Legal
Privacy
Factual description of what this product stores. Not legal advice. Last updated 2026-09-10.
Account
Creating an account stores your email, name, and authentication credentials in Supabase Auth on the RunbookHQ project. Profile fields you edit (display name, avatar) live in the app's user row. We do not sell this.
Organization content
Scripts, runbooks, standards, reports, comments, files, and settings belong to the organization you put them in. Members see what membership, module grants, named groups, and restricted-folder grants allow. Hosted MCP uses the same access rules as the workbench.
Cookies on this site
First-party cookies keep you signed in, remember appearance, remember the last organization, and remember whether this browser is a phone or a workbench. They are not advertising cookies.
Auth messages (confirm, reset) go through Resend SMTP as noreply@runbookhq.app. Invitation mail uses the Resend API. We send those because you asked for an account or an invite — not a newsletter.
Payments
When Stripe is connected, Checkout and the Customer Portal run on Stripe. Card numbers stay with Stripe. We store plan, status, and Stripe customer/subscription ids on the organization billing row so entitlements can be shown.
Analytics
Public marketing and auth pages send cookieless pageviews to Vercel Web Analytics (same host as the site). Query strings are stripped. Workbench, share, and invite URLs are not sent. Speed Insights records Core Web Vitals on marketing pages only.
Feedback
The Feedback link opens Featurebase in a new tab. What you post there is on Featurebase's service, not in this database.
What we do not do
We do not run your scripts or report generators on the server. Desktop confirms on your computer; output stays there. We do not add a second analytics vendor. We do not sell personal data.
Your choices
You can leave an organization, revoke MCP tokens, and turn off share links. To close an account, use Feedback and say so. Terms cover use of the service.