Legal
Privacy policy
Last updated 2026-06-01.
This policy explains what data Runnev processes when you use the service, why, and what rights you have over it. It is written to be read, not to be survived.
What we process
- Account data. Your email address, and, for paid plans, billing details handled by our payment processor. We do not store full card numbers.
- API keys. Stored hashed. We can show you a key's prefix and when it was last used, not its full value after creation.
- Event payloads. The batches you publish. These are opaque to us: in
rawmode we never parse them, and injsonmode we parse only enough to validate structure and count events. Payloads are retained only for the retention window you configure on each stream, then evicted. - Operational metadata. Request logs containing timestamps, method, path template, status, byte counts, a request id, and the calling key id. We use these to operate, debug, and bill the service. They do not contain event payload contents.
What we do not do
- We do not sell personal data.
- We do not read the contents of your event payloads for any purpose other than the
structural validation and counting described above, and not at all for
rawstreams. - We do not run third-party advertising or analytics trackers on this site. The usage analytics we keep are first-party and aggregate.
Subprocessors
We rely on a small number of infrastructure providers, described here by role. A current list with the specific providers is available on request to support@runnev.dev.
- A cloud infrastructure provider that hosts the compute and storage.
- A content delivery network that terminates TLS at the edge and routes requests.
- A payment processor for paid plans.
- An email provider for transactional email.
Retention and deletion
Event payloads are retained only for the per-stream window you set and are evicted after that. Operational logs are retained for 30 days and then deleted. Account data is retained while your account is active and for a short wind-down period after closure, after which it is deleted or anonymized. You can request deletion of your account and associated data at any time.
Your rights
Depending on where you live, you may have rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing. To exercise any of these, email support@runnev.dev from the address on your account and we will respond within the timeframe the applicable law requires.
Security
Data is encrypted in transit with TLS. API keys are stored hashed. To report a vulnerability, see /.well-known/security.txt. We are working toward SOC 2 and will state plainly when we have completed it.
Changes
We will update the date at the top of this page when this policy changes and, for material changes, notify account holders by email.
Contact
Questions about this policy go to support@runnev.dev.