Legal
Privacy Policy
Effective and last updated
What this policy covers
This policy describes how Runestone Labs (“Runestone,” “we,” “us”) handles information when you visit the Gatekeeper website, join Cloud demand validation, or use a future Gatekeeper Cloud beta made available to you. The open-source Gatekeeper software runs locally by default. Data that stays in your local installation is controlled by you and is not collected by us.
Information we collect
- Account and organization data: your name, verified email address, account identifier, organization membership, role, and sign-in activity. Authentication is provided by Clerk.
- Google sign-in data: if you choose Google, we receive the basic identity information needed to authenticate you, including your name, email address, profile image, and Google account identifier. Gatekeeper does not request access to Gmail, Drive, Calendar, or other Google product data.
- Connected-instance data: instance and run identifiers, tool name, policy decision, reason and risk category, policy hash, action digest, timestamps, duration, cost, token count, approval status, and approver identity. Built-in summaries may include a shell executable with sanitized arguments, a normalized file path with byte count and content hash, or an HTTP method and origin.
- Billing data: subscription status, plan, and Stripe customer and subscription identifiers. Payment-card details are handled directly by Stripe and are not stored by Gatekeeper.
- Website and operational data: page visits, referrer, approximate location, device/browser information, diagnostic logs, security events, and interactions with product or pricing links. We use Plausible and Google Analytics for website measurement.
Information Gatekeeper Cloud does not receive
Gatekeeper Cloud is designed not to receive raw prompts, tool results, file contents, HTTP bodies or headers, environment values, complete URLs containing query strings, or custom tool arguments unless a scalar field is explicitly allowlisted. Selected values pass through secret detection, home-path normalization, truncation, and hashing before export. Your local audit store remains authoritative.
How we use information
We use information to:
- authenticate users and maintain organizations and approver identities;
- deliver approvals, policy coordination, audit history, alerts, and weekly reports;
- operate subscriptions, provide support, and communicate service changes;
- secure, troubleshoot, measure, and improve Gatekeeper; and
- comply with law and enforce our agreements.
We do not sell personal information. We do not use Google sign-in data for advertising, and we do not use it to train general-purpose AI models.
Service providers and disclosures
We use service providers to run the product, including Clerk for authentication, Amazon Web Services for hosting and storage, Stripe for billing, Resend for email delivery, and Plausible and Google Analytics for website measurement. They process information on our behalf under their own terms and privacy commitments. We may also disclose information when required by law, to protect users or the service, or as part of a merger, financing, acquisition, or sale of assets with appropriate safeguards.
Retention and deletion
Cloud beta qualification responses are retained while we evaluate demand and communicate beta updates, unless you ask us to delete them. If Cloud accounts are later activated, their stated retention periods will be disclosed before general availability. Account, billing, fraud-prevention, and security records may be retained while your account is active and for a limited period afterward. Local Gatekeeper records follow the retention settings you control. You may request account deletion using the contact below; we may keep limited records required for legal, security, or accounting purposes.
Security
We use encryption in transit and at rest, tenant-scoped authorization, hashed instance tokens, restricted operational access, audit integrity checks, and monitoring. No security measure eliminates all risk, so you should route only intended actions through Gatekeeper and protect your local credentials and recovery methods.
Your choices and rights
Depending on where you live, you may have rights to access, correct, export, delete, or restrict certain uses of personal information. You may sign in without Google by using a verified email code. You can disconnect a local Gatekeeper instance without disabling its local enforcement. Contact us to exercise a privacy right; we may need to verify your identity first.
Children and international use
Gatekeeper is intended for business and developer use and is not directed to children under 13. Information may be processed in the United States and other countries where our service providers operate, subject to applicable safeguards.
Changes and contact
We may update this policy as Gatekeeper changes. We will revise the date above and provide additional notice when required. Questions or privacy requests can be sent to evan@runestonelabs.io .
Runestone LabsUnited States