R
Runic
/
Privacy Policy
Back to Runic

Privacy Policy

Last updated: 11 July 2026 · Written for GDPR and KVKK (Turkish Law No. 6698)

What we collect

Account data: your name, email address and a salted hash of your password (never the password itself). Content: the documents you write, their version snapshots, your AI chat history (stored so the assistant can refer back to it), the share/embed links you create, team memberships and pending team invites, and the names/usage timestamps of any API (MCP) tokens you create. Billing: subscription status; card details are handled entirely by Stripe and never touch our servers. Technical: standard server logs (IP address, timestamps) kept briefly for security, including login-attempt limits.

Why we process it

To provide the service you signed up for (contract), to secure accounts and prevent abuse (legitimate interest), and to send strictly transactional email — verification, password reset — (contract). We don't sell personal data and we don't send marketing email without separate consent.

AI features

Some features are powered by Anthropic (Claude): the AI chat, AI edits and suggestions, flow generation, imports from screenshots or Mermaid, and the Build package. Only when you use one of these features, the relevant document text and your prompt are sent to Anthropic's API to produce the result. Under Anthropic's commercial API terms this data is not used to train their models. If you never invoke an AI feature, your documents are never sent to Anthropic. Connections you create yourself (personal MCP tokens) let your own AI tools read and edit your documents — those tokens are shown once, stored only as hashes, and revocable at any time.

Processors we use

Vercel (hosting), Turso (database), Resend (transactional email), Anthropic (AI features, only when invoked), and Stripe (payments, once billing is enabled). Each receives only what it needs to perform its function. Fonts are self-hosted — pages make no requests to Google or other third-party CDNs.

Business customers (DPA)

If you use Runic for your organisation (including Teams), we act as your processor for the content your team stores, and this policy's processor list doubles as your sub-processor list. A signable Data Processing Agreement incorporating the EU Standard Contractual Clauses is available on request from info@odeontech.com — we'll countersign and return it. We notify business customers before adding a new sub-processor.

Retention and deletion

Your data is kept while your account exists. Deleting your account (account menu → delete, confirmed with your password) permanently removes your profile, documents, versions and share links. Backups expire on their own schedule shortly after.

Your rights — everywhere

Regardless of where you live, you can: access everything we hold about you (account menu → "Download my data" gives you a machine-readable export instantly), correct your details, delete your account and all data (account menu → delete), and take your data with you (the same export, plus the text Export button). For anything else, contact info@odeontech.com — we respond within 30 days.

Region-specific notes

EU & UK (GDPR / UK GDPR): the legal bases above apply; you additionally have the rights to restrict or object to processing and to lodge a complaint with your supervisory authority (any EU DPA, or the ICO in the UK). We do not carry out automated decision-making with legal effects. Our processors (Vercel, Turso, Resend, Anthropic, Stripe) operate in the United States, so personal data is transferred outside the EEA/UK. These transfers rely on the EU-U.S. Data Privacy Framework where the processor is certified, and on Standard Contractual Clauses otherwise.

United States (incl. CCPA/CPRA — California): we do not sell or share personal information for cross-context behavioural advertising, so there is nothing to opt out of. California residents may exercise the rights to know, delete and correct via the in-app tools or the email above, without discrimination for doing so.

Canada (PIPEDA): we collect, use and disclose personal information only with consent and for the purposes described here; you may withdraw consent by deleting your account, and you may challenge our compliance with the Office of the Privacy Commissioner of Canada.

Japan (APPI): we state the purpose of use above and use personal information only within it; we do not provide personal data to third parties except the processors listed (equivalent to entrustment under the APPI) and we honour disclosure, correction and cessation-of-use requests via the tools and email above.

Türkiye (KVKK): all Law No. 6698 data-subject rights apply; complaints may be lodged with the Kişisel Verileri Koruma Kurumu. Transfers abroad (the US-based processors above) take place under KVKK Art. 9 on the basis of your explicit consent given at signup and, where applicable, the Board's adequacy/undertaking mechanisms.

Security & breach notification

Passwords are stored only as salted scrypt hashes; sessions use httpOnly cookies; access to production data is restricted; reset and verification links are single-use and expire. If a breach is likely to result in a risk to you, we will notify you and the relevant authority without undue delay (within 72 hours where GDPR applies).

Children

Runic is not directed at children. You must be at least 16 to create an account (or the age of digital consent in your country, if higher).

Cookies

One httpOnly session cookie keeps you signed in — strictly necessary, so no consent banner is required. No advertising, analytics or cross-site tracking cookies, and no third-party scripts. Editor preferences (layout widths, export style and similar) live in your browser's localStorage and never leave your device. See the full Cookie Policy.