RunMacro

Privacy Policy

This Policy explains how RunMacro processes information through runmacro.app, RunMacro Studio, QMacro Runner, RunMacro Smart HTML, licensing and payment services, optional cloud and AI features, and support channels.

Effective July 14, 2026 · Version 1.0

For privacy questions or requests, contact RunMacro at support@runmacro.app.

1. Scope

This Policy applies to the RunMacro website, RunMacro Studio for Windows, QMacro Runner, the RunMacro Smart HTML Chrome extension, license activation and update services, optional cloud synchronization and Team Template Cloud, user-configured AI and API features, purchases, newsletters, and customer support.

Different features process different information. A feature-specific notice may provide additional detail in the future. Until such a notice is published and linked, this Policy controls.

2. Website and browser storage

When you access runmacro.app, Cloudflare or another hosting and network provider may process ordinary request information such as IP address, user agent, requested URL, date and time, language, approximate region, and security or diagnostic data.

The current website stores your language preference in localStorage. During checkout it may temporarily store checkout recovery information or a status token in sessionStorage. The current website application does not set first-party analytics or advertising cookies. If that changes, we will update this Policy and provide notices or choices required by applicable law.

The website may load Google Fonts and link to third-party services such as Creem, WhatsApp, Telegram, GitHub, X, and YouTube. Those services receive information according to their own policies when your browser connects to them.

3. Information you provide

We may process information you voluntarily provide, including your name or display name, email address, company or team name, support messages, feedback, bug reports, order reference, license-owner information, newsletter preference, and files, screenshots, logs, or diagnostics you choose to send.

Do not send passwords, authentication tokens, private keys, complete payment-card details, or other secrets through support unless an approved secure process specifically requires them.

4. Licensing, trials, and device identifiers

RunMacro generates a persistent pseudonymous device identifier by hashing several operating-system and device values. Depending on the system, inputs include the operating system, computer or node name, architecture, a network-node value commonly derived from a MAC address, and Windows MachineGuid. This identifier is pseudonymous, not anonymous.

Paid-license verification sends the license key and device identifier. Trial reporting may send the device identifier, trial start and expiry dates, and application version. Free-use reporting may send the device identifier and application version. Online paid-license rechecks normally occur no more often than approximately every six hours, and a local offline cache may permit an approximately 72-hour grace period.

Backend licensing records may contain readable customer email, plan, status, expiry, seat and device metadata, first- and last-seen timestamps, application version, trial or usage status, and signed license data. Uninstalling RunMacro or deleting a locally saved license does not automatically delete backend licensing records or all local trial and usage records.

5. Local files, settings, and secret storage

RunMacro normally stores settings, licensing data, logs, and related app state under %APPDATA%\RunMacro. Local data may include PMacro and QMacro files, workflow commands, selectors, images, variables, schedules, templates, logs, browser or integration settings, and a stable random installation author identifier included in locally authored macro metadata.

On Windows, configured credentials and licensing caches are normally protected with user-bound Windows DPAPI. This includes supported API keys, GitHub or Team Template tokens, and saved licensing secrets. Ordinary settings, macros, logs, images, and other local files are not necessarily DPAPI-encrypted. A developer or environment option can permit plaintext secret-storage fallback.

Local files remain until you delete them, reset the relevant feature, or remove them through the applicable operating-system or application controls. Uninstalling the application may not remove every local file.

6. Smart HTML extension and local bridge

RunMacro Smart HTML can operate on HTTP and HTTPS pages selected by the user. Its packaged scripts may access page URLs and titles, frames, tab identifiers, DOM text and attributes, accessibility labels, selectors, form metadata and values, links, images, styles, geometry, clicks, typing, selections, supported keys, scrolling, navigation, and timing when required for selection, recording, or automation.

The extension normally sends selector, profile, command, and Smart Record data to RunMacro Studio through a loopback HTTP connection at 127.0.0.1:9888 or localhost on your device. This transfer leaves the browser process but normally remains on the same device. The extension does not normally send that recording data directly to a RunMacro-hosted remote service.

The extension uses Chrome local storage for a random client identifier and session storage for a bridge token and temporary recording or recovery state. During temporary delivery failures, the Chrome Web Store build may keep up to 500 recording envelopes in service-worker memory and retry each up to three times; this outbox is not persisted as recorded payload storage. For selected file inputs it reads metadata only (name, MIME type, size, and last-modified time), not local paths, file contents, or file bytes. It requests permissions needed for tab routing, script injection, context-menu selection, local state, and recording continuity. The Chrome Web Store build does not request the Chrome cookies API, Native Messaging, or local-file URL access and does not load remotely hosted executable code.

