Privacy Policy
DRAFT — pending legal review. Placeholders are marked with [BRACKETS].
Effective date: [SET BEFORE PUBLISHING]
This Privacy Policy explains how RAW DEVOPS LTDA (CNPJ 51.460.107/0001-53, registered address [FULL REGISTERED ADDRESS]) — "Runtz", "we", "us" — processes personal data when you use the Runtz platform, the runtz.dev website and related services.
We act as the data controller for the personal data described here. For Scan Data processed in the Cloud Service on behalf of your organization, we act as a processor/operator and your organization is the controller.
Self-hosted note: if you run a Self-Hosted Deployment, your scan data and account data stay in your own infrastructure. We only receive the licensing telemetry described in Section 1.4.
1. Data We Collect
1.1 Account data
Name, email address, username, hashed password (for password login), and workspace membership. If you sign in with Google or GitHub, we receive your name, email and account identifier from the provider — we never receive your password.
1.2 Billing data
Plan, subscription status and billing events. Payments are processed by Stripe; we do not store full card numbers. Stripe processes your payment data as described in its own privacy policy.
1.3 Scan Data (Cloud Service)
Data submitted by the CLI/scanners: dependency and package inventories, findings, vulnerability matches, project names, hostnames, container image names, Kubernetes resource metadata and related technical information. Scan Data may incidentally contain personal data present in your systems (e.g., a hostname with a person's name); avoid submitting unnecessary personal data.
1.4 Self-hosted licensing telemetry
Self-Hosted Deployments with paid plans contact our central engine to activate and periodically validate licenses ("heartbeat"). This includes the license identifier, installation identifier, plan and validation status. It does not include your Scan Data.
1.5 Technical data
Logs (IP address, user agent, timestamps, request metadata), and strictly necessary cookies/local storage for authentication and session state. We do not use advertising cookies.
1.6 Communications
Messages you send us (support, security reports) and transactional emails we send via Resend (e.g., sign-in codes and invitations).
2. Why We Process Data (Legal Bases — LGPD art. 7)
| Purpose | Legal basis |
|---|---|
| Providing the Services (accounts, scans, dashboards) | Performance of contract |
| Billing and license management | Performance of contract; legal obligation |
| Security, fraud and abuse prevention, audit logs | Legitimate interest; legal obligation |
| Transactional email (codes, invites, billing notices) | Performance of contract |
| Service improvement with aggregated, de-identified data | Legitimate interest |
| Marketing communications (if any) | Consent (opt-in, revocable) |
3. Sharing and Processors
We do not sell personal data. We share data only with processors needed to run the Services:
- Stripe — payments and subscription management
- Resend — transactional email
- Google — optional sign-in (OAuth)
- GitHub — optional sign-in (OAuth)
- Cloudflare — network, DNS and traffic protection
- Cloud/hosting infrastructure providers used to operate the Cloud Service
We may also disclose data if required by law or competent authority, and in a merger/acquisition context under equivalent safeguards.
4. International Transfers
Some processors listed above process data outside Brazil (e.g., in the United States). Transfers rely on the safeguards of LGPD arts. 33–36 (e.g., contractual clauses with processors) and, for EEA/UK users, on GDPR mechanisms such as Standard Contractual Clauses.
5. Retention
- Account data: for the life of the account and up to 5 years after closure where needed for legal defense and obligations.
- Billing records: as required by Brazilian tax law (at least 5 years).
- Scan Data (Cloud Service): while your workspace is active; deleted or anonymized within 30 days after account termination, except where law requires longer.
- Logs: up to 12 months, unless needed for an ongoing security investigation.
6. Your Rights
6.1 LGPD (Brazil)
You may request: confirmation of processing, access, correction, anonymization or deletion, portability, information about sharing, and review of automated decisions, and you may revoke consent (LGPD art. 18). Contact: [email protected]. You may also complain to the ANPD (Autoridade Nacional de Proteção de Dados).
6.2 GDPR (EEA/UK users)
You have equivalent rights of access, rectification, erasure, restriction, portability and objection, and the right to lodge a complaint with your supervisory authority.
6.3 US users
Depending on your state (e.g., California), you may have rights to know, delete and correct personal information and to opt out of "sales" or "sharing" — we do not sell or share personal information as defined by the CCPA/CPRA.
We respond to verified requests within the timelines required by applicable law.
7. Security
We apply technical and organizational measures appropriate to a security product, including encryption in transit (TLS), hashed passwords, scoped API keys, secret-management practices and access controls. No system is 100% secure; report vulnerabilities to [email protected] (see our Security Policy).
8. Children
The Services are not directed to children under 18, and we do not knowingly process their data.
9. Changes
We will post updates on this page and, for material changes, notify you by email or in-app notice at least 15 days before they take effect.
10. Contact / DPO
- Privacy requests: [email protected]
- Data Protection Officer (Encarregado, LGPD art. 41): [NAME], [email protected]
RAW DEVOPS LTDA · CNPJ 51.460.107/0001-53 · Copyright © 2026 Runtz. All rights reserved.