Privacy Policy
Effective August 10, 2026
Runza is an all-in-one tool for running a business on your own — a website, customers, money, and marketing in one place. It is operated by RealQuestAI, Inc., a United States company, which is the controller of the personal data described here. This policy explains what we collect, why, who we share it with, and what you can tell us to do about it.
Two kinds of personal data pass through Runza, and they are not the same. There is information about you, the person running the business — and information about your customers, which you collect using Runza. For the first we are the controller. For the second, you are the controller and we are your processor: it is your data, we hold it on your behalf, and we act on your instructions. Section 3 covers what that means in practice.
1. Who this applies to
Runza is for adults running a business. You must be at least 18 to have a Runza account.
We also operate RealQuest, a separate student edition for founders aged 13–17 with a parent or guardian involved. It has its own policy at realquest.ai/privacy and different rules appropriate to minors. If you are using RealQuest, that policy governs, not this one.
2. What we collect about you
- Account. Your name, email address, and how you signed in. We never see or store a password — sign-in is handled by Google or by a one-time code sent to your email.
- Business details. What you tell us about your business so the AI can write for it: what you do, your brand, your products and prices, your postal address for email compliance.
- Content you create. Websites, apps, designs, documents, posts, invoices and quotes you build in Runza.
- Financial records you enter. Income and expenses you log in the money tracker, and the ledger derived from them.
- Payment information. Handled by Stripe. Card numbers never reach Runza — payment details are entered on Stripe’s own checkout. We store Stripe identifiers, amounts, and whether a payment succeeded.
- Connected accounts. When you connect a social platform or calendar, we store the access tokens needed to act on your behalf. They are held server-side and never sent to your browser.
- Usage and technical data. Log data from our hosting and database providers, and basic analytics about how the product is used.
3. Data about your customers
When someone fills in a form on your site, places an order, books an appointment or messages you, that record is yours. We process it so that Runza works — storing it, showing it to you, sending the emails you ask us to send — and for nothing else.
Specifically, we do not:
- Sell it, rent it, or share it with anyone for their own purposes.
- Use it to advertise to your customers.
- Use it to train AI models. See section 5.
- Mix it with another business’s data. Every record is scoped to the business that collected it, and that separation is enforced by the database itself, not only by application code.
Your obligations. You are the controller of that data. You are responsible for having a lawful basis to collect it, for telling your customers what you do with it, and for honouring their requests. If a customer of yours asks us directly, we will refer them to you and tell you about it.
4. Why we use it
- To provide the product — to run your site, your CRM, your books and your campaigns.
- To generate what you ask for: copy, designs, apps, and suggestions.
- To take payments and pay you out, through Stripe.
- To send you service messages about your account, and marketing you can unsubscribe from at any time.
- To keep the service secure and prevent abuse.
- To comply with the law.
5. AI features
Runza’s generation features send the relevant part of your business information — a brief, your brand details, the content being edited — to a third-party AI provider (today, Anthropic) to produce a result. We send what the request needs, not your whole account.
Your content and your customers’ data are not used to train AI models — not by us, and not by our AI provider under the terms we use. Output is yours; see the User Agreement.
AI output can be wrong. It is a draft for you to check, and that is especially true of anything with legal, tax, or financial consequences.
6. Who we share it with
We use a small number of service providers to run Runza. They may process data only to provide their service to us:
- Supabase — database and authentication.
- Netlify — hosting and serverless functions.
- Stripe — payments, subscriptions, and payouts to you.
- Anthropic — the AI features described above.
- Email and SMS providers — to deliver messages you send and the ones we send you.
- Social platforms and calendar providers — only those you choose to connect, and only to do what you asked.
We may also disclose information if the law requires it, or to protect the rights and safety of our users. If Runza is ever involved in a merger or acquisition, your data may transfer as part of it, and this policy travels with it.
We do not sell personal information, and we do not share it for cross-context behavioral advertising.
Mobile phone numbers and text-message consent are never shared with or sold to third parties or affiliates for marketing purposes. Numbers are passed only to the messaging provider that delivers the message you asked for, and consent is recorded against the business you gave it to — a number you give one Runza business is never made available to another, and never to us for our own marketing.
7. Bank connections
We are building the ability to connect your bank account so transactions can be imported into your books. When that ships it will run through a regulated aggregator, and your banking credentials are entered with them, never with Runza — we receive transaction data, not your login. You will be asked to confirm a second authentication factor before you can connect an account, and you will be able to disconnect it at any time. This section will be updated with the provider’s name before the feature is available.
8. How we protect it
Data is encrypted in transit and at rest. Access to the database is denied by default and mediated by server-side code that checks, on every request, that you are allowed to see what you asked for. Card numbers never touch our systems. Connecting a bank account will require a second authentication factor.
Our security practices are written down rather than implied, including the parts we have not finished — see our Information Security Policy, available on request at hello@runza.ai. No system is perfectly secure, and we will tell you promptly if something happens that affects your data.
9. How long we keep it
We keep your data while your account is active. If you delete your account or ask us to delete your data, we remove it from our primary systems within 30 days, and the last encrypted backup containing it ages out within a further 7 — so it is fully gone within 37 days. The exceptions are records we must keep by law, such as payment records for tax purposes, which we hold for seven years.
10. Your choices and rights
- Export. Your orders, contacts, financial records and site content can be exported from inside the product whenever you like. You do not need to ask us.
- Correct or delete. Edit your data in the product, or ask us to delete your account.
- Unsubscribe. Every marketing email has an unsubscribe link. Service messages about your account are not marketing and continue.
- Disconnect. Revoke any connected social or calendar account at any time, in the product and at the provider.
Depending on where you live you may have additional rights — to access what we hold, to object to or restrict processing, to portability, and to complain to a regulator. Contact us and we will honour them. We will not treat you differently for exercising a right.
11. Where your data is
Runza is operated from the United States and our providers store data there. If you use Runza from outside the US, you are sending your information to the US, where privacy laws differ from your own.
12. Changes
If we make a material change we will update the effective date above and tell you in the product or by email before it takes effect.
13. Contact
Questions, requests, or anything that looks like a security problem: zach@realquest.ai.