Legal

Privacy Policy

Version 2026-09-run-v3 · Last updated 11 September 2026

This is the edition in force. It describes the service as it actually runs today. When we make a material change we publish the new version here and announce it, and for the documents you have accepted we ask you to accept the new version in your workspace.

Who is responsible for your data

Run is operated by Void Music Group (SASU), registered in France under SIREN 992 576 322, with its registered office at 25 rue de Ponthieu, 75008 Paris, France. For the personal data described here, Void Music Group is the data controller within the meaning of the General Data Protection Regulation.

The full registration record is on our Terms of Service page. We have not appointed a Data Protection Officer, which we are not required to do; data protection requests reach us directly at privacy@run.audio.

What we collect

Account and identity

Your email address, your password in hashed form, and, if you turn it on, your two-factor authentication setup. We record sign-in events, the plan your account is on, and the moment you accept a version of our terms, with the browser user agent used. We deliberately do not record your IP address against that acceptance.

Account security and abuse prevention

While you are signed in we record the IP address your session connects from and when we last saw it, and we keep the addresses seen on your account for as long as the account exists. They are part of the copy of your data you can download from Settings. If we close an account for breaking our rules, the addresses tied to it stay on an abuse denylist after the account itself is gone, so that a closure can be recognised rather than quietly restarted under a new sign-up. We rely on our legitimate interest in keeping the service safe and in preventing fraud, impersonation and circumvention of an enforcement decision. We use these addresses for nothing else: no advertising, no working out where you live, and no tracking of you on other sites.

Artist and release data

The artist profiles you create (name, photo, website and social links, and the store profiles you connect), and everything that makes up a release: titles, credits, contributor and writer names, roles and publishing splits, ISRCs and barcodes, release dates, AI disclosures, rights lines, the audio and artwork you upload, and any clearance document you attach. Credits and splits describe real people, so this includes personal data about your collaborators, which you provide to us.

Billing

Subscription state: your customer and subscription reference at our payment provider, your plan, its status and its renewal date, plus the invoices generated. Payment details are entered directly with our payment provider. We never receive or store your full card number.

Earnings and analytics

Statement, transaction and royalty data reported to us for your releases, and the streaming and engagement figures the platforms report, which reach us as aggregates by release, period, country, age band and gender band, not as data about identified listeners.

Communications and support

A record of the transactional emails we send you (template, subject and recipient, never the message body), whether they bounced or were marked as spam, the in-app notifications you receive, and the content of messages you send us. If you use Run Copilot, the assistant in the workspace, the question you type and the recent conversation are sent to our AI assistant provider to generate the answer. We keep a record of each request (when, from which section of the workspace, the outcome and its cost) and never the text of the question or the answer; the conversation itself stays in your browser tab.

Technical data

Server and delivery logs kept for security, abuse prevention and debugging, which can include IP addresses, timestamps, browser and device information, and the actions taken in your account. Administrative actions and release state changes are written to an audit log.

Why we use it, and on what legal basis

  • To run the service you asked for (performance of our contract): creating and securing your account, checking and delivering your releases, connecting your store profiles, reporting delivery, earnings and analytics back to you, taking payment, handling takedowns and answering support requests.
  • To meet our legal obligations: accounting and tax records, invoices, and responding to lawful requests and to rights holders’ complaints.
  • Our legitimate interests: keeping Run and its users safe, preventing fraud, impersonation and artificial streaming, screening submitted audio for unauthorised use, enforcing our terms and store policies, and improving how the service works. We balance these against your rights, and we use the minimum data that achieves the purpose.
  • Your consent, where we ask for it: non-essential cookies, and any optional message you opt into. You can withdraw consent at any time, which does not affect what we did before you withdrew it.

We do not sell personal data, and we do not use it for behavioural advertising or profiling for advertising purposes.

Who we share it with

The stores you select. Delivering a release means sending its audio, artwork, metadata, credits and AI disclosures to the streaming services and download stores you choose. Once a release is with a store, that store handles it under its own terms and privacy policy.

Service providers acting on our instructions. They are bound by contract, may only use the data to provide their service to us, and cannot use it for their own purposes. Here is every category of them, what it does, and where it is:

Music distribution partner
Receives your release, its metadata and credits, and delivers them to the stores you selectRegion: United States
Hosting and infrastructure providers
Run this website and the workspace, the application backend, the account database, and storage for the audio and artwork you uploadRegion: European Union (database and uploaded files) and United States (application hosting)
Payment provider
Subscription payments, invoices and tax calculationRegion: United States
Email provider
Sends transactional email such as sign-in links and release status updatesRegion: United States
Audio recognition provider
Fingerprint matching on submitted tracks, to detect unauthorised use and impersonationRegion: European Union
Bot-protection provider
Protects the sign-up and sign-in forms against automated abuseRegion: Global
AI assistant provider
Generates the answers of the assistant in the workspace from the question you type and the recent conversation; it receives no catalog or account dataRegion: United States

We publish categories rather than company names. If you want to know which specific companies sit behind them, ask us and we will tell you: it is your right, and we answer it. Write to privacy@run.audio and we will name the companies behind any category above. This website is hosted by Vercel Inc. (United States), vercel.com.

Others, when we have to. Our accountants and professional advisors, rights holders and their representatives where a complaint concerns your release, and authorities or courts where the law requires it. If the business is ever restructured or transferred, data may move with it, and this policy travels with the data.

International transfers

Run is operated from the European Union, and your account database and uploaded files are hosted in the European Union. Some of the recipients listed above are established in the United States, as their regions show, so distributing your music and running the service involve transfers outside the European Economic Area.

