RuneSpoke
InvestorsDocs

Compliance

Last Updated: 2026

RuneSpoke is committed to handling data responsibly and to supporting our customers' own compliance obligations. As a cloud-hosted, AI-native developer platform, we process code, project data, and configuration on your behalf. This page describes how we process data, our posture toward privacy regulations such as the GDPR and CCPA, the subprocessors we rely on, our retention and deletion practices, and our certification roadmap.

Data Processing

We process customer data only to provide and improve the Service, to support and secure it, and to comply with applicable law. For most customer data, you are the data controller and RuneSpoke acts as a data processor that handles data according to your instructions and these terms. We do not sell customer data, and we do not use your private code to train our own models. AI requests are routed to the AI providers you connect under your own Bring Your Own AI keys, and the handling of data by those providers is governed by their terms.

GDPR Posture

For customers and end users subject to the EU and UK General Data Protection Regulation (GDPR), we support the rights afforded to data subjects, including access, rectification, erasure, restriction, portability, and objection. We process personal data on recognized lawful bases, limit processing to what is necessary, and are prepared to enter into a Data Processing Addendum that incorporates standard contractual clauses for international transfers where required. Requests relating to GDPR rights can be sent to legal@runespoke.ai.

CCPA Posture

For California residents covered by the California Consumer Privacy Act (CCPA), as amended by the CPRA, we support rights to know, access, correct, and delete personal information, and the right to opt out of any sale or sharing of personal information. RuneSpoke does not sell personal information. We act as a service provider with respect to customer data and process it only for the business purposes described in our agreements. Requests can be sent to legal@runespoke.ai.

Subprocessors

We use a limited set of subprocessors to deliver the Service. These include:

  • Cloud infrastructure. Amazon Web Services (AWS) for hosting, compute, storage, and networking.
  • Managed database and storage. Our managed PostgreSQL provider for application data, backups, and authentication.
  • AI providers you choose. Under the Bring Your Own AI model, requests are routed to the third-party AI and inference providers you connect with your own keys. Data sent to those providers is governed by their terms and your configuration.
  • Operational tooling. Email, analytics, and monitoring services used to communicate with you and to keep the Service reliable and secure.

We will maintain an up-to-date list of subprocessors and provide notice of material changes on request. Contact legal@runespoke.ai for the current list.

Data Retention and Deletion

We retain customer data for as long as your account is active or as needed to provide the Service. When you delete data or close your account, we delete or anonymize the associated personal data within a commercially reasonable period, except where we are required to retain it for legal, accounting, or security reasons. Backups are retained on a rolling basis and are purged in accordance with our retention schedule. Upon termination, we make customer data available for export for a reasonable period before deletion.

SOC 2 Roadmap

We are actively working toward SOC 2 Type II. This effort is in progress and on our roadmap, including formalizing controls around security, availability, and confidentiality, and preparing for independent audit. We have not yet completed the certification and do not claim to currently hold it. We are happy to share our progress and supporting documentation with prospective customers under appropriate confidentiality.

Contact Us

For compliance, privacy, and data protection inquiries:
Email: legal@runespoke.ai
General inquiries: hello@runespoke.ai
RuneSpoke, Walnut Creek, CA

This page is a general overview of our compliance posture and is not a substitute for your own legal review or due diligence. Please consult your legal counsel and contact us if you require additional documentation for your evaluation.