Runer←Volver al inicio

Política de privacidad

Última actualización: 2026-08-12

This Privacy Policy describes how Runer(“Runer”, “we”, “us”, or “our”) collects, uses, and discloses information when you use the Runer website at runerapp.com (the “Site”) and the Runer desktop application (the “App”, collectively the “Service”).

We have tried to keep this policy plain and short. If anything is unclear, email us at hi@runerapp.com.

1. Who We Are

Runer is a foreign-language reading and vocabulary application. The Site is a marketing and email signup page. The App is a desktop client that runs locally on your computer and stores your library, vocabulary, and reading data on your device.

Runer is operated by an independent developer. For privacy requests, email hi@runerapp.com.

2. Information We Collect

2.1 On the Site (runerapp.com)

DataPurposeLegal basis (GDPR)
Email address (updates)To send Runer release updates, early-bird pricing, and major noticesConsent
Country code (derived from IP at request time; IP itself is not stored)Regional statisticsLegitimate interest
Privacy-preserving traffic analytics (page views, referrer, device class) via Vercel Web AnalyticsUnderstand site performanceLegitimate interest
Website usage analytics (page views, referrer, device, and approximate location) via Google AnalyticsUnderstand site performanceLegitimate interest
Download attribution data: UTM campaign fields, external referrer domain, internal Runer tool path, landing path, country code, locale, and selected app package detailsUnderstand which promotions and Runer tools lead to app downloadsConsent

We use Google Analytics to understand how the Site is used. Google Analytics may set cookies and process technical, usage, and approximate location data under the Google Privacy Policy. We do not use Google Analytics for advertising, remarketing, or cross-site advertising identifiers.

If you allow download attribution, we store tagged promotion, external referrer, or internal Runer tool attribution in a first-party, HTTP-only cookie for up to 30 days. External referrers are reduced to the domain name; paths are retained only for pages on runerapp.com. We do not store your IP address, full external referrer URL, or chosen download mirror in download attribution records.

A necessary first-party preference cookie remembers your allow or decline choice for up to 180 days. You can change that choice using Cookie settings in the Site footer. Declining or withdrawing consent deletes the attribution cookie and stops download attribution storage.

2.2 In the App

The App is local-first. Your books, highlights, notes, and vocabulary are stored on your device only. We do not have access to them.

The App may send a periodic pseudonymous heartbeat containing:

  • A keyed hash of a randomly generated installation fingerprint (not directly reversible to your identity)
  • App version
  • Operating system family (e.g., “macOS”, “Windows”)
  • Release channel, if provided by the App
  • Client timestamp, if provided by the App
  • Country code derived from your IP at request time (IP itself is not stored)

The heartbeat helps us count active installations, understand version adoption, and protect the endpoint from abuse. It does not include your name, email, files, reading history, or any personally identifying content.

2.3 Information We Do Not Collect

  • We do not collect your books, documents, highlights, notes, or vocabulary entries.
  • We do not collect your reading history or reading behavior.
  • We do not sell or rent any data to third parties.

3. Service Providers

We use the following service providers to operate the Service. These providers process data on our behalf under their own privacy policies.

ProviderPurposeData processedLocation
Vercel Inc.Website hosting, Web Analytics, edge networkIP address (at request time), request metadata, aggregated page-view eventsUnited States and global edge locations. Privacy policy
Supabase Inc.Email subscription storage, heartbeat counter databaseEmail address, locale, promotion and download attribution, device hash, country code, app version, platform, release channel, timestampsAWS us-west-1. Privacy policy

If you are located in the European Economic Area, the United Kingdom, or another jurisdiction with cross-border data-transfer restrictions, please note that your data may be transferred to and processed in the United States. We rely on the standard contractual clauses and the providers’ compliance programs as the legal mechanism for such transfers.

4. Bring Your Own Key (BYOK) — AI Providers You Configure

Runer follows a Bring Your Own Key (BYOK) model for AI features (translation, sentence analysis, etc.).

This means:

  • You sign up directly with the AI provider of your choice and obtain your own API key.
  • You enter that API key into the App. The key is stored locally on your deviceand is never transmitted to Runer’s servers.
  • When you use an AI feature, the App sends your request (e.g., a sentence to translate) directly from your device to the AI provider you selected, using your key.
  • Runer does not receive, see, store, log, or proxy this AI traffic. We have no access to the content of your requests or responses.

Because of this, the AI provider you choose becomes an independent data controller for the data you send them. Their privacy policies, terms of service, and jurisdiction govern that data. We strongly recommend you read the privacy policy of any provider before configuring it.

Providers currently supported

Listed for transparency. Inclusion does not imply endorsement. Availability and applicable laws differ by region — please choose providers appropriate to your jurisdiction and data-sensitivity needs.

Runs locally on your device — no third-party data transfer:

  • Ollama — local inference, runs entirely on your machine.

Servers in the United States / international:

  • OpenAI — OpenAI Privacy Policy
  • Anthropic — Anthropic Privacy Policy
  • Google Gemini — Google Privacy Policy
  • z.ai — z.ai Privacy Policy
  • MiniMax (Global) — MiniMax Privacy Policy
  • OpenRouter — OpenRouter Privacy Policy

Servers in mainland China:

  • DeepSeek — DeepSeek Privacy Policy
  • MiniMax (China) — MiniMax Privacy Policy
  • Moonshot — Kimi Privacy Policy
  • Kimi (China) — Kimi Privacy Policy

Some of the above providers store data in mainland China and are subject to Chinese law, including the Personal Information Protection Law (PIPL) and the Cybersecurity Law. If you are located outside mainland China and choose one of these providers, your data may be transferred to and processed in China. Please review the provider’s policy before use.

5. How Long We Keep Your Data

  • Email subscription: until you ask us to remove it, or until we no longer need the address for release updates, early-bird pricing, and major product notices.
  • Download attribution records: retained in pseudonymous form to compare promotion sources and download trends. The first-party attribution cookie expires after 30 days, and the consent preference expires after 180 days.
  • Heartbeat records: retained in pseudonymous form to measure active installations, version adoption, and regional usage trends. These records are not linked to your email, files, or reading content.
  • Server logs (Vercel): retained per Vercel’s standard policy (typically 30 days).

6. Your Rights

Depending on where you live (GDPR, UK GDPR, CCPA, PIPL, etc.), you may have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate data
  • Delete your data (“right to be forgotten”)
  • Object to or restrict processing
  • Withdraw consent at any time
  • Lodge a complaint with your local data-protection authority

To exercise any of these rights, email hi@runerapp.com. To delete your subscription email, please contact us from the same email address when possible. Since the only directly identifying personal data we hold for most users is an email subscription address, deletion usually takes a single request.

California residents: we do not “sell” or “share” personal information as those terms are defined under the CCPA/CPRA.

7. Children

Runer is not directed at children under 13 (or under 16 in the EEA/UK). We do not knowingly collect data from children. If you believe a child has provided us with information, please contact us and we will delete it.

8. Security

We use industry-standard measures: HTTPS everywhere, hashed device identifiers, restricted database access, and least-privilege service credentials. No system is perfectly secure; if you discover a vulnerability, please email hi@runerapp.com responsibly.

9. Changes to This Policy

We may update this Policy from time to time. Material changes will be announced on the Site and, where required, by email. The “Last updated” date at the top reflects the most recent revision.

10. Contact

Email: hi@runerapp.com

For any privacy-related question, please reach out — we read every message.

Runer
© 2026 Todos los derechos reservados.
  • Conversor de subtítulos
  • Términos de uso
  • Política de privacidad