alvrun.

Privacy

Last updated 18 August 2026

This explains what Alvrun collects, why, and what you can ask us to do about it. It is written to be read, not to be survived.

Who we are

Alvrun is run by Glauser Creative AB, a company registered in Sweden. You can reach us at hello@alvrun.com about anything on this page.

We have two different roles

This matters more than it sounds, because it decides who you ask for what.

For your own account, we are the controller. We decide what to store and why, and you can come straight to us.

For the conversations your customers have with your agent, you are the controller and we are your processor. We handle that data on your instructions to run the service for you. If one of your customers wants their chat deleted, they should ask you, and you can ask us.

What we collect

  • Your account. Your name and email address, from Google sign in or from an emailed code. There are no passwords, so we never hold one.
  • Your website. The public pages we read to learn your business. We fetch them the same way a browser or a search engine does, and we only read what is already public.
  • Conversations. What your visitors write, what the agent answers, and a random session id that keeps one visitor's thread separate from another's. If a visitor asks to hear back from you, we store the email address they give us for that purpose.
  • Anything you teach it. Facts you write or files you upload so the agent can answer better.
  • Operational records. IP addresses for rate limiting and abuse prevention, error logs, and counts of how much each conversation cost to run.

The support chat has no login and asks for no personal details. Please do not use it to collect sensitive information from your customers.

Why we are allowed to hold it

  • To provide the service you asked for. That is our contract with you.
  • To keep the service working and affordable, which covers rate limits, abuse prevention, debugging and cost tracking. That is our legitimate interest, and we keep it to the minimum that does the job.
  • To meet legal obligations, such as accounting records once you are a paying customer.

Who else touches the data

We use a small number of suppliers to run the service. Each one only gets what it needs to do its job.

  • Supabase, our database, sign in and file storage. Hosted in the EU, in Stockholm.
  • Vercel, our hosting. The code that touches your data runs in Stockholm.
  • OpenAI, which writes the answers. Messages and the relevant parts of your website content are sent there to produce a reply. OpenAI does not use data sent through its API to train its models.
  • Firecrawl, used only for website pages that block a plain request. Most pages never reach it.
  • Resend, which sends sign in codes and notification emails.
  • Cloudflare, which handles our domain, the bot check on the public form, and the public DNS lookups the agent runs when it diagnoses an email setup.

Some of these are based outside the EU. Where that is the case, transfers rely on the European Commission's standard contractual clauses. We do not sell your data, and we do not use it for advertising.

How long we keep it

  • Previews, the ones you start by pasting a URL without signing up, are deleted automatically after 7 days.
  • Account and business data is kept while your account is open. Close it and we delete it, apart from records we have to keep for accounting.
  • Conversations are kept while your account is open, so the agent can learn and you can read back what was said. Ask us and we will delete any of them sooner.
  • Operational logs are kept for a short period and then rotate away.

Cookies

We do not use tracking or advertising cookies, and there is no analytics on this site.

The chat stores a random session id in your browser's local storage. It is what keeps your conversation yours, and it identifies a thread rather than a person. Sign in uses a cookie to remember that you are signed in. Cloudflare's bot check on the public form sets nothing that follows you around.

Your rights

Under the GDPR you can ask us for a copy of your data, ask us to correct it, ask us to delete it, ask us to limit what we do with it, ask for it in a portable format, or object to us relying on legitimate interest. Email hello@alvrun.com and we will answer within a month.

If you think we have got it wrong, you can complain to your data protection authority. In Sweden that is Integritetsskyddsmyndigheten, at imy.se.

Changes

If we change this in a way that matters, we will email the address on your account rather than quietly editing the page. The date at the top always tells you which version you are reading.