1. Scope
This Policy applies to the RunMacro website, RunMacro Studio for Windows, RunMacro Runner, RunMacro Manager and its Manager Agent, the RunMacro Smart HTML Chrome extension, license activation and update services, optional cloud synchronization and Team Template Cloud, user-configured AI and API features, product analytics and first-touch attribution, purchases, newsletters, and customer support.
Different features process different information. A feature-specific notice may provide additional detail in the future. Until such a notice is published and linked, this Policy controls.
2. Website and browser storage
When you access runmacro.app, Cloudflare or another hosting and network provider may process ordinary request information such as IP address, user agent, requested URL, date and time, language, approximate region, and security or diagnostic data.
The current website stores your language preference and first-touch attribution parameters in localStorage. When you visit localized RunMacro web pages carrying recognized campaign parameters (source, campaign, content_id, template_id), the website validates and stores the first valid touch in localStorage; subsequent visits never overwrite an existing valid first touch. During checkout the website forwards the validated attribution tuple to payment creation and may temporarily store checkout recovery information or a status token in sessionStorage. The RunMacro Support chat stores a random visitor identifier until you clear browser site data. It also stores up to 20 messages separately for each interface language for seven days from the most recent chat change; clearing the conversation removes the messages for the current language. The website uses Google Analytics 4 to measure traffic. It sets the first-party cookies _ga and _ga_0YSB7PDNNS, which hold a randomly generated visitor and session identifier so we can see how many people visit, which pages they use and which sources bring them; Google processes that page and event data as our measurement provider. Visitors in the European Economic Area, the United Kingdom and Switzerland are asked before those cookies are set and Google Consent Mode stays in the denied state until a choice is made, so no analytics cookie or Google request happens beforehand. Elsewhere measurement starts with the page and can be switched off at any time through the Cookie settings control in the site footer, which also deletes the cookies. Storing the first-touch campaign parameters described above follows the same choice: where we ask first, nothing is written until you allow it, and declining clears anything already kept. Google Analytics never receives licence keys, machine identifiers, workflow contents, support messages or anything you type into RunMacro.
The website may load Google Fonts and Google Analytics, and link to third-party services such as Creem, WhatsApp, Telegram, GitHub, X, and YouTube. Those services receive information according to their own policies when your browser connects to them.
3. Information you provide
We may process information you voluntarily provide, including your name or display name, email address, company or team name, support messages, feedback, bug reports, order reference, license-owner information, newsletter preference, and files, screenshots, logs, or diagnostics you choose to send.
When you use Report AI content, the desktop app sends the category, generated content and optional details you reviewed, the source surface, interface language, application version, and a random report identifier directly to RunMacro Support over encrypted HTTPS. It does not automatically include your prompt, conversation history, diagnostics, license key, machine ID, files, or screenshots. If direct delivery fails, you may separately choose the email fallback; only after you confirm does the app copy the prepared report to the Windows clipboard and ask Windows to open an email draft.
When you send a support request from the website chat, the form sends the email address, Telegram username and message you enter, interface language, a random ticket identifier, and the user and assistant messages displayed in the transcript preview. The Telegram username is normalized to lowercase without a leading @. The form links to the official RunMacro Telegram group; its single checkbox records your confirmation that the transcript may be sent and your self-attestation that you joined the group. RunMacro does not independently verify Telegram membership through this form.
Do not send passwords, authentication tokens, private keys, complete payment-card details, or other secrets through support unless an approved secure process specifically requires them.
4. Licensing, trials, and device identifiers
RunMacro generates a persistent pseudonymous device identifier by hashing several operating-system and device values. Depending on the system, inputs include the operating system, computer or node name, architecture, a network-node value commonly derived from a MAC address, and Windows MachineGuid. This identifier is pseudonymous, not anonymous.
