Legal

Privacy Policy

Effective September 4, 2026

In short. Openrun runs AI agents that do operational work for your company: research, drafting, publishing, and email handling. To do that we store your account, the work inside your workspace, and encrypted credentials for accounts you choose to connect. We never sell personal data, we do not use your content to train AI models, and Google user data is handled under Google's Limited Use requirements. You can disconnect any account or delete your workspace at any time.

01Who this policy covers

This Privacy Policy explains how Openrun AI ("Openrun", "we", "us") collects, uses, shares, and protects information in connection with the Openrun web application at openrunai.com, our APIs, the AI agents we operate on your behalf, published workspace sites, and related services (together, the "Service").

It applies to three groups of people:

  • Customers and workspace members who create an account, join a workspace, and direct the agents.
  • Audience members who subscribe to a newsletter or visit a site that a customer publishes through Openrun. For this data the customer is the controller and we act as their processor (see Audience and subscriber data).
  • Visitors to openrunai.com who do not hold an account.

Our Terms of Service govern use of the Service. Capitalized terms not defined here have the meaning given there.

02Information we collect

Information you provide

  • Account details. Name, email address, and profile image, collected through our authentication provider (Clerk) when you sign up with email or a Google account.
  • Workspace details. Workspace name and slug, your role, members you invite, the company context, tone and source preferences you configure, and approval settings.
  • Work content. Tasks and instructions you give the agents, chat messages, files, screenshots, and URLs you upload or reference, drafts, edits, approvals, and the outputs the agents produce.
  • Billing details. Plan, invoices, credit balance, and payment status. Card details are entered directly with Stripe and never touch our servers.
  • Communications. Anything you send us by email or through the product.

Information from accounts you connect

When you connect a third-party account, we receive an access token and, where the provider supports it, a refresh token, plus the profile identifiers needed to show which account is connected. What the agents can then read or write is described in Connected accounts.

Information collected automatically

  • Run and audit logs. Each agent run records its steps, tool calls, model usage, cost, timing, approvals, and errors so you can inspect what was done and we can operate the Service reliably.
  • Technical data. IP address, browser and device type, referring page, and timestamps, held in server logs by our hosting providers.
  • Essential cookies. Session and authentication state only. See Cookies.

Public information the agents gather

To complete tasks, agents retrieve publicly available content such as web pages, articles, public posts, video transcripts, and company information from the sources you point them at or from web search. This content may include names and statements of public figures. We process it only to produce the work you asked for and we do not build profiles of individuals from it.

03Connected accounts

Integrations are optional and are enabled per workspace by an owner or admin. We request the narrowest scopes each platform offers for the feature, we store tokens encrypted at rest with AES-256-GCM, and we use them only to carry out the actions listed below on your instruction. Disconnecting an integration deletes the stored tokens.

PlatformWhat we accessWhat the agents do with it
X (Twitter)Profile identity; read and write posts; upload media; offline access.Publish approved posts, threads, images, and videos from your account; read public posts you ask the agents to research.
LinkedInOpenID profile and email; post to your member feed. Organization posting only if you opt in.Publish approved posts and media to your feed or, if enabled, to a company page you administer.
Google (Gmail)OpenID profile and email; read Gmail messages; modify Gmail (labels, archive, drafts).Read inbox threads to triage them, create reply drafts for your approval, send approved drafts, and apply labels or archive. See the Google section below.
Other platformsAs described in the connection screen at the time you connect.Only the actions shown in that screen. We update this table as integrations ship.

Your use of each platform remains subject to that platform's own terms and privacy policy. You can also revokeOpenrun's access from the platform's own security settings at any time.

04Google user data

If you connect a Google account, Openrun requests the Gmail scopes listed above so that our email agent can triage your inbox and prepare responses for you. Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • We use Gmail data only to provide and improve the user-facing email features you have enabled: reading and summarizing threads, drafting replies, sending drafts you have approved, and organizing messages.
  • We do not transfer Gmail data to third parties except as necessary to provide those features (for example, sending message content to our AI model provider to draft a reply), to comply with law, or as part of a merger or acquisition with notice to you.
  • We do not use Gmail data for advertising, and we do not sell it.
  • We do not use Gmail data to develop, improve, or train generalized AI or machine-learning models. Our model providers are contractually prohibited from training on it as well.
  • No human at Openrun reads your Gmail data unless you ask us to for support, it is required for security or legal reasons, or the data has been aggregated and de-identified.

Message content is held only as long as needed to complete the run and to show you the resulting drafts and audit trail in your workspace. Disconnecting Google deletes your tokens immediately. You can also revoke access at myaccount.google.com/permissions.

05How we use information

  • To provide, operate, secure, and support the Service and the agents you direct.
  • To carry out the specific actions you request, including publishing and sending on your behalf after approval.
  • To keep an auditable record of what each agent did, and to let you review, correct, and roll back that work.
  • To bill you, manage credits and plans, and prevent fraud or abuse.
  • To send transactional messages such as approval requests, run results, invites, and billing notices, and occasional product updates you can opt out of.
  • To improve the Service, using aggregated or de-identified usage data. We do not use your content or outputs to train AI models, and we do not permit our providers to do so.
  • To comply with law and enforce our Terms.

