Legal
Last updated August 2026.
This policy explains what Runwisely ("we," "us") collects when you use runwisely.com and the Runwisely application, why we collect it, and how you can have it deleted. It covers everyone who visits the site, signs up, or connects a third-party account (like Google Calendar) to a Runwisely agent.
Runwisely is built BYOK (bring your own key): the AI provider keys and connected-service credentials you give us are used only to act on your own behalf, at your own provider's cost — we never see, log, or resell them. The sections below are specific about what that means in practice.
Your idea and interview answers are sent, once, to Anthropic's API to generate your org chart — this first pass is funded by Runwisely's own capped platform key, not yours, so signing up never costs you anything before you've decided to continue. Every AI call after that point runs on your own connected key, billed to you directly by your provider, and is used only to do the work you've configured your agents to do.
Account information authenticates you and scopes every request to your own organization's data — enforced at the database level (row-level security), not just in application code, so one tenant's data is structurally invisible to another's session.
When you connect a third-party service, we request the narrowest access that lets the specific agent do its specific job — never broader "just in case" access.
https://www.googleapis.com/auth/calendar.events. Used only by your Scheduling and Event coordinator agents, only when connected, to read and create calendar events on your behalf — for example, booking an appointment or flagging a scheduling conflict. We never request broader Calendar access, and we never read or modify any calendar you haven't explicitly connected.Every connected-service token is bound to one specific agent and one specific capability at the moment you connect it — an agent can never use a token to act outside the job you connected it for, and a token for one service can never be read or reused by a different agent. You can disconnect (revoke) any connected service at any time from within the app; the agent it powered goes back to drafting for you to send yourself, nothing else changes.
We don't sell your data, and we don't share it for advertising. We share only what's operationally necessary:
Every key and connected-service credential is envelope-encrypted at rest — a per-tenant encryption key protected by a master key, never stored as plaintext. Decryption happens only for the single call that needs it, in memory, for that call's duration, then the plaintext is discarded — never written to disk, logs, or anywhere an AI model itself could read it back. The application UI only ever shows a masked fingerprint (like sk-...4f2a) once a key is connected, never the real value again.
You can request deletion of everything we hold about you — your account, business data, and any connected-service credentials and tokens — at any time. Email privacy@runwisely.com from the address on your account and we'll confirm and complete the deletion within 30 days. If you connected a service through Meta (Facebook/Instagram), see our data deletion instructions page for that path specifically, including how to revoke access directly from your Meta account.
Revoking a single connected service is faster and doesn't require an email — do it anytime from within the app, and that one credential is purged immediately.
Questions about this policy, or anything else data-related: privacy@runwisely.com.