Runi Privacy Policy

Effective date: 2026-09-08

This policy describes how the Runi browser extension processes data. “Runi” means the extension and its developer.

1. Summary

Runi has no developer-operated backend, account service, analytics, or advertising SDK. This does not mean that no data leaves your device. When you initiate an AI request, Runi sends recent conversation content, relevant current-page tool results, and content from files you selected for that request directly from the extension to the AI provider endpoint you configured. The provider, not Runi, receives and processes that request under its own terms and privacy policy.

Provider settings, API keys, interface preferences, and conversation history are stored locally in your browser. Runi does not sell user data.

2. Data we process

Data category What may be processed Local handling External transmission
Current-page identity and content Page title, URL, language, readable text, selected text, HTML, DOM structure and attributes, page metadata, inline or external scripts and stylesheets, and computed styles, depending on the tools used for your request Held in runtime memory and tool context; page tool results are not added to Runi’s persistent conversation database Relevant text and tool results are sent directly to your configured AI provider so it can answer or act on your request
Visible-tab screenshot An image of the visible area of the active target tab, only when the screenshot tool is used Resized and re-encoded as JPEG in the run context for the current task, and not added to Runi’s persistent conversation database The screenshot tool is offered to the model only when you have declared your selected model image-capable; when it runs, the screenshot is sent directly to your configured AI provider as image input. A screenshot is pixels, so the text redaction rules described in this section do not apply to it, and anything visible on screen at capture time can reach the provider
User-selected attachments File name, MIME type, size, and the content of a text file, image, or PDF that you explicitly attach to a request Text and image attachment content may be stored with browser-local conversation history. PDF text is extracted locally for the current request; only PDF metadata is stored, while extracted PDF text is not persisted When you send the request, text content, image bytes, or locally extracted PDF text are sent directly to your configured AI provider so it can answer your request
Conversation content Your prompts, quick-action prompts, recent conversation history, and AI responses; this content may include personal or confidential information that you choose to enter Conversation messages are stored in browser-local IndexedDB The current prompt and recent conversation context are sent directly to your configured AI provider
Provider configuration and credentials Provider name, Base URL, model, protocol, and API key Stored in chrome.storage.local and not synced by Runi The Base URL selects the destination. The model and request content are sent to that endpoint, and the API key is sent to that endpoint as an authentication header
Interface preferences Language preference and theme preference Stored in chrome.storage.local Not sent to the AI provider by Runi
Session state The conversation associated with a tab, the current multi-tab operating target, and whether the in-page execution overlay is active Stored in chrome.storage.session, which is browser-session storage and is not synced by Runi Not sent as session records to the AI provider

Content from tabs referenced via @ is treated the same as current-page content: text goes through the same redaction pipeline and is sent to your AI provider only when you initiate a request.

For Chrome Web Store disclosure purposes, Runi treats Website content and the applicable categories that may appear in user-entered conversations or user-selected files as collected/processed because that content is transmitted off-device to the AI provider selected by the user for the core feature. Runi’s developer does not receive that content through a Runi backend.

3. How data is used

Runi processes data only to provide the user-requested core feature: understand the current page and user-selected files, answer grounded questions, analyze page implementation, and perform page actions. Known page actions run automatically; detected form submissions require confirmation every time.

Runi does not use data for advertising, profiling, credit or eligibility decisions, unrelated product development, or sale to third parties. The configured AI provider may have its own processing, retention, or model-training terms, which you must review separately.

4. Privacy disclosure and user-directed requests

The Settings page provides privacy disclosures explaining which data stays in your browser and which data may be sent to your configured AI provider. The same disclosures are maintained in this policy. Runi does not store a separate consent record.

When you initiate an Agent request, you direct Runi to send your current prompt, recent conversation context, API key, any relevant page-derived results, and content from files you selected for that request to your configured AI provider as needed to fulfill that request. Read-only tools and known page actions may run after you initiate the request. Runi asks before executing a detected form submission, every time.

