Legal
Privacy policy
What the hosted control plane stores, what stays on your box, and how to ask us about your data.
Last updated August 30, 2026
1. Introduction
This Privacy Policy explains how cloudrun (“we”, “our”, or “us”) collects, uses, shares, and protects personal information when you use the hosted control plane at www.cloudrun-ai.com and related sign-in, billing, and support surfaces (the “Service”).
It does not govern a copy you run yourself. If you self-host cloudrun, you are the operator of that instance and decide how it handles data. See the self-hosting guide.
Using the Service is also subject to our Terms of Service. Questions: hello@useopenbrain.dev.
2. Who this covers
This policy applies to people who visit the public site, create an account, join an organization, pay for deployments, or contact us. cloudrun is built for organizations. If you use it through an employer, that organization may have additional rules, and we process your account data to provide the Service to them.
3. Control plane and boxes
cloudrun is a control plane, not the place your agents think. We provision an isolated machine (“box”) per project, configure the runtime, and store what we need to reach that box. Skills, channels, automations, memory, and transcripts live on the box.
To operate a deployment we keep identifiers and credentials the control plane uses to talk to the runtime (for example a box id, public URL, and dashboard session material). Anything you connect an agent to — mail, issue trackers, docs — is accessed by that agent through the connector you authorize, not scraped into a marketing database.
4. Information we collect
Account and organization
When you sign in we receive, and store in our database:
- Email address, name, and profile image, as provided by you or your sign-in provider
- A stable authentication id from our identity provider
- Organization name, slug, membership, roles, and invitations (including invitee emails)
Projects and deployments
- Project names, slugs, descriptions, and images you set
- Engine kind and name, and the metadata needed to reach the box (id, URL, runtime credentials)
- API keys you create in the product: we store a hash and a prefix, not the secret in cleartext
- Profile templates you save, including visibility (private, organization, or public) and the template payload
Billing
Payment cards are handled by Polar. We store Polar customer and subscription ids, subscription status, and seat quantity (which follows the number of running deployments). We do not store full card numbers.
Connectors
If you connect third-party apps to an agent, Composio holds the connection and tokens for that agent identity. We see connection status and toolkit metadata so the canvas can list what is linked. The third-party account’s own content stays with that provider and on the box that uses the connection.
Box contents
Files, prompts, logs, and memory on a box belong to that deployment. The control plane can read and write box files when it provisions, configures, or repairs a runtime. We do not use box contents to train foundation models or to advertise to you.
Automatically collected
- Technical logs such as IP address, timestamps, user agent, and request paths, generated by the host and by sign-in
- Theme preference in the browser (local storage)
- Sidebar open/closed state in the app (a first-party cookie)
We do not run a third-party product-analytics or advertising pixel on the marketing site or in the app today.
Communications
If you email us, we receive whatever you send, including the address you use to write.
5. How we collect it
- Directly from you: sign-up, organization settings, project and engine configuration, support mail
- Automatically: cookies and logs needed to sign you in and keep the product working
- From processors acting for us: Clerk (identity), Polar (checkout and subscription state), Upstash Box (compute), Composio (connector accounts), and our database and application hosts
We do not buy personal information from data brokers.
6. How we use it
We use this information to:
- Create accounts, organizations, projects, and deployments, and keep the canvas connected to the right box
- Charge for running deployments, open Polar’s billing portal, and pause or resume a fleet when a subscription lapses or returns
- Invite teammates, apply roles, and issue hashed API keys
- Diagnose failures, prevent abuse, and keep the Service secure
- Send transactional mail about the account, billing, or an incident — not a marketing newsletter unless you have asked for one
- Comply with law and enforce the Terms of Service
7. Legal bases
If you are in the UK or EEA, we process personal data only where a legal basis applies:
- Contract — to provide the Service you asked for (account, boxes, billing, connectors you enable)
- Legitimate interests — to secure the Service, understand reliability, and improve how provisioning works, in ways that do not override your rights
- Legal obligation — tax, accounting, and lawful requests
- Consent — where we ask for it, including non-essential cookies if we add them later. You can withdraw consent without affecting processing that already happened
9. International transfers
You may use the Service from outside the country where a processor stores data. Identity, billing, connectors, and boxes may be processed in the United States, the European Union, or other countries where those providers operate. Where the GDPR or UK GDPR applies, we rely on the safeguards those processors offer (such as Standard Contractual Clauses or an adequacy decision) as described in their documentation.
10. Retention
- Account and organization records — for as long as the account or organization exists, then until we finish deletion after a valid request or closure
- Running boxes — until you delete the deployment. If a subscription ends, we pause the fleet and keep paused boxes for 30 days, then delete them
- API key hashes — until you revoke the key or the organization is removed
- Billing identifiers — as long as needed to bill, refund, or meet tax and accounting rules (Polar also keeps its own records)
- Logs — for a limited operational window, then they age out of the host and identity provider
11. Your rights
Depending on where you live (including the EEA, UK, and California), you may be able to:
- Access a copy of personal information we hold about you
- Correct inaccurate information
- Delete information, subject to legal retention
- Export information in a portable form
- Object to or restrict certain processing
- Opt out of sale or sharing of personal information, if that ever applied (it does not today)
- Appeal a refusal, and complain to a data protection authority
Email hello@useopenbrain.dev. We may need to confirm it is you. We aim to respond within 30 days, or sooner if the law requires. If you use cloudrun through an organization, some requests must go through that organization’s admin because they control the workspace.
We will not deny the Service, charge a different price, or give a lesser quality of Service because you exercised a privacy right, except as the law allows when a request is genuinely unfounded or excessive.
13. Security
The Service is served over HTTPS. Control-plane records live in a managed PostgreSQL database. Boxes are isolated machines. Access inside our team is limited to people and systems that operate the product. No method of transmission or storage is perfectly secure. You are responsible for protecting account credentials and for what you put on a box or in a public template.
14. Children
cloudrun is a business product. It is not directed at children under 16, and we do not knowingly collect their personal information. If you believe we have, write to hello@useopenbrain.dev and we will delete it.
15. Sale and advertising
We do not sell personal information and we do not share it for cross-context behavioural advertising. California residents may still send a “do not sell or share” request to the address below; we will confirm that we have nothing to opt you out of under that definition today.
16. Changes
We will post updates on this page and change the “Last updated” date. If a change is material, we will also notify you through the Service or the email on your account before it takes effect, where we can. Continued use after the effective date means you accept the revised policy.
17. Contact
Privacy requests and questions: hello@useopenbrain.dev. The hosted Service is www.cloudrun-ai.com.
We have not published a registered office or appointed an EU/UK representative in this document. If that changes, we will add it here.
