Last updated: 2026-07-06
Run402 provides cloud infrastructure — databases, APIs, authentication, storage, and static site hosting. Unlike a static website, Run402 necessarily stores and processes data to deliver its services. This policy explains what data we collect, how we use it, and how we protect it.
Run402 collects and stores the following data as part of normal service operation:
We use the data we collect exclusively for:
Run402 does not sell your data. We do not use your data for advertising. We do not train AI models on your data.
Your data lifecycle follows a ~104-day soft-delete grace. Your live site and end-user traffic keep working throughout — only the project owner's control-plane access (deploys, secret rotation, subdomain claims) is gated after day 14.
Any tier renewal, topup, or upgrade during grace instantly reactivates the project and clears the countdown. Server logs are retained for 30 days and then automatically deleted.
Data stored by the applications you build on Run402 — including end-user data collected by your apps — is your responsibility. You are the data controller for any personal data your applications collect. Run402 acts as a data processor on your behalf. You are responsible for ensuring your applications comply with applicable privacy laws (GDPR, CCPA, etc.).
Run402 uses the following third-party services:
Run402's own pages set no cookies and use no third-party analytics. To measure which ad campaigns deliver real users, if you arrive from an ad the page stores the click's attribution parameters (such as gclid and UTM tags) in your browser's local storage and sends them only to our own API.
Run402 is not directed at children under 13. We do not knowingly collect personal information from children. If you are a developer building an application directed at children, you are responsible for ensuring COPPA compliance in your application.
You may export your data at any time using the Run402 API while your lease is active. If you need to exercise data subject rights (access, correction, deletion) for data stored in your project's database, you can do so directly through the API. For requests related to Run402 organization-level data, contact legal@kychee.com.
We may update this privacy policy from time to time. The "last updated" date at the top of this page reflects when changes were last made. Continued use of Run402 after changes constitutes acceptance of the updated policy.
Privacy questions? Email legal@kychee.com.