Paid-license verification sends the license key and device identifier. Trial reporting may send the device identifier, trial start and expiry dates, application version, and, only while product analytics is allowed, the validated first-touch attribution parameters described in section 16 so a Trial can be attributed to the page or campaign it came from. Free-use reporting may send the device identifier and application version. Online paid-license rechecks normally occur no more often than approximately every six hours, and a local offline cache may permit an approximately 72-hour grace period.
Backend licensing records may contain readable customer email, plan, status, expiry, seat and device metadata, first- and last-seen timestamps, application version, trial or usage status, and signed license data. Uninstalling RunMacro or deleting a locally saved license does not automatically delete backend licensing records or all local trial and usage records.
5. Local files, settings, and secret storage
RunMacro normally stores settings, licensing data, logs, and related app state under %APPDATA%\RunMacro. Local data may include editable PMacro and packaged workflow files, workflow commands, selectors, images, variables, schedules, templates, logs, browser or integration settings, and a stable random installation author identifier included in locally authored macro metadata.
On Windows, configured credentials and licensing caches are normally protected with user-bound Windows DPAPI. This includes supported API keys, GitHub or Team Template tokens, and saved licensing secrets. Ordinary settings, macros, logs, images, and other local files are not necessarily DPAPI-encrypted. A developer or environment option can permit plaintext secret-storage fallback.
Local files remain until you delete them, reset the relevant feature, or remove them through the applicable operating-system or application controls. Uninstalling the application may not remove every local file.
6. Smart HTML extension and local bridge
RunMacro Smart HTML can operate on HTTP and HTTPS pages selected by the user. Its packaged scripts may access page URLs and titles, frames, tab identifiers, DOM text and attributes, accessibility labels, selectors, form metadata and values, links, images, styles, geometry, clicks, typing, selections, supported keys, scrolling, navigation, and timing when required for selection, recording, or automation.
The extension normally sends selector, profile, command, and Smart Record data to RunMacro Studio through a loopback HTTP connection at 127.0.0.1:9888 or localhost on your device. This transfer leaves the browser process but normally remains on the same device. The extension does not normally send that recording data directly to a RunMacro-hosted remote service.
The extension uses Chrome local storage for a random client identifier and session storage for a bridge token and temporary recording or recovery state. During temporary delivery failures, the Chrome Web Store build may keep up to 500 recording envelopes in service-worker memory and retry each up to three times; this outbox is not persisted as recorded payload storage. For selected file inputs it reads metadata only (name, MIME type, size, and last-modified time), not local paths, file contents, or file bytes. It requests permissions needed for tab routing, script injection, context-menu selection, local state, and recording continuity. The Chrome Web Store build does not request the Chrome cookies API, Native Messaging, or local-file URL access and does not load remotely hosted executable code.
7. Smart Record and sensitive values
Smart Record starts only after the user enables recording. It may capture typed or selected values, including passwords, one-time codes, payment entries, private messages, and other sensitive information. The current implementation does not exclude password fields.
Use sample values or variables where possible. Stop recording when it is not needed and review workflows before saving, exporting, synchronizing, sharing, or sending them to an AI or external service.
8. Cloud synchronization and Team Template Cloud
If you configure GitHub Gist synchronization, RunMacro may upload or download complete macro packages. Packages can contain commands, assets, selectors, metadata, and user-entered content. Base64 is an encoding format, not encryption. GitHub tokens and Gist identifiers are supplied by you and normally stored locally.
Team Template Cloud may upload template packages and descriptive manifest metadata, download shared templates, keep local cached copies, update or delete remote entries, and make content available to people authorized to access the configured Gist. A remote deletion may not erase GitHub revision history, forks, clones, collaborator copies, backups, or local synchronized caches.
An optional setting can allow cloud downloads without normal TLS certificate verification. That mode reduces transport security and should be used only when you understand the risk. GitHub processes synchronized data under its own terms and privacy policy.
