Version 2026-09-15
Privacy Policy
This policy is a draft. It has not been reviewed by a lawyer. It is an accurate description of the processing Runo performs, and it will be reviewed before Runo accepts payment.
1. Controller
The controller of your personal data is an individual established in Finland. No company has been incorporated; when one is, this section and the version of this policy will be updated. Contact: support@runoaudio.com.
2. Personal data collected
- Account data. Your username, a hash of your password if your account has one, your plan, and the date the account was created. Runo does not store your password, and does not ask for your name or date of birth. If you turn your password off, the hash is deleted.
- Passkeys. If you add a passkey: its public key, the identifier your passkey provider gave it, the name you give it, which connection types it supports, whether your provider backs it up, the model identifier your provider reports, a counter your device advances at each use, and when it was added and last used. Runo also gives your account a random identifier that your provider stores with the passkey; it contains nothing about you. The passkey itself is kept by your device or password manager, labelled with your email address, under your own agreement with that provider; Runo sends the provider nothing directly. Your fingerprint, face or screen lock never leave your device: Runo receives only a signature showing that the device holds the key.
- Recovery code. While you have a passkey, a hash of your one-time recovery code and the date it was issued. The code itself is shown to you once and is not stored.
- Account recovery through support. If you lose your passkeys and your recovery code and ask support to recover your account, Runo records the request: the address it was checked against, when it was opened, when its sign-in link was sent and when that link expires, and how the request ended. The links are stored only as hashes. Support asks for nothing except a reply from your account's address, and never reads your library.
- Waiting list data. If you request an invitation, Runo stores your email address and the date of the request. No other data is collected, and no email is sent in response to the request. If an invitation is issued, the address becomes your account address. If no invitation is issued, the address is deleted within 90 days. You may request earlier deletion at any time.
- Email address. Your address is used to sign in, to reset your password, to tell you when a passkey, your recovery code or your password is added, removed, changed or used, and to recover your account through support. It is used for no other purpose, and Runo sends no marketing. A change of address takes effect only when you follow a confirmation link sent to the new address; until then the account keeps the previous one. Two accounts created before an address was required hold none, and remain usable.
- Uploaded text. The documents you upload, divided into chapters.
- Generated audio. The narration produced from your text, and the caption files accompanying it.
- Playback data. Your position in each book, your bookmarks and any notes attached to them, and the voice last used.
- Usage data. A record of narration produced, used to enforce your monthly allowance.
- File processing records. When a file was uploaded, whether it was imported or refused, when a chapter was narrated or deleted, and when a file was downloaded. Books are identified by id rather than by title, so these records do not disclose what you read. They are retained for two years and are deleted with your account.
- Session data. A hash of your sign-in cookie; when the session began, when it was last used and when you last confirmed that it was you; how it was opened (with a password, a passkey, your recovery code or a support recovery link) and whether you last confirmed with a password or a passkey; and which passkey opened it, if one did. When you turn your password off, this is how Runo ends the sessions the password opened. A session ends after 14 days unused or 30 days after sign-in, whichever comes first.
- Sign-in challenges. While a passkey is being added or used, a single-use random value. It is valid for five minutes, and is deleted when used or at the next routine clean-up, which runs about every 15 minutes while Runo is running.
- Policy acceptances. Which version of these documents your account accepted, and when.
- Reports and restriction decisions. If someone reports content on Runo as illegal, Runo retains the report, the reporter's name and the reporter's address, in order to respond and to act on it. Where an upload or an account is restricted, Runo retains the decision and the reasons given.
Runo uses no analytics, no advertising and no third-party trackers. It sets two cookies, both strictly necessary: one that keeps you signed in, and one that holds a passkey sign-in in progress for at most five minutes. There is accordingly no cookie banner.
Your browser stores your display settings locally: the light or dark theme, the position and size of the player, and your reading text size. These are not transmitted to Runo.
3. Purposes and legal bases
Most processing is necessary for the performance of a contract with you: Runo cannot narrate a book it may not store.
