is treated differently: because a voiceprint is biometric data, we do not rely on legitimate interest for it — the user who enrolls or names a non-user is responsible for obtaining that person's consent first.
We do not use non-user personal data for our own marketing, to build profiles for our own purposes, or for anything other than providing the Services to the user who recorded the meeting.
If you are a meeting attendee and want to access, correct, or delete your personal data, or object to its processing, contact admin@joinruna.com with details of the meeting — date, time, organizer, your role — so we can find the record. Because we usually hold that data as part of a meeting record controlled by our user, we may need to refer you to them or their organization, or coordinate with them, to give effect to your request. We respond within the timelines applicable law requires.
10. How We Share Your Information
With the vendors who run the Services, with the people and tools you choose, and where the law requires. Never with advertisers.
We do not sell personal data, and we do not "share" it for cross-context behavioral advertising as those terms are defined under California law. We disclose it only as follows.
Service providers and subprocessors. We engage vendors that process personal data on our behalf under written contracts limiting their use to providing services to us: cloud infrastructure and generative AI (Google Cloud Platform, Cloudflare), speech-to-text (AssemblyAI, Deepgram, ElevenLabs), web search (Google), payments (Stripe), identity providers for sign-in, email delivery, product analytics, error monitoring, support tooling, and security and fraud prevention. We require each to process data only as instructed, keep it confidential, secure it appropriately, comply with data protection law, permit audits, and sign Standard Contractual Clauses or an equivalent mechanism for international transfers. Our current subprocessor list is available at admin@joinruna.com; enterprise customers also receive it and notice of new subprocessors under their DPA.
Parties you authorize. Teammates and workspace members you share a meeting, note, or output with; apps you connect; assistants you connect through MCP; organizations through which you access Runa, such as your employer on an enterprise plan; and anyone you choose to share Runa content with externally. Where organization features are enabled, a person or company Runa creates from your meetings — and the notes and facts attached to them — is by default visible to your organization so teammates who know them can see it; this is opt-out, and once you un-share an item it stays un-shared. Where you make a meeting visible to your organization or share it with a teammate, its content may surface to them through cross-meeting chat and search, and theirs to you; meetings you keep private are not shared this way. If you create a public share link for a meeting, anyone with that link can view it — attendees, summary, action items, and full transcript — and chat with it anonymously, without signing in, until you revoke the link.
Organizational email disclosure. If you used an email address provisioned by an organization to create a personal account that organization does not manage, that organization may request, and we will disclose, the email address associated with your account. We will not transfer your other account information or its contents without your consent.
Legal, safety, and compliance. We may disclose personal data where we believe in good faith it is necessary to comply with law, legal process, or a lawful request from a public authority; to enforce our Terms; to investigate fraud or security issues; or to protect the rights, property, or safety of Runa, our users, or others. Where lawful, we will notify the affected individual before disclosing personal data in response to a government request.
Corporate transactions. In a financing, reorganization, merger, acquisition, or sale of assets, personal data may transfer to the counterparty or successor, subject to this Policy or a comparable one. We will give notice before personal data becomes subject to a different policy. Data received through Google APIs transfers in such a transaction only after we give you notice and obtain your explicit consent.
Aggregated and de-identified data. We may share data that does not identify anyone for any lawful business purpose. We will not attempt to re-identify it, will not allow anyone else to, and commit to maintaining it as de-identified consistent with CCPA § 1798.140(m). Data received through Google APIs is excluded: we do not aggregate, de-identify, or share it for any purpose beyond providing and improving the features described in Google User Data.
11. Cookies, Analytics, and Marketing
Essential, functional, and analytics cookies only. No advertising networks.
Our Site and Services use cookies and similar technologies — pixel tags, web beacons, and scripts — in three kinds: essential (needed to authenticate you and deliver features you requested), functional (remembering your choices and settings), and performance/analytical (understanding how the Services are used so we can improve them). You can block or delete cookies through your browser settings, though doing so may affect functionality.
We use product analytics and error-monitoring providers, which process data on our behalf and are prohibited from using it for their own purposes. We do not engage in cross-context behavioral advertising and do not allow advertising networks to collect personal data on the Site or in the Services. We do not respond to browser "Do Not Track" signals, but we honor Global Privacy Control signals where required by law. Under California Civil Code §§ 1798.83–1798.84, we do not knowingly disclose personal data to third parties for their direct-marketing purposes, and we do not offer financial incentives in exchange for the collection or sale of personal data.
You can opt out of marketing emails using the unsubscribe link in any of them, or by contacting us. Opting out does not affect transactional messages, which are required for the Services.
12. Security
Encrypted in transit and at rest, hosted in the U.S., with least-privilege access.