9. AI and external API providers
When you configure and invoke an AI provider or compatible custom endpoint, the desktop application sends credentials and request content directly to the selected provider. Supported configurations may include Anthropic, OpenAI, Gemini, DeepSeek, OpenRouter, and custom compatible endpoints.
Request content may include prompts, selected workflow commands or context, URLs, selectors, errors, files or images intentionally included by the user, system and schema instructions, model identifiers, and response settings. Model-list requests may also transmit credentials.
The selected provider’s retention, model-training, location, and security terms apply. Do not submit passwords, payment data, private keys, or confidential information unless you understand and accept that provider’s practices.
10. Screen capture, images, OCR, logs, and diagnostics
Automation, browser capture, image matching, OCR, debugging, and error handling can capture visible desktop or browser content. Windows OCR processing is local, but screenshots, selected regions, image references, and debug images may persist on disk when saved or generated by a feature.
Local logs may contain timestamps, workflow lines, command values and results, URLs, paths, application version, errors, stack traces, and runtime metadata. The reviewed implementation does not impose a general automatic expiry on desktop logs.
A diagnostics archive may include operating-system and runtime information, executable path and arguments, working directory, administrator status, selected environment and PATH summaries, redacted settings, file existence and size metadata, recent log tails, and an error screenshot. Redaction is best-effort and cannot guarantee removal of every secret. Inspect archives before sharing them.
11. Newsletter
If you subscribe to the newsletter, the service stores your normalized email address, subscription status, source, locale, consent version, and subscription timestamp in Cloudflare KV. The lookup key is derived from a SHA-256 hash of the email, but the stored subscriber record contains the readable email address.
Authorized administrators can list subscriber records. The current implementation does not impose an automatic expiry and does not yet provide self-service unsubscribe. Until self-service removal is available, request removal at support@runmacro.app.
12. Purchases and payment processing
RunMacro purchases do not automatically renew unless the checkout page expressly states otherwise before payment. We may retain expiry dates, purchase history, and records of extensions or renewals purchased manually. Those records do not by themselves mean recurring billing is enabled.
Checkout and payment records may include email, plan, duration or billing cycle, optional voucher, order code, status token, provider, amount, seats, timestamps, provider checkout, invoice, payment or transaction identifiers, license and payment history, voucher data, and validated first-touch attribution parameters (source, campaign, content_id, template_id) forwarded during checkout to attribute paid subscription conversions.
Payment providers such as Creem, SePay or VietQR, and NOWPayments may process billing identity, email, country or region, amount, payment method, tax, transaction, and fraud-prevention information under their own policies. RunMacro does not normally receive complete payment-card details.
Pending-order records currently expire after approximately 24 hours and paid-order records after approximately 90 days. Payment history, issued-license, machine, and voucher datasets in the current service do not have a general code-enforced expiry and remain until deleted or operationally cleaned, subject to legal and accounting requirements.
13. Operational providers and email delivery
Cloudflare provides network, Worker, KV, D1 SQL analytics database, and related infrastructure. Google Apps Script or Google Sheets may receive purchase information such as order code, email, plan, duration, amounts, dates, provider, and a truncated license-key prefix for operator-side records. For Report AI content, a dedicated Google Sheet receives the random report identifier, receipt time, category, reviewed AI content and optional details, source surface, interface language, application version, and review status; the report form does not automatically collect the reporter’s email address. A separate support-ticket Sheet receives the ticket identifier, receipt time, email, normalized Telegram username, interface language, message, explicitly confirmed chat transcript, the combined transcript-and-group confirmation indicator, handling status, review time, and operator resolution notes.
Resend may receive the purchaser’s email address, sender identity, and transactional message contents, including the complete license key and purchase details, to deliver a license email. Currency-rate services such as jsDelivr-hosted data or Frankfurter may support price conversion without being intentionally sent workflow content.
We may also use hosting, support, professional-adviser, and security providers where reasonably necessary. Each independent provider processes information under its own terms and privacy policy.
