Privacy Notice

Local-first does not mean “no data leaves your device.”

Core workspace data stays on your Windows computer by default. Account, licensing, invited-beta, optional telemetry, encrypted backup, and user-invoked hosted AI features have specific cloud boundaries described below.

Pre-release privacy draft. The controller identity or required qualified reviews are not yet confirmed. External beta and paid release must remain disabled until the real operator details and final legal review are complete.

Controller identity

The controller’s real legal name, registered address, and country have not been configured. “Runeka” is a product name, not a complete controller identity. No operator should enable an external beta or paid offer in this state. Questions and deletion requests currently route to support@runeka.com.

What stays local

Tasks, plans, Diary entries, focus history, wellbeing notes, rewards, generated reflections, approved memories, and the main Runeka SQLite database live on your device by default. The live SQLite file is not represented as application-level encrypted. Windows account security, BitLocker or equivalent disk encryption, device access controls, and physical security may protect it, depending on your setup.

Data, purpose, and legal basis

  • Beta access request: normalized email, request time, and bounded UTM campaign tags (source, medium, campaign, content, and term), to respond to your request for an invitation and measure campaign sources. Runeka does not store the referring page or advertising-platform click identifiers in that request.
  • Account, trial, license, and device: email, license/account identifiers, device label and status, authentication and entitlement records, to provide the contract, secure accounts, prevent abuse, and meet legal obligations. An account is required to begin a trial, purchase, and activate; entitlement is validated online and during the documented offline grace period.
  • Billing: order, plan, transaction, tax, renewal, cancellation, and refund status needed to provide a paid offer. Paddle is intended to act as merchant of record and handles payment-card data under its own notice.
  • Optional hosted AI: the exact selected text/context shown in the scope receipt, to generate the response you request. Diary and wellbeing text can reveal sensitive or health-related information, so the feature requires a separate explicit cloud-processing consent and user invocation.
  • Optional encrypted backup: client-encrypted database blob plus bounded device/object metadata, to store, list, restore, and delete backups. Runeka does not receive the recovery passphrase.
  • Optional telemetry and crash reports: closed, content-free events and scrubbed diagnostics only after the separate telemetry choice, to understand reliability and beta behavior.
  • Security and support: bounded operational records and material you deliberately provide, to protect the Service, investigate failures or abuse, and respond to you.

Depending on the operation and jurisdiction, processing relies on steps requested before a contract, performance of a contract, legal obligations, legitimate interests in security and reliable operation, or consent. Consent is used only where identified; it can be refused or withdrawn without converting a different purpose into “contract necessity.” A senior lawyer must confirm the final basis mapping.

Diary Reflection and wellbeing

Private Journal sends no Diary reflection to the cloud. In other modes, Runeka sends only the exact selected source entries, optional user-confirmed wellbeing, individually approved memories, and bounded session context shown before transmission. The API does not add unrelated tasks, calendar, focus, email, or other workspace data. AI output is labelled AI-generated and may be wrong. AI cannot silently change user-reported wellbeing values.

Runeka’s API processes the request in memory and does not add raw Diary input/output to its usage ledger, logs, Sentry, or ordinary telemetry. The server can route to configured Anthropic or OpenAI services. Their retention, training, region, and subprocessor behavior depends on the deployed account and agreement and must be verified and disclosed before external beta; this notice does not promise zero provider retention.

Backups

Cloud backups are encrypted on the Windows client before upload. Runeka stores the encrypted blob and metadata needed to list, enforce quota, restore, and delete it, but not the passphrase needed to decrypt it. Losing the passphrase can make a backup unrecoverable. Encrypted data is still personal data if it can be related back to an account or later decrypted.

Recipients and international processing

Depending on enabled features, recipients can include infrastructure/storage providers, Resend for email, Paddle for payment and merchant-of-record functions, Anthropic or OpenAI for user-invoked AI, Sentry for consented scrubbed diagnostics, and Plausible for the query-free marketing root. Professional advisers and authorities may receive limited data where legally necessary.

Some providers may process data outside your country or the EEA. The operator must verify provider locations, roles, transfer mechanism, contractual safeguards, and supplementary measures before release and make current subprocessor information available. No unverified transfer safeguard is promised here.

Analytics and diagnostics

The marketing site can load Plausible only on the query-free public root when production analytics are configured. Account, magic-link, beta-download, policy, error, and query-bearing routes do not load it. Desktop product telemetry and Sentry crash reporting are off until the user makes the separate telemetry choice. Ordinary telemetry excludes Diary/note text, task titles, AI prompts/responses, backup content, email, license/API keys, file paths, window titles, process names, and typed content.

Retention

  • Beta access requests are kept until the beta program ends or you ask for deletion.
  • Raw hosted-AI request/response content is not persisted in Runeka’s own API database; provider-side retention follows the verified deployed provider agreement.
  • Content-free AI usage-ledger and consented telemetry rows use a 90-day server-side retention window.
  • Encrypted backups remain until you delete them, the applicable account/plan cleanup occurs, or a documented retention rule requires removal.
  • Account, licensing, transaction, fraud-prevention, tax, dispute, and support records are kept only for the contract, security, or legal period that applies, then deleted or irreversibly anonymized where appropriate.
  • Already received Sentry reports follow the configured Sentry retention; turning telemetry off prevents future reporting but cannot retroactively shorten a provider-held retention period.

Your choices and rights

You can keep cloud Diary reflection off, use Private Journal, exclude entries, inspect exact scope, Keep or Discard output, delete saved reflections, review/revoke/delete approved memories, and withdraw Diary AI consent. Withdrawing consent stops future processing under that consent; it does not automatically delete separately stored local derivatives or records retained under another lawful basis. Telemetry has its own off/delete controls.

Subject to applicable law, you may request access, correction, deletion, restriction, portability, or object to processing, and may withdraw consent at any time without affecting earlier lawful processing. You may complain to the data-protection authority where you live, work, or believe an infringement occurred. Contact support@runeka.com; identity verification may be required without asking for more information than necessary.

Automated decisions and AI inferences

Runeka does not use Diary interpretations to make legal or similarly significant decisions about you, change your entitlement, or create a hidden psychological profile. Licensing, quota, fraud, and security controls may apply automated rules needed to operate the Service; support can review disputed outcomes where applicable. Rejected interpretations do not become approved memory.

Security and deletion limits

Runeka uses data minimization, transport security, bounded validation, redaction, content-free observability, DPAPI for desktop credentials, and client-side backup encryption where implemented. No system is completely secure. Deleting an account-side record cannot erase a local file, an exported copy, a device already holding synchronized data, or a provider record that must temporarily remain under a lawful retention rule.

Adults-only beta and changes

The initial external beta is intended only for adults aged 18 or older. Runeka is not knowingly inviting minors into this beta. Material changes to this notice, purposes, recipients, or optional processing require clear notice; an updated notice does not silently recreate a withdrawn consent.

Related documents and contact

Read the Terms of Use and AI & wellbeing disclaimer. Privacy: support@runeka.com. Support: support@runeka.com.

Last updated: July 31, 2026.

Rejoining the server...

Rejoin failed... trying again in seconds.

Failed to rejoin.
Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session.
Please retry or reload the page.