Local-first does not mean “no data leaves your device.”
It means your workspace lives on your Windows computer, and the cloud is used only for the specific features you turn on. This page lists exactly what those features send, why, and what happens to it.
The short version
- Your tasks, plans, Diary, and wellbeing data stay on your device by default.
- We never sell personal data, and we show no ads.
- No tracking cookies and no ad pixels — which is why there is no cookie banner.
- Every cloud feature is opt-in, with a visible, bounded scope.
- You can see, correct, export, and delete what we hold about you.
Who is responsible
RUNEKA, Grega Nerat s.p., Razvanjska cesta 109, 2000 Maribor, Slovenia is the controller for Runeka’s website, account, licensing, beta, support, optional telemetry, backup metadata, and hosted-feature processing. Privacy contact: support@runeka.com.
What stays on your device
Tasks, plans, Diary entries, focus history, wellbeing notes, rewards, generated reflections, approved memories — the whole workspace SQLite database — live on your Windows device. The app uploads none of it in the background; the cloud features below process specific pieces only when you turn a feature on and use it. The live database file is not encrypted by the app itself: Windows account security and disk encryption such as BitLocker protect it, depending on your setup.
What we collect and why
- Beta access request: your email address, the request time, and bounded UTM campaign tags (source, medium, campaign, content, and term), so we can invite you and see which campaign a request came from. Runeka does not store the referring page or advertising-platform click identifiers.
- Account and licensing: email, license and device identifiers, authentication and entitlement records — to run your account, secure it, and prevent abuse. An account is required to begin a trial, purchase, and activate the app; after activation, the app can keep working offline through the documented offline grace period.
- Billing: order, plan, transaction, tax, renewal, and refund records needed for a paid plan. Paddle acts as merchant of record and handles payment-card data under its own privacy policy — we never see your card number.
- Hosted AI: exactly the text and context shown in the scope receipt before you send it, to generate the response you asked for. Nothing more.
- Encrypted backup: the encrypted database blob plus the minimal metadata needed to list, restore, enforce quota, and delete it. Your passphrase never reaches us.
- Telemetry and crash reports (optional): content-free events and scrubbed diagnostics, only after you switch telemetry on.
- Support: whatever you choose to send us, used to help you.
Legal bases
Runeka is built for the GDPR rather than retrofitted to it. We process your data to take the steps you request before a contract and to perform it (Art. 6(1)(b) — account, licensing, billing), to meet legal obligations (Art. 6(1)(c) — tax and accounting), and for our legitimate interest in keeping the Service secure and reliable (Art. 6(1)(f)). Optional telemetry runs on your consent (Art. 6(1)(a)) and nothing else.
Diary text gets the strictest basis in the product, because it can reveal health information and other special-category data. Cloud processing of it rests on your explicit consent (Art. 9(2)(a)) — asked separately from every other switch, refusable without losing the rest of Runeka, and withdrawable at any time.
Diary reflection and wellbeing
Diary text can reveal health-related and other sensitive information, so this feature has the strictest boundary in the product. Private Journal never sends anything to the cloud. Other modes require a separate, explicit consent plus a per-use action, and send only the selected entries, any wellbeing values you confirmed, individually approved memories, and bounded session context — all shown to you before sending. Unrelated tasks, calendar, focus, and workspace data are excluded.
Our API processes the request in memory and does not write your Diary text or the AI response into its logs, analytics, or usage ledger. The request is served by Anthropic or OpenAI, selected server-side; the providers in use and their retention terms will be published before the public beta. AI output is labelled AI-generated, may be wrong, and never silently changes your wellbeing records.
Encrypted backups
Backups are encrypted on your device before upload. We store the encrypted blob and its metadata; we cannot decrypt it, and we never receive your passphrase. That cuts both ways: if you lose the passphrase, we cannot recover the backup for you.
