Privacy Policy
Last updated: July 20, 2026
This Privacy Policy describes how CJ Studio LLC ("Runcept", "we", "us") collects, uses, and shares your information when you use our AI Tool marketplace and API platform at runcept.com (the "Service"). "Tool" means any capability listed, connected, called, or executed through the Service, including functions, data services, actions, AI-powered tools, workflows, and autonomous agents; "Agent" means a Tool that can autonomously plan or select actions in pursuit of a goal. See our Terms of Service for the full definitions.
1. Information We Collect
Account Data
When you create an account, we collect your email address. If you sign up via Google OAuth, we receive your name and email from Google. Passwords are hashed by our authentication provider (Supabase) and are never stored in plaintext.
Payment Data
Balance top-ups are processed by Stripe. We never receive or store your full credit card number. We store your Stripe customer ID to manage your account balance.
Tool & Run Data
When you call a Tool, we store the run's input, output, status, and cost so it appears in your run history. If you publish a Tool as a builder, we store the Tool's metadata, schema, endpoint URL or code, and pricing.
Usage & Device Data
We automatically collect information about how you use the Service, including pages visited, features used, API calls, and balance transactions. We also collect device information such as browser type, operating system, and IP address through our analytics providers.
2. How We Use Your Data
- Provide, maintain, and improve the Service.
- Process balance top-ups and builder payouts.
- Route and execute Tool runs, and meter their cost.
- Analyze usage patterns to improve user experience (via PostHog and Vercel Analytics).
- Communicate with you about your account (email verification, password resets).
- Detect and prevent fraud, abuse, and automated bot activity.
- Comply with legal obligations.
3. Third-Party Data Processors
We share data with the following third-party services to operate the platform:
| Service | Purpose | Data Shared |
|---|---|---|
| Supabase | Database, authentication, file storage | Email, hashed password, account and Tool data |
| Stripe | Balance top-up payment processing | Email, Stripe customer ID; card data stays with Stripe |
| PayPal | Builder payout processing | PayPal email address, payout amount |
| Anthropic (Claude) | LLM execution for platform-executed Tools | Tool run inputs and outputs, for Tools that call an LLM |
| Brave Search | Web search results for Tools that use the web-search tool | Search query text, only when that Tool is invoked |
| PostHog | Product analytics | Page views, identified user profiles, custom events |
| X Ads | Advertising attribution and conversion measurement | Page views, ad click identifiers, hashed email, device and network information |
| Reddit Ads | Advertising attribution, retargeting, and conversion measurement | Page views, ad click identifiers, hashed email and account identifier, device and network information |
| Vercel | Hosting, analytics, edge functions | Page views, server-side function events |
| Cloudflare Turnstile | Bot verification during account creation | Turnstile verification tokens |
4. Cookies & Tracking Technologies
Essential Cookies
Supabase authentication cookies are required for login and session management. These are set automatically when you sign in.
Analytics Cookies
- PostHog:
ph_*cookies — product analytics and user identification. - Vercel Analytics: Privacy-focused analytics with minimal cookie usage.
- X Ads: first-party and X cookies or click identifiers used for advertising attribution and deduplicated conversion measurement.
- Reddit Ads: Reddit Pixel cookies and click identifiers used for advertising attribution, retargeting, and deduplicated conversion measurement.
No Advertising Cookies From Third Parties
Aside from the X Ads and Reddit Ads attribution described above, we do not use other third-party advertising cookies or cross-site tracking pixels, and we do not sell your data to advertisers.
Local Storage
We use browser localStorage to store your theme preference (light/dark) and temporarily hold onboarding state during signup. No personally identifiable information is stored in localStorage.
5. Data Retention
- Account data: Retained until you delete your account.
- Tools & run history: Retained until you unpublish the Tool or delete your account. Account deletion cascade-deletes all published Tools, run history, and balance transaction history.
- Analytics data: Subject to each analytics provider's retention policy (typically 12–26 months).
- Payment records: Retained as required by applicable tax and financial regulations (typically 7 years).
6. Your Rights
- Access: View your data through your dashboard and account settings.
- Deletion: Delete your account at any time from Settings. This permanently deletes all your published Tools, run history, API keys, and remaining balance.
- Export: Download your run history from the Activity dashboard at any time.
- Correction: Update your email and password in your account settings.
- Data portability: Contact us at support@runcept.com to request a full export of your data.
If you are located in the European Economic Area (EEA), United Kingdom, or California, you may have additional rights under GDPR, UK GDPR, or CCPA respectively. Contact us at support@runcept.com to exercise these rights.
7. Data Security
We implement the following security measures to protect your data:
- Row-Level Security (RLS) on all database tables — users can only access their own data.
- HTTPS/TLS encryption for all data in transit.
- All API keys and secrets are stored server-side only and never exposed to the client.
- Passwords are hashed using industry-standard algorithms (handled by Supabase Auth).
- Cloudflare Turnstile for human verification during account creation.
8. Children's Privacy
The Service is not intended for users under the age of 18. We do not knowingly collect personal information from children. If you believe we have inadvertently collected data from a minor, please contact us at support@runcept.com and we will promptly delete it.
9. International Data Transfers
Your data may be processed in the United States, where our infrastructure is primarily hosted (Vercel US regions, Supabase, PostHog US datacenter). By using the Service, you consent to the transfer of your data to the United States. We rely on standard contractual clauses and our service providers' data processing agreements to ensure adequate protection.
10. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via the Service or email. The "Last updated" date at the top will reflect the most recent revision. Your continued use of the Service after changes are posted constitutes acceptance.
11. Contact
For privacy-related questions or to exercise your data rights, contact us at:
CJ Studio LLC
Email: support@runcept.com
See also: Terms of Service