Skip to content
Rungbase
Product
Engineering workspace PLC logic, revisions, and reviewed AI edits. Machine & simulation Connect the code to a modeled machine. Team projects & handoff Keep the source and engineering record together.

One project. From the first rung to handoff.

Built for integrators
For integrators About
Sign inRequest a demo
Product Engineering workspaceMachine & simulationTeam projects & handoffFor integratorsAboutSign in
Terms of ServicePrivacy Policy
# Rungbase Privacy Policy

**Review draft — not yet effective.** The deletion schedule, access restrictions, age controls, and international-processing details must be implemented or verified before publication. See `Rungbase-Publication-Notes.md`; remove this notice when those items are resolved.

**Effective date:** [Insert publication date]

**NTL Software LLC** (“NTL,” “we,” “us,” or “our”) operates Rungbase at [rungbase.com](https://rungbase.com), its browser workspace, Windows desktop agent, and related services (the “Service”). This policy explains how we collect, use, disclose, and retain personal information. Contact us at **[email protected]**.

Controller programs, manuals, and plant information can be confidential even if they contain no personal information. Our Terms of Service also address the ownership, confidentiality, and permitted processing of that content.

## 1. Information we collect

We collect information you provide, information generated through your use of the Service, and information supplied by authorized organization administrators or connected systems.

| Category | Examples |
| --- | --- |
| Account and organization information | Name, email address, authentication records, company details, workspace membership, roles, and permissions. |
| Customer projects and files | Code, controller projects, uploaded manuals, documents, comments, revision history, and project metadata. Files can contain names, contact details, or other personal information you include. |
| AI interactions | Prompts, personal AI chats, generated responses, tool requests, and project or controller context used in those interactions. |
| Connected-system information | Controller identifiers, network addresses, configuration, live tag values, alarms, operating information, and results of supported reads or approved writes. What is collected depends on the connection and features you use. |
| Access information | Device credentials, access tokens, or other connection secrets that you provide to supported features, together with account authentication information. |
| Usage and technical information | IP addresses, browser and device details, session identifiers, timestamps, feature and AI usage, errors, crash or diagnostic records, project activity, and controller-operation or approval records. |
| Billing information | Subscription and seat details, purchase and payment status, billing contact details, invoices, and payment-related information supplied through Stripe. Payment information entered through Stripe checkout is processed by Stripe. |
| Communications and permissions | Support emails, correspondence, reports, and records needed to document agreement, parent/guardian authorization where required, and any separate optional consent. |

The Windows agent accesses supported equipment and connection information when installed, configured, and used. Relevant information is transmitted to our servers to provide the browser workspace and enabled features. Rungbase is a hosted service; projects and other Service data are stored on our servers rather than remaining exclusively on your computer.

Only connect systems and upload information you have permission to access and process. Avoid including unnecessary personal information or secrets in project text, manuals, or AI prompts.

## 2. How we use information

We use information to:

- Create and authenticate accounts, administer workspaces, and enforce permissions.
- Store, display, organize, and edit projects and files and provide available project-history features.
- Provide AI assistance and process the context needed for requested AI interactions.
- Communicate with supported controllers, display information, and carry out user-approved operations.
- Measure usage, enforce plan limits, administer seats and AI allowances, process payments, and maintain billing records.
- Respond to support requests, diagnose errors, and maintain the reliability and security of the Service.
- Investigate suspected fraud, unauthorized access, misuse, or security incidents.
- Send account, billing, security, service, and policy notices.
- Meet legal obligations, handle rights requests, and establish or defend legal claims.

We may use operational metrics, such as feature-use counts and error rates, to improve the Service. This does not authorize model training on your projects or chats. We do not use customer project or chat content for unrelated model evaluations, training, or fine-tuning without separate express permission from an authorized rights holder.

## 3. AI processing and model training

Rungbase uses **OpenAI’s API** to provide AI features. We send prompts and the relevant selected context needed for an interaction. Depending on your use, this may include project code, uploaded-file excerpts, controller configuration, tag values, tool results, and other controller information.

When AI controller-reading tools are enabled, the AI can request available information needed to address your request. Across multiple reads, this may expose substantial parts of a controller or project to OpenAI; it is not necessarily limited to the one passage you typed or selected. Information read from a controller may also be recorded in the related chat or Service records. Every write to an actual machine through Rungbase requires user approval; this does not mean every read or AI-context transmission has a separate approval prompt.

**NTL does not use your projects, files, or chats to train or fine-tune AI models, or authorize provider training, without a separate express opt-in from a person authorized to grant permission.** Ordinary use of the Service does not provide that permission. If optional training or evaluation is offered, we will explain the content, purpose, providers, and withdrawal process separately. Organization or client content requires authorization from the relevant rights holder, not merely an individual engineer’s personal consent.

OpenAI states that API inputs and outputs are not used to train its models by default unless the API customer opts in. We do not enable that sharing for your content without the separate permission described above.

**No training does not mean no retention.** OpenAI may retain content for abuse monitoring and for API features that store application state. Retention depends on the feature and account settings, and legal or security exceptions can apply. Some stored files or conversation objects remain until deleted. We do not promise zero retention by OpenAI. Details are available in [OpenAI’s API data controls documentation](https://developers.openai.com/api/docs/guides/your-data).