14. IP addresses, rate limiting, and security records
Cloudflare and RunMacro services may process IP address, user agent, request metadata, and security signals to deliver the service, prevent fraud, and enforce rate limits. Some lookup tokens and rate-limit identifiers are stored as SHA-256 hashes; this does not mean all operational records are anonymized or hashed.
Some short-lived license, payment, or voucher rate-limit keys may include an IP address, while newsletter rate-limit identifiers hash the IP. Report AI content and website support tickets use separate HMAC-derived network identifiers for daily and burst limits. Their rate-limit state contains counters, random request identifiers, payload fingerprints, and successful receipts, but not the reported content, support email, Telegram username, support message, or chat transcript. Active state keeps at most two UTC-day buckets and an inactive limiter is scheduled for deletion after approximately 48 hours. Operational records may otherwise contain readable email addresses, machine identifiers, purchase metadata, and signed license strings.
15. RunMacro Manager and remote Jobs
When you use RunMacro Manager, we process the license key used for authentication; workspace, plan, seat, capability and Manager-session metadata; a persistent pseudonymous machine identifier; hostname and display name; application, Agent and protocol versions; machine presence, activity and progress; and browser or request security metadata such as user agent, platform hint and a hashed IP-derived value. A one-use realtime ticket connects the Manager browser to live invalidation events.
If you configure GitHub Gist for Manager, we process the Gist identifier, catalog and package metadata, revision and configuration state, and an encrypted GitHub credential. Job data may include names, selected machines and packages, schedules, time zones, after-Job dependencies, runtime and browser settings, profile URLs, scalar input values, commands, acknowledgements, bounded log tails, errors, structured results and files submitted through Manager. We use this information to authenticate users and Agents, bind and monitor machines, synchronize configured Gists, authorize, dispatch, schedule and control Jobs, display realtime status and results, enforce service limits, troubleshoot and protect the service from fraud or abuse.
Manager data is processed by RunMacro’s Manager API and PostgreSQL-backed service and may pass through Cloudflare or related hosting and network infrastructure. GitHub, Google Sheets, Chrome and other user-selected services process information under their own terms when a configured Job uses them. Redaction and sensitive-column filtering are best-effort; Job inputs, notes, URLs, logs, results and files may still contain personal, confidential or credential-like information. Do not submit secrets unless you understand and accept the relevant feature and provider practices.
Manager sessions normally expire after about 24 hours, one-use realtime tickets after about 60 seconds, and pending commands after a configurable period that defaults to about five minutes. Runtime log chunks are currently assigned a 30-day expiry, but this is not a promise that every copy is deleted exactly at that time. Jobs, schedules, execution and history records, Gist and catalog state, results, files, machine-session history and activity records do not share one general code-enforced deletion period and may remain until deleted, operationally cleaned, backup retention ends or another legal or technical deletion process applies. Local Agent state and artifact caches remain until deleted or reset.
16. Product analytics and first-touch attribution
RunMacro collects privacy-minimized product telemetry to understand feature usage, measure active users, monitor execution outcomes, and improve automation templates. Telemetry uses a strict positive allowlist and includes eight Phase 1 events: app_first_open (recorded once per installation upon first launch to measure activation), app_session (emitted at most once per UTC day per device to measure 7-day and 30-day active usage), workflow_first_success (emitted once per user upon their first successful workflow run to measure onboarding), workflow_run (emitted upon macro completion to track execution mode, origin, duration buckets from <1s to 10m+, command-count buckets from 1 to 100+, and high-level outcome such as succeeded, completed_with_errors, failed, stopped, or rejected), workflow_failed (emitted for failed runs with a bounded error code enum to aggregate error categories without transmitting raw exceptions), template_used (emitted when an official template is opened or inserted to measure template discovery), trial_started (server-authored after authoritative Trial issuance), and subscription_activated (server-authored after successful paid fulfillment).