We protect personal data with physical, technical, organizational, and administrative measures appropriate to its sensitivity. The Services run on Google Cloud Platform in the United States, with meeting audio stored on Cloudflare R2; certain AI inference may run on a provider's global multi-region endpoint. Personal data is encrypted in transit using TLS 1.2 or higher and at rest using AES-256 with keys managed by our cloud providers. Certain sensitive data — including documents you upload and stored credentials for connected tools — is additionally encrypted by Runa at the application layer, using keys held separately from the data.
Our program also includes network isolation, least-privilege access controls with multi-factor authentication for administrative access, audit logging, vulnerability management and periodic third-party penetration testing, hardened secrets management, backup and disaster recovery with restore testing, vendor security review, and personnel security including confidentiality obligations and training.
If we become aware of a security incident affecting your personal data, we will notify you and the applicable authorities as required by law. Notifications to enterprise customers are governed by their DPA.
You can help by using a strong, unique password, enabling multi-factor authentication, limiting access to your devices, and reviewing carefully what you share through connected services and what you approve from agent features. No method of transmitting or storing data is completely secure, and we cannot guarantee absolute security.
13. Data Retention and Deletion
We keep data as long as we need it to serve you, and delete it when you tell us to.
We retain personal data only as long as necessary to provide the Services and fulfill the purposes in this Policy, unless a longer period is required or permitted by law. The criteria we apply are the purpose of the processing, the sensitivity of the data, our legal obligations, and your reasonable expectations.
CategoryRetentionMeeting audioUnder your Audio retention setting (Settings → Data & privacy). By default kept until you delete the meeting or your account; you can set automatic deletion as short as 24 hoursTranscripts, summaries, notes, meeting memoryLife of your account, or until you delete the meeting or a retention window you set expiresVoiceprintsPer our Biometric Data Retention & Destruction Schedule — destroyed when you delete the person, the source meeting, or your accountContent read from a connected appNot retained. Fetched live and discarded; what persists is limited to items you asked Runa to prepare, derived content in a stored brief, and the write ledgerConnected-app credentialsWhile the connection exists. Deleted when you disconnect or delete your account, and revoked with the provider where one offers revocationProfile and account dataLife of account, plus up to 3 years to bring or defend legal claims and meet tax and audit obligationsPayment dataUp to 7 years for tax, audit, and accounting purposesTelemetry and diagnostic logs12 to 24 months, then deleted or anonymizedSecurity and audit logsUp to 24 months, longer where required for investigation or legal holdSupport communications3 years after resolutionMarketing dataUntil you opt out, plus a suppression period to honor the opt-out
When you delete your account we delete or anonymize your personal data within 30 days, except where retention is required by law or necessary to assert or defend legal claims. Backups expire on a rolling basis under our backup retention schedule.
14. Your Rights and Choices
Controls in the app, plus the rights your local law gives you. We will not discriminate against you for exercising them.
In the application
Delete a meeting from the meeting itself; delete your account at Settings → Profile → Delete Account; manage connected apps — including every Google connection — at Settings → Connectors; set how long audio, transcripts, and notes are kept at Settings → Data & privacy; pause or stop capture at any time during a meeting; unsubscribe from marketing email; and manage cookies in your browser. You can also revoke Runa's access to your Google account at any time from your Google Account permissions page.
U.S. state privacy rights
If you are a resident of California, Nevada, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Iowa, Delaware, New Hampshire, New Jersey, Minnesota, Maryland, Rhode Island, Indiana, Kentucky, or Tennessee, you may have the right to know what personal data we collect, the sources, the purposes, and the categories of third parties we disclose it to; to access and receive a portable copy; to correct inaccurate data; to delete data, subject to permitted exceptions; to opt out of sale, sharing, targeted advertising, and certain profiling; and to limit the use of sensitive personal information. Your specific rights depend on your state's law, and you may have a right to appeal our decision on a request.
We do not sell or share personal data, do not engage in targeted advertising, and do not profile in a way that produces legal or similarly significant effects. We honor Global Privacy Control and other recognized universal opt-out signals where required. For California residents, the disclosures in Information We Collect, How We Use Your Information, and How We Share Your Information cover the 12 months preceding this Policy; in that period we sold or shared no personal data, and we disclosed the categories listed there to the recipients described there for business purposes.
Illinois (BIPA), Texas (CUBI), and Washington biometric laws. Runa creates and stores voiceprints treated as biometric identifiers under these laws. We maintain a publicly available written Biometric Data Retention & Destruction Schedule; we do not sell, lease, trade, or otherwise profit from biometric data; we use and disclose voice data only to provide the speaker-labeling features described above and to the providers that store it for us; and voice recognition is optional and deletable at any time. These laws generally require an individual's informed written consent before their voiceprint is created — where you enroll, name, or recognize another person through Runa, obtaining that consent is your responsibility.
