Trust & data

What happens to the material you put into runime — who can see it, who it is sent to, how long it is kept, and how to get it deleted. Written to be checked, not admired: everything on this page is true of the product as it ships today, and where something is a commitment rather than an automated guarantee, it says so.

Last updated:

We do not train on your work

runime does not train any model on your prompts, your uploads or anything it generates for you. There is no training pipeline in the product: your screenplay, reference images, voice samples, boards and finished shots exist to make your film and for nothing else.

We do not sell, rent or trade your content or your personal data, and we do not use it to target advertising — not ours and not anyone else's.

Nobody here browses your projects. Access to production data is limited to the people who operate the service, and is used to diagnose a fault or answer a support request you raised — not to look at your film.

What the model providers do with it

Your material is sent to a model provider only at the moment you ask for a generation, and only the part that generation needs. Every provider below is bound by a data processing agreement, and under their enterprise/API terms Google Vertex AI and OpenAI do not use API inputs to train their models.

Two exceptions we would rather you heard from us:

  • Runway's terms of use reserve the right to use inputs and outputs for model training. If a production must never touch anyone's training set, choose a different video model for it — the model is a per-project setting.
  • sync.so, the lip-sync pass (reached through fal.ai), takes a broad, sublicensable licence over content uploaded to it, including for its own marketing. For unreleased client work, either keep the lip-sync pass off or ask us about enterprise terms first.

Named subprocessors

The complete list of third parties that can receive your data, what each one is for, where it runs, and its own policy. This is the same list the Privacy Policy renders — there is one source for it in the codebase, so the two pages cannot drift apart. Providers are added here before they are switched on.

Google Cloud Firebase (Firestore + Authentication)

Account authentication (Sign in with Google), user profile, project/screenplay data and token-wallet records storage.

Region: US / EU regions · Privacy policy

Google Cloud Vertex AI (Gemini, Veo, and third-party models served through Model Garden)

Generating screenplay/dialogue text, scene images and video clips. Your screenplay, instructions and reference images are passed to the model as system context during generation; under the provider's enterprise terms these inputs are not used to train models.

Region: US / EU regions · Privacy policy

fal.ai, Inc.

Running video (Kling, Luma, Seedance), image (FLUX, Nano Banana) and audio (ElevenLabs reseller) models. Image/text/audio inputs sent for generation are processed.

Region: United States · Privacy policy

ElevenLabs Inc.

Dialogue voice-over (TTS), sound effects, film score and voice changing (voice-changer / STS). For the voice-change feature, the user's own recorded voice is processed.

Region: US / EU regions · Privacy policy

OpenAI, L.L.C.

Generating certain scene images (GPT Image). Image/text inputs are processed; API inputs are not used to train models.

Region: United States · Privacy policy

xAI Corp. (Grok Imagine)

Used as a fast generation model for video and image generation (when the user selects it).

Region: United States · Privacy policy

Runway AI, Inc.

Generating video clips with high character/motion consistency (Gen-4.5).

Region: United States · Privacy policy

Google Cloud Storage + Cloud Run

Storing/delivering generated image, video and audio files and running the full-film MP4 export (ffmpeg).

Region: US / EU regions · Privacy policy

Stripe, Inc. (Managed Payments)

Sale of paid subscriptions and token packs, secure card-data processing (PCI DSS Level 1), billing and global VAT / sales-tax collection. Acts as Merchant of Record; card details are taken directly by Stripe and never written to IS.TEAM LLC servers.

Region: US / EU / United Kingdom · Privacy policy

sync.so (reached through fal.ai)

The lip-sync pass: the rendered shot and its dialogue audio are sent so the character's mouth matches the real recorded line. Note that sync.so's terms take a broad, sublicensable licence over content uploaded to it — see the Trust page.

Region: United States · Privacy policy

TopView AI

Running certain video and image generations (Veo / Wan / Seedream routes). The prompt and any reference frames for that shot are sent for generation.

Region: United States · Privacy policy

Vercel Inc.

Hosting the web application, edge-network caching and basic performance metrics.

Region: Global edge · Privacy policy

Functional Software, Inc. (Sentry)

Error and crash monitoring. Receives the stack trace, the page URL and the account identifier of a failing request — not your screenplay, prompts or generated media.

Region: US / EU regions · Privacy policy

Resend, Inc.

