The Short Version

The full policy is below, but these are the commitments that matter most.

Who We Are

WebRun is a United States based company. For visitors and customers in the European Economic Area and the United Kingdom, WebRun acts as the data controller for account and website data, and as a data processor for the content your automations handle on your behalf. Where we act as a processor, we handle that data only on your documented instructions.

Information We Collect

We collect four broad categories of information. Expand each one for the specifics.

  • Account details: name, email address, company name, and password credentials used to sign in
  • Billing information: billing address, plan selection, and transaction history. Payment card numbers go directly to our payment processor and are never stored on WebRun systems
  • Support and sales conversations: messages you send through contact forms, live chat, or email, including any information you choose to include in them
  • Content you submit: workflow descriptions, automation templates you author, and configuration you enter into the platform

This is the category unique to browser automation, and the one we want to be most explicit about. When a workflow runs, WebRun may store:

  • Screenshots and session recordings: visual captures of the automated browser session, retained so you can debug, replay, and verify what your automation actually did
  • Page content and extracted output: the text, HTML, and structured data your automation pulled from the sites it visited, stored as part of your run results
  • Prompts and workflow definitions: the natural language instructions you wrote and the saved automations built from them
  • Execution logs and metadata: timestamps, URLs visited, step by step status, error messages, and credit or token consumption

An important note on this data. If your automation visits a page containing personal information about other people, that information may end up in your screenshots, extracted output, or logs. You are responsible for having a lawful basis to collect it and for using it in line with applicable privacy law and our Usage Policy. We process it strictly on your behalf and for no purpose of our own.

Some automations need to sign in to a site to do their job. When you supply credentials for that purpose:

  • They are encrypted at rest using industry standard encryption
  • They are never written to our logs in plaintext and are redacted from diagnostic output
  • They are decrypted only at runtime, injected into the browser session that needs them, and discarded from memory when the session ends
  • They are never shared with third parties, and no WebRun employee accesses them in the ordinary course of operating the service

Because an authenticated session displays account content by design, screenshots of a logged in session may show the contents of that account. Keep this in mind when deciding which runs to retain.

  • Device and connection data: IP address, browser type and version, operating system, screen size, and referring URL
  • Behavioral data: pages viewed, links clicked, time on page, scroll depth, and navigation paths through the site
  • Attribution data: the campaign, source, or referrer that brought you to the site, stored so we can understand which channels work
  • Product usage data: feature usage, run volume, and error rates within the platform, used to improve reliability and prioritize what to build

How We Use Information

We use the information above for the following purposes, and nothing beyond them.

How We Do Not Use Information

Stating the negative matters as much as stating the positive.

Legal Bases for Processing

If you are in the European Economic Area or the United Kingdom, we rely on the following legal bases under the GDPR and UK GDPR.

Cookies and Similar Technologies

We use cookies and similar technologies to keep the site working, remember your preferences, and understand how the site is used. You can block or delete cookies through your browser settings, though doing so may affect how parts of the site behave.

Required for the site and platform to function. These cannot be switched off.

  • Session and authentication cookies that keep you signed in
  • Security cookies that protect against cross site request forgery
  • Load balancing and content delivery cookies set by our infrastructure providers

First party cookies we set to make the site more useful on repeat visits. All are prefixed wr_.

  • wr_tpl_seen: remembers which automation templates you have viewed, so we can recommend relevant ones
  • wr_ref and wr_src: record the referrer and source that brought you to the site
  • wr_attr_captured: marks that attribution has already been recorded, so we do not overwrite it on later visits

Set by third party services that help us measure site performance and manage customer relationships.

  • Google Analytics (_ga, _gid): measures traffic, page views, and navigation patterns. You can opt out using the Google Analytics Opt-out Browser Add-on
  • Microsoft Clarity (_clck, _clsk): analyzes how visitors interact with pages so we can improve layout and usability
  • HubSpot (hubspotutk, __hstc, __hssc): powers our contact forms and chat, and links your enquiries to your activity on the site

Service Providers

We share data with a small set of vendors who help us run the service. Each is bound by contract to protect the data, use it only for the purposes we specify, and delete it when the relationship ends. We do not share your personal information with anyone else except where this policy says so or where the law requires it.

Data Retention

Your workflow and session data is retained until you delete it. We do not impose an automatic expiry, because deciding what to keep is your call, not ours. You can delete individual runs, screenshots, and workflows from your account at any time, and deletion removes the data from active systems promptly.

Security

We protect data with the following measures.

We are currently pursuing SOC 2 compliance. We will update this page when that work is complete.

No system is perfectly secure, and we will not pretend otherwise. If we become aware of a breach affecting your personal data, we will notify you and the relevant regulators within the timeframes the law requires.

International Data Transfers

WebRun is based in the United States and our infrastructure providers operate globally, so your data may be transferred to and processed in countries outside your own, including the United States. Where we transfer personal data out of the European Economic Area or the United Kingdom, we rely on appropriate safeguards, including Standard Contractual Clauses approved by the European Commission and the UK International Data Transfer Addendum. You can request a copy of the relevant safeguards by writing to [email protected].

Your Privacy Rights

Depending on where you live, you have some or all of the rights below. We honor these requests regardless of your location, because drawing a line based on geography seemed like the wrong instinct.

  • Access: get a copy of the personal data we hold about you
  • Rectification: correct data that is inaccurate or incomplete
  • Erasure: have your personal data deleted, subject to legal retention duties
  • Restriction: limit how we process your data while a dispute is resolved
  • Portability: receive your data in a structured, machine readable format
  • Objection: object to processing based on our legitimate interests, including direct marketing
  • Withdraw consent: withdraw consent at any time, without affecting processing that already happened
  • Complain: lodge a complaint with your local supervisory authority, or with the Information Commissioner's Office in the United Kingdom

California residents have the following rights.

  • Right to know: what categories of personal information we collect, the sources, the business purpose, and the categories of third parties we disclose it to
  • Right to delete: request deletion of personal information we collected from you
  • Right to correct: request correction of inaccurate personal information
  • Right to opt out: opt out of the sale or sharing of personal information. WebRun does not sell or share personal information, so there is nothing to opt out of
  • Right to limit: limit the use of sensitive personal information. We do not use sensitive personal information for purposes beyond providing the service
  • Right to non discrimination: we will never deny service, charge you more, or give you a lower quality experience for exercising any of these rights

Categories of personal information collected in the last 12 months: identifiers such as name, email, and IP address; commercial information such as plan and transaction history; internet activity such as browsing and interaction data; and the contents of workflows and automation runs you create.

  • Email [email protected] with the request you want to make
  • We will verify your identity, usually by confirming control of the email address on the account
  • We respond within 30 days. If a request is complex we may extend that period and will tell you why
  • There is no charge, unless a request is repetitive or clearly excessive
  • An authorized agent may submit a request on your behalf with written proof of authorization

Children

WebRun is a developer tool intended for business use and is not directed to children. We do not knowingly collect personal information from anyone under 18. If you believe a child has provided us with personal information, contact [email protected] and we will delete it.

Changes to This Policy

We will update this policy as the product changes and as privacy law evolves. When we make material changes, we will update the date at the top of this page and notify account holders by email or through the platform before the changes take effect. Continuing to use WebRun after a change means you accept the updated policy.

Contact Us

For any privacy question, request, or complaint, write to [email protected]. We read every message and aim to reply within a few business days.

To report abuse of the WebRun platform, use [email protected] instead, which reaches the team faster for that specific case.

This Privacy Policy works alongside WebRun's Usage Policy, which sets out what you may and may not do with the platform.