Privacy Policy
Last updated August 2026
On this page
RunKey rents GPU compute, metered by the second. This policy describes the data that takes, and it is written to match what the system actually stores rather than what a policy usually says.
1. What we collect
- Account: your email address, an optional display name, and a hashed password. The password itself is never stored.
- SSH public keys you add, with the name and fingerprint shown in Settings. Public keys only — we never ask for and cannot use a private key.
- Instances: which GPU and node you deployed, when it started and stopped, its specifications and address, and the event log for that instance.
- Balance and statement: your credit balance and the transactions that moved it — top-ups and metered usage.
- Payments: which pack was bought, the amount, the state of the payment and the reference our payment provider gave it. No card number, expiry or CVC ever reaches RunKey.
- Support messages you send us by email, and whatever you choose to put in them.
- Server logs: requests to the API with their path, status and timing, kept for debugging and abuse handling. Network-level logs at our hosting layer may include IP addresses.
We run no advertising trackers, no third-party analytics and no session recording. The site loads no third-party scripts at all.
2. How we use it
- To run the service: start instances, meter them, keep your balance right and show you what is running
- To let you into your instances — your public keys are written into each one you deploy
- To take payments and put the credits on the correct account
- To answer support and investigate what happened to a specific instance or payment
- To detect fraud, abuse and payment reversals
- To meet legal and accounting obligations
We do not sell personal data, and we do not use your data or your workloads to train models.
3. Payments
Card processing is done by third-party payment providers. When you start a payment we send them the pack you picked, a reference for the purchase and the email address on your account so they can bill and receipt you. They send back whether the payment succeeded, and a reference of their own.
That is the whole exchange: your card details are entered on their page, held by them, and are never visible to RunKey. Their own privacy policy governs what they do with them.
4. Your instances
The underlying hardware is operated by third-party node operators sourced through a GPU marketplace. Deploying an instance sends that marketplace what it needs to start it: the specification and a startup script containing the SSH public keys on your account and the credentials that instance's panel will use. Your email address, password and payment history are not sent.
What you then do on the instance is outside our systems. We do not read your disk, your processes or your traffic — but it runs on hardware operated by someone else, and that operator has the access this implies. Treat an instance accordingly: keep secrets you cannot afford to expose off it, and copy off anything you want to keep before terminating, because the disk is destroyed with the instance.
The panel on each instance reaches the outside through a relay we run. The relay carries that traffic; each instance has credentials of its own, and the panel is opened with a link that is valid for under a minute.
5. Who else sees it
We share the minimum needed to run the service, with:
- The GPU marketplace and node operators — as described above, to start and run your instance
- Payment providers — to take a payment and match it back to the purchase
- Our own infrastructure providers — the hosting the console and API run on
- Authorities — where we are legally required to, and only to that extent
- A successor — if the service were ever sold or merged, with this policy carried over
6. Cookies
One cookie holds your login session, and a second is set only for operators signing into the operations console. Both are HttpOnly and neither is used for tracking. There are no advertising or analytics cookies, and nothing third-party sets one either — so there is no cookie preference to manage. Signing out clears the session.
7. How long we keep it
- Account data — while the account exists.
- Instances, transactions and payment records — kept after the instance is gone, because they are the accounting record behind what you were charged. We keep them as long as tax and fraud rules require.
- SSH keys — until you delete them; deleting one removes it from the account, but not from an instance already running with it installed.
- Sessions — until they expire or you sign out.
- Instance disks — not retained at all. They are destroyed with the instance, and we hold no copy.
8. Security
Traffic to the console and API is served over TLS. Passwords are hashed with bcrypt. Each instance's panel credentials are unique to it and are never returned by the API, rendered in the console, or written to a log — a shared secret there would let one customer reach another's instance, which is exactly why there isn't one.
We hold no card data, which removes the most sensitive class of information from the problem entirely. We make no certification claims: RunKey is a small service, and no method of storage or transmission is perfectly secure.
9. Your rights
Depending on where you live you may have the right to access, correct, export or delete your personal data, to object to some processing, or to complain to your data protection authority. Your name and password can be changed in Settings, and your SSH keys added and removed there.
Closing the account is self-service: Settings → Close this account, confirmed with a code we email you. That deletes your address, your name, your SSH keys and your sessions, and releases the address so you could sign up again with it later. The transactions and payments stay, with no address attached to them, because they are the accounting record behind money that moved — it is the one thing we are not free to delete. For anything else, including a copy of your data, write to support@runkey.ai from the address on the account.
10. Where data lives
Our database and the console run on infrastructure we operate. The instances you rent may be in any region the marketplace offers — the region is shown before you deploy, so where your workload runs is your choice. Payment providers process data in their own regions under their own terms.
11. Changes and contact
We may update this policy; the current version is always on this page with the date it was last changed at the top. For questions, or to exercise any of the rights above, contact support@runkey.ai.