Run Edit Run · Privacy

Privacy policy

How we handle information when you browse, contact us or authorise us to help manage your software.

Last updated: 20 September 2026


01

Who and what this covers

Run Edit Run is a JustEvery product operated by Peter Industries Pty Ltd as trustee for Peter Family Trust, ABN 13 588 984 088 (“we”, “us”). This policy explains how we handle personal information about website visitors, people who contact us, and people using our accounts, paid services or managed-service pilots.

Our public catalogue offers software that owners can run in their own accounts. Assisted and Managed enrollment is opening in stages and may be subject to qualification. The account, connected-service, billing and AI provisions below apply when you submit a paid enrollment or use those features through an active installation, pilot or other agreed service; browsing the catalogue does not create a management account.

02

Your application and our service

The owner of an application deployed from our code decides how that application collects and uses its customers’ information. Its privacy notice and chosen providers apply to that activity. Downloading or running our code does not, by itself, send the application’s customer database to us.

We handle our website, account, support and service administration information for our own operational purposes. Where an owner authorises us to manage an application, we also process information on their behalf to carry out that work. Depending on the selected path, the application may run in your cloud account or in an operator cloud and private repository. Depending on the permissions granted and the task, management work can include source code, configuration, deployment information, logs and application data. Keeping an application in your cloud account does not mean that management tools or authorised support personnel can never access its data.

Information included in a prompt, support request, diagnostic record or agent task can pass through our management service and its providers. Application owners are responsible for having authority to share it and for explaining that processing to affected people.

03

Information we handle

  • Website requests: hosting providers process technical request information such as IP address, browser details, requested address, time and error or security information when serving the site.
  • Correspondence: contact details, messages and attachments you send when asking for help or discussing the service.
  • Management accounts: email address, magic-link sign-in records, GitHub account identifiers where connected, login and profile name, sessions, team membership and permissions.
  • Connected accounts: selected repository and cloud account identifiers, authorisations, encrypted access or refresh credentials, and configuration needed for the work you authorise.
  • Management work: prompts, conversations, source snapshots, changes, generated assets, build and verification results, deployment records, errors, activity history, provider identifiers and usage records. If you enable voice features, the voice provider processes audio and the service can retain transcripts and resulting conversation or task records.
  • Editor page context: the authorised in-app editor automatically reads a limited amount of rendered page text, the page title and path, and element context to support editing requests. This context is sent to management and relevant AI providers with the request. Page-context sharing is part of this editor and has no separate sharing toggle. Input values and regions the application marks private are excluded, but other visible text may still contain personal or confidential information. This capture reads page text; it does not take a screenshot.
  • Local companion: device and project identifiers, connection status and records or artifacts returned by authorised work on your machine.

We collect information from you, your browser or connected device, your authorised integrations and providers, and people you permit to work on your installation. Avoid including unnecessary personal information or secrets in prompts and support attachments. Browsing the public site does not require sign-in; declining necessary account or connection information may prevent a managed feature from working.

Assisted and Managed enrollment is opening in stages. When you submit a paid enrollment or use a paid installation, we handle the account, installation, billing, payment, tax, service-period, included management/update AI allowance, usage, cancellation and exit records needed to provide and administer that service. Payment providers may process payment details under their own terms; we receive the transaction and billing records needed to reconcile the service. Availability and activation depend on the flow shown to you, so this policy does not represent that every paid path is generally available or that an installation has been activated.

04

Cookies, fonts and external links

The public marketing site does not set cookies or include advertising or analytics trackers. It loads typefaces from Google Fonts, so your browser makes requests to Google that disclose technical information, including your IP address. See Google’s explanation of Google Fonts privacy.

A management sign-in uses session cookies and authentication records. GitHub, Cloudflare and other services you connect or visit have their own privacy practices and may use their own cookies. This public-site statement does not describe cookies used by independently operated applications deployed from our code.

05

How we use information

We use information to serve and secure the website, answer enquiries, authenticate users, maintain permissions, connect the accounts you select, perform authorised engineering and deployment work, show its results, diagnose failures, manage service costs and keep appropriate business records. We may also use it to investigate abuse, comply with law and resolve disputes.

We do not sell personal information or use it for targeted advertising. This policy does not grant permission to publish your private source code, conversations or customer data.