5. Local storage and deletion

You can delete individual conversations and remove provider configurations in Runi. Clearing the extension’s browser data or uninstalling Runi removes its local data. Deleting Runi’s local data does not delete copies already processed or retained by your AI provider; use that provider’s controls and policy for those copies.

6. Third-party AI providers

You choose and configure the provider endpoint. Runi supports OpenAI-compatible and Anthropic-compatible APIs, including custom or locally hosted endpoints.

For each AI request, Runi connects directly to the configured Base URL and may send the model identifier, system instructions, tool definitions, your current prompt, recent conversation context, relevant page-derived tool results, and content from files you selected for that request. The API key is included as an authentication credential for that endpoint. Runi does not proxy these requests through a developer-operated server and cannot control the provider’s security, retention, training, or disclosure practices.

Before using a provider, review its privacy policy and terms. Do not submit page content, conversation content, or file content that you are not authorized to share with that provider.

Use an HTTPS Base URL for every remote provider. Runi sends requests to the configured URL as entered and does not upgrade an insecure remote HTTP URL. A loopback HTTP URL such as http://localhost may be used for a provider running on the same device.

7. Browser permissions

Runi 1.4.0 uses this permission set:

Permission Purpose
activeTab Supports user-invoked access to the active page
tabs Identifies and validates the target tab, reads its title and URL, opens the extension settings page, performs user-requested navigation, and — as a known action executed automatically — opens, closes, or switches between tabs Runi itself opened
scripting Runs packaged read and structured-write functions in the target page
storage Stores provider settings, API keys, shortcuts, language, theme, and workbench preferences, plus temporary tab-to-conversation state, the multi-tab operating target, and execution-overlay state
sidePanel Hosts Runi’s primary interface
alarms Keeps the extension service worker alive while a user-initiated Agent task is running, and clears the alarm when the task ends; not used to schedule any background work
Host access: <all_urls> Lets the same current-page Agent work on user-selected HTTP and HTTPS sites and fetch page-referenced resources

Read-only tools and known page actions may run after you initiate an Agent request. Detected form submissions require approval every time. Runi does not passively build a browsing-history profile.

8. External resources and SSRF protection

For page-implementation analysis, Runi may follow HTTP or HTTPS URLs found in the current page’s <script src> and stylesheet <link href> elements to retrieve source text. The request goes directly to the referenced resource host, which can receive normal network metadata such as your IP address.

Before fetching, Runi rejects non-HTTP(S) URLs and literal hosts matching localhost, unspecified, loopback, common private-network, link-local, IPv6 unique-local, and IPv4-mapped IPv6 forms of those ranges. Redirects are requested in manual mode. If the browser exposes a redirect target, Runi resolves and validates it before making the next request; if Chrome hides the target as an opaque redirect, Runi rejects the redirect rather than following an address it cannot validate. Allowed source text may be sent to your configured AI provider as part of the requested analysis. These checks reduce server-side request forgery (SSRF) risk but are not a guarantee against every network or DNS-based attack; use Runi on pages and networks you trust.

9. Children’s privacy

Runi is not directed to children under 13 and does not knowingly solicit children’s personal information. Runi does not operate accounts or an age-verification service. A parent or guardian who believes a child entered personal information should clear the extension’s local data, contact the configured AI provider about any transmitted copy, and may contact us at the address below.

10. Chrome Web Store Limited Use

Runi’s use and transfer of information received from Google APIs complies with the Chrome Web Store User Data Policy, including its Limited Use requirements. Data is used only to provide or improve the user-facing core feature, and transfers are limited to the AI provider selected by the user and resource hosts contacted as necessary for a user-requested operation.

Runi does not sell user data, use it for advertising, use it to determine creditworthiness or lending eligibility, or permit humans to read it through a Runi backend.

11. Policy changes

If this policy changes, we will update the effective date and record the change in the project repository. Review the updated policy before continuing to use Runi when a change materially affects what data Runi processes or where it is sent.

12. Contact

Questions about this policy can be sent to:

liudong.ucas@gmail.com