Legal
Privacy Policy
Last updated 9 September 2026
Who operates Runnable
Runnable is operated by Authaz Tecnologia da Informação LTDA., with its registered office at Rua Pais Leme 215, Conj. 1713, São Paulo–SP 05424-150, Brazil.
Privacy questions and data-rights requests can be sent to privacy@runnable.cloud.
The short version
You pay Runnable to run your CI. Your development activity is not an advertising asset and not a training corpus.
We process customer content only to provide, secure, support, and bill the service. We never sell it, never use it for advertising or competitive analysis, and never use it to train or improve AI models — ours or anyone else's. This applies on every plan, with no opt-out required.
What we process
Account data. Your identity is handled by Authaz: an account identifier, email address, organization membership, and role. We do not store passwords.
Repository metadata. Repository names, owners, default branches, installation identifiers, provider coordinates, and the commit references we were asked to build.
Workflow content. The workflow files we are asked to parse, and the immutable execution plans derived from them.
Source code, transiently by default. Each job fetches the requested commit onto one clean, single-use machine. That machine is destroyed when the job ends and its disk does not persist. If you explicitly enable Runnable's workspace-handoff extension, the selected job workspace is stored as a private internal artifact for one day so a dependent job can restore it.
Job output. Logs, customer artifacts, and opt-in internal workspace snapshots your workflows produce, stored as immutable objects in a private bucket. Secret values are masked from logs before storage; arbitrary files written into a workspace snapshot are not content-inspected or rewritten.
Secrets and variables you choose to store, encrypted as described below.
Integration data. For Slack notifications, the workspace and selected channel identifiers and names, plus the encrypted channel credential Slack issues during installation.
Usage and billing data. Normalized minute counts, job and run records, plan and subscription state. Payment card details are handled by Stripe and never reach Runnable.
Operational data. Request logs, error traces, and audit events recording who did what in your organization.
Compatibility checker submissions. The checker requires no account. Workflow source is processed transiently and never retained. We store a de-identified summary containing fixed feature categories, compatibility and diagnostic codes, recognized public actions and major versions, runner-size categories, job count, the recommended plan, estimated monthly minutes, a workflow-size range, and a broad acquisition channel. We do not store workflow, job, or step names; commands; environment values; paths; repository identifiers; arbitrary action coordinates; or the workflow itself. If you choose to give us an email address so we can send you the report, we store that address alongside the workflow name, compatibility state, job count, recommended plan, and minute estimate.
How it is protected
Each organization has its own versioned workspace encryption key. Each secret receives a fresh data key wrapped by that workspace key, with the organization, repository, environment, and name forming the authenticated encryption context. Root key material is held outside the database.
Jobs receive only a job-scoped, short-lived credential. Database, Git provider, payment, storage, and infrastructure credentials never enter the job environment. Fork pull requests receive no customer secrets at any scope.
Jobs can reach public internet destinations required by customer workflows, while provider-enforced rules block private, loopback, link-local, carrier-grade NAT, and cloud-metadata networks. Every tenant-owned record carries an organization identifier that is combined with the resource identifier on every customer query.
How long we keep it
Logs and artifacts follow the retention window of your plan — from 7 days on Hobby through custom Enterprise retention — after which they are purged.
Run, job, and usage records are retained while your account is active, because they are the basis of your invoices.
Secrets are retained until you delete them or the organization is deleted.
Slack operational records — terminal notification attempts, terminal Slack queue items, and minimal signed-event receipts — are retained for 90 days by default, then removed by a bounded daily lifecycle job. Disconnecting Slack immediately deletes that organization's channel credential and delivery history.
Source code exists only on the ephemeral machine for the duration of a job by default. An explicitly enabled workspace-handoff snapshot is retained for one day, hidden from customer artifact listings, and then purged.
Derived compatibility summaries are retained for 24 months, then deleted. They are not linked to an account, email address, repository, network identifier, or the separate rate-limit counters.
Checker email addresses are kept until you ask us to remove them. They are stored separately from derived compatibility summaries, not merged into customer records, not sold, and not used for any mailing you did not ask for.
When an organization is deleted, we delete its content and retain only what we are required to keep for tax, accounting, and fraud-prevention purposes.
Who else touches it
We use a small number of subprocessors, each for a specific and limited purpose:
Vercel — application hosting and the isolated machines that execute jobs.
Stripe — subscription billing and payment processing.
GitHub — repository access, event delivery, and status reporting for GitHub-connected repositories.
Entire — repository access for Entire mirrors and Entire-native repositories.
Authaz — authentication and session management.
Slack — delivery of build notifications to a workspace and channel you explicitly connect.
Managed Postgres and object storage providers — the database and the private bucket holding logs and artifacts.
We will publish material changes to this list before they take effect.
Your choices
You can export or delete secrets, variables, repositories, and connected integrations at any time from the dashboard, and delete your organization entirely.
You can set retention-relevant controls — spend caps, allowance behaviour, and budget alerts — yourself.
Depending on where you live you may have rights to access, correct, export, or delete personal data we hold about you. Contact us and we will action it.
International transfers
Runnable operates in regions selected for the service. Where data crosses borders we rely on appropriate safeguards with our subprocessors. If regional residency matters to your team, contact us before you subscribe — it is a reasonable question and we would rather answer it up front.
Changes and contact
If we change this policy in a way that materially affects how customer content is handled, we will say so before it takes effect rather than quietly updating the date.
Questions, requests, or security reports: privacy@runnable.cloud.