Analytics uses separate, privacy-safe identity grains: a locally generated random UUIDv4 device_id created once per installation (not derived from hardware, hostname, MAC address, MachineGuid, browser profiles, or workflow files), an analytics service UUIDv4 user_id, and signed license_id records. When an anonymous device activates a license or completes a purchase, the server associates the device with the customer account using a server-side keyed HMAC (identity_hash) of the normalized customer email; raw email addresses are never stored in analytics tables. Two separate anonymous Free installations on different devices remain two distinct anonymous users; we do not perform fingerprinting or speculative cross-device tracking for anonymous Free users.
Every product event also carries ordinary technical metadata: the application version, the release channel (Store or Direct), the interface language, the event timestamp, and for execution events a random run identifier created for that run. Execution events record the run mode (desktop window or background Chrome) and where the run started (editor, RunMacro Runner, scheduler, or a Manager job), so remote, scheduled and unattended work is measured the same way as work started by hand. Template attribution uses a hash of the workflow path that stays on the device and is never transmitted; only the official template identifier is sent.
First-touch attribution captures only four allowlisted parameters from localized RunMacro routes: source, campaign, content_id, and template_id. Values are validated against strict length and character constraints. The first valid touch per property is immutable in browser storage and is forwarded to payment creation so subscription activations can attribute conversion to the original content or template.
The same four parameters may also be handed to the installed Windows application through a runmacro://attribution link, which carries nothing else and never opens or runs a workflow. The desktop app validates them against the identical allowlist, keeps the first valid value per property, stores them only while product analytics is allowed, and discards them if you decline. It then includes them with authoritative Trial issuance so a Trial can be attributed to the page or campaign it came from; unknown parameters on such a link, including UTM parameters and advertising click identifiers, are discarded rather than stored.
The analytics service strictly excludes sensitive data. We never collect or store: workflow contents or AST command dictionaries, user-entered text, prompts, variables, passwords, API keys, authentication tokens, session cookies, visited URLs, DOM selectors, page DOM contents, raw error messages or stack traces, file paths, file contents, screenshots, images, raw document.referrer, advertising click identifiers (such as gclid or fbclid), email addresses in event tables, or payment and banking credentials. These exclusions describe RunMacro’s own product analytics service only. The separate Google Analytics measurement on the website, described in section 2, follows Google’s own processing terms and does receive page paths and referrer information.
Analytics events are transmitted over encrypted HTTPS to RunMacro’s Cloudflare Worker ingestion endpoint and stored in a dedicated Cloudflare D1 SQL database (ANALYTICS_DB) co-located with the license worker. Analytics is purely observational and strictly decoupled from licensing and execution: failure or unavailability of analytics storage never alters, delays, rejects, or blocks license verification, Trial issuance, or payment fulfillment. Analytics data is never sold or shared with third-party behavioral advertising or cross-context tracking networks. Event records are retained in Cloudflare D1 to support standard reporting periods (7-day, 30-day, 90-day, and all-time). On the first normal launch, RunMacro asks separately whether the user allows product analytics; the choice is not bundled with Terms acceptance, applies consistently to Store and Direct builds, and can be changed later in Settings. Until that choice is made no product event is collected or queued, so an installation that never reaches the question, such as an unattended machine running Manager jobs, never contributes product analytics. If the user chooses No, no desktop product events are collected or queued, while licensing and entitlement telemetry continue independently. Users and customers may contact support@runmacro.app to request privacy review or deletion of records associated with their license or customer identity, subject to identity verification, technical feasibility, and applicable legal exceptions.
17. Purposes of processing
We process information to provide requested automation features, operate the website and extension, activate and manage licenses, process purchases and refunds, deliver transactional messages and newsletters, synchronize data when requested, send requests to user-selected AI or API providers, deliver product telemetry and first-touch attribution to understand feature usage and improve templates, provide updates and support, diagnose errors, protect users and RunMacro from fraud or abuse, and comply with applicable obligations.
We do not currently use workflow or extension data for third-party advertising or cross-context behavioral advertising, and we do not sell that data as part of the current service model.