Passkeys, the recovery code and the emails that tell you about changes to how your account signs in are likewise necessary for the performance of the contract, since an account is of use only if it is yours alone. They are also among the security measures Article 32 GDPR requires of Runo.
Account recovery through support is likewise necessary for the performance of the contract: it returns an account to an owner who has lost every way of signing in. Keeping the record of a request after it ends rests on legitimate interest in being able to tell you who recovered your account and when, and in recognising repeated attempts on the same account.
Error reports and the usage ledger rest on legitimate interest in maintaining the service and in not being billed for computation nobody requested.
File processing records rest on legitimate interest in responding to copyright complaints about a specific book and in establishing, exercising or defending legal claims. They are limited to identifiers and timestamps, contain no titles and no text, and are included in your data export.
Reports of illegal content and the decisions taken on them rest on legal obligation under the Digital Services Act to operate a reporting mechanism, to respond to the person who used it and to give reasons to anyone restricted, and on legitimate interest in retaining that record so that a repeated complaint can be distinguished from a first one.
Uploaded text may reveal information about you, including beliefs, health or sexuality. Runo does not analyse it, does not profile you, and uses it only to generate your audio. Your library is accessible to you and to no other user.
4. Recipients
Runo uses the processors below. This list is complete.
| Who | What for | What they see | Where |
|---|---|---|---|
| Hetzner | The server and database | Everything | Helsinki, Finland |
| Cloudflare | The edge in front of the site: it terminates the encrypted connection, filters traffic and absorbs attacks | All traffic in unencrypted form, including credentials submitted at sign-in, the contents of uploaded files, and the address of every visitor whether or not they hold an account | The edge nearest you, operated by a company in the United States |
| Cloudflare R2 | Storing audio and backups | Your audio, and database backups. The backups are encrypted and Cloudflare does not hold the key | Western Europe |
| Modal | Running the narration model | Chapter text, in transit, while it is being narrated | United States, and other countries outside the EU |
| Migadu | The mailboxes Runo replies from | Anything you write to Runo, and the replies | France |
| Scaleway | Sending confirmation, password-reset and security email | Your address, and the message sent to you | European Union |
| Sentry | Error reports | Crash details, with URLs and identifying values stripped | European Union |
5. Transfers outside the EU
Two transfers to the United States take place. Both are made under the European Commission's standard contractual clauses under Article 46(2)(c) GDPR. Runo does not rely on the EU–US Data Privacy Framework: the adequacy decision covers only organisations certified under it.
5.1 Modal, Inc.
Chapter text is processed outside the EU, principally in the United States, by the GPU service that generates the speech. The text is transmitted, narrated, and not retained on that machine. Modal uses infrastructure providers of its own, not all of which are in the United States; region pinning is not available on the plan Runo uses, so no single country can be guaranteed. Modal's list of those providers is public.
The clauses are incorporated by Modal's data processing addendum, where you can read them, and they apply to onward transfers: Modal may pass chapter text to one of its own providers only where that provider assumes equivalent obligations, the country has an adequacy decision, or another safeguard applies. Runo has assessed the effect of United States surveillance law on this transfer and reviews that assessment when the law, the processor, or the data transmitted changes.
5.2 Cloudflare, Inc.
All traffic between you and Runo passes through Cloudflare's network, which terminates the encrypted connection in order to filter traffic and mitigate attacks. Request content is therefore accessible to Cloudflare in unencrypted form before it is forwarded to the server in Helsinki. This includes credentials submitted at sign-in and the contents of any file you upload, and it applies to every visitor, whether or not they hold an account.
Cloudflare, Inc. is established in the United States. The transfer falls under Chapter V of the GDPR irrespective of where the server handling a given request is located, and the clauses are incorporated by Cloudflare's data processing addendum.