Washington My Health My Data Act. We do not knowingly collect consumer health data. If it incidentally appears in a transcript, we treat it under the safeguards in this Policy and do not use it for any secondary purpose.
EEA, UK, and Swiss rights
If you are in the EEA, UK, Switzerland, Liechtenstein, Norway, or Iceland, this section applies; if you are in Brazil, read references to the GDPR as the analogous provisions of the LGPD.
Runa Labs Inc. is the controller of personal data processed through the direct Services. Where Runa acts as a processor for an enterprise customer, that customer is the controller. We will appoint EU and UK representatives under Article 27 where required; contact details are available at admin@joinruna.com.
Our lawful bases under Article 6 are performance of a contract (to provide the Services — most categories of data in Information We Collect depend on this, and withholding them may make parts of the Services unavailable); legitimate interests (to operate, secure, and improve the Services, prevent fraud, market to business contacts, complete corporate transactions, and create de-identified data — you can object to this basis, and none of these bases are applied to data received through Google APIs beyond operating, securing, and improving the features you connected it for); consent (for optional features such as voice recognition and certain marketing, withdrawable at any time); legal obligation; and, rarely, vital interests.
We intentionally process one special category of data under Article 9: the voiceprints described above. Our basis is your explicit consent under Article 9(2)(a), given by enabling voice recognition and withdrawable by disabling the feature and deleting the affected profiles. Where you create a voiceprint of another person, obtaining their explicit consent is your responsibility. Other special categories may only incidentally appear in a transcript; we do not seek out, infer, or use them.
You have the right to access your personal data and obtain a copy; rectify it (note that transcripts cannot be modified after creation, though you can edit the summaries and notes generated from them); erase it; restrict processing; object to processing based on legitimate interests, absolutely so for direct marketing; port your data in a machine-readable format; withdraw consent; not be subject to solely automated decisions with legal or similarly significant effects; and lodge a complaint with your supervisory authority — the EDPB list for the EU, the ICO in the UK, and the FDPIC in Switzerland.
For non-user attendees, personal data is collected from the organizer's calendar and from audio captured by the Runa user, as described in Meeting Attendees Who Aren't Runa Users.
How to submit a request
Email admin@joinruna.com with the subject line "Privacy Request: [nature of request]," including enough information for us to verify your identity and find the records — typically your name, the email address associated with your account or the meeting, what you are asking for, and any relevant dates. You may also use the in-product controls above.
We verify identity proportionately to the sensitivity of the data and the risk of unauthorized access, and will not use verification information for any other purpose. If we cannot verify you, we will say so and explain what we need. You may use an authorized agent, in which case we require written permission from you and verification of your identity with us directly, unless the agent holds a valid power of attorney.
We respond within the timelines applicable law requires — typically 45 days for U.S. state requests, extendable by 45 days, and 30 days under the GDPR, extendable by 60 for complex requests. If we deny a request in whole or in part, you may appeal by replying with the subject line "Privacy Appeal," and we will respond within 60 days or the period the law requires; if we deny the appeal we will explain why and tell you how to contact your supervisory authority or attorney general.
If we hold your personal data on behalf of an enterprise customer, direct your request to that customer. If you send it to us, we will refer you to them where reasonable and notify them of your request.
15. International Data Transfers
We operate from the United States and use approved transfer mechanisms to get data there.
The Services are hosted and operated in the United States. By using them, you acknowledge that personal data is transferred to, stored, and processed in the United States and may be processed in other countries where Runa or its subprocessors operate, whose laws may differ from those where you live.
Where required, we rely on lawful transfer mechanisms — the European Commission's Standard Contractual Clauses for transfers from the EEA, the UK International Data Transfer Addendum for the UK, and the Swiss-recognized SCCs for Switzerland — together with supplementary technical, organizational, and contractual safeguards. Where the EU–U.S., UK, and Swiss data privacy frameworks apply, we may rely on the relevant adequacy decisions and self-certifications. A copy of the mechanism applicable to your data is available on request.
16. Changes to This Policy
We will tell you when something material changes.
We may update this Policy from time to time; the "Last updated" date at the top reflects the current version. We will notify you of material changes by posting the updated Policy at this URL, emailing the address associated with your account, or providing notice in the Runa application. If you continue using the Services after an update takes effect, you agree to it. If you do not agree, stop using the Services and exercise your rights as described above.
17. Contact Us
Questions about this Policy or our privacy practices:
Runa Labs Inc.
Attn: Privacy
Email: admin@joinruna.com
EEA, UK, and Swiss residents may also lodge a complaint with their local supervisory authority. Contact details for our EU/UK Article 27 representative are available on request.