Privacy
What we collect, why we have it, who else sees it, and how to get rid of it.
Last updated 16 September 2026
What we collect
- Account
- Your email address, your display name if you set one, and which workspaces you belong to. Sign-in is handled by Supabase Auth; we never see your password.
- What you run
- The URLs you test, the task and steps you write, and the personas you choose.
- What a run produces
- Screenshots of the pages the persona saw, the actions it took, what it reported thinking, and the report written from all of it.
- Email you send us
- The message and your address, kept so we can answer and follow up.
- Operational records
- Usage lines for each run (models used, tokens, browser minutes, cost), server logs, and error reports.
Screenshots capture whatever was on screen, including anything you typed into a form. Use test accounts and staging data, and keep real customer data out of a run.
Why we have it
To run the service you asked for, to keep it working and secure, to bill for it, and to answer you when you write to us. We do not sell personal data and we do not use your content to train models.
Who else processes it
- OpenAI
- Drives the personas and writes the report. Screenshots and page text are sent to the model. Data sent through the API is not used to train their models.
- Browserbase
- Runs the hosted browsers a persona drives, and records the session replay.
- Supabase
- Authentication, the database, and the screenshot store.
- Railway
- Hosts the application and the worker.
- Resend
- Sends our email: sign-in links, invitations, and notices when a run finishes. It sees your email address and the message.
- Cloudflare
- Runs our domain, and forwards email you send to our addresses to the person who answers it.
This is the whole list as of the date above. It changes when we add a service, and this page changes with it.
Our servers and data are in the United States. If you are in the UK or the EU, your information is transferred there under the standard contractual clauses our processors use.
How long we keep it
Runs, screenshots and reports stay until they are deleted. Deleting a run deletes its screenshots with it, immediately. Deleting your account removes your profile, your sign-in identity, and every workspace only you belong to, along with their runs and screenshots. A workspace you share with other people needs another owner first, or deleting. Backups roll off within 30 days. Usage lines are kept for accounting.
Your choices
You can see, correct, export or delete what we hold, without asking us. Delete a run from the run itself, export a report as Markdown, and delete your whole account under Settings. For anything else write to hello@runmeerkat.com and we will answer within 30 days. If you are in the UK or the EU you may also complain to your data protection authority.
Cookies
The app keeps a sign-in session in your browser, which is necessary for it to work. There are no advertising cookies and no third-party trackers on these pages.
Who to write to
Meerkat — hello@runmeerkat.com.