Privacy Policy
The short version. Your scan data never leaves your browser. Stripe handles payments. Our web host keeps normal server logs. We don't use analytics, ad trackers or our own cookies, and we don't sell data.
1. Scan data
- The scanner makes no network connections. It writes one JSON file on the machine where it runs.
- The report tool reads that file with your browser's File API and classifies it with JavaScript on your computer. The file's contents are never sent to us or anyone else.
- So that your loaded scans survive the trip through checkout, the report tool keeps them in your browser tab's
sessionStorage. Browsers delete it when the tab is closed. You can also remove scans with “Clear all”.
2. What your browser stores
- Unlock token (
localStorage, after purchase): your plan, your Stripe checkout session ID, an expiry date and a signature. It contains no scan data and no payment card details. - Report preferences (
localStorage): the organization name and employee count you type into the report, so you don't have to retype them. They stay on your computer.
You can delete all of this by clearing site data for runtimeclear.com in your browser settings.
3. Payments
Checkout happens on Stripe's pages. Stripe collects your payment details, email address and billing information and processes them under the Stripe Privacy Policy. We never see or store your full card number. From Stripe we receive the information needed to run the business: your name and email, the plan, amount, date, country and payment status.
When you return from checkout, the report page sends the checkout session ID to our server (/api/verify.php). The server asks Stripe whether that session was paid and for which plan, then returns an unlock token. Later visits send only the token so the server can check its signature and expiry.
4. Server logs
Our hosting provider records standard web server logs for every request: IP address, date and time, requested URL, referring page, and browser user agent. These logs are used for security and troubleshooting and are kept according to the host's standard retention. To limit abuse, the verification endpoint keeps a short-lived request counter keyed by a one-way hash of your IP address, stored on the server for about ten minutes.
5. Third-party resources
Pages load typefaces from Google Fonts, so your browser connects to Google's servers, which receive your IP address and browser details under Google's Privacy Policy. Links to GitHub, Oracle and Stripe take you to sites with their own policies.
6. Email
If you email us, we keep the message and your address to answer you and to handle refunds or access requests.
7. What we don't do
- No analytics or advertising scripts, and no cookies set by us.
- No selling or renting of personal information.
- No sharing, except with the service providers above (Stripe, our web host, Google Fonts, our email provider) to run the service, or when required by law.
8. Retention
We keep purchase records for as long as tax and accounting law requires (generally up to seven years). Emails are kept as long as needed to support you and then deleted.
9. Your choices and rights
You can ask us for a copy of the personal information we hold about you, or ask us to correct or delete it, by emailing lsramos@techbuilddreams.com. We will respond within 30 days. Depending on where you live (for example the EU, UK or California) you may have additional rights; we honor those requests regardless of location, subject to records we must keep by law.
10. Children
RuntimeClear is a business tool and is not directed to children under 16.
11. Changes and contact
If we change this policy, we will update the effective date above. Questions: Tech Build Dreams LLC, 2125 Biscayne Blvd, Ste 204 #11842, Miami, FL 33137 · lsramos@techbuilddreams.com