Privacy Policy.
What we collect, why, and — just as important — what we deliberately never hold. Effective July 14, 2026. Operated by Uai Tech, Inc. ("Uai," "we").
The short version
- Your code stays on your host. The cloud orchestrates; it does not store your repositories.
- The cloud is secret-blind. AI keys, SSH keys, GitHub tokens, and connection credentials live encrypted on your own machine — we designed the system so our servers never hold them at rest.
- We don't sell your data or train models on it. No ad networks, no cross-site tracking, cookieless analytics on this site.
What we collect
- Account data. Name, email, avatar, and organization membership, via our sign-in provider (Clerk).
- Product data. What the Service needs to work: organizations, project configuration (repository URLs and settings — not repository contents), task names and status, chat transcripts between you and your agents, connection metadata (which services you connected, never their credentials), and host status.
- Billing data. Plan and subscription status. Card details go to our payment processor (Stripe, via Clerk Billing); we never see full card numbers.
- Operational logs. Standard server logs and error diagnostics, kept briefly, used to run and debug the Service.
- This website. Cookieless, aggregate analytics — page views and clicks, no personal profiles, no fingerprinting.
What we deliberately don't hold
AI provider keys, SSH private keys, GitHub tokens, and OAuth credentials for connected services are stored encrypted on your host, under a key that stays on your host. Environment variables for your projects follow the same rule: the cloud knows the key names, your host holds the values. Repository contents never transit our servers. The full trust model is on the security page.
How we use data
To provide and improve the Service, to secure it (abuse prevention, debugging), to bill subscriptions, and to send transactional messages (e.g. task notifications you enable). We do not sell personal data, we do not run ads, and we do not use your content to train AI models.
Who processes data for us
We use a small set of subprocessors to run Uai: Fly.io (cloud hosting), Clerk (authentication and billing), Stripe (payments), Vercel (this website), and GitHub (source hosting and the Uai GitHub App, when you connect it). Services you choose to connect — AI providers, GitHub, Slack, Linear, and other MCP vendors — receive data as directed by you and your agents, under their own privacy policies.
Retention and deletion
Product data is kept while your account is active. Delete a task, a project, or your account and the corresponding cloud data is deleted or de-identified within a commercially reasonable period; backups expire on a rolling schedule. Data on your host is yours to delete directly, and uninstalling a host removes its cloud registration.
Your rights
You can access, correct, export, or delete your personal data — email privacy@runuai.com and we'll respond within 30 days. Depending on where you live (e.g. the EEA, UK, or California) you may have additional statutory rights, which we honor. We don't discriminate for exercising them.
Children
Uai is not directed to children and may not be used by anyone under 16. We don't knowingly collect data from children.
Changes and contact
We'll post updates here and give notice for material changes. Questions: privacy@runuai.com or runuai.com/support.