Privacy Policy

Effective date: [PLACEHOLDER: effective date — set on publish] · Last updated: [PLACEHOLDER: last-updated date — set on publish]

This policy explains what Runs True collects, why, who processes it on our behalf, how long we keep it, and the rights you have over it. It is written to match what the software actually does — not boilerplate.

Runs True is operated from Pennsylvania, United States. Questions, access requests, or complaints: privacy@runstrue.co.

1. The short version

  • You can use the core feature — a sizing verdict on the product page you're looking at — without an account. We mint an anonymous session so you get an instant first verdict with no signup wall.
  • To save your measurements, brand lists, and wishlist across devices, you claim your account with an email and password. Your anonymous data carries over to the same account; we don't make you start over.
  • Your body measurements are encrypted at rest. They are decrypted only to compute a verdict for you or to export them to you.
  • To produce a verdict, the product page content and your relevant measurements are sent to our AI provider (Anthropic / Claude), which reads the page and sizes you.
  • Payments are handled by Stripe. We never see or store your card number.
  • You can export everything we hold about you and delete your account at any time from /account. Deletion is final after a 30-day grace window.

2. What we collect, and why

We collect only what the product needs to function. There is no third-party advertising or analytics tracking, and we do not sell your data.

  • Account email — to anchor (claim) your account so your data follows you across devices, and to reach you for data-export delivery and service notices. Optional until you claim an account.
  • Password — to authenticate you. Stored as a hash by our auth provider (Supabase Auth); we never store or see the plaintext.
  • Body measurements — the core input to a sizing verdict. Encrypted at rest (see §4). Decrypted only to compute a verdict for you or to export them to you.
  • Preferred units and measurement set — to render and interpret your measurements correctly.
  • Brand lists (favorites and dislikes) — to personalize verdicts. The dislike list is included — it is your data and is exported and deleted with everything else.
  • Reference garments — items you already own that fit you well, used to calibrate sizing.
  • Wishlist — products you saved. Stored with a scrubbed product URL (see §4).
  • Sizing / verdict history — to show your past verdicts and to operate the service (reachability, latency, and cost telemetry). Product URLs are scrubbed of tracking parameters before storage, and no measurements are stored in this history (see §4).
  • Subscription and billing metadata — tier, status, trial/grace dates, and your Stripe customer/subscription identifiers. The actual payment instrument lives only with Stripe (see §3).
  • Account-lifecycle audit records — a minimal, append-only record that a deletion or data-export request occurred, for compliance evidence (an opaque user identifier and non-card, non-measurement event detail).

We do not collect your card number, advertising identifiers, or location, and we do not run third-party ad/analytics trackers.

3. Who processes your data (sub-processors)

We use a small set of processors to run the service. Each receives only what it needs.

Anthropic (Claude) — the AI that produces your verdict

To generate a verdict, we send the content of the product page you're viewing and the measurements relevant to sizing you to Anthropic's Claude models. Claude reads the page and your measurements and returns the sizing recommendation and rationale. This is the one processor that necessarily receives your measurements in the clear, at the moment of a verdict, because computing the verdict is the whole point.

We use Anthropic's API on a zero-data-retention (ZDR) basis: your prompts and the model's outputs are processed to return your verdict and are not retained by Anthropic after the request, and are not used to train models.

Note (to be confirmed before publish): the zero-data-retention claim reflects our intended configuration. The exact Anthropic tier and Data Processing Addendum terms must be confirmed in writing before this policy is published.

Stripe — payments

If you subscribe, Stripe processes your payment. Card details are entered directly with Stripe and never touch our servers — we store only Stripe's customer and subscription identifiers plus your plan status.

Invoice / tax-record retention (an exception to erasure). When you delete your account, we ask Stripe to delete your customer record, but Stripe is legally required to retain invoice and tax records for a statutory period. Those financial records therefore survive account deletion. This is a lawful records-retention exception to the right to erasure; it is the only category of your data that persists after a completed deletion, and it sits with Stripe, not with us.