7. Smart Record and sensitive values

Smart Record starts only after the user enables recording. It may capture typed or selected values, including passwords, one-time codes, payment entries, private messages, and other sensitive information. The current implementation does not exclude password fields.

Use sample values or variables where possible. Stop recording when it is not needed and review workflows before saving, exporting, synchronizing, sharing, or sending them to an AI or external service.

8. Cloud synchronization and Team Template Cloud

If you configure GitHub Gist synchronization, RunMacro may upload or download complete macro packages. Packages can contain commands, assets, selectors, metadata, and user-entered content. Base64 is an encoding format, not encryption. GitHub tokens and Gist identifiers are supplied by you and normally stored locally.

Team Template Cloud may upload template packages and descriptive manifest metadata, download shared templates, keep local cached copies, update or delete remote entries, and make content available to people authorized to access the configured Gist. A remote deletion may not erase GitHub revision history, forks, clones, collaborator copies, backups, or local synchronized caches.

An optional setting can allow cloud downloads without normal TLS certificate verification. That mode reduces transport security and should be used only when you understand the risk. GitHub processes synchronized data under its own terms and privacy policy.

9. AI and external API providers

When you configure and invoke an AI provider or compatible custom endpoint, the desktop application sends credentials and request content directly to the selected provider. Supported configurations may include Anthropic, OpenAI, Gemini, DeepSeek, OpenRouter, and custom compatible endpoints.

Request content may include prompts, selected workflow commands or context, URLs, selectors, errors, files or images intentionally included by the user, system and schema instructions, model identifiers, and response settings. Model-list requests may also transmit credentials.

The selected provider’s retention, model-training, location, and security terms apply. Do not submit passwords, payment data, private keys, or confidential information unless you understand and accept that provider’s practices.

10. Screen capture, images, OCR, logs, and diagnostics

Automation, browser capture, image matching, OCR, debugging, and error handling can capture visible desktop or browser content. Windows OCR processing is local, but screenshots, selected regions, image references, and debug images may persist on disk when saved or generated by a feature.

Local logs may contain timestamps, workflow lines, command values and results, URLs, paths, application version, errors, stack traces, and runtime metadata. The reviewed implementation does not impose a general automatic expiry on desktop logs.

A diagnostics archive may include operating-system and runtime information, executable path and arguments, working directory, administrator status, selected environment and PATH summaries, redacted settings, file existence and size metadata, recent log tails, and an error screenshot. Redaction is best-effort and cannot guarantee removal of every secret. Inspect archives before sharing them.

11. Newsletter

If you subscribe to the newsletter, the service stores your normalized email address, subscription status, source, locale, consent version, and subscription timestamp in Cloudflare KV. The lookup key is derived from a SHA-256 hash of the email, but the stored subscriber record contains the readable email address.

Authorized administrators can list subscriber records. The current implementation does not impose an automatic expiry and does not yet provide self-service unsubscribe. Until self-service removal is available, request removal at support@runmacro.app.

12. Purchases and payment processing

RunMacro purchases do not automatically renew unless the checkout page expressly states otherwise before payment. We may retain expiry dates, purchase history, and records of extensions or renewals purchased manually. Those records do not by themselves mean recurring billing is enabled.

Checkout and payment records may include email, plan, duration or billing cycle, optional voucher, order code, status token, provider, amount, seats, timestamps, provider checkout, invoice, payment or transaction identifiers, license and payment history, and voucher data.

Payment providers such as Creem, SePay or VietQR, and NOWPayments may process billing identity, email, country or region, amount, payment method, tax, transaction, and fraud-prevention information under their own policies. RunMacro does not normally receive complete payment-card details.

Pending-order records currently expire after approximately 24 hours and paid-order records after approximately 90 days. Payment history, issued-license, machine, and voucher datasets in the current service do not have a general code-enforced expiry and remain until deleted or operationally cleaned, subject to legal and accounting requirements.

13. Operational providers and email delivery

Cloudflare provides network, Worker, KV, and related infrastructure. Google Apps Script or Google Sheets may receive purchase information such as order code, email, plan, duration, amounts, dates, provider, and a truncated license-key prefix for operator-side records.

Resend may receive the purchaser’s email address, sender identity, and transactional message contents, including the complete license key and purchase details, to deliver a license email. Currency-rate services such as jsDelivr-hosted data or Frankfurter may support price conversion without being intentionally sent workflow content.

