Privacy Policy
This policy explains what ParallelSandbox, operated by Runvo LLC, collects about you, why, how long it is kept, and how to have it removed.
Last updated: September 16, 2026
1. What we collect
Account
When you sign in with GitHub we receive your GitHub user id, username, primary email address and avatar URL. We do not receive your GitHub password and we do not read your repositories unless you install the ParallelSandbox GitHub App on them.
API keys
We store a hash of each key, its name, creation date and last use. The key itself is shown to you once and not kept.
Usage
For every box: its id, start and stop times, the services and wiring you declared, the state changes, and usage events (minutes run, bytes transferred, bytes of logs written and stored, bytes of files kept) with the credits charged.
Files, screenshots and recordings
Screenshots, recordings and files you fetch from a box are stored in your tenant's storage until you delete them or close your account.
Logs you send
Pages that use the log SDK send whatever you configure them to send: messages, stacks, URLs, release ids, box ids. You decide what goes in. If it includes personal data of your own users, you are the controller of that data and responsible for informing them.
Billing
Stripe processes payments. We receive a Stripe customer id, subscription status and invoice records. Card numbers are handled by Stripe and never reach us.
Support and website
Emails you send us are kept to answer them. The website uses no analytics or advertising cookies; web servers keep standard access logs (IP address, browser type, requested page) for security, deleted after 30 days.
2. What we do not collect
We do not inspect the contents of your boxes, your code or your logs in the ordinary course of operating the Service. We do not sell personal data and we do not use it for advertising.
3. Why we use it
- to provide the Service: start boxes, route takeovers, store what you asked for;
- to bill you and keep the accounting records the law requires;
- to keep the Service secure and detect abuse;
- to answer your support requests;
- to comply with legal obligations.
4. Who receives it
Amazon Web Services hosts the Service in the Tokyo region (ap-northeast-1). Stripe processes payments. GitHub provides sign-in. Each of them receives only what their role requires. We disclose data to authorities only when legally compelled, and we tell you when we are allowed to.
5. How long we keep it
- Box contents: destroyed when the box stops.
- Files, screenshots, recordings and logs: until you delete them or close your account, then removed within 30 days.
- Account and usage records: for the life of the account, then removed within 30 days.
- Billing records: as long as tax and accounting law requires.
- Web server access logs: 30 days.
6. Security
All traffic uses TLS. Boxes are isolated from each other, hold no cloud credentials, and accept only one-time tokens issued by the control plane for takeovers. Secrets are encrypted at rest and never written to platform logs. API keys are stored as hashes.
7. Your rights
You can see and delete your files, logs, secrets and API keys in the app at any time, and delete your account from the account page. For a copy of the data we hold about you, a correction, or deletion of anything you cannot remove yourself, email us; we answer within 30 days. Depending on where you live you may have further rights under laws such as the GDPR or the CCPA, and we honour them.
8. Children
The Service is not directed at children under 16 and we do not knowingly collect data from them.
9. Changes
We may update this policy. The current version is always at parallelsandbox.com/privacy/ with the date of the last change; material changes are announced in the app.
10. Contact
Privacy questions and requests: runvo.tech@gmail.com