Privacy notice

The short version: no tracking and no advertising. We use only a few small cookies that the site and console need to work. We store only what you give us, and you can download or delete it at any time.

Last updated: 25 September 2026

1. Who is responsible

The controller under the EU General Data Protection Regulation (GDPR) is:

Runemic Labs
[Full name of the owner or company]
[Street and number]
[Postcode and city], Germany
Email: hello@runemic.com

2. Visiting the website

runemic.com is a static website hosted on GitHub Pages (GitHub, Inc., USA). When you open a page, your browser sends technical data such as your IP address, the page requested, date and time, and browser type. GitHub processes this data to deliver the site and keep it secure; we do not receive or store it. Domain name resolution is provided by Cloudflare (Cloudflare, Inc., USA).

Legal basis: our legitimate interest in providing a secure, working website (Art. 6(1)(f) GDPR).

  • No analytics, advertising or tracking tools, and no tracking cookies.
  • Fonts and images are served from runemic.com itself; no requests are sent to Google or other font or ad services.
  • Two small functional cookies may be set on runemic.com and its subdomains: theme remembers light or dark mode (1 year), and rk_signed_in tells the website that you are signed in to the console so it can show "Open console" (30 days; it contains no personal data). Your theme choice is also kept in your browser's local storage.

3. The early-access form

If you join the early-access list, we store the details you enter: email address (required), and optionally your name, area of interest, languages or scripts, and what you want to read, together with the page you signed up from and the time.

Purpose: to invite you to Runemic products and contact you about early access. Legal basis: your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time by emailing us, and steps at your request before a possible contract (Art. 6(1)(b) GDPR).

The form is processed by our API at api.runemic.com, which runs on Cloudflare Workers, and stored in a Cloudflare D1 database located in Western Europe. To protect the form against abuse, your IP address is used briefly to limit the number of requests; it is not stored. The form gives the same answer whether or not an address is already on the list, so nobody can use it to find out who signed up.

How long: until you ask us to remove you, or at the latest 24 months after our last contact with you.

4. Runemic Console and API

If you sign in at console.runemic.com, you do so with your GitHub or Hugging Face account. We receive and store your account ID, username, display name, email address and profile picture link from that provider. We never see or store your password. If you create your account from the free OCR tool, we note that on the account (to count how many sign-ups the tool brings); your earlier use of the tool is not linked to it.

  • Cookies: __Host-rk_session keeps you signed in for up to 30 days (a random token; we store only a fingerprint of it), and __Host-rk_oauth_state protects the sign-in step for 10 minutes. When an AI assistant asks to connect, __Host-oauth-consent ties the "Allow" page to your browser for a few minutes. All are strictly necessary.
  • API keys: stored only as fingerprints, so nobody, including us, can read them back.
  • Connected apps: when you let an AI assistant (such as Claude or ChatGPT) use your account, we keep the app's name, what you allowed and when, and its access tokens as fingerprints. Disconnect it at any time in the console; deleting your account disconnects every app.
  • Usage records: time, model, number of pages, cost and status of each request, to show your usage and credit balance and to prevent abuse.
  • Your documents: images you send to the API or the playground are processed by the selected model on Cloudflare Workers AI and returned to you. We do not store them and do not use them for training.

The free OCR tool (runemic.com/try). You can use it without an account. The image you upload is sent to the model on Cloudflare Workers AI and the text is returned to you; the image is not stored and not used for training. To limit free use to a few pages a day, api.runemic.com sets one cookie, rk_try: a random, signed ID with no personal data that only counts your free pages (30 days). We also count pages per network using the daily keyed IP hash described below. These counts are deleted after at most 7 days. Legal basis: our legitimate interest in offering a free tool without it being misused (Art. 6(1)(f) GDPR); the cookie is strictly necessary for that.

Preventing abuse. The preview is free, so we protect it against misuse:

  • We count requests and pages per network using a keyed hash of your IP address that changes every day. It cannot be turned back into your IP address or linked across days, and it is deleted after at most 7 days.
  • If you delete your account, we keep only an irreversible hash of your GitHub or Hugging Face account ID for 12 months, so that the free credit can't be claimed twice and a block can't be avoided by deleting and re-creating an account.
  • We may block accounts that break our terms or put the service at risk for others. A blocked account can't use the console or its API keys, sees a reference number, and can contact us, download its data or ask us to delete it. Blocks and their reasons are recorded in an internal log.

Legal basis: providing the service you signed up for (Art. 6(1)(b) GDPR) and our legitimate interest in keeping the service secure and fair for everyone (Art. 6(1)(f) GDPR). How long: for as long as your account exists. You can download all your data or delete your account yourself under Settings in the console, or email us.

5. Emailing us

Emails to hello@runemic.com are forwarded by Cloudflare Email Routing to a mailbox hosted by Google (Google Ireland Ltd. / Google LLC). We use your message and address only to reply to you and keep the conversation for as long as needed for that purpose.

6. Service providers and transfers outside the EU

We use these providers to run the site; they process data only on our behalf or as described above:

  • GitHub, Inc. (USA): website hosting
  • Cloudflare, Inc. (USA): DNS, console, API, AI models, database, email forwarding
  • GitHub, Inc. and Hugging Face, Inc. (USA): sign-in, if you choose them
  • Google (Ireland / USA): email mailbox

Where data is transferred to the USA, this is based on the EU–US Data Privacy Framework, under which these companies are certified, and on the EU Standard Contractual Clauses.

We do not sell your data, do not use it for advertising, and do not make automated decisions about you.

7. Your rights

You have the right to access your data, to have it corrected or deleted, to restrict or object to its processing, to receive it in a portable format, and to withdraw consent at any time with effect for the future (Articles 15–21 and 7(3) GDPR). In the console you can download your data and delete your account yourself under Settings; for anything else, email hello@runemic.com.

You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU member state where you live or work.

8. Changes

We will update this notice when our services change, for example when the Runemic API or the Runemic Scan app launches. The date at the top shows the latest version.