We may also use hosting, support, professional-adviser, and security providers where reasonably necessary. Each independent provider processes information under its own terms and privacy policy.

14. IP addresses, rate limiting, and security records

Cloudflare and RunMacro services may process IP address, user agent, request metadata, and security signals to deliver the service, prevent fraud, and enforce rate limits. Some lookup tokens and rate-limit identifiers are stored as SHA-256 hashes; this does not mean all operational records are anonymized or hashed.

Some short-lived license, payment, or voucher rate-limit keys may include an IP address, while newsletter rate-limit identifiers hash the IP. Current rate-limit counters expire after approximately two minutes. Operational records may otherwise contain readable email addresses, machine identifiers, purchase metadata, and signed license strings.

15. Purposes of processing

We process information to provide requested automation features, operate the website and extension, activate and manage licenses, process purchases and refunds, deliver transactional messages and newsletters, synchronize data when requested, send requests to user-selected AI or API providers, provide updates and support, diagnose errors, protect users and RunMacro from fraud or abuse, and comply with applicable obligations.

We do not currently use workflow or extension data for third-party advertising or cross-context behavioral advertising, and we do not sell that data as part of the current service model.

16. Legal bases

Where applicable law requires a legal basis, processing may be necessary to provide a requested service or perform a contract, based on consent, necessary for legitimate interests such as security, reliability, support, and fraud prevention, or required to comply with law.

The legal basis depends on the feature, jurisdiction, and circumstances. Where processing relies on consent, consent may be withdrawn subject to legal and technical limitations.

17. International processing

Cloudflare, GitHub, Google, Resend, payment providers, AI providers, and other configured services may process information in countries outside your location. We do not promise that all data remains in Vietnam or in your country.

Where safeguards are legally required, we will use measures applicable to the service and relationship. Users who independently configure cloud, AI, GitHub, or API providers should review those providers’ data-location and transfer practices.

18. Retention and deletion

Retention depends on the dataset and purpose. Short-lived rate-limit counters currently last about two minutes, pending orders about 24 hours, and paid-order records about 90 days. Local files remain until deleted or reset. Several subscriber, issued-license, machine, payment-history, voucher, and desktop-log datasets have no general code-enforced expiry.

Uninstalling the application or extension may not remove every local or remote record. Deleting a saved license does not delete local trial or usage records or backend licensing records. Provider-hosted copies, transaction records, backups, revision history, synchronized caches, and legally required records may require separate deletion steps or may need to be retained.

We aim to retain personal information only as long as reasonably necessary for the stated purpose, security, dispute handling, accounting, or legal obligations. Contact support@runmacro.app to request review or deletion of records associated with you. We may need to verify identity and may retain information where a lawful exception applies.

19. Security

RunMacro uses reasonable technical and organizational measures appropriate to the feature, which may include loopback-only communication, session tokens, DPAPI for supported secrets on Windows, TLS, access controls, integrity checks, rate limiting, and logging.

No system is completely secure. Not every local file is encrypted, redaction is best-effort, and externally configured providers have their own security practices. Protect macro files, API keys, GitHub tokens, license keys, templates, diagnostics, logs, and backups.

20. Your controls and privacy rights

You can start or stop recording, control extension site access, disable or uninstall the extension, close RunMacro Studio, disable optional synchronization, remove configured tokens, delete local workflows and logs, choose whether to send files to support, and manage or deactivate supported license installations.

Depending on applicable law, you may have rights to request access, correction, deletion, restriction, objection, withdrawal of consent, portability, or information about data categories and recipients, and to complain to an appropriate authority. Whether a right applies depends on the law and circumstances. We may require reasonable identity verification.

California residents may contact us to request information about rights that may apply to them. We do not currently use personal information for cross-context behavioral advertising. Applicability of a specific California right depends on legal thresholds, exceptions, and the circumstances of the request.

21. Children

RunMacro is not designed for children under 13 or under the minimum age required by applicable local law to consent to personal-data processing. We do not knowingly seek personal information from a child who requires parental authorization.

22. Changes and contact

We may update this Policy when product behavior, providers, security practices, or legal requirements change. The revised Policy will display a new effective date and version. Material changes may also be communicated through the website, application, or another appropriate channel.

Questions, privacy requests, newsletter-removal requests, and deletion requests may be sent to support@runmacro.app. Include enough information to identify the relevant license, order, subscription, or support record, but do not include passwords, complete payment-card details, or private API keys.

Contact

Email support@runmacro.app

RunMacro robot

Ready to automate smarter?

Download RunMacro and start automating your desktop, browser, and business workflows today.