Sending transactional email (collaboration invites, billing and export notifications). Receives the recipient address and the message body only.

Region: United States · Privacy policy

Google Analytics (Google LLC)

Anonymous, aggregate usage measurement. Loaded ONLY if you accept analytics cookies; declining keeps the script off the page entirely. See the Cookie Policy.

Region: US / EU regions · Privacy policy

Upstash, Inc.

Shared rate-limit counters across server instances. Stores a short-lived counter key — the endpoint plus the caller's IP address — and a hit count, which expires with the rate-limit window. No account data, no prompts, no media. Used only where the shared rate-limit backend is enabled.

Region: Global (multi-region Redis) · Privacy policy

How long we keep things

Projects, screenplays and generated media live for as long as your account does — a film you are still cutting must not evaporate. Delete a film, or close the account, and every byte of it is erased within 24 hours. Server access logs are kept 90 days. Billing records are kept 7 years because US tax law requires records that support a filed return, and no deletion request can shorten that one.

The full table, category by category with the legal basis for each, is in the Privacy Policy.

Privacy Policy — retention periods

How to have it deleted

You do it yourself, and nobody has to be in the loop. Delete a film from its own menu, or close the whole account from the account page. Either way the material disappears from the product at once and is erased from our storage within 24 hours by a job that runs every hour — not by someone reading an inbox. Copies held by a model provider fall under that provider's own retention window; we pass the request on where the provider offers a channel for it.

The 24-hour gap is the only undo there is, and it exists for a reason: a film may still be rendering when you delete it, and pulling the bytes out from under a running job leaves fragments nobody can reach. Write to us inside that window and we can stop it. After it, there is nothing left to restore from.

Deletion requests: support@runime.com

Digital replicas and voice consent

runime can clone a voice from a sample, and can recast a recording into a character's voice. Because that is digital-replica technology, consent is not a checkbox in the browser: the server refuses to create a cloned voice unless it can write down who gave consent, whose voice it is and their relationship to that person, the exact sentence they agreed to, when, and for which production. The record is kept apart from the project so it survives the film being archived or deleted.

If you need that record for a delivery pack, a broadcaster's compliance form or a festival submission, ask us and we will export it for the production.

Cloning a voice you do not have permission to use is a breach of the Terms of Service, and our audio provider independently screens and blocks samples it recognises as protected or synthetic.

Security — and what we are not

Traffic is encrypted with TLS. Sign-in runs through Firebase Authentication and we never hold a password. Only the server-side service account reads the database; the browser cannot reach it directly. Your IP address is used to rate-limit abuse-sensitive endpoints — it lives in a counter that expires with its window, and we do not write it to our database; our hosting provider keeps its own access logs. Card details never reach our servers — Stripe takes them directly and is PCI DSS Level 1. If a personal-data breach occurs we notify the affected people and the supervisory authority within 72 hours.

What we are not: runime is not SOC 2 audited and not ISO 27001 certified, and we hold no other security certification. If your procurement process requires one, we would rather you knew now than after a signature. We are happy to complete a security questionnaire and to answer anything on this page in writing.

What we hand you at delivery

Every generated take records the model that made it, so a finished film knows exactly which providers touched it. The project info panel turns that into a per-film licence report: which providers were used, what each one's terms require of the person shipping the film (credits, permissions, plan conditions), and what does not transfer to a client. It is a summary of terms we read, not legal advice — but it is specific to your film rather than generic. The report itself is written in Turkish today, in both interfaces.

Beside the picture, an export can carry what a festival, a broadcaster or a post house asks for: subtitles as .srt and .vtt (optionally prefixed with the speaker's name), separate dialogue and M&E stems for dubbing and re-mixing, and a mix conformed to EBU R128 at −23 LUFS with the measured loudness report a channel's QC reads. Each of those is priced and rendered as its own master.

Every downloaded film carries a stereo track and, alongside it, a genuine 5.1 surround track — element-based routing with decorrelated rears, not a gain-scaled copy of the fronts. Stereo stays the default track so ordinary players are unaffected; a surround-capable player will offer the 5.1. If the surround encode fails the film still ships, stereo-only.

Who to contact

One inbox, read by us: privacy and deletion requests, security reports, unauthorised-likeness and copyright notices, security questionnaires, and anything on this page you want confirmed in writing.