Who receives data
We use processors to run the cloud side: infrastructure and storage providers, Resend for email, Paddle for payments, Anthropic or OpenAI for AI requests you invoke, Sentry for opted-in crash reports, and Plausible for cookieless visit counts on the public landing page. When the AI Coach’s guided voice ships, spoken audio will be generated by a speech-synthesis provider, named on this page before the feature is enabled. Processors handle data for us under contract — we never sell personal data, and nobody receives it for advertising. Authorities or professional advisers may receive limited data where the law requires it.
International transfers
Some providers process data outside the EEA, mostly in the United States. Where they do, the transfer rests either on the European Commission's adequacy decision for the EU–US Data Privacy Framework, for providers certified under it, or on the EU standard contractual clauses together with the extra safeguards those require. Before the public beta we will publish, provider by provider, where processing happens and which safeguard applies.
How long we keep things
- Beta access requests: until the beta program ends or you ask us to delete yours.
- AI requests: your Diary text and the response are not stored in our database at all; provider-side retention follows the published provider terms.
- Content-free AI usage and telemetry records: 90 days.
- Encrypted backups: until you delete them or your plan’s cleanup rules remove them.
- Account, license, transaction, tax, and support records: as long as the contract, security, or a legal obligation requires, then deleted or anonymized.
- Crash reports already sent to Sentry follow Sentry’s configured retention; switching telemetry off stops future reports.
Cookies
The website sets exactly one cookie: a first-party antiforgery cookie (name beginning “.AspNetCore.Antiforgery.”) that protects forms such as the beta request and sign-in against cross-site request forgery. It is HttpOnly, SameSite=Strict, contains no tracking identifier, and expires with your browser session. Signing in to the account portal keeps your signed-in state in the browser’s own session storage — created only by your sign-in, never used for tracking, and cleared when the session ends. Plausible, where enabled, is cookieless. Because all of this is strictly necessary for things you explicitly ask for, EU ePrivacy rules require disclosure but not consent — which is why the site shows no cookie banner.
Analytics and diagnostics
Plausible loads only on the query-free public landing page, and only when production analytics are configured — never on account, sign-in, download, policy, or error pages. Desktop telemetry and Sentry crash reporting are off until you opt in, and they exclude by design: Diary and note text, task titles, AI prompts and responses, backup content, email addresses, keys, file paths, window titles, and anything you type.
Your rights and choices
In the product: keep cloud reflection off entirely, use Private Journal, exclude entries, inspect the exact scope before sending, keep or discard output, delete saved reflections, review and revoke approved memories, and withdraw Diary or telemetry consent at any time. Withdrawing consent stops future processing; it does not by itself delete what was already stored — the deletion controls and support do that.
Under the GDPR you can request access, correction, deletion, restriction, or portability, and object to processing. Write to support@runeka.com; we answer within one month, we may need to verify it’s you, and we won’t ask for more information than that verification requires. Exercising a right is free and never costs you the product.
You can also complain to the data-protection authority of the EU or EEA country where you live, where you work, or where the problem happened.
Living somewhere else does not mean fewer rights. The regional privacy supplement sets out what the law gives you in the United Kingdom, Switzerland, the United States, Canada, Australia, Brazil, Japan, South Korea, India, and South Africa — including the authority you can complain to. People in Washington and Nevada also have a separate Consumer Health Data Privacy Policy, because their law requires it to be published on its own page.
No profiling, no automated decisions
We do not use your Diary to build a hidden psychological profile or to make decisions with legal or similar effects about you. Licensing, quota, and fraud checks apply simple automated rules needed to run the Service; support can review a disputed outcome.
Security — and its honest limits
We minimize what we collect, encrypt data in transit, encrypt backups on your device, store desktop credentials with Windows DPAPI, and keep content out of logs and telemetry. No system is perfectly secure. And deleting a server-side record cannot erase copies you exported or data on your own devices.
Adults only
Runeka’s beta is for adults aged 18 or older. We do not knowingly invite minors, and the Service is not directed at children.
Changes and contact
If this notice changes in a way that matters, we will say so clearly before the change takes effect — an update never silently recreates a consent you withdrew. Read the Terms of Use and the AI & wellbeing disclaimer alongside this notice. Privacy: support@runeka.com. Support: support@runeka.com.
Last updated: August 18, 2026.
