Privacy Policy
Last updated: August 8, 2026
WebRun provides browser automation infrastructure for AI agents and applications. Running automation on someone's behalf means handling their data, so this policy explains exactly what we collect, why we collect it, who we share it with, and what control you have over it.
This policy covers the webrun.ai website and the WebRun platform at app.webrun.ai, including our API, MCP server, and integrations. Questions about anything below can go to [email protected].
The Short Version
The full policy is below, but these are the commitments that matter most.
- We do not train AI models on your data. Your prompts, workflows, page content, and results are never used to train or fine tune any model, ours or anyone else's.
- We do not sell your personal information. Not to advertisers, not to data brokers, not to anyone.
- Your workflow data stays until you delete it. You control retention. When you delete a workflow or close your account, the associated data is removed.
- Credentials are encrypted and never logged in plaintext. Login details used by your automations are encrypted at rest and redacted from our logs.
- You can get your data out, or have it erased. Email [email protected] and we will handle it.
Who We Are
WebRun is a United States based company. For visitors and customers in the European Economic Area and the United Kingdom, WebRun acts as the data controller for account and website data, and as a data processor for the content your automations handle on your behalf. Where we act as a processor, we handle that data only on your documented instructions.
Information We Collect
We collect four broad categories of information. Expand each one for the specifics.
- Account details: name, email address, company name, and password credentials used to sign in
- Billing information: billing address, plan selection, and transaction history. Payment card numbers go directly to our payment processor and are never stored on WebRun systems
- Support and sales conversations: messages you send through contact forms, live chat, or email, including any information you choose to include in them
- Content you submit: workflow descriptions, automation templates you author, and configuration you enter into the platform
This is the category unique to browser automation, and the one we want to be most explicit about. When a workflow runs, WebRun may store:
- Screenshots and session recordings: visual captures of the automated browser session, retained so you can debug, replay, and verify what your automation actually did
- Page content and extracted output: the text, HTML, and structured data your automation pulled from the sites it visited, stored as part of your run results
- Prompts and workflow definitions: the natural language instructions you wrote and the saved automations built from them
- Execution logs and metadata: timestamps, URLs visited, step by step status, error messages, and credit or token consumption
An important note on this data. If your automation visits a page containing personal information about other people, that information may end up in your screenshots, extracted output, or logs. You are responsible for having a lawful basis to collect it and for using it in line with applicable privacy law and our Usage Policy. We process it strictly on your behalf and for no purpose of our own.
Some automations need to sign in to a site to do their job. When you supply credentials for that purpose:
- They are encrypted at rest using industry standard encryption
- They are never written to our logs in plaintext and are redacted from diagnostic output
- They are decrypted only at runtime, injected into the browser session that needs them, and discarded from memory when the session ends
- They are never shared with third parties, and no WebRun employee accesses them in the ordinary course of operating the service
Because an authenticated session displays account content by design, screenshots of a logged in session may show the contents of that account. Keep this in mind when deciding which runs to retain.
- Device and connection data: IP address, browser type and version, operating system, screen size, and referring URL
- Behavioral data: pages viewed, links clicked, time on page, scroll depth, and navigation paths through the site
- Attribution data: the campaign, source, or referrer that brought you to the site, stored so we can understand which channels work
- Product usage data: feature usage, run volume, and error rates within the platform, used to improve reliability and prioritize what to build
How We Use Information
We use the information above for the following purposes, and nothing beyond them.
- To run the service: executing your automations, returning results, and storing your workflows so they persist between sessions
- To operate your account: authentication, billing, plan limits, and transactional email such as receipts and security notices
- To provide support: diagnosing failures, reproducing bugs, and answering your questions
- To improve the product: understanding which features are used, where automations break, and what to build next, using aggregated and usage level data
- To keep the platform safe: detecting abuse, enforcing our Usage Policy, preventing fraud, and protecting the integrity of the wider web
- To market responsibly: sending product updates you can unsubscribe from at any time, and measuring which channels bring people to the site
- To meet legal obligations: responding to lawful requests, maintaining financial records, and defending legal claims
How We Do Not Use Information
Stating the negative matters as much as stating the positive.
- We do not train AI models on your content. Your prompts, workflow definitions, page content, extracted data, screenshots, and results are never used to train, fine tune, or evaluate any machine learning model. This applies to models we might build and to any third party model.
- We do not sell personal information and we do not share it for cross context behavioral advertising as those terms are defined under California law.
- We do not read your workflow content except when you explicitly ask us to for support, or when we are legally compelled to, or when we have a concrete reason to investigate a Usage Policy violation.
Legal Bases for Processing
If you are in the European Economic Area or the United Kingdom, we rely on the following legal bases under the GDPR and UK GDPR.
- Contract: processing needed to deliver the service you signed up for, including running automations, storing results, and billing you
- Legitimate interests: securing the platform, preventing abuse, understanding product usage, and marketing our own services to business contacts, balanced against your rights and freedoms
- Consent: non essential cookies and analytics, and optional marketing communications. You may withdraw consent at any time
- Legal obligation: tax, accounting, and responses to valid legal process
Cookies and Similar Technologies
We use cookies and similar technologies to keep the site working, remember your preferences, and understand how the site is used. You can block or delete cookies through your browser settings, though doing so may affect how parts of the site behave.
Required for the site and platform to function. These cannot be switched off.