Where the GDPR or UK GDPR applies, we rely on performance of a contract for the core Service, legitimate interests for security, logging, and product improvement, consent for optional integrations and marketing, and legal obligation where required.

06AI processing

The agents are powered by large language and speech models operated by third-party providers, currently Anthropic and OpenAI for text and reasoning, and Groq and AssemblyAI for transcription and speaker identification. To complete a task we send them the relevant context: your instructions, workspace context, source material, and, for the email agent, the message threads being handled. We use these providers under commercial terms that prohibit training on your data and that limit retention to what is needed for abuse monitoring.

AI outputs can be wrong. The Service is designed so that a human in your workspace reviews and approves consequential actions before they are taken, and every run is logged so you can see the sources and reasoning behind an output.

07How we share information

We do not sell personal data and we do not share it for cross-context behavioral advertising. We share it only:

  • With your workspace. Members of a workspace can see the tasks, drafts, runs, and connected accounts of that workspace according to their role.
  • With platforms, on your instruction. When an approved post is published or an approved email is sent, that content goes to the platform you connected.
  • With service providers that process data for us under contract, listed below.
  • For legal reasons when required by law, subpoena, or to protect the rights, safety, or property ofOpenrun, our users, or the public.
  • In a business transfer such as a merger, acquisition, or asset sale, in which case we will notify you before your data becomes subject to a different policy.

Service providers

ProviderPurpose
ClerkAuthentication and account management
StripePayments, subscriptions, and credit purchases
Vercel and RailwayApplication hosting and background job processing
Managed PostgreSQL and RedisPrimary database and job queue
S3-compatible object storageUploaded files, generated images, video clips, and rendered artifacts
Anthropic, OpenAILanguage model inference for agent reasoning and drafting
Groq, AssemblyAIAudio transcription and speaker identification
Firecrawl, Brave SearchFetching and searching public web content requested by agents
ResendTransactional email and newsletter delivery

08Audience and subscriber data

Customers can publish newsletters and sites through Openrun and collect email subscribers. For those subscribers, the customer decides what is collected and how it is used; Openrun processes the data only on the customer's behalf and under their instructions.

  • We collect the subscriber's email address, the time of subscription, and the source page.
  • Every message sent through the Service includes a working unsubscribe link, and unsubscribes take effect immediately.
  • We do not use subscriber lists for our own marketing, and we never share one customer's list with another.

If you are a subscriber and want to access, correct, or delete your data, contact the publisher directly, or write to us at g@guillermoflor.com and we will forward your request and assist.

09Retention and deletion

  • Account and workspace data is kept while your account is active. Deleting a workspace (Settings → General, owner only) permanently removes its tasks, drafts, runs, connected-account tokens, and subscriber lists.
  • Connected-account tokens are deleted the moment you disconnect the integration.
  • Run logs and outputs are retained as part of your workspace history so you can audit past work, and are deleted with the workspace.
  • Backups roll off within 30 days of deletion.
  • Billing records are kept as long as tax and accounting law requires.
  • Server logs containing IP addresses are retained for up to 90 days for security purposes.

To delete your account entirely, email g@guillermoflor.com from the address on the account. We complete deletion within 30 days and confirm by email, except where retention is required by law.

10Security

All traffic is encrypted in transit with TLS. Connected-account credentials are encrypted at rest with AES-256-GCM using keys held outside the database. Access to production systems is restricted to authorized personnel. Agents run with per-workspace permissions and cannot reach another workspace's data. Consequential actions require a human approval step by default.

No system is perfectly secure. If we learn of a breach affecting your personal data we will notify you and the relevant authorities as required by law. Please report suspected vulnerabilities to g@guillermoflor.com.

11Your rights and choices

Depending on where you live, you may have the right to:

  • Access the personal data we hold about you and receive a copy in a portable format.
  • Correct inaccurate data.
  • Delete your data, subject to the exceptions above.
  • Object to or restrict certain processing, and withdraw consent where processing is based on consent.
  • Opt out of marketing email using the link in any message or by contacting us.
  • Lodge a complaint with your local data protection authority.

California residents have the rights described above under the CCPA/CPRA. We do not sell or share personal information as those terms are defined there, and we do not discriminate against anyone who exercises their rights.

To exercise any right, email g@guillermoflor.com. We may need to verify your identity. We respond within 30 days, or sooner where the law requires.

12International transfers

We are operated from and store data in the United States, and our providers may process data in other countries. Where data about people in the EEA, UK, or Switzerland is transferred outside those regions we rely on Standard Contractual Clauses or an equivalent lawful mechanism with each provider.

13Cookies

We use only the cookies needed to keep you signed in and to protect against request forgery. We do not run advertising cookies, cross-site tracking, or third-party analytics on the application. Blocking cookies in your browser will prevent sign-in.

14Children

The Service is for businesses and is not directed at anyone under 18. We do not knowingly collect data from children. If you believe a child has provided us data, contact us and we will delete it.

15Changes to this policy

We will post any update here with a new effective date. For material changes we will also notify workspace owners by email or with a notice in the product before the change takes effect.

16Contact

Openrun AI
Privacy and data requests: g@guillermoflor.com