RunLite

Privacy Policy

Last updated: 3 October 2026

RunLite (“RunLite”, “we”, “us”) provides website hosting, a form backend, and a connector for AI coding tools (“the Service”). This policy explains what data we collect and why.

1. Who this policy is for

Two different groups of people interact with the data RunLite handles, and this policy covers both:

  • Account holders — the developer, agency, or business that creates a RunLite account, deploys a site, and configures a form.
  • Visitors — anyone who fills out a form embedded on a site an account holder has deployed. Their form submissions are collected on the account holder’s behalf, not ours. RunLite acts as a data processor for this data; the account holder is the data controller and is responsible for how their own visitors’ data is used, consistent with whatever they’ve told their own customers.

2. What we collect

About an account holder:

  • Email address, once the account is claimed — an account created with “Continue with a new account” has no email at all until then
  • API keys — we store only a salted hash and a short display prefix; the full key is shown once, at creation, and never again
  • Site files uploaded for hosting, and form definitions
  • Billing details processed via Razorpay (we never see or store card numbers — see Section 5)

About a visitor submitting a form:

  • Whatever fields the account holder’s form asks for
  • IP address, user agent, and referring page, used for spam filtering and rate-limiting
  • A basic automated spam score

About someone reporting abuse through our Report abuse form:

  • The address and description you report, and your email address if you choose to give it
  • A one-way fingerprint of your IP address (not the address itself), used only to limit how many reports one person can send

3. Why we collect it

  • To provide the Service — hosting, form delivery, notifications
  • To prevent abuse — spam filtering, rate limiting, and automated checks of deployed sites for phishing and malware
  • To bill for paid plans
  • To communicate with account holders about their account

We do not sell personal data, and we do not use form-submission data for advertising.

4. Retention

  • Unclaimed accounts are deleted, along with everything under them, 72 hours after creation if never claimed.
  • Form submissions are retained for 90 days by default, then deleted automatically. An account holder can configure a different retention period for their own account.
  • Rate-limiting records (used to detect abuse) are deleted after 24 hours.
  • Abuse records — the reasons for any deployment we refused, site we flagged or took offline, or account we suspended, and what a deleted site contained (file names and fingerprints, never the files or form submissions) — are kept for 180 days to investigate abuse reports, then deleted.
  • Abuse reports sent through our Report abuse form are kept for 180 days, then deleted.

5. Who else sees this data

We use the following service providers to run RunLite. Each only sees the data it needs to perform its function:

  • Amazon Web Services (ap-south-1, Mumbai) — hosting, file storage, compute. Sees site files and submission data.
  • Supabase — database and authentication. Sees account and submission data.
  • Razorpay — payment processing. Sees billing details; we never see card numbers.
  • Resend and Amazon Simple Email Service (part of Amazon Web Services) — transactional email delivery. See the content of the emails they deliver.
  • Cloudflare (Turnstile) — spam and bot filtering. Sees form-submission metadata.

6. Your rights

Depending on where you’re located, you may have rights to access, correct, or delete your personal data. Account holders can request deletion of their account and its data at any time by contacting us. Visitors who submitted a form should contact the account holder whose form they submitted — the data controller for that submission. We can assist an account holder with a request but do not have an independent relationship with visitors.

7. Security

API keys and claim tokens are stored as salted hashes, never in plain text. Database access that bypasses row-level security is limited to trusted server-side code; the dashboard itself never receives elevated privileges.

8. Changes to this policy

We may update this policy from time to time. We’ll update the date at the top when we do.

9. Contact

Questions about this policy: support@runlite.in