## 4. Personal workspaces, organizations, and access

**Personal AI chats:** An organization administrator cannot access the contents of your personal AI chats solely because you belong to the organization. Administrators may see usage information for organization administration and billing, such as attributed AI usage and seat activity.

**Organization projects:** Projects created in an organization workspace are controlled by that organization and are available to its authorized members according to workspace permissions. Those projects remain in the organization when an engineer leaves or deletes their personal account. Project activity or attribution needed to maintain the organization’s project records may also remain, subject to applicable privacy rights and retention limits.

**Personal projects:** Projects created in your personal workspace remain personal unless you intentionally share or transfer them through available features. Membership in an organization does not itself give the organization access to those projects.

If you apply an AI-generated change to an organization project, the applied content becomes part of that project. Personal-chat privacy does not hide changes, code, or related activity records deliberately placed in a shared project. You may also choose to share information yourself by exporting, copying, or sending it to another person.

**NTL access:** Authorized personnel may inspect projects, personal AI chats, and related records only where reasonably necessary for support, troubleshooting, service operation, security, investigating misuse, or legal compliance. That access can occur without a specific support request. It is limited to legitimate service or legal purposes and subject to access restrictions and confidentiality duties. “Personal” refers to access within customer workspaces; it does not mean NTL or providers never process the information.

## 5. Providers and other disclosures

We disclose information to providers to the extent reasonably needed for their functions:

| Provider | Function and relevant information |
| --- | --- |
| **DigitalOcean** | Hosting our US-based servers and associated stored Service information. |
| **Cloudflare** | Network delivery, protection, and related infrastructure. Depending on the configuration, Cloudflare processes request, network, and security information and traffic passing through its services. |
| **OpenAI** | Processing AI prompts, outputs, and selected or tool-retrieved project/controller context, as described above. |
| **Stripe** | Payment processing, subscription transactions, billing information, and fraud prevention for payments. |
| **Google Workspace** | Email delivery and storage of email correspondence, including account or support information contained in those communications. |

Providers may process some information under their own legal obligations and privacy notices, such as payment fraud-prevention and transaction records. Their independent records may have separate retention requirements. We remain responsible for our own information practices and our use of providers.

We may also disclose information:

- To authorized organization members, as described in Section 4.
- At your direction, such as when you share or export information or authorize an integration.
- Where legally required, or as reasonably necessary to address fraud, unlawful conduct, security incidents, or threats to rights and safety.
- To advisers acting under appropriate confidentiality duties when needed for legal, accounting, or business matters.
- As part of a merger, acquisition, financing diligence, reorganization, or sale of the relevant business, subject to appropriate confidentiality safeguards and applicable law. A transaction does not eliminate existing privacy commitments or justify unrelated new uses without the notice or consent required by law.

We do not disclose customer projects or chats to other customers without authorization. We do not use advertising trackers or disclose personal information to third parties for cross-context behavioral advertising.

## 6. Cookies and tracking

Our Service currently uses authentication and session cookies or similar session identifiers to keep you signed in and administer your session. We do not currently use advertising trackers.

Cloudflare and payment flows may process technical information and use mechanisms needed for their security or transaction functions. The exact behavior depends on how those services are configured. You can manage cookies through your browser, but blocking necessary session cookies may prevent sign-in or normal operation.

We collect technical and usage records as described in Section 1 even without advertising cookies. The Service does not currently alter its information collection in response to a browser’s Do Not Track setting. Where an applicable law requires us to honor a recognized opt-out preference signal, we will do so for processing covered by that requirement.

## 7. Retention and deletion

We retain account information and active projects and chats while needed to provide the Service, maintain the applicable workspace, or fulfill the purposes described in this policy. Retention also depends on your actions, organization instructions, and legitimate legal or security needs. We do not retain personal information indefinitely merely because it might be useful.

You can use available controls to request deletion of your personal account, projects, or chats, or contact [email protected] for assistance. Organization-controlled content must be handled by an authorized organization representative. An account-deletion request is separate from cancellation of any organization subscription.

**Deletion schedule:** A deletion request first marks the relevant content as deleted and removes it from ordinary active use. Except for the limited records described below, we purge deleted personal projects and chats and their deleted associated content from active databases within **30 days of the deletion request**. Backup copies containing that content expire or are removed within **90 days of the deletion request**. These deadlines also apply when an authorized organization representative deletes organization content. We propagate deletion to copies and stored objects under our control that must be deleted, including applicable provider-held application objects.

Backups are retained for recovery, restricted from routine use, and subject to the same confidentiality protections. If a backup is restored, we reapply recorded deletions before making the recovered content available for ordinary use. These schedules do not delay an earlier deletion deadline required by applicable law.

**Limited exceptions:** We may retain particular billing and transaction records, consent records, security or controller-operation records, and information subject to a legal hold for as long as reasonably necessary to meet applicable law, investigate an actual incident, or resolve or defend a claim. We restrict that information to those purposes, avoid retaining project or chat bodies when an adequate record can be maintained without them, and remove it when the reason ends. Routine project/chat content is not retained beyond the stated schedule solely for general product improvement.