Supabase — database, authentication, and storage

Supabase hosts our Postgres database, authentication, and file storage. Your account, encrypted measurements, brand lists, wishlist, and verdict history live in this database. Access is governed by row-level security and least-privilege roles: for example, the background job that erases deleted accounts runs under a restricted role that cannot read your measurements — it deletes your other records and hands the final account deletion to the auth layer, which removes the measurement record without the job ever decrypting it.

4. How we protect your data

  • Measurements are encrypted at rest. Body measurements are stored encrypted in the database, with integrity (tamper-detection) protection, via pgcrypto. The decryption key is supplied only for the duration of a single database transaction and is never persisted on a shared connection. Measurements are decrypted only (a) to compute a verdict for you, or (b) to include in a data export you requested.
  • Product URLs are scrubbed. Before we store a product URL (in your wishlist or your verdict history), we strip tracking, affiliate, and session parameters (e.g. utm_*, fbclid, gclid, affiliate and session identifiers) and remove URL fragments and any embedded credentials. Server access logs record only the URL's host and path — never the query string.
  • No measurements in verdict history. Your stored verdict history records the outcome (the brand, the scrubbed product URL, the recommendation, confidence, and operational fields) but does not store your measurements.
  • Least-privilege access. Internal roles are scoped to the minimum they need; the deletion worker, for instance, has no access to the measurement table at all.

5. Retention and deletion

Retention

We keep your data for as long as your account exists, because it is the data that makes the product work for you. Anonymous sessions you never claim are subject to routine cleanup.

Your right to delete (erasure)

You can delete your account at any time from /account:

  1. Deleting schedules your account for permanent erasure and immediately blocks sign-in. Your subscription is canceled at the same time.
  2. You have a 30-day grace window to change your mind. To recover within that window, go to /account/reactivate and sign in with your email and password.
  3. After 30 days, your data is permanently purged and cannot be recovered.

What the permanent purge erases (everything we hold that is tied to you): your measurements and fit profile, your brand lists (favorites and dislikes), your reference garments, your wishlist, your verdict/sizing history, your subscription metadata, your authentication record, and your per-account audit log.

What survives deletion: only the Stripe invoice/tax records described in §3, which Stripe is legally required to keep. We also retain a minimal, opaque record that a deletion occurred (no measurements, no card data) as compliance evidence.

6. Your rights (GDPR and CCPA/CPRA)

Depending on where you live, you have rights over your personal data. We honor these regardless of jurisdiction.

  • Right of access / portability. You can get a machine-readable copy of everything we hold about you. From /account, choose "Email me my data" — we assemble your account details, your decrypted measurements, brand lists, reference garments, wishlist, verdict history, subscription metadata, and your account audit trail, and email it to you as a JSON file.
  • Right to erasure ("right to be forgotten"). Delete your account from /account as described in §5. The only lawful exception is Stripe's invoice retention (§3).
  • Right to rectification. Edit your measurements, brands, units, and wishlist directly from your account (/account, /wishlist).
  • Right to withdraw consent / object. See §7.
  • California (CCPA/CPRA): we do not sell or "share" your personal information, and we do not use it for cross-context behavioral advertising. You may exercise access and deletion as above; we do not discriminate against you for exercising these rights.

How we fulfill requests. Access/export and erasure are self-service from /account and are fulfilled by email (export) or on the 30-day purge schedule (erasure). If you can't use the in-product flows — for example, you used Runs True only anonymously and never set an email — contact us at privacy@runstrue.co and we will fulfill your request within the period required by applicable law.

8. International transfers

Our processors (Anthropic, Stripe, Supabase) may process data in the United States and other countries. Where required, transfers rely on appropriate safeguards such as the processors' standard contractual clauses.

9. Children

Runs True is not directed to children and is not intended for use by anyone under the age required by your jurisdiction (for example, under 16 in much of the EU, or under 13 in the United States). We do not knowingly collect data from children.

10. Changes to this policy

If we make a material change, we will update the "Last updated" date above and, where appropriate, notify account holders by email.

11. Contact

Questions or requests: privacy@runstrue.co
Operated by Runs True, Pennsylvania, United States.
Governing law: the Commonwealth of Pennsylvania, United States.