We collect three categories of information. First, information you provide when you contact us, your name, work email, employer, and the contents of your message. Second, information collected automatically when you visit bladerun.ai, IP address, user agent, referrer, requested URL, and aggregate page-load metrics. Third, information related to enterprise platform deployments, limited to operational metadata necessary to support the deployment, governed by the customer master services agreement.
Section 02We use the information you provide to respond to your inquiry, schedule meetings, and route the request to the right person on our team. We use website telemetry to operate, secure, and improve the bladerun.ai website. For enterprise customers, we use platform metadata strictly to operate the deployment, deliver contracted support, generate audit-ready evidence, and improve product reliability, under the data-processing terms in the customer agreement.
Section 03We do not sell personal information. We share limited information with subprocessors that operate parts of our infrastructure (cloud hosting, email delivery, error reporting, analytics) under written data-processing agreements that bind them to the same standards we hold ourselves to. A current subprocessor list is available to enterprise customers under NDA. We may disclose information when required by law, valid legal process, or to protect the rights and safety of BladeRun, our customers, or the public.
Section 04The BladeRun Federation Network is a cross-institution threat-signal channel. By design, no raw prompt, response, customer record, model output, or business data ever leaves the customer environment. Only one-way signal hashes, with k-anonymity guarantees, are exchanged. Membership is double-blind. The Federation privacy contract is reviewed on a separate signoff path so the platform agreement is never gated by federation legal review. A full description is available in the Federation white paper.
Section 05If you are in the European Economic Area, the United Kingdom, or California, you have rights regarding your personal information that we honor for any individual on request, regardless of jurisdiction.
Website inquiry information is retained for as long as needed to handle the inquiry and any resulting business relationship, plus a defined archive period for legal and audit purposes. Website telemetry is retained in aggregate form. Enterprise platform data is retained per the contractual retention schedule defined in the customer master services agreement, typically configured by the customer and stored in customer-controlled infrastructure. We will delete or anonymize information sooner on valid request, subject to applicable legal retention requirements.
Section 07We follow industry-standard administrative, technical, and physical safeguards designed to protect information from loss, misuse, unauthorized access, disclosure, alteration, and destruction. We hold a SOC 2 Type I report today and Type II is in scope. Access to systems is least-privilege, multi-factor, and audited. Subprocessors are reviewed annually. The Federation Network is engineered so that the most sensitive customer data physically cannot leave the customer environment, by construction.
Section 08BladeRun is an enterprise platform sold to regulated institutions. Our website and services are not directed to children under 16, and we do not knowingly collect personal information from children. If you believe we have inadvertently collected information from a child, contact privacy@bladerun.ai and we will delete the information.
Section 09BladeRun is a US-headquartered company. Where information is transferred from the European Economic Area, the United Kingdom, Switzerland, or other jurisdictions with cross-border restrictions, we rely on appropriate transfer mechanisms, Standard Contractual Clauses, the EU-US Data Privacy Framework where applicable, and customer-controlled deployment options that keep data inside the customer's chosen region. Enterprise customers can require deployments that never leave a specified jurisdiction.
Section 10We may update this policy to reflect changes to our practices, our products, or applicable law. The effective date and last-updated date at the top of this page reflect the most recent revision. Material changes will be communicated through the website and, for enterprise customers, through the contractual notice channels defined in the customer agreement. Continued use of the website or platform after a revision becomes effective constitutes acceptance of the revised policy.
For privacy questions, data subject rights requests, or any complaint regarding this policy, contact privacy@bladerun.ai. For security disclosures, use security@bladerun.ai. For all other inquiries, contact@bladerun.ai is read by the founders.
Privacy and data rights requests are reviewed by the BladeRun privacy team and routed for verification. Identity verification is required before sensitive personal information is released. We will respond within the timelines required by applicable law, typically within 30 days for GDPR rights requests and 45 days for CCPA rights requests.