Skip to content
Prerun
Legal

Prviacy Policy

Effective January 1, 2026

Prerun AI, LLC, a Maine limited liability company ("Prerun," "Company," "we," "our," or "us"), respects your privacy and is committed to protecting Personal Information entrusted to us.

This Privacy Policy explains how we collect, use, disclose, store, transfer, protect, and otherwise process Personal Information when you access or use the Services.

This Privacy Policy applies to the Prerun marketing website, Prerun Studio, APIs, MCP services, integrations, applications, and related products and services unless a separate privacy notice or agreement applies. GDPR privacy notices commonly identify the organization, categories of information collected, purposes of processing, legal bases, sharing practices, international transfers, retention periods, and individual rights.

1. WHO WE ARE

Prerun AI, LLC

State of Maine, United States

Website:
https://www.prerun.ai

Privacy Requests:
privacy@prerun.ai

Legal Notices:
legal@prerun.ai

Support:
support@prerun.ai

2. SCOPE OF THIS PRIVACY POLICY

2.1 Covered Services

This Privacy Policy applies to:

(a) the Prerun marketing website;

(b) Prerun Studio;

(c) APIs;

(d) MCP services;

(e) integrations;

(f) customer support services;

(g) subscription services;

(h) certification and training functionality; and

(i) related products and services provided by Prerun.

2.2 Covered Individuals

This Privacy Policy applies to:

(a) website visitors;

(b) prospective customers;

(c) customers;

(d) Authorized Users;

(e) API users;

(f) MCP users;

(g) integration users;

(h) event attendees;

(i) support contacts; and

(j) other individuals interacting with the Services.

2.3 Third-Party Services

This Privacy Policy does not apply to third-party websites, applications, platforms, products, or services that may be connected to the Services.

Such third parties maintain independent privacy practices and policies.

Prerun is not responsible for the privacy practices of third-party services.

3. DEFINITIONS

3.1 Personal Information

"Personal Information" means information that identifies, relates to, describes, references, is reasonably capable of being associated with, or could reasonably be linked to an identified or identifiable individual.

3.2 Personal Data

"Personal Data" shall have the meaning assigned under the General Data Protection Regulation ("GDPR"), UK GDPR, and similar applicable privacy laws.

3.3 Customer Content

"Customer Content" means information, files, assets, documents, prompts, configurations, knowledge entries, metadata, and other content uploaded, submitted, generated, stored, transmitted, or otherwise made available through the Services by customers or their Authorized Users.

3.4 Authorized User

"Authorized User" means any employee, contractor, consultant, representative, or other individual authorized by a customer to access or use the Services.

3.5 Processing

"Processing" means any operation performed on Personal Information or Personal Data, including collection, storage, use, disclosure, transmission, analysis, deletion, destruction, or other handling.

4. INFORMATION WE COLLECT

4.1 Information You Provide

Prerun may collect information voluntarily provided by you, including:

(a) name;

(b) email address;

(c) company name;

(d) job title;

(e) telephone number;

(f) billing information;

(g) support requests;

(h) survey responses;

(i) account preferences; and

(j) other information submitted through the Services.

4.2 Account Information

Prerun may collect information associated with Accounts, including:

(a) user profiles;

(b) organization names;

(c) workspace names;

(d) authentication details;

(e) user roles;

(f) permissions;

(g) API credentials; and

(h) MCP credentials.

4.3 Customer Content

Customers may upload, create, store, manage, validate, publish, distribute, and otherwise process Customer Content through the Services.

Customer Content may include:

(a) company information;

(b) brand standards;

(c) voice and tone guidance;

(d) messaging frameworks;

(e) product information;

(f) customer personas;

(g) standard operating procedures;

(h) policies;

(i) documentation;

(j) whitepapers;

(k) images;

(l) PDFs;

(m) presentations;

(n) files;

(o) AI-generated content;

(p) knowledge entries;

(q) assets; and

(r) metadata.

Customers control the Customer Content they upload and manage through the Services.

4.4 Payment Information

Payments are processed through third-party payment processors.

Prerun does not store complete payment card numbers.

Prerun may receive limited billing information including:

(a) billing address;

(b) transaction status;

(c) subscription status; and

(d) payment history.

5. INFORMATION COLLECTED AUTOMATICALLY

5.1 Technical Information

When you access or use the Services, Prerun may automatically collect:

(a) IP address;

(b) device identifiers;

(c) browser type;

(d) operating system;

(e) language settings;

(f) referring URLs;

(g) usage activity;

(h) request metadata;

(i) authentication events;

(j) API usage metrics;

(k) MCP usage metrics;

(l) error reports; and

(m) performance information.