Deleting a personal account does not delete projects the organization continues to control and use. Necessary attribution may remain in those organization records; that is a separate continuing purpose, not a claim that your deleted personal chats remain accessible to the organization. Copies independently exported or retained by another party are outside our deletion control. Providers acting for their own legal or security purposes may retain their independent records under their applicable policies and obligations.

## 8. Your choices and privacy rights

You can update available account details, manage workspace membership where authorized, disconnect the agent or supported equipment, manage browser cookies, and use available deletion controls. You can stop using AI features without providing an optional training opt-in. A later withdrawal of optional consent does not invalidate processing that was lawful before withdrawal; any limits on reversing completed model training must be disclosed before an opt-in is obtained.

Depending on where you live and which law applies, you may have rights to request access to your personal information, correction, deletion, portability, restriction, or objection to certain processing; withdraw consent; appeal a denied request; or complain to a competent regulator. Some rights are subject to exceptions and identity verification.

Send requests to **[email protected]**. We may ask for information reasonably needed to verify your identity or authority, without requesting unnecessary sensitive documents. We will respond within applicable legal time limits. An authorized agent may submit a request where permitted by law, subject to appropriate verification. If a law gives you a right to appeal our response, reply to the same address stating that you wish to appeal.

For personal information within an organization-controlled project, the organization may be responsible for the decision on your request. We will direct the request to it or assist with processing where appropriate, and will handle information for which NTL is independently responsible. We will not deny applicable rights merely because you are an organization member or charge a higher price for exercising a protected privacy right.

We do not use advertising trackers or provide information for cross-context behavioral advertising. If a future material change introduces a new use, we will update this policy and provide the notices, choices, and consents required before that use begins.

## 9. International users and processing

NTL is based in the United States, and our primary hosting is on DigitalOcean servers in the United States. Our providers may process information in the United States or other countries where they operate. Laws in those locations may differ from the laws where you live. Accepting this policy does not itself waive applicable rights or constitute a blanket consent to all international transfers.

Where applicable law requires a lawful transfer mechanism, the relevant processing must be covered by that mechanism, such as an applicable adequacy decision or appropriate contractual safeguards. Contact [email protected] for information about safeguards applicable to your processing.

**[Before publication: identify and verify the transfer mechanisms actually applicable to NTL and its providers, any required data processing agreement, and whether an EEA/UK representative is required. Replace this drafting instruction with concrete information about the safeguards in use and how to obtain a copy or description. Do not claim SCCs, adequacy certification, or a representative that has not been established.]**

Where European or UK data-protection law applies, NTL generally acts as controller for account administration, direct billing and support, and our own security and legal purposes. For personal information within organization projects that we handle on the organization’s instructions, the organization generally acts as controller and NTL as processor; the specific role depends on the processing activity and relevant agreement.

For processing for which NTL is controller, the legal basis, where required, is performance of a contract for providing requested account and paid-service functions; legitimate interests in protecting and maintaining the Service, investigating misuse, and responding to support, balanced against your rights; compliance with legal obligations for required records and disclosures; and consent for optional processing such as an authorized training opt-in. Processing for organizations follows their lawful instructions and the applicable processing agreement. We do not rely on your acceptance of this policy as consent for every processing purpose.

## 10. Younger users

Rungbase is intended for users **16 and older**, subject to any higher minimum age required where they live. Users below legal majority must have parent or guardian authorization through the required consent process. Real-machine use by a minor also requires the qualified adult authorization and supervision described in our Terms.

The Service is not intended for children under 16, and we do not knowingly allow them to create accounts. If you believe an ineligible child has supplied personal information, contact [email protected] so we can investigate, restrict access, and arrange appropriate deletion. Parent or guardian agreement does not remove privacy rights or other requirements that apply to younger users.

## 11. Security

We use administrative and technical measures intended to protect information, including account authentication and access restrictions. No internet service, device connection, or storage method can be guaranteed completely secure. Protect your account and agent, secure the systems you connect, and report suspected unauthorized access promptly. We will provide incident notifications when required by applicable law.

## 12. Changes and contact

We may update this policy as the Service or legal requirements change. We will post the updated policy with a new effective date and provide additional notice of material changes through email or the Service where appropriate or required. We will obtain any consent required before a new processing use begins. Changes do not retroactively authorize model training or override existing applicable privacy rights.

**Privacy contact:** NTL Software LLC — **[email protected]**.

Better prepared.
From the first rung.

Let’s talk
Rungbase

A connected workspace for
the people behind the machine.

Logic. Context. Confidence.

Product

Engineering workspaceMachine & simulationTeam projects & handoffCurrent capabilities

Rungbase

For integratorsAboutContactCommon questionsTerms of ServicePrivacy Policy

Get started

Request a demoStart a projectSign in
Rungbase
© 2026 Rungbase

Allen-Bradley, Logix and Studio 5000 are trademarks of Rockwell Automation, Inc. Rungbase is independent and not affiliated with Rockwell Automation.

Back to top