Legal

Privacy Policy

Last updated: September 8, 2026

This Privacy Policy describes how ARS Technologies Inc. ("Runars", "we", "us", or "our") collects, uses, discloses, and protects personal information when you use runars.ca, the Runars platform at platform.runars.ca, and the Runars Inference API (collectively, the "Services"). We are responsible for the personal information we hold and handle it in accordance with applicable Canadian privacy law, including the Personal Information Protection and Electronic Documents Act (PIPEDA) and, where applicable, substantially similar provincial laws such as Quebec's Law 25.

1. Who we are

Runars is a Canadian AI infrastructure company headquartered in Canada. We provide an inference API and GPU compute hosted entirely in Canadian data centres. You can reach us at privacy@runars.ca for any privacy question, concern, or request.

2. Information we collect

Account information

When you create an account we collect your email address, name (if provided), and the name of your organization. We also store the authentication credentials managed by our identity provider.

Usage and log data

When you use the Services we process request metadata — timestamps, model identifiers, token counts, latency, error codes, and API keys used — to meter billing, prevent abuse, and operate the service.

Prompts and completions

Model inputs and outputs are processed to serve your request. We do not use your prompts, completions, or uploaded files to train models. Where prompt caching is enabled, cached content is stored in-region in Canada.

Payment information

Payments are processed by our payment processor. We do not store full card numbers on our systems; we receive only transaction references, billing contact details, and amounts.

Communications

If you contact support, submit a capacity-seller form, or otherwise write to us, we keep a record of that correspondence.

3. How we use information

  • To provide, operate, secure, and improve the Services
  • To create your account, authenticate you, and manage your organization and memberships
  • To meter usage, issue invoices and receipts, and process payments
  • To monitor for abuse, enforce our Acceptable Use Policy, and protect the integrity of the platform
  • To send service notices (security, billing, incident) and respond to support requests
  • To comply with legal obligations and respond to lawful requests

We do not sell your personal information, and we do not share it for cross-context behavioural advertising.

4. Canadian data residency

All inference compute, prompt caching, and application storage are hosted in Canadian data centres (Montreal and Calgary). Customer content — prompts, completions, uploaded files, and request logs — is stored and processed in Canada and is not transferred outside Canada for processing. Some limited operational data (such as email delivery and DNS) may transit trusted global providers; where that occurs we contractually restrict use to the delivery of the service.

5. Service providers and sub-processors

We rely on a limited set of sub-processors to operate the Services. The current list is published on our Security page. Each is bound by contractual obligations to protect personal information no less stringent than our own.

6. Cookies and analytics

We use essential cookies to keep you signed in and secure (session cookies), and may use privacy-respecting analytics to understand aggregate site usage. We do not use advertising or cross-site tracking cookies.

7. Retention

We retain personal information only as long as necessary for the purposes described above and to meet legal, accounting, or regulatory requirements. Request logs are retained for service assurance and abuse investigation, then deleted or de-identified on a rolling basis. Account records are retained for the life of the organization and following termination as required by law.

8. Your rights and choices

Subject to applicable law, you may request access to the personal information we hold about you, request correction, withdraw consent, or ask questions about our practices. Organization owners may update member information in the dashboard at any time. To exercise a right, contact us at privacy@runars.ca. We respond within 30 days. If you are not satisfied with our answer you may complain to the Office of the Privacy Commissioner of Canada.

9. Breach notification

In the event of a breach of security safeguards involving your personal information that creates a real risk of significant harm, we will notify you and the appropriate authorities as required under PIPEDA and keep records of all such breaches as required by law.

10. Security

We protect personal information with safeguards appropriate to its sensitivity, including encryption in transit, encryption at rest, role based access controls, and least-privilege access. See our Security page for details and our responsible disclosure process.

11. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be announced on the platform or by email to account holders. The date of the latest revision appears at the top of this page.

12. Contact us

ARS Technologies Inc. — Privacy Office
privacy@runars.ca