Privacy record

Privacy policy

Effective · July 15, 2026

Controller

Who is responsible

The legal operator and mailing address must be supplied before general commercial launch. Privacy requests can be sent to runleak@proton.me.

§ 01

Data we collect

Account data includes email, username, name, authentication identifiers, settings, and workspace membership. Service data may include connected-agent metadata, repository identifiers, rules, run events, assignments, evidence drafts, review decisions, passports, findings, usage and efficiency measurements, support messages, and audit/security events. Technical data may include IP address, device/browser information, cookies, timestamps, and request logs.

§ 02

How we use data

We use data to authenticate users; provide workspaces and controlled-run features; enforce permissions and limits; preserve approved records; support users; prevent fraud and abuse; diagnose reliability and security issues; measure product performance; comply with law; and communicate service or policy changes. We do not use workspace content to train general-purpose AI models unless we first obtain a separate, explicit agreement.

§ 03

Legal bases for European users

Where European data-protection law applies, processing is based on performance of our contract, legitimate interests in operating and securing the service, compliance with legal obligations, and consent where required. You may object to processing based on legitimate interests.

§ 04

Sharing and processors

We disclose data to infrastructure, database/authentication, communications, security, and support providers only as needed to operate M9R; to connected agent or provider services you direct us to use; during a corporate transaction; or when required to protect rights, safety, and comply with law. We do not sell personal information or share it for cross-context behavioral advertising.

§ 05

Retention

Account and workspace data is retained while your account is active and according to configured retention settings where available. We may retain security logs, billing records, approved evidence, review records, backups, and deletion records longer when reasonably necessary for integrity, fraud prevention, dispute resolution, or legal obligations. Retention is category-specific; deletion from backups may take additional time.

§ 06

Security

We use access controls, encryption in transit, workspace isolation, redaction, rate limits, audit records, and operational monitoring appropriate to the service. No internet service is hack-proof or guaranteed secure. You are responsible for securing credentials, repositories, agents, endpoints, and the data you choose to submit.

§ 07

Your choices and rights

You may update account data and settings, request access, correction, export, deletion, restriction, or objection, and withdraw consent where applicable. European users may complain to their supervisory authority. California residents may request to know, correct, or delete covered personal information and may exercise applicable opt-out and non-discrimination rights. We will verify requests and may retain data when law permits or requires.

§ 08

International transfers

Providers and systems may process data in countries other than yours. Where required, we use recognized transfer mechanisms and safeguards. Contact us for information relevant to your data.

§ 09

Cookies

We use necessary cookies and local storage for authentication, security, workspace preferences, and onboarding state. Any optional analytics or marketing technology should be subject to any consent required in your location.

§ 10

Children

M9R is for adults and is not directed to children under 18. We do not knowingly collect personal information from children.

§ 11

Changes and contact

We may update this policy and will post a new effective date and provide additional notice for material changes when required.