5.2 Operational Uses

Prerun may use automatically collected information to:

(a) operate the Services;

(b) detect abuse;

(c) maintain security;

(d) improve performance;

(e) troubleshoot issues; and

(f) analyze platform usage.

6. INFORMATION RECEIVED FROM INTEGRATIONS

6.1 Third-Party Integrations

Customers may connect third-party services to the Services.

Depending on permissions granted by the customer, Prerun may receive information from connected systems.

Examples include:

(a) AI platforms;

(b) workflow platforms;

(c) development tools;

(d) content management systems;

(e) automation tools; and

(f) identity providers.

6.2 Customer-Controlled Access

The information received by Prerun depends upon the permissions, configurations, and authorizations established by the customer.

7. HOW WE USE INFORMATION

Prerun may use information to:

(a) provide the Services;

(b) authenticate users;

(c) manage subscriptions;

(d) deliver customer support;

(e) process payments;

(f) prevent fraud;

(g) detect abuse;

(h) maintain security;

(i) improve performance;

(j) analyze platform usage;

(k) operate APIs;

(l) operate MCP services;

(m) generate AI-powered functionality;

(n) conduct agent training;

(o) conduct agent certification;

(p) generate readiness assessments;

(q) validate knowledge;

(r) generate recommendations;

(s) send transactional communications;

(t) send product updates;

(u) comply with legal obligations; and

(v) enforce agreements.

8. AI PROCESSING

8.1 AI Functionality

Prerun utilizes artificial intelligence technologies to support functionality including:

(a) content generation;

(b) knowledge validation;

(c) readiness scoring;

(d) agent certification;

(e) classification;

(f) categorization;

(g) summarization;

(h) gap analysis;

(i) recommendations; and

(j) organizational assistance.

8.2 AI Outputs

AI outputs may be generated using internal systems and third-party AI providers.

Customers remain responsible for reviewing, validating, testing, and approving outputs before relying upon them.

AI-generated outputs may contain inaccuracies, omissions, outdated information, or unexpected results.

9. AI TRAINING COMMITMENT

9.1 Customer Content Protections

Prerun recognizes that Customer Content may contain confidential, proprietary, and commercially sensitive information.

9.2 No Foundation Model Training

Except where expressly authorized by a customer, Prerun does not use Customer Content to train proprietary foundation models.

9.3 No Intentional Contribution to Public Training Datasets

Prerun does not intentionally contribute Customer Content to publicly available foundation model training datasets.

9.4 Enterprise AI Providers

Where commercially reasonable, Prerun seeks to utilize enterprise-grade and API-based AI providers that contractually restrict use of submitted content for model training purposes.

9.5 Customer-Directed AI Processing

Customer acknowledges that Customer Content may be transmitted to, processed by, analyzed through, or otherwise handled by artificial intelligence systems and model providers selected by Prerun or configured by Customer for purposes of delivering requested functionality.

9.6 De-Identified Information

Nothing in this Privacy Policy prohibits Prerun from using aggregated, anonymized, de-identified, or statistical information that cannot reasonably identify an individual or customer for analytics, benchmarking, security, service improvement, operational planning, and product development.

10. LEGAL BASES FOR PROCESSING

Where the GDPR, UK GDPR, or similar privacy laws apply, Prerun relies upon one or more of the following legal bases for processing Personal Data.

10.1 Performance of a Contract

Prerun processes Personal Data where necessary to:

(a) provide the Services;

(b) authenticate users;

(c) maintain Accounts;

(d) process subscriptions;

(e) provide customer support;

(f) deliver requested functionality; and

(g) fulfill contractual obligations.

10.2 Legitimate Interests

Prerun may process Personal Data where necessary for legitimate business interests, including:

(a) security;

(b) fraud prevention;

(c) abuse detection;

(d) platform administration;

(e) analytics;

(f) service improvement;

(g) operational planning;

(h) product development; and

(i) protecting the Services and customers.

10.3 Legal Obligations

Prerun may process Personal Data where necessary to comply with:

(a) legal requirements;

(b) court orders;

(c) governmental requests;

(d) regulatory obligations; and

(e) lawful enforcement requests.

10.4 Consent

Where required by law, Prerun relies upon consent.

Individuals may withdraw consent at any time, although withdrawal does not affect processing that occurred before consent was withdrawn.

11. HOW WE SHARE INFORMATION

11.1 Service Providers

Prerun may disclose Personal Information to service providers, contractors, subprocessors, and vendors that assist in operating the Services.

