Privacy statement

Version 1.5 · Last updated 2026-08-30

This explains what this product collects about people who visit a website running it, what happens to that information, and the choices a person has. It is written to describe how the software actually behaves rather than to describe an intention.

What is collected, and from whom

Two different groups of people show up in this product, and what is collected about them is not the same.

People who visit a website running this product
Pages visited, the approximate organisation the visit appears to come from, and the network address the request arrived from. In the United States, and only there, a visit can also be matched to a named person — see the section on how far identification goes.
People who open the chat widget
What you type, and information about the session itself: when it started, the network address it came from, whether it was matched to someone already known, and events such as the panel being opened. If you leave feedback, the comment you write is kept with it.
What the chat widget does not collect
It does not record your screen, your camera, or your microphone, and it does not read your browser's user-agent string. If you use the microphone button, your own browser turns your speech into text and only the text is sent — no audio reaches this product.
People who work for a customer using the product
The account details needed to sign in and the record of what they did in the product. This is ordinary business-account information, held for as long as the account exists.
Business contacts held by a customer
A customer can import and hold business contact details in the product. That data is theirs, collected under their own decisions about who to contact; the product stores and processes it on their behalf.

How far identification goes, and where it stops

When someone visits a site running this product, the software tries to work out where the visit came from. How far it is allowed to go depends on where the visitor is, and the decision is made by the software rather than left to whoever installed it.

There are three outcomes. It can resolve nothing. It can resolve the organisation a visit