Legal

Data Processing

Enterprise data processing terms are available on request. We are happy to discuss specific contractual requirements for data processing agreements, including standard contractual clauses and data protection provisions.

Do not submit regulated personal data until an applicable Data Processing Agreement has been signed. For data-processing questions or to request an agreement, contact runleak@proton.me.

How we handle data today

  • Account and workspace data is processed to provide controlled runs, evidence review, records, support, reliability, and security.
  • We do not train models on evidence, run activity, or any other submitted content.
  • Evidence and run content pass through regex-based secret redaction before storage. This is best-effort and not a guarantee — avoid including secrets in what you submit.
  • Connections use HTTPS.

Current controls and limitations

  • Settings provides a self-service workspace-data purge; limited records may remain where required for security, integrity, disputes, or law.
  • Sensitive review actions and controlled-run events create audit records.
  • Application rate limits protect covered endpoints. Edge firewall and bot controls are operated separately and may vary by deployment.
  • Redaction is best-effort. Users must avoid submitting secrets or regulated data and should redact before transmission.