Privacy policy
What the hosted copy of Runlog stores about you, where it is, and how to have it deleted.
Version 2026-09-06 · applies from 2026-09-06
The short version:
- Without an account, nothing about you leaves your browser. There are no analytics and no tracking cookies.
- With an account, we store your runs and packs so they can reach your other devices and the people you invite.
- We keep the address you sign in with, and the addresses you invite, and nothing else about anyone.
- Deleting your account deletes what we hold, at once, from the app.
1. Who is responsible
SCRT HQ operates the service at runlog.scrthq.com and is the controller of the personal data described here.
Contact: runlog@scrthq.com.
Confirm the legal entity, whether a representative in the EU or UK is required, and whether a data-protection officer must be named.
2. Using the app without an account
The app runs in your browser. Your packs, runs, settings and any license keys are kept in the browser's own storage on your device. They are not sent to us. The only requests your browser makes are for the app's files and, when you open the catalog, for the list of packs. Nothing about those requests is kept (see section 6).
The same app can be downloaded and run from a file on disk, in which case no request reaches us at all.
3. What an account adds
When you sign in, we store on our servers:
- Your sign-in
- Handled by WorkOS, which holds your email address, your name if you gave one, and the passkey, password or provider you sign in with. We receive an identifier, and the app reports the name and address to us so we can show them and address invitations.
- Your runs
- Every move in a synced run, with the time it was made and which account made it, so devices can share the run.
- Your packs
- Packs you have switched sync on for, in full, so your other devices can play them. Packs marked not redistributable are still only ever shown to you.
- License keys
- The keys for sealed packs you have bought or been given, so they follow you between devices.
- Invitations
- The email address you invite, who invited them, which run, and whether the invitation was used. We send one email to that address and nothing else, ever.
- People you played with
- A list of accounts you have shared a run with, so the next invitation is a name rather than an address.
- Your profile
- When the account was first seen and last seen, the run you touched last, which version of the terms you accepted, and — when plans are on — which plan you are on.
- Command-line keys
- A hashed copy of any API key you make for publishing from the command line, with its label and when it was last used.
4. Payments
When plans and the marketplace are switched on, payments are taken by Stripe. Stripe holds your card details; we never see them. We keep the Stripe customer identifier, which plan you are on, and for a purchase: which pack, the amount, when, and the address the receipt went to. A publisher sees the sale in their ledger with the buyer's email address, because a license belongs to a person and they may need to reissue it.
Confirm the basis for sharing the buyer's address with the publisher (contract performance) and whether it should be named in the checkout consent.
5. Why we process this, and on what basis
- To provide the service you asked for: sync, invitations, purchases (performance of a contract).
- To keep the service secure and to answer support: service logs, key hashes (legitimate interest).
- To send the one invitation email a player asked us to send (legitimate interest of the inviter; you can ignore it).
- To meet legal duties around payments and tax (legal obligation).
We do not profile you, we do not advertise, and we do not sell or rent any of this.
6. Logs
The edge keeps no access logs. The API keeps a service log: when a request failed and why, with no request body and no addresses, so that problems can be found. Those lines are kept for one month by Amazon CloudWatch and then deleted. Sign-in attempts are logged by WorkOS under its own policy.
7. Who else sees data
We use these providers, each under its own terms, to run the service:
- Amazon Web Services
- Hosting, storage and email, in the United States (us-east-1 and us-west-2).
- WorkOS
- Sign-in and sessions.
- Stripe
- Payments and payouts, when plans are on.
Data is stored in the United States. If you are in the EU, UK or another place with rules on transfers, those transfers rest on the providers' standard contractual clauses.
Confirm data-processing agreements are in place with each provider and that the transfer mechanism is named correctly.
8. How long we keep things
- Account data: until you delete your account.
- Invitations: seven days if unused; the record of an accepted one lives with the run.
- Purchase records: for as long as tax law requires, typically seven years, even after the account is closed.
- Service logs: one month.
Decide whether dormant accounts should be deleted after a fixed period, and add it here once the sweep exists; nothing deletes an account today but its owner.
9. Your rights
You can see everything we hold from your profile in the app, export your runs and packs at any time, and delete your account with one button, which deletes what we hold immediately. Purchase records stay for the period above. Depending on where you live, you also have rights to access, correct, restrict, port and object, and to complain to a supervisory authority; write to runlog@scrthq.com and we will answer within a month.
10. Children
The service is not directed at children under 16, and we do not knowingly hold an account for one. If you believe we do, tell us and we will delete it.
11. Changes
When this policy changes in a way that matters, the app asks you to read and accept it again, and the version and date at the top change.