Privacy
Privacy Policy
RunWhale is local by design. This policy explains what stays on your device, what leaves it when you use connected services, and how the website is measured.
Last updated: September 2, 2026
Scope
This policy applies to the RunWhale mobile app and the runwhale.dev website. It does not replace the privacy policies of model providers, Git hosts, package registries, or other services you choose to connect.
Information handled by the app
RunWhale stores projects, Git history, agent sessions, attachments, preferences, project caches, and generated project data in the app’s local container on your device. Model-provider API keys are stored using the operating system’s secure storage.
RunWhale does not operate an account service or a cloud backend that stores copies of your app projects or agent sessions.
Information sent to services you choose
When you run an agent, RunWhale sends your prompt and the project or session context needed to answer it directly to the model provider you selected. Depending on your request, that context may include source code, file contents, images, tool results, and conversation history. Supported providers may include Anthropic, DeepSeek, Google, and OpenAI.
When you clone, fetch, pull, or push a repository, the app communicates with the Git host you specified. Installing dependencies may contact package registries. Those services process information under their own terms and privacy policies, and their retention rules are controlled by them and by your account settings.
Website analytics and hosting
runwhale.dev uses Google Analytics to understand aggregate website traffic and improve the site. Google Analytics may process information such as pages viewed, interactions, browser and device details, approximate location derived from an IP address, and cookies or similar identifiers. The site’s hosting and security providers may also process ordinary request and security logs.
Website analytics and infrastructure records are retained only as needed for measurement, reliability, and security, subject to the applicable provider settings and policies.
How information is used and shared
Information is used to provide the features you request, operate and secure the website, diagnose problems, and understand aggregate website usage. RunWhale does not sell your personal information or use app project content for advertising.
Information is shared only with services you direct the app to use, website infrastructure and analytics providers, or when required to comply with law, protect rights and safety, or investigate abuse.
Retention, deletion, and your choices
You control app data stored on your device. You can delete individual sessions or projects in RunWhale, remove saved API keys in Settings, or remove the app and its local data through your device. Deleting local data does not delete copies already sent to a model provider, Git host, package registry, or other third party; contact that service to exercise rights over data it controls.
You may limit website analytics using browser privacy controls, content blockers, or Google’s available opt-out tools. To ask about information controlled by RunWhale, request deletion, or withdraw consent where applicable, email runwhale@runwhale.dev.
Security and children
RunWhale uses technical safeguards appropriate to its local-first design, but no storage or transmission method is completely secure. Do not place secrets in project files, prompts, attachments, logs, or Preview output.
RunWhale is a developer tool and is not directed to children under 13. We do not knowingly collect personal information from children through the app.
Changes and contact
We may update this policy as RunWhale changes. The date above identifies the latest version. For product help, visit RunWhale Support. Questions and privacy requests can be sent to runwhale@runwhale.dev.