- Session and authentication cookies that keep you signed in
- Security cookies that protect against cross site request forgery
- Load balancing and content delivery cookies set by our infrastructure providers
First party cookies we set to make the site more useful on repeat visits. All are prefixed wr_.
wr_tpl_seen: remembers which automation templates you have viewed, so we can recommend relevant oneswr_refandwr_src: record the referrer and source that brought you to the sitewr_attr_captured: marks that attribution has already been recorded, so we do not overwrite it on later visits
Set by third party services that help us measure site performance and manage customer relationships.
- Google Analytics (
_ga,_gid): measures traffic, page views, and navigation patterns. You can opt out using the Google Analytics Opt-out Browser Add-on - Microsoft Clarity (
_clck,_clsk): analyzes how visitors interact with pages so we can improve layout and usability - HubSpot (
hubspotutk,__hstc,__hssc): powers our contact forms and chat, and links your enquiries to your activity on the site
Service Providers
We share data with a small set of vendors who help us run the service. Each is bound by contract to protect the data, use it only for the purposes we specify, and delete it when the relationship ends. We do not share your personal information with anyone else except where this policy says so or where the law requires it.
- Cloud infrastructure providers: host the platform, run browser sessions, and store your data
- Content delivery and security providers: serve the site quickly and protect against attacks
- AI model providers: process the natural language instructions that drive your automations. These providers operate under contractual terms that prohibit using your content for model training
- Stripe: processes payments. Card details go to Stripe directly and are never stored by WebRun
- HubSpot: manages customer relationships, contact forms, chat, and marketing email
- Google Analytics and Microsoft Clarity: provide website analytics
Data Retention
Your workflow and session data is retained until you delete it. We do not impose an automatic expiry, because deciding what to keep is your call, not ours. You can delete individual runs, screenshots, and workflows from your account at any time, and deletion removes the data from active systems promptly.
- Account data: kept while your account is active. When you close your account we delete or anonymize it, except where we must retain records for legal reasons
- Billing records: retained for as long as tax and accounting law requires, typically seven years
- Support conversations: retained while they remain useful for context on your account
- Website analytics: retained according to each provider's standard retention window
- Backups: deleted data may persist in encrypted backups for a short period before those backups rotate out
Security
We protect data with the following measures.
- Encryption in transit: all traffic to and from WebRun uses TLS
- Encryption at rest: stored data, including credentials, is encrypted on disk
- Access controls: internal access is role based, limited to staff who need it, and logged
- Session isolation: browser sessions run isolated from one another, so one customer's automation cannot observe or reach another's
We are currently pursuing SOC 2 compliance. We will update this page when that work is complete.
No system is perfectly secure, and we will not pretend otherwise. If we become aware of a breach affecting your personal data, we will notify you and the relevant regulators within the timeframes the law requires.
International Data Transfers
WebRun is based in the United States and our infrastructure providers operate globally, so your data may be transferred to and processed in countries outside your own, including the United States. Where we transfer personal data out of the European Economic Area or the United Kingdom, we rely on appropriate safeguards, including Standard Contractual Clauses approved by the European Commission and the UK International Data Transfer Addendum. You can request a copy of the relevant safeguards by writing to [email protected].
Your Privacy Rights
Depending on where you live, you have some or all of the rights below. We honor these requests regardless of your location, because drawing a line based on geography seemed like the wrong instinct.
- Access: get a copy of the personal data we hold about you
- Rectification: correct data that is inaccurate or incomplete
- Erasure: have your personal data deleted, subject to legal retention duties
- Restriction: limit how we process your data while a dispute is resolved
- Portability: receive your data in a structured, machine readable format
- Objection: object to processing based on our legitimate interests, including direct marketing
- Withdraw consent: withdraw consent at any time, without affecting processing that already happened
- Complain: lodge a complaint with your local supervisory authority, or with the Information Commissioner's Office in the United Kingdom
California residents have the following rights.
- Right to know: what categories of personal information we collect, the sources, the business purpose, and the categories of third parties we disclose it to
- Right to delete: request deletion of personal information we collected from you
- Right to correct: request correction of inaccurate personal information
- Right to opt out: opt out of the sale or sharing of personal information. WebRun does not sell or share personal information, so there is nothing to opt out of
- Right to limit: limit the use of sensitive personal information. We do not use sensitive personal information for purposes beyond providing the service
- Right to non discrimination: we will never deny service, charge you more, or give you a lower quality experience for exercising any of these rights
Categories of personal information collected in the last 12 months: identifiers such as name, email, and IP address; commercial information such as plan and transaction history; internet activity such as browsing and interaction data; and the contents of workflows and automation runs you create.
- Email [email protected] with the request you want to make
- We will verify your identity, usually by confirming control of the email address on the account
- We respond within 30 days. If a request is complex we may extend that period and will tell you why
- There is no charge, unless a request is repetitive or clearly excessive
- An authorized agent may submit a request on your behalf with written proof of authorization
Children
WebRun is a developer tool intended for business use and is not directed to children. We do not knowingly collect personal information from anyone under 18. If you believe a child has provided us with personal information, contact [email protected] and we will delete it.
Changes to This Policy
We will update this policy as the product changes and as privacy law evolves. When we make material changes, we will update the date at the top of this page and notify account holders by email or through the platform before the changes take effect. Continuing to use WebRun after a change means you accept the updated policy.
Contact Us
For any privacy question, request, or complaint, write to [email protected]. We read every message and aim to reply within a few business days.
To report abuse of the WebRun platform, use [email protected] instead, which reaches the team faster for that specific case.
This Privacy Policy works alongside WebRun's Usage Policy, which sets out what you may and may not do with the platform.