Privacy Policy
How RunPR handles account information, client workspace content, AI requests, measurement and aggregate research.
1. Who we are and what this policy covers
Embargo Industries operates RunPR. This policy describes how we handle information through our website and services. Contact jeff@runpr.ai.
For account administration, billing, security and our own website operations, we determine how information is used. When an organization uses RunPR to process information about its clients or contacts, we also act on that organization’s instructions and applicable agreements. The organization may have its own privacy obligations and notices.
2. Information we process
We receive information from you, your organization’s authorized users, connected services, public sources and activity within RunPR.
- Account and organization information, such as name, email address, sign-in identifiers, membership, role and client-account settings.
- Workspace content, such as client websites and briefs, company and voice profiles, writing samples, contact imports, research instructions, drafts, approvals and reports.
- Communications information, such as sender and recipient details, messages sent through RunPR, connected replies and provider-reported delivery, bounce and engagement events.
- Research and AI visibility information, such as public-source material, scan questions, model responses, citation links, engine labels and usage records.
- Billing information, such as subscription status, purchased allowances and payment-provider identifiers. Payment-card entry is handled by our payment provider rather than in RunPR briefs or prompts.
- Technical and usage information, such as network and device information, logs, errors, feature activity and optional measurement data described below.
3. How we use information
We use information to provide requested features, authenticate users, manage organization access, process payments, prepare research and drafts, send authorized messages, support customers, diagnose problems, protect the service and comply with applicable obligations.
We may analyze service performance to improve reliability and product behavior. External publication of research is subject to the separate safeguards below. We do not treat a subscription as permission to publish a named customer story or private workspace material.
4. AI, research and service providers
A requested AI or research feature may send relevant prompts, client context, public-source text or draft content to a provider. Outputs and source links can then be stored in your workspace for review and later comparison. You should not put secrets or highly sensitive personal information into those inputs.
Depending on the feature, RunPR uses services including Clerk for identity, Stripe for payments, Resend for email, Vercel and Cloudflare for infrastructure and artifact handling and OpenAI, Anthropic, Google, xAI, Exa and Perplexity for AI or research. We also use a hosted database and may use other providers performing the same kinds of operational functions.
Providers receive information relevant to their functions and process it under applicable arrangements and their service terms. Their retention and processing practices vary by service and configuration. This policy does not represent that every provider keeps no data or that a provider’s consumer-app policy governs its API service.
6. Cookies and optional page measurement
Necessary cookies and similar storage support sign-in, security, organization selection and requested settings. These functions are distinct from optional website measurement.
Our optional analytics control governs optional first-party acquisition measurement and Google Analytics. Optional measurement is off until you allow it. The control respects supported browser privacy signals. You can change your choice using the optional analytics control in the site footer.
RunPR’s optional first-party measurement stores selected RunPR page paths for up to 30 days and can connect those visits with workspace creation and product activity. It does not collect URL query strings or browsing history on other websites through that feature. This 30-day browser window is not a promise that every resulting server-side record is erased after 30 days.
If enabled, Google Analytics processes usage and technical information to help us understand site use. Advertising personalization signals are disabled in our configuration. Turning measurement off prevents future optional measurement in that browser; it does not automatically delete previously collected provider data. Your choice is browser-specific.
Email delivery and engagement records are separate from website measurement. Email providers may report delivery, opens or clicks where configured. These signals can be incomplete or affected by recipient privacy software and are not proof that a person read a message.
7. De-identified and aggregate research
Where authorized by applicable agreements and law, we may combine service activity and results into de-identified research, benchmarks or statistical findings. For example, we may report citation patterns across a group of AI scans without identifying the customers whose scans contributed.
We will not publish customer or client identities, private prompts, unpublished drafts, private correspondence or identifiable account-level findings under a general aggregate-research permission. Named case studies and attributable quotes require separate permission.
Before publication we review the information for confidentiality and re-identification risk. We remove identifying detail, avoid identifying small groups and do not attempt to re-identify information prepared for anonymous research. An output is not treated as anonymous just because names have been removed.
This policy does not itself establish retroactive permission for new uses of previously collected information. We will assess the governing agreements, applicable law and any required consent before that use. Information that is irreversibly anonymized may no longer be linkable to an account or removable through an account-specific request.
8. Retention and deletion
We retain information for the time reasonably needed to provide the service and for purposes such as security, billing, legal obligations, disputes and legitimate operational records. Retention depends on the type of information, customer instructions and applicable provider arrangements. We do not apply one universal retention period to every record.
Archiving a client or canceling a subscription does not immediately erase historical drafts, communications, reports or research. Contact jeff@runpr.ai to request deletion or information about retained records. We will verify authority, assess applicable requirements and explain relevant limitations. Backups and records that must be preserved may follow separate removal schedules.
9. Your choices and requests
You can manage available profile and workspace settings, restrict integrations you control and change optional page measurement through the footer. Workspace administrators can manage authorized users and client access.
Depending on your location and the information involved, you may have rights to request access, correction, deletion, portability or restriction, object to certain processing or withdraw consent. Contact jeff@runpr.ai to make a request. We may need to verify your identity or authority without asking for unnecessary sensitive information.
If your information was supplied by a RunPR customer, that organization may be the appropriate party to respond. We will assist as required by the applicable relationship and law. Where applicable, you may also contact your privacy regulator or request review of a decision about your request. We will not unlawfully discriminate against you for exercising privacy rights.
10. Security and processing locations
We use access controls and other safeguards appropriate to operating the service. No system can guarantee absolute security. Protect your credentials and contact us if you suspect unauthorized access.
Our providers may process information in the United States and other locations. Applicable transfer requirements and safeguards depend on the service and relationship. Contact us if you need information about a particular processing arrangement or a data-processing agreement.
11. Children
RunPR is intended for business users age 18 and older, not children. If you believe a child has supplied personal information to RunPR, contact us so we can assess and address it.
12. Changes and contact
We will update the version and effective date when this policy changes. For material changes we will provide appropriate notice and seek consent when required. We will not rely on a quiet policy update to override earlier privacy commitments.
Questions and requests: jeff@runpr.ai.