Where that happens, the transfer is covered by the European Commission’s Standard Contractual Clauses or another mechanism recognised under Chapter V of the GDPR, together with the technical measures described elsewhere in this policy. Ask us and we will tell you which safeguard applies to a specific transfer, and to which company.

How long we keep it

  • Account, artist and release data: for as long as your account is open. Deleting your account in Settings schedules the erasure 14 days ahead and stays cancellable during those days. After that we erase your profile, your artist profiles, your drafts, the audio and artwork you uploaded and your notifications, and keep only what is necessary for the records below, in a form that no longer carries your name, your email or your address.
  • Delivered releases: while the release is distributed, and afterwards for as long as the delivery and rights record has to be kept, since a release that has shipped may still be the subject of a claim or a royalty correction.
  • Accounting and tax records, including invoices, statements and royalty records: ten years, as French commercial law requires.
  • Records of terms you accepted: for as long as the agreement can be relied on, since they are the proof that it was accepted.
  • Email delivery records and the do-not-contact list: for as long as needed to keep honouring an unsubscribe or a complaint.
  • Assistant usage records: 90 days, then deleted, and sooner if the account is erased. What outlives an erasure is a daily and a monthly total of what the assistant cost us across every account, which carries no account reference.
  • Sign-in addresses: the addresses seen on your account are kept while the account is open, and they go when it is erased. Addresses tied to an account we closed for breaking our rules stay on our abuse denylist afterwards, because outliving the closed account is the whole point of them; that entry holds the address and the reason it was added, and no name, no email address and no link back to the erased account. Write to us if you think an entry should go, and a person looks at it.
  • Technical logs: short retention, in the order of weeks to months, except where an entry is part of a security or abuse investigation.

Automated checks on your releases

Releases you submit are checked automatically before they are delivered: metadata against store requirements, audio files against format and quality requirements, and audio against a fingerprint database to detect unauthorised use, impersonation and undisclosed reuse. Copies of the audio are sent to our matching provider for that check.

These checks can hold a release or send it back to you with reasons. They are not a decision taken solely by automated means about you as a person: anything flagged is reviewed by a member of our team before a release is rejected, you are told why, and you can correct the release and resubmit it, or write to us to contest the outcome.

Your rights

Under the GDPR you can ask us for access to your personal data, for a copy in a portable format, for correction of anything inaccurate, for erasure, for restriction of processing, and you can object to processing based on our legitimate interests. Where processing rests on your consent, you can withdraw it at any time.

Much of this is immediate in the workspace: your profile, artist details and releases are yours to edit, and Settings carries two controls for the rest. Download your data assembles everything we hold about your account into one machine-readable file and emails you when it is ready; you download it from Settings while signed in. That file is your personal data in one place, so store it somewhere private. Delete your account schedules the erasure 14 days ahead, stays cancellable in Settings until then, and requests a takedown for any release already at the stores.

For anything else, write to privacy@run.audio from the address on your account. We answer within one month, and tell you if we need longer because a request is complex. Both flows, and the limits on them, are set out step by step on our GDPR page.

Some requests have limits. We cannot erase records we are required to keep: billing and accounting records, for the ten years French commercial law asks for; the audit log; and the record that an agreement version was accepted. Those stay, in anonymised form. We also cannot recall a release from a store’s own systems: we can request its removal from the stores, which they then action on their own schedule. If we closed your account for breaking our rules, the addresses tied to it stay on our abuse denylist, for the reason given under How long we keep it.

If you gave us data about your collaborators (credits, writers, splits), you are responsible for having the right to give it to us and for telling them how it is used. Point them to this page, and they can exercise their rights with us directly.

Cookies

This website uses essential cookies only. They keep you signed in to the workspace, tell this site whether a workspace session exists so it can show the right button, protect the sign-in forms against automated abuse, and remember the choice you made in the cookie notice. Essential cookies do not need your consent, and we do not currently set any analytics or advertising cookies.

If that changes, non-essential cookies will only be set after you accept them in the notice, and choosing “Essential only” keeps them off. You can also clear or block cookies in your browser, though blocking the essential ones will stop the workspace from keeping you signed in. Every cookie we set is listed individually, with its purpose and lifetime, in our Cookie Policy.

Security

Access to your data is restricted at the database level so that an account reaches only its own records. Credentials for the services we use are held as server-side secrets and never shipped to the browser. Traffic is encrypted in transit, uploads are checksummed and validated, incoming webhooks are signature verified, and administrative access requires two-factor authentication. Administrative actions are recorded in an audit log.

No service can promise perfect security. If a breach affects your personal data, we notify the CNIL and, where the law requires it, you.

Children

Run is not intended for children. You must be at least 16 to hold an account, and under 18 you need a parent or legal guardian to accept our terms with you. If you believe a child has given us personal data, write to us and we will remove it.

Changes to this policy

We update this policy as the service changes. The version and date at the top of this page always tell you which edition is in force, and that line is how a new edition is announced: this policy is published rather than agreed, so there is nothing here for you to re-accept. Where a change also touches a document you did accept, our Terms of Service or the distribution agreement, we put the new edition in front of you in the workspace before it binds you. This edition has not been reviewed by external counsel, and it will say so here until it has been.

Contact and complaints

Privacy requests and questions: privacy@run.audio
Void Music Group SASU, 25 rue de Ponthieu, 75008 Paris, France

If you are not satisfied with how we handled your request, you can complain to the French data protection authority, the Commission Nationale de l’Informatique et des Libertés (CNIL), 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, www.cnil.fr, or to the supervisory authority of the country where you live.