Residual risk. Runo cannot mitigate this transfer by technical means, because terminating the encryption is the function being procured. Two measures would reduce it and are not in place. Removing Cloudflare from the request path would eliminate the transfer, at the cost of the attack mitigation the service depends on. Passkeys, available since September 2026, keep the password out of the transfer for anyone who signs in with one: what crosses Cloudflare at sign-in is a signature valid for that single sign-in, not a secret that could be used again. The session cookie issued afterwards still crosses it with every request, as all traffic does, and so does the recovery code when it is shown to you and when you use it. Once your account has a passkey you can turn your password off, and from then on no password of yours crosses it.
6. Retention
- Books and audio. Until you delete them, or delete your account.
- Sessions. Until you sign out, 14 days unused, or 30 days after sign-in, whichever comes first. A session that has ended stops working at once, and is deleted at the next routine clean-up, which runs about every 15 minutes while Runo is running.
- Passkeys. Until you remove them, or delete your account.
- Recovery code. Until it is used or replaced, until you remove your last passkey, or until you delete your account.
- Password hash. Until you change your password or turn it off, or delete your account.
- Account recovery requests. 90 days after the request ends, then deleted automatically. Also deleted with your account.
- Sign-in challenges. Until used, or the next routine clean-up after they expire.
- Uploaded files. The file is discarded once its text has been extracted. Only the extracted text is retained, as your book.
- Database backups. Taken nightly and rotated. A deleted account may persist in a backup until that backup is rotated out.
- Usage ledger. Deleted with your account.
- File processing records. Two years, then deleted automatically. Also deleted with your account.
- Waiting list requests. Until an invitation is issued, or 90 days, whichever comes first.
- Reports about content. Two years, then deleted automatically. A report is a third party's record, so deleting your account removes the link to you but not the report.
- Restricted uploads. The audio is deleted immediately. The extracted text is retained, inaccessible, for six months so that you can contest the decision, and is deleted thereafter. Deleting your account erases it immediately instead.
- Statements of reasons. Until you delete your account.
7. Your rights
Two rights are exercisable directly from your account page:
- Access and portability. The export button returns everything Runo holds about you as a JSON file, immediately. Audio is excluded because it is already downloadable and would run to gigabytes; the export lists what exists. Credentials are excluded too: it lists your passkeys, your sessions by date and how each was opened, whether a recovery code exists, and any account recovery requests, but never contains a password hash, a session token, a passkey's key or identifier, the recovery code, or a recovery link.
- Erasure. The delete button removes your account, your passkeys and recovery code, your books, your audio including copies held by the storage provider, your playback data, your usage records, your file processing records, any account recovery requests, and any statement of reasons issued to you. It is immediate and irreversible, and no restriction or suspension delays it.
You also have the right to rectification of inaccurate data, to object to or restrict processing, and to lodge a complaint with a supervisory authority. In Finland this is the Office of the Data Protection Ombudsman (tietosuoja.fi). You may also complain to the authority in your country of residence.
Complaints about the handling of reports of illegal content, or about a decision to restrict material, are directed to Traficom, the Finnish Transport and Communications Agency, which is Finland's Digital Services Coordinator under the Digital Services Act.
8. Security
Passwords are hashed with scrypt. Passkeys are checked by public-key signature, and the public keys Runo holds cannot be used to sign in. The recovery code is stored as a hash. Adding or removing a passkey and creating or replacing the recovery code require you to confirm that it is you, and Runo emails you when a passkey or recovery code is added, removed or used. Turning your password off or setting one again requires confirming with a passkey, and Runo emails you when either happens. A recovery through support always waits three days, which nobody can shorten. Your account's address is told when it begins, every signed-in session shows a notice, and it can be cancelled from either or by signing in with a passkey or your recovery code. The site is served over HTTPS. Audio is served through short-lived links that verify ownership first. Runo is a small service operated by one person: it is built carefully, and it has not been independently audited.
9. Changes to this policy
Where this policy changes materially, the version changes and you are asked to accept the new one. Runo records which version each account accepted, and when.