Rumrunner

Rumrunner privacy policy — DRAFT

Each clause ends with the invariant or task that makes it true. A clause without one does not belong here. Invariants are numbered as in the product repo's CLAUDE.md; RR- tasks are in mikeypiro/rumrunner, OPS- tasks in this repo.

Rumrunner is made by Whatever, No Big Deal LLC ("we"). It is a program that runs on your Mac and decides, for each request your tools make, whether to answer it on your Mac or send it to a provider you chose.

1. What stays on your Mac

1.1 Your prompts and their context stay on your Mac. They leave it only when you have configured a nearshore or frontier route and the request is sent on that route. [invariant 1]

1.2 When a prompt does leave, it goes from your Mac directly to the provider you configured, authenticated with your own key. It does not pass through any server we operate. [invariant 1] [OPS-040]

1.3 Before a prompt leaves your Mac, recognisable secrets in it are replaced with a redaction marker. This is a safety net, not a guarantee; see the terms. [RR-034]

1.4 A request whose context touches a folder you have fenced is answered on your Mac no matter what the router would otherwise decide, and if your Mac cannot answer it, it fails rather than being sent anywhere. [invariant 4] [RR-034]

1.5 The record of every routing decision and the ledger of what each request cost and saved are files on your Mac. We do not receive them. [invariant 5]

1.6 Your API keys are stored in the macOS Keychain. They are never sent to us, written to a configuration file, or included in a log or an error message. [invariant 3]

2. What we receive from the program

2.1 The program fetches a registry of models and prices from api.rumrunner.io. That fetch carries ordinary request metadata and no prompt content. [RR-050 / docs/05]

2.2 Once licensing ships, the program checks its license with the same server. The check carries the license token and no prompt content. [RR-051] [OPS-024]

2.3 Telemetry is off by default. If you turn it on, what is sent is a set of aggregate counters — tokens per lane, request counts, lane mix, savings totals, program version and hardware tier. It contains no prompt content and no application names, and our server rejects any payload containing a string longer than 64 characters. [RR-052] [invariant 5]

2.4 Our server does not keep your IP address. A salted hash of it lives in memory for sixty seconds for rate limiting and is then gone. [RR-052]

3. What the website collects

3.1 Loading getrumrunner.com sends nothing to anyone but the host that serves the page. There are no analytics, no fonts fetched from elsewhere, and no scripts from third parties. [RR-093]

3.2 If you type your email address into the form, we store the address, the time, where on the site you submitted it, and the exact consent wording you saw. [RR-091]

3.3 We send one confirmation email. Until you click the link in it you are not subscribed and we do not email you again. [RR-092]

3.4 You can ask for a copy of what we hold about your address, or for its deletion, by emailing hello@getrumrunner.com. The store exports, so this is a real request rather than a promise. [RR-091]

4. Who else sees anything

4.1 The providers you configure receive your prompts when the router sends a request to them. They act under your own account and their own terms. The current list, with links to each provider's privacy page and data-processing terms, is published at the address RR-094 gives it and is updated in the same change as any change to the program's providers. [OPS-051]

4.2 Our website and registry are hosted by Vercel. When payments ship, they will be handled by Stripe, which will receive your name, email and payment details at checkout. Inbound mail to hello@ is forwarded by ImprovMX. [OPS-051]

4.3 We do not sell, rent or share any of the above with anyone not on the published list. [OPS-051]

5. Changes

5.1 Any change to sections 1 through 4, to the published subprocessor list, or to how long we keep anything is dated on the published page and emailed to subscribers before it takes effect. [OPS-050 §8]

5.2 A change that would route prompts through a server we operate is a change to the product, not to this policy, and would require your explicit opt-in. [OPS-050 §8] [OPS-040]

6. Retention

6.1 How long each item in sections 2 and 3 is kept is stated in a separate retention statement that is not yet written. [OPS-052]