Legal
Privacy Policy
This policy explains what ABE, the business that operates runabe.ai ("ABE", "we"), collects when you visit runabe.ai, what ABE processes when a customer runs it on their backlog, and the choices you have. We wrote it to be read, not skimmed.
1. The website
runabe.ai is a static site. It sets no cookies, runs no analytics, and carries no advertising or tracking pixels. Fonts load from Google Fonts, which receives your IP address and browser details to serve them. The site is served through Cloudflare, which keeps short-lived connection logs (IP address, user agent, requested page) for security and abuse prevention. If you email us, we keep your message and address to reply and to follow up. If we add analytics later, we will update this policy first.
2. The Service
When a customer connects ABE to their ticketing system and repositories, ABE processes the material needed to work a ticket: ticket text, comments, and attachments; source code, commit history, and pull-request metadata; build and test output; screenshots and traces from reproduction; and the configuration the customer sets. This material can contain personal data, most often the names and email addresses of people who filed tickets, commented, or authored commits, and occasionally personal data present in tickets, logs, or test data.
For that material we act as a processor on the customer's instructions under a Data Processing Addendum. The customer decides which projects and repositories ABE can see, which paths are excluded, what ABE may change, and when ABE stops. We do not use customer material to train machine-learning models, and we do not sell it.
Each run produces a record: a journal of what ABE did, a report, the gate decisions, and the evidence behind them. In hybrid deployments this record lives in the customer's own environment.
3. AI model providers
ABE sends the minimum context a task needs, not whole repositories, to third-party model providers. Today those are Amazon Web Services (Amazon Bedrock), Anthropic, and OpenAI, under accounts we manage. We select provider settings under which customer material is not used to train the provider's models and is retained only as long as the provider's terms require for abuse monitoring, and we keep a current list of providers and their retention terms for customers on request. Customers can restrict which providers and models ABE may use, and enterprise deployments can run models inside the customer's own cloud account.
4. Business contacts
If you correspond with us, request a pilot, or work with us as a customer or partner, we keep your name, email, employer, role, and our correspondence. We use it to run the relationship, provide the Service, send service notices, and, if you ask, product updates. Our legal basis is the contract with you or your employer and our legitimate interest in running the business. We do not send marketing to people who have not asked for it.
5. Who we share data with
We share data only with:
- Subprocessors that help us run the Service and the site: Amazon Web Services (hosting and Amazon Bedrock), Anthropic and OpenAI (model inference), and Cloudflare (site delivery, DNS, and email routing). Customers receive notice before we add a subprocessor that will handle their material.
- Professional advisers such as lawyers and accountants, under confidentiality.
- Authorities where the law requires, after we have checked the request is valid and, where allowed, told the customer.
- A successor if we merge with or are acquired by another company, under this policy.
6. Retention
- Website logs: retained by Cloudflare for its standard short window; we do not extract or store them.
- Correspondence and business contacts: for the life of the relationship and two years after, unless you ask us to delete sooner.
- Customer material and run records: for the term of the engagement and the retention period the customer configures. Within 30 days after an engagement ends we delete or return customer material, with backups purged within 90 days, except where law requires longer.
7. Security
All traffic between ABE, customers' systems, and model providers is encrypted in transit. Connector credentials are stored encrypted and scoped to the least access the task needs. Each customer's deployment, data, and run records are isolated from every other customer's. ABE applies configurable redaction patterns to ticket content before it reaches a model provider, honors customer path exclusions, and enforces spend ceilings per day and per ticket. No security program prevents every incident; if one affects you, we will tell you without undue delay and, for customers, within the window in the Data Processing Addendum.
8. International transfers
We operate in the United States and our subprocessors process data there. Where we process personal data from the European Economic Area, the United Kingdom, or Switzerland, we rely on Standard Contractual Clauses and, for the UK, the International Data Transfer Addendum, together with the safeguards in this policy.
9. Your rights
Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal data, to object to or restrict certain processing, to withdraw consent, and to complain to a supervisory authority. Email hello@runabe.ai and we will respond within 30 days. If your data reached ABE through a customer's tickets or repositories, that customer controls it; we will point you to them and help them respond.
10. Children
runabe.ai and the Service are for businesses and people 18 and over. We do not knowingly collect data from children.
11. Changes
We will post any change here with a new effective date. If a change materially affects how we handle customer material, we will notify customers before it takes effect.
12. Contact
ABE · United States · hello@runabe.ai