Runlow - Privacy Policy
Last updated: 14 September 2026
Runlow is designed to be private by default. This policy explains what the app does and does not do with your information.
The short version
Runlow does not collect, transmit, sell, or share any personal data. There is no Runlow account, no analytics, no crash reporting and no third-party tracking. Runlow has no servers of its own. Everything the app does happens on your own devices and in your own iCloud, and you can switch syncing off.
What stays on your device
- Sign-in credentials. You connect a service by pasting a session key (Claude) or a token or API key (Codex, Gemini CLI, Cursor, GitHub Copilot, OpenRouter) from your own account. On the Mac, Codex, Gemini and GitHub Copilot can also be read from their own files on your computer. Credentials are stored in your device's secure Keychain. Sign-in sync is on unless you turn it off (Settings, iCloud sync); while it is on, they are also kept in your own iCloud Keychain, so a key you paste on one device signs in your other devices too. They never pass through anything of ours.
- Usage data. The app requests your usage limits directly from each service you connected, using your own credentials, and displays them to you. This data is cached on your device so widgets, the Lock Screen card, the watch and the Mac menu bar can show it, and kept as a local history so the app can chart it. While sign-in sync is on, your latest numbers (percentages, reset times and when they were fetched) are also shared between your own devices through your own iCloud, so one device can show what another has just fetched. From version 1.8.7, the readings behind the History chart can be kept in your own private iCloud too, so a new or reset device picks them up; the switch is under Settings, iCloud sync, and turning it off removes the iCloud copy. Usage data is never sent anywhere else.
- Settings. Your preferences (colours, themes, chosen meters, notification thresholds, and so on) are stored on your device. If you turn on settings sync, they travel between your devices through your own iCloud and nowhere else. It is off unless you turn it on.
- Sync records. While sign-in sync is on, a small record travels through your own iCloud Keychain so your devices agree: which services each device is signed into, each device's name and type, and the Claude accounts you connected (the account's email address, plus the nickname, colour and icon you gave it unless you turn that switch off). The record holds no keys, and it never reaches us.
Network connections
The app contacts exactly the addresses below. The same list is shown inside the app (Settings, General, About, Privacy) and is checked against the app's own code.
- The services you connected, to read your own usage with your own credentials: claude.ai (Claude), chatgpt.com (Codex), cloudcode-pa.googleapis.com (Gemini CLI), cursor.com (Cursor), api.github.com (GitHub Copilot), openrouter.ai (OpenRouter). Your sign-in goes to these and nowhere else.
- Public status pages, fetched with no credentials, so the app can tell you a service is down: status.claude.com, status.openai.com, status.cloud.google.com, www.google.com (Google Workspace status), status.cursor.com, www.githubstatus.com, status.openrouter.ai, api.onlineornot.com.
- Runlow's own files on GitHub Pages (leonfigueira.github.io): the notices you see in the app, the list of known meters, and the provider setup instructions. These are static files, the same for everybody. The app downloads them and sends nothing.
- The App Store (apps.apple.com), only when you tap to leave a review.
None of these requests carry personal information about you beyond the credentials you chose to connect, which go only to the service they belong to.
Tips
The app offers optional tips as in-app purchases. Apple handles the payment; Runlow receives no payment details and nothing in the app changes whether you tip or not. If you tip, the app keeps a note of which tip and when, on your device and in your own iCloud, and nowhere else.
Notifications
If you enable them, alerts (for example at 80% / 95% or when a limit resets) are generated and shown locally on your device. No notification data is sent to any server.
Children
Runlow does not target children and collects no data from anyone.
Changes
If this policy changes, the updated version will be posted here with a new date.
Contact
Questions? Email leonfigueira@gmail.com.
Runlow is an independent app and is not affiliated with, endorsed by, or sponsored by Anthropic, OpenAI, Google, Cursor, GitHub or OpenRouter.