06

Providers and disclosure

The website and management infrastructure use Cloudflare. Management connects to GitHub for identity, repositories and build workflows, and to Cloudflare for authorised cloud operations. Hosted AI features use OpenAI for conversation, engineering agents and, where enabled, image generation and voice. When video generation is enabled, we send the video prompt to fal.ai to generate the requested video using its Veo model service. The context needed to perform the requested work is sent to those services; it may contain personal information you or your application include.

If you use a local agent, its selected provider also processes the context supplied to that agent under your provider arrangement. Provider processing and retention depend on the feature, account and applicable terms. We do not promise that content stays on your device or make a blanket promise about every provider’s training or retention practices.

We may disclose information to people and providers supporting the authorised service, professional advisers, parties involved in a business transfer subject to appropriate protections, or authorities where required or permitted by law. We may also disclose information with your consent or at your direction.

07

Processing outside Australia

We are based in Australia. Our providers operate internationally, including in the United States, and information may be processed outside Australia through their infrastructure and authorised personnel. Your own cloud location does not determine where every management or AI request is processed.

Applicable safeguards and transfer obligations depend on the service and the law that applies. Contact us before sharing information subject to a particular location or transfer requirement so that the proposed arrangement can be assessed.

08

Security and retention

Management safeguards include access controls, encrypted stored connection credentials, hashed session secrets and private artifact storage. Access depends on the permissions granted and the service configuration. No system is completely secure; protect your own accounts and review the access you authorise.

We retain information for the time needed to provide and support the service, maintain useful change and release evidence, address security issues, and meet legal or business record obligations. Retention varies by record type and provider. We do not currently promise a fixed automatic deletion period for all management content.

Temporary preview environments have separate cleanup arrangements. The current preview system schedules cleanup after 24 hours; replacement previews and provider or access failures can affect the timing. Preview resources, their data and associated preview artifacts may be deleted. They are not production storage: keep an independent copy of anything you need. Preview access links expire separately and should be kept confidential. Expiry of a link does not mean every stored copy has been deleted.

Disconnecting a provider disables its use by management. If revocation cannot be confirmed, encrypted credentials may remain for a subsequent revocation attempt. Disconnecting does not automatically erase historical conversations, source artifacts or release records. You may also revoke access in the provider’s settings and contact us about deletion. Copies held in your own repositories, cloud accounts or exports remain under your control; Standalone and Assisted resources remain in the customer accounts that own them. For Managed, operator copies and resources enter the documented exit lifecycle: management, update and new-deployment authority ends at the paid-period boundary, while existing Workers or background runtime are not automatically suspended and continued runtime is not guaranteed. We retain the Managed handover/export path for at least 30 days under the accepted policy; operator hosting may then be manually retired without automatically deleting retained source or data. Retain an export needed for continued operation.

09

Requests and complaints

You can ask what personal information we hold about you, request access or correction, or ask us to delete information by contacting the privacy contact below. Please describe your request and the account or interaction concerned. We may need to verify your identity or authority, and will explain any applicable limitation or refusal.

If the information is held by an independently operated application, contact its owner first. Where we process that information on the owner’s behalf, we may refer your request to them or assist them in responding.

Depending on the law that applies, you may have additional rights, including objection, restriction, portability or withdrawal of consent. Raising a privacy concern will not itself affect your access to our services.

For a complaint, describe what happened and the outcome you seek. We will review it, seek any necessary clarification and respond within a reasonable time. If Australian privacy law applies and you are dissatisfied with the response, you may be able to complain to the Office of the Australian Information Commissioner. Other applicable laws may provide a right to contact your local privacy regulator.

10

Contact and policy changes

Privacy contact: Peter Industries Pty Ltd as trustee for Peter Family Trust, operator of Run Edit Run
ABN 13 588 984 088
12 Dulku Close
Craiglie, QLD 4877
Australia

Email: privacy@runeditrun.com. For service enquiries: support@runeditrun.com.

Please identify Run Edit Run in your message. Address postal correspondence to “Run Edit Run — Privacy”.

We may update this policy as the website and service change. We will publish the revised policy with its updated date and take reasonable steps to draw material changes to affected service users’ attention.