18. Legal bases
Where applicable law requires a legal basis, processing may be necessary to provide a requested service or perform a contract, based on consent, necessary for legitimate interests such as security, reliability, support, product improvement, and fraud prevention, or required to comply with law.
The legal basis depends on the feature, jurisdiction, and circumstances. Where processing relies on consent, consent may be withdrawn subject to legal and technical limitations.
19. International processing
Cloudflare, GitHub, Google, Resend, payment providers, AI providers, and other configured services may process information in countries outside your location. We do not promise that all data remains in Vietnam or in your country.
Where safeguards are legally required, we will use measures applicable to the service and relationship. Users who independently configure cloud, AI, GitHub, or API providers should review those providers’ data-location and transfer practices.
20. Retention and deletion
Retention depends on the dataset and purpose. Short-lived rate-limit counters currently last about two minutes, pending orders about 24 hours, and paid-order records about 90 days. Analytics events in Cloudflare D1 are retained to provide aggregate reporting across standard time ranges (7-day, 30-day, 90-day, and all-time). Local files remain until deleted or reset. Several subscriber, issued-license, machine, payment-history, voucher, and desktop-log datasets have no general code-enforced expiry.
Uninstalling the application or extension may not remove every local or remote record. Deleting a saved license does not delete local trial or usage records or backend licensing records. For anonymous installations, removing local application data or uninstalling the application disconnects the local installation from subsequent reporting. AI report and support-ticket content is not stored in the license or payment KV namespace or in rate-limit state, but each dedicated Google Sheet row remains until it is manually deleted or operationally cleaned after support review, security or dispute handling, subject to provider retention and legal obligations. Provider-hosted copies, transaction records, backups, revision history, synchronized caches, and legally required records may require separate deletion steps or may need to be retained.
We aim to retain personal information only as long as reasonably necessary for the stated purpose, security, dispute handling, accounting, or legal obligations. Contact support@runmacro.app to request review or deletion of records associated with you. We may need to verify identity and may retain information where a lawful exception applies.
21. Security
RunMacro uses reasonable technical and organizational measures appropriate to the feature, which may include loopback-only communication, session tokens, DPAPI for supported secrets on Windows, TLS, access controls, integrity checks, rate limiting, and logging.
No system is completely secure. Not every local file is encrypted, redaction is best-effort, and externally configured providers have their own security practices. Protect macro files, API keys, GitHub tokens, license keys, templates, diagnostics, logs, and backups.
22. Your controls and privacy rights
You can start or stop recording, control extension site access, disable or uninstall the extension, close RunMacro Studio, disable optional synchronization, remove configured tokens, clear browser storage to reset locally stored first-touch attribution parameters, configure supported application telemetry options where provided in the active release, delete local workflows and logs, choose whether to send files to support, and manage or deactivate supported license installations.
Depending on applicable law, you may have rights to request access, correction, deletion, restriction, objection, withdrawal of consent, portability, or information about data categories and recipients, and to complain to an appropriate authority. Whether a right applies depends on the law and circumstances. We may require reasonable identity verification.
California residents may contact us to request information about rights that may apply to them. We do not currently use personal information for cross-context behavioral advertising. Applicability of a specific California right depends on legal thresholds, exceptions, and the circumstances of the request.
23. Children
RunMacro is not designed for children under 13 or under the minimum age required by applicable local law to consent to personal-data processing. We do not knowingly seek personal information from a child who requires parental authorization.
24. Changes and contact
We may update this Policy when product behavior, providers, security practices, or legal requirements change. The revised Policy will display a new effective date and version. Material changes may also be communicated through the website, application, or another appropriate channel.
Questions, privacy requests, newsletter-removal requests, and data deletion requests may be sent to support@runmacro.app. Include enough information to identify the relevant license, order, subscription, or support record, but do not include passwords, complete payment-card details, or private API keys.