Examples may include providers of:

(a) cloud infrastructure;

(b) hosting services;

(c) content delivery services;

(d) analytics services;

(e) customer support tools;

(f) payment processing services;

(g) security services;

(h) authentication services;

(i) email delivery services;

(j) AI services; and

(k) monitoring services.

11.2 Customer-Directed Integrations

Where a customer enables an integration, Prerun may transmit information to the connected third-party platform at the customer's direction.

11.3 Corporate Transactions

Prerun may disclose information in connection with:

(a) a merger;

(b) acquisition;

(c) financing transaction;

(d) corporate restructuring;

(e) sale of assets; or

(f) similar business transaction.

11.4 Legal Requirements

Prerun may disclose information where reasonably necessary to:

(a) comply with law;

(b) comply with legal process;

(c) respond to lawful governmental requests;

(d) enforce agreements;

(e) investigate fraud;

(f) protect rights;

(g) protect safety; or

(h) protect the Services.

11.5 With Consent

Prerun may disclose information with the consent or direction of the applicable individual or customer.

12. INTERNATIONAL DATA TRANSFERS

12.1 International Processing

Prerun operates in the United States and may process information in the United States and other countries where Prerun, its Affiliates, service providers, or subprocessors operate.

12.2 Transfer Safeguards

Where required by applicable law, Prerun implements appropriate safeguards for international transfers of Personal Data.

Such safeguards may include:

(a) Standard Contractual Clauses;

(b) contractual commitments;

(c) adequacy mechanisms;

(d) transfer impact assessments; and

(e) other lawful transfer mechanisms.

12.3 Acknowledgement

By using the Services, individuals acknowledge that information may be transferred to and processed in jurisdictions that may have privacy laws different from those in their country of residence.

13. DATA RETENTION

13.1 Retention Principles

Prerun retains Personal Information only for as long as reasonably necessary to:

(a) provide the Services;

(b) fulfill contractual obligations;

(c) comply with legal obligations;

(d) resolve disputes;

(e) enforce agreements;

(f) maintain security; and

(g) operate the Services.

13.2 Retention Periods

Retention periods vary depending on:

(a) the nature of the information;

(b) applicable legal requirements;

(c) customer instructions;

(d) operational needs;

(e) security requirements; and

(f) regulatory obligations.

13.3 Backups and Logs

Information may remain in backups, archives, audit logs, disaster recovery systems, and security records for a reasonable period following deletion from active systems.

14. ACCOUNT DELETION AND DATA DELETION

14.1 Customer-Controlled Deletion

Customers may delete Customer Content through functionality made available within the Services.

14.2 Account Closure

Customers may request closure of Accounts in accordance with applicable subscription terms and contractual obligations.

14.3 Post-Termination Retention

Following termination, Prerun may retain information where reasonably necessary for:

(a) legal compliance;

(b) dispute resolution;

(c) fraud prevention;

(d) security purposes;

(e) financial recordkeeping; and

(f) enforcement of agreements.

14.4 Deletion Requests

Individuals may submit privacy-related deletion requests using:

privacy@prerun.ai

Prerun will evaluate and respond to such requests in accordance with applicable law.

15. GDPR AND UK GDPR RIGHTS

Where the GDPR, UK GDPR, or similar privacy laws apply, individuals may possess certain rights regarding Personal Data, including rights of access, correction, deletion, portability, restriction, objection, and related protections.

15.1 Right of Access

Individuals may request confirmation regarding whether Prerun processes Personal Data relating to them and may request access to such information.

15.2 Right to Rectification

Individuals may request correction of inaccurate or incomplete Personal Data.

15.3 Right to Erasure

Individuals may request deletion of Personal Data where applicable law provides such rights, commonly referred to as the "right to be forgotten."

15.4 Right to Restrict Processing

Individuals may request restriction of processing under circumstances permitted by applicable law.

15.5 Right to Data Portability

Individuals may request a copy of Personal Data in a structured, commonly used, and machine-readable format where required by applicable law.

15.6 Right to Object

Individuals may object to certain processing activities where permitted by applicable law.

15.7 Automated Decision-Making Rights

Where applicable law provides such rights, individuals may request review of decisions based solely upon automated processing.

15.8 Exercising Rights

Requests relating to privacy rights may be submitted to:

privacy@prerun.ai

Prerun may require reasonable verification of identity before fulfilling requests.

16. CALIFORNIA PRIVACY RIGHTS

16.1 California Residents

Residents of California may possess rights under the California Consumer Privacy Act ("CCPA"), California Privacy Rights Act ("CPRA"), and related laws.

16.2 California Rights

Subject to applicable law, California residents may have rights to:

(a) know what Personal Information is collected;

(b) know how Personal Information is used;

(c) request deletion of Personal Information;

(d) request correction of Personal Information;

(e) access categories of Personal Information collected;

(f) access categories of recipients receiving Personal Information; and

(g) exercise other rights provided under applicable California law.

16.3 No Sale of Personal Information

Prerun does not sell Personal Information in exchange for monetary compensation.

16.4 No Sensitive Data Profiling

Prerun does not use sensitive Personal Information for purposes requiring a separate right to limit use under California law except as otherwise disclosed and permitted by applicable law.

17. MARKETING COMMUNICATIONS AND CAN-SPAM COMPLIANCE

17.1 Transactional Communications

Prerun may send transactional communications relating to:

(a) Accounts;

(b) subscriptions;

(c) billing;

(d) security notifications;

(e) service updates;

(f) legal notices; and

(g) operational communications.

17.2 Marketing Communications

Prerun may send marketing communications where permitted by applicable law.

17.3 Opt-Out Rights

Recipients may opt out of marketing communications at any time by:

(a) using unsubscribe functionality;

(b) adjusting account preferences; or

(c) contacting Prerun.

17.4 CAN-SPAM Compliance

Prerun intends to comply with applicable email marketing laws, including the CAN-SPAM Act and similar laws governing commercial electronic communications.

Opt-out requests will be processed within commercially reasonable timeframes and in accordance with applicable legal requirements.

18. COOKIES AND TRACKING TECHNOLOGIES

18.1 Use of Cookies

Prerun may use cookies, pixels, local storage technologies, SDKs, and similar technologies to operate, secure, analyze, and improve the Services.

18.2 Categories of Cookies

Cookies and similar technologies may include:

(a) strictly necessary cookies;

(b) authentication cookies;

(c) security cookies;

(d) preference cookies;

(e) analytics cookies;

(f) performance cookies; and

(g) marketing or advertising cookies where permitted by applicable law.

18.3 Browser Controls

Most web browsers permit users to control cookie settings.

Disabling certain cookies may impact the functionality, availability, or performance of portions of the Services.

18.4 Analytics Technologies

Prerun may utilize analytics technologies to better understand how visitors and customers interact with the Services, improve user experience, and measure performance.

19. CLOUDFLARE TURNSTILE AND ABUSE PREVENTION

19.1 Security Services

Prerun utilizes technologies designed to protect the Services from spam, automated abuse, credential attacks, fraudulent activity, denial-of-service attacks, and malicious automation.

Such technologies may include Cloudflare Turnstile and related security services.

19.2 Information Processed

When Cloudflare Turnstile is used, certain technical, browser, device, network, and security-related information may be collected or processed for purposes of bot detection, fraud prevention, abuse prevention, and platform protection.

19.3 Third-Party Privacy Documentation

Additional information regarding Cloudflare Turnstile is available through:

Cloudflare Turnstile Privacy Addendum:

https://www.cloudflare.com/turnstile-privacy-policy/

Cloudflare Privacy Policy:

https://www.cloudflare.com/privacypolicy/

19.4 Customer Acknowledgement

By interacting with portions of the Services protected by Cloudflare Turnstile, users acknowledge that information may be processed by Cloudflare and related service providers as described in the above documentation.

20. SECURITY AND INCIDENT RESPONSE

20.1 Security Measures

Prerun maintains administrative, technical, and organizational safeguards designed to protect Personal Information and Customer Content.

Such safeguards may include:

(a) encryption in transit;

(b) authentication controls;

(c) authorization controls;

(d) audit logging;

(e) monitoring systems;

(f) access controls;

(g) infrastructure protections;

(h) backup procedures; and

(i) security review processes.

20.2 No Absolute Security Guarantee

No method of transmission, storage, processing, or security control can guarantee complete security.

Accordingly, Prerun cannot guarantee that unauthorized access, disclosure, alteration, destruction, loss, or compromise of information will never occur.

20.3 Security Reporting

Individuals who believe they have identified a security vulnerability or security concern are encouraged to contact:

security@prerun.ai

20.4 Incident Response

Prerun maintains processes intended to investigate, respond to, and remediate security incidents.

Where required by applicable law, affected parties may be notified of certain security incidents.

21. DATA PROCESSING ADDENDUM (DPA)

21.1 Availability of DPA

Prerun makes available a Data Processing Addendum ("DPA") for customers that require data processing terms under GDPR, UK GDPR, and similar privacy laws.

Current DPA:

https://www.prerun.ai/legal/dpa

21.2 DPA Applicability

The DPA applies where Prerun processes Personal Data on behalf of a customer acting as a Controller, Business, or equivalent designation under applicable law.

21.3 DPA Controls

In the event of a conflict between this Privacy Policy and an executed DPA regarding Personal Data processing obligations, the DPA shall control solely with respect to those obligations.

22. CONTROLLER AND PROCESSOR ROLES

22.1 Customer Data

For Customer Content and Personal Data processed on behalf of customers:

(a) the customer acts as Controller, Business, or equivalent designation under applicable law; and

(b) Prerun acts as Processor, Service Provider, or equivalent designation under applicable law.

22.2 Customer Instructions

Prerun processes Personal Data on behalf of customers in accordance with:

(a) customer instructions;

(b) contractual obligations;

(c) the Services;

(d) the DPA; and

(e) applicable law.

22.3 Independent Processing

For information relating to Prerun's own business operations, website visitors, prospective customers, billing administration, marketing activities, security operations, and legal compliance, Prerun acts as an independent Controller.

23. SUBPROCESSORS

23.1 Use of Subprocessors

Prerun may engage subprocessors, vendors, contractors, and service providers to assist in providing the Services.

23.2 Categories of Subprocessors

Subprocessors may provide:

(a) cloud hosting;

(b) infrastructure services;

(c) content delivery services;

(d) analytics services;

(e) monitoring services;

(f) customer support services;

(g) payment processing;

(h) authentication services;

(i) security services;

(j) email delivery services;

(k) artificial intelligence services; and

(l) operational support services.

23.3 Subprocessor List

Prerun maintains a current Subprocessor List available at:

https://www.prerun.ai/legal/subprocessors

23.4 Subprocessor Obligations

Prerun requires subprocessors to maintain obligations regarding privacy, confidentiality, and security that are substantially similar to those applicable to Prerun where required by law or contract.

23.5 Responsibility

Prerun remains responsible for its subprocessors to the extent required by applicable law and contractual obligations.

24. TRUST CENTER AND COMPLIANCE DOCUMENTATION

24.1 Trust Center

Prerun maintains security, privacy, compliance, and governance documentation through its Trust Center.

Trust Center:

https://www.prerun.ai/resources/trust-center

24.2 Available Documentation

The Trust Center may include:

(a) security information;

(b) privacy documentation;

(c) subprocessors;

(d) compliance documentation;

(e) AI transparency information;

(f) legal documentation; and

(g) related governance materials.

25. CHILDREN'S PRIVACY

25.1 No Intended Use by Children

The Services are not directed toward children under thirteen (13) years of age.

25.2 No Knowing Collection

Prerun does not knowingly collect Personal Information directly from children under thirteen (13).

25.3 Removal Requests

If Prerun becomes aware that Personal Information has been collected from a child in violation of applicable law, Prerun will take reasonable steps to delete such information.

Parents or guardians who believe a child has provided Personal Information may contact:

privacy@prerun.ai

26. CHANGES TO THIS PRIVACY POLICY

26.1 Updates

Prerun may update this Privacy Policy from time to time.

26.2 Notice

Material changes may be communicated through:

(a) the Services;

(b) account notifications;

(c) email communications; or

(d) other reasonable means.

26.3 Effective Date

The "Last Updated" date at the top of this Privacy Policy indicates when the current version became effective.

Continued use of the Services following the effective date of an updated Privacy Policy constitutes acknowledgement of the revised Privacy Policy.

27. CONTACT INFORMATION

Prerun AI, LLC

State of Maine, United States

Privacy Requests:
privacy@prerun.ai

Legal Notices:
legal@prerun.ai

Support:
support@prerun.ai

Security Reports:
security@prerun.ai

Website:
https://www.prerun.ai

28. PRIVACY POLICY ACKNOWLEDGEMENT

By accessing or using the Services, you acknowledge that you have read and understood this Privacy Policy.

You further acknowledge that:

(a) Prerun may process Personal Information as described in this Privacy Policy;

(b) Prerun may engage subprocessors and service providers to operate the Services;

(c) Personal Information may be processed in the United States and other jurisdictions where Prerun and its providers operate;

(d) Customer Content may be processed through AI systems and providers as described in this Privacy Policy and applicable agreements; and

(e) your rights regarding Personal Information are subject to applicable law and any verification requirements necessary to protect privacy and security.

This Privacy Policy should be read together with the Terms of Service, Data Processing Addendum, Subprocessor List, Trust Center documentation, and other legal notices made available by Prerun.