Updated September 5, 2026
Privacy
Self Runtime stores the personal context you choose to add, and shares it only through the connections you authorize. Here is what that means in practice.
Your context and your choices
You decide which claims to add, confirm, correct, export or delete. An application can read only the exact fields allowed by its active grant. Sensitive categories require additional permission. Imported facts always require your confirmation. Application suggestions require review unless you explicitly authorize eligible automatic updates for that connection.
We do not sell personal context. The service does not use vault contents to train models. Access for personalization does not give an application permission from Self Runtime to use your context for unrelated purposes.
What the service stores
- Account information: your name, email, authentication records and active sessions. If you choose an enabled social sign-in option, the identity provider supplies information needed to sign in.
- Personal claims: values, namespaces, labels, sensitivity, source, confidence, validity and previous versions. Claims you supersede remain in your history until deleted with the vault.
- Connections: application names, purpose, approved fields, permissions, expiry, retention declarations and optional webhook and privacy-policy URLs.
- Activity: context reads, claim changes, delivery attempts and application acknowledgements. These records help you inspect how access was used.
- Billing: plan and payment-provider references when paid billing is enabled. Stripe handles payment details; the application does not store card numbers.
- Operational information: request and error records needed to operate and troubleshoot the service. Do not place personal values in webhook URLs or application names.
Imports and proposals
Selected chat exports, including a ChatGPT ZIP containing conversations.json, and PDF, Markdown, text and Word (.docx) files can be processed into proposed claims. The raw upload is not retained after extraction. Structured suggestions and source references, including filenames or evidence excerpts, are stored for review. Review filenames and document contents before uploading.
Structured namespace/value imports can be processed without an external AI provider. Natural-language extraction may send selected content to the configured Anthropic provider only with your explicit extraction consent. Suggested facts remain proposals until you confirm them. Uploading does not automatically authorize another application to read them.
When another application receives information
A connection uses a secret grant token. A successful context read returns current, confirmed claims within the grant's scopes and records a receipt. Grant tokens should be given only to the intended application and kept out of public code or shared conversations.
Change events identify that a permitted field changed without including its previous or new value. A connected application must make an authorized context read to receive the current value. If you enable proposals, that application may suggest changes for you to review. A separate automatic-update permission, disabled by default, lets it make approved non-sensitive fields current when the submitted facts are valid now. Sensitive and future-dated changes still require review. Application provenance and version history remain attached, and you can disable the permission or revoke the connection. This permission does not apply to document or text imports.
The application's purpose and retention period are declared commitments. Self Runtime can control access through its own API, but cannot inspect every copy an application makes or enforce deletion outside the service. Review an application's own privacy policy before granting access.
Revocation, expiry and deletion
Revoking or expiring a grant stops future context reads and updates through the service. Revocation can request downstream invalidation; it does not guarantee erasure of data already received. An acknowledgement records what the application reports.
You can export the vault, copy a current context card, reset your vault or delete your account through the application. Resetting the vault removes its stored claims, connections and activity. Account deletion also removes the account and ends its paid subscription when applicable. It does not delete copies held by connected applications.
Operational backups and provider records may have separate retention periods. Deleting active application records does not represent immediate erasure from every backup. Contact us for information about a particular deletion request or billing record.
Storage and service providers
Self Runtime is a hosted, server-side service. It is not a zero-knowledge or local-only vault. Authorized service operations can process stored context to provide the features you request.
Hosting, database, authentication, transactional email and payment services may process information needed to operate the deployment. Stripe processes paid billing when enabled. Anthropic processes selected import content for AI extraction when configured and explicitly consented to. Email and social sign-in providers are used only when configured and relevant to your request. Contact us for the current service-provider information for your account.
Cookies and website analytics
The application uses cookies to maintain your signed-in session. The public website can load Google Analytics to measure visits and interactions. Google Analytics may use cookies for this purpose. This analytics tag is limited to the public website and is not installed in the private vault application.
Keeping access secure
Protect your sign-in credentials and grant tokens. Revoke or rotate a token if it may have been exposed. Sensitive personal information should be added only when you understand the receiving application's purpose and handling practices.
Report a suspected security issue to security@selfruntime.dev. Avoid sending sensitive vault contents in an initial report.
Questions and requests
For access, correction, deletion or privacy questions, contact privacy@selfruntime.dev. We may need to verify that a request relates to your account. The date above identifies the current version of this notice; material changes will be reflected here and communicated where appropriate.