← Back to DotRun

Beta privacy notice

Privacy Policy

Last updated: August 6, 2026

This Privacy Policy explains how DotRun handles personal data when you visit the service, publish a project, create an account, submit an abuse report, or contact the operator.

1. Data controller

DotRun is currently operated as an independent private-beta project. The DotRun operator acts as the controller for account, publication, security, and support data described in this Policy. Privacy requests can be submitted through the Report Abuse page. Additional registered-business details will be published before paid services are offered.

2. Data we process

  • Account data, such as your email address, account status, plan, and authentication timestamps.
  • Anonymous-session data, including a random session identifier and hashed management credentials.
  • Technical data, such as IP-derived security hashes, user agent, request identifiers, timestamps, rate-limit events, and security logs.
  • Project data, including HTML or ZIP uploads, static website files, project slug, deployment reports, file counts, sizes, repair results, publication status, and expiration time.
  • Support and moderation data, including abuse reports, reporter contact details when provided, investigation notes, and moderation actions.
  • Anti-abuse signals produced when Cloudflare Turnstile is used to distinguish legitimate visitors from automated traffic.

3. Why we process data

  • To create sessions, accounts, projects, and public URLs.
  • To validate, safely repair, publish, update, expire, and delete static websites.
  • To authenticate users and send requested magic-link emails.
  • To prevent phishing, credential theft, malware, spam, fraud, abuse, and attempts to compromise the service.
  • To investigate reports, enforce policies, maintain backups, and recover from operational failures.
  • To comply with legal obligations and protect legitimate rights.

4. Legal bases

Depending on the context, processing is based on performing the service you request, taking steps before providing that service, legitimate interests in operating and securing DotRun, compliance with legal obligations, and consent where applicable. You may withdraw consent for future processing where consent is the legal basis.

5. Public project content

Published projects are intentionally public at their*.dotrun.siteaddress. Do not upload secrets, private personal data, access tokens, passwords, private keys, confidential documents, or content you are not authorised to publish.

6. Cookies and local storage

DotRun uses essential cookies or equivalent browser storage for anonymous project ownership, authenticated sessions, security, and abuse prevention. DotRun does not currently use advertising cookies or sell personal data for targeted advertising.

Cloudflare Turnstile may set or read security-related browser data as described in Cloudflare's Turnstile Privacy Addendum.

7. Service providers

DotRun relies on service providers for infrastructure, storage, content delivery, security, email delivery, monitoring, and backups. These currently include Cloudflare services such as DNS, CDN, Turnstile, Workers, and R2, together with VPS, transactional email, and encrypted backup providers.

Providers receive only the data reasonably required to deliver their service and may process data in multiple countries subject to applicable contractual and legal safeguards.

8. Retention

  • Anonymous projects normally remain available for up to 24 hours.
  • Free-account projects normally remain available for up to seven days unless renewed, updated, disabled, or deleted earlier.
  • Account and project metadata are retained while needed to operate the account, enforce limits, resolve disputes, and meet legal or security requirements.
  • Security and audit logs may be retained for a limited period appropriate to investigation and abuse prevention.
  • Encrypted disaster-recovery backups may be retained for up to approximately 370 days and then rotated automatically.

Data may remain in encrypted backups until the applicable backup expires, even after active records have been deleted.

9. Security

DotRun uses separation between the application domain and user content domain, secure session cookies, hashed management tokens, rate limits, Turnstile, restricted file types, automated safety checks, encrypted backups, and access controls. No online service can guarantee absolute security.

10. Your rights

Depending on applicable law, you may have rights to request access, correction, deletion, restriction, portability, or objection to processing, and to withdraw consent. You may also have the right to complain to your local data-protection authority.

Submit a privacy request through the Report Abuse page and clearly mark the request as a privacy request. Identity verification may be required before account data is disclosed or deleted.

11. Children

DotRun is not directed to children under 16. Do not use the service or submit personal data if you are below the minimum age required to consent to online services in your jurisdiction.

12. Changes

This Policy may be updated as DotRun changes. The current version will be posted here with a revised “Last updated” date. Material changes may also be highlighted in the application.