PRIVACY
Your financial data remains yours.
This policy describes the personal data Runaway processes, why it is processed, how long it is kept, and the rights available to you.
In force since 21 July 2026
Data controller
Runaway is operated by [to complete: operator legal name], a sole proprietor established at [to complete: business address]. This person determines the purposes and means of the processing described below and is the controller under the GDPR.
For any question or request about your data: [to complete: privacy email]. No data protection officer has been appointed, as the appointment is not mandatory for this activity.
Two modes of use, two levels of processing
In sandbox mode, Runaway works without an account: the plans you create stay in your browser storage and are not sent to our servers. Only the technical requests needed to display the site and fetch market data pass through our servers.
With an account, your plans are stored server-side so they can sync across devices. All of the processing described below then applies.
Data we process
- Account data: name, email address, email verification status, interface language and declared tax residence, and a hashed password.
- Plan data: amounts, assets, income, spending, accounts, holdings and assumptions you enter. This data is sensitive in the everyday sense, though it does not fall within the special categories of article 9 GDPR.
- Session and security data: session identifier, IP address and user agent tied to your sign-ins, technical and anti-abuse logs.
- Support data: name, email, subject and content of messages sent through the contact form.
- Subscription data, where a paid plan is taken: Stripe customer and subscription identifiers, subscription status and expiry. Card details are entered at Stripe and never reach us.
- Audience measurement and error data: pages viewed, aggregated technical data, application error reports.
Purposes and legal bases
- Providing the service, creating and managing your account, saving and syncing your plans — performance of the contract (art. 6(1)(b) GDPR).
- Managing a paid subscription, collecting payment, issuing invoices — performance of the contract and legal accounting obligation (art. 6(1)(b) and 6(1)(c)).
- Answering support requests — performance of the contract, or legitimate interest in replying to people who write to us without an account (art. 6(1)(b) and 6(1)(f)).
- Securing the service, preventing fraud and abuse, rate-limiting automated submissions — legitimate interest in protecting the service and its users (art. 6(1)(f)).
- Measuring site audience in aggregate and diagnosing application errors — legitimate interest in maintaining and improving the service (art. 6(1)(f)).
- Sending service emails (address verification, password reset, confirmations) — performance of the contract (art. 6(1)(b)).
Where processing relies on legitimate interest, you may object at any time under the conditions set out in "Your rights".
Cookies and audience measurement
Runaway only sets strictly necessary cookies and local storage: the authentication session cookie, interface preferences and, in sandbox mode, the local copy of your plans. These are exempt from consent, so no banner is displayed.
Site audience measurement uses Vercel Web Analytics, without cookies and without a persistent identifier that could track you across sites. No advertising cookies, no third-party tracking and no sale of data are involved.
Recipients and processors
Your data is never sold, rented or shared with third parties for advertising. It is accessible to the operator and to the following technical providers, which act only to deliver their service and on instruction:
- Vercel Inc. — hosting of the site and API, audience measurement.
- Neon Inc. — database hosting.
- Resend Inc. — transactional and support email delivery.
- Functional Software, Inc. (Sentry) — application error reports, configured not to forward personal information by default.
- Stripe, Inc. and Stripe Payments Europe, Ltd. — payment and subscription management, where a paid plan is taken.
- Market data providers — called server-side for quotes and exchange rates; no personal data is sent to them.
Data may also be disclosed to an administrative or judicial authority where the law requires it.
Transfers outside the European Union
Some of the providers above are established in the United States or may process data there. Those transfers rely on the European Commission’s standard contractual clauses and, where the provider is certified, on the EU–US Data Privacy Framework, supplemented by the technical measures applied to the service, in particular the encryption of plans before storage.
You can ask for details of the safeguards applying to a specific provider by writing to [to complete: privacy email].
Retention periods
- Account and synced plans: for the life of the account, deleted when the account is deleted.
- Inactive accounts: deleted after three years without sign-in, preceded by an email reminder.
- Sessions and security logs: twelve months at most.
- Support messages: three years from the last exchange.
- Invoices and accounting records: ten years, under article L123-22 of the French commercial code.
- Audience measurement data: kept in aggregate form, with no way to re-identify you.
Deleting your account from the app cascades to your plans, sessions and sign-in credentials in the application database. Only records subject to a legal retention obligation are kept, separated from day-to-day use.
Security
Plan contents and plan names are encrypted before being written to the database (AES-256-GCM). The encryption key is held server-side: this protects data at rest, it is not end-to-end encryption, and the operator remains technically able to decrypt data where the service requires it.
Passwords are stored hashed, never in clear text. Account access relies on signed sessions, email verification and attempt rate-limiting. Traffic to the service is encrypted in transit. No system is infallible, so these measures reduce risk rather than remove it.
No automated decision-making
Runaway makes no decision producing legal effects concerning you based solely on automated processing, and performs no profiling for advertising. The projections shown are hypothetical simulations built from the assumptions you choose: they inform you, they do not decide for you.
Your rights
You have the rights of access, rectification, erasure, restriction, objection and portability, as well as the right to give directions on what happens to your data after your death. Where processing relies on your consent, you may withdraw it at any time without affecting processing already carried out.
To exercise these rights, write to [to complete: privacy email]. You will receive a reply within one month, extendable by two months for complex requests. Proof of identity may be requested where there is serious doubt about the requester's identity.
You may also lodge a complaint with the French data protection authority: CNIL, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, www.cnil.fr.
Changes to this policy
This policy may change as the service evolves. Any substantial change will be signalled by email or in the app before it takes effect. The effective date of the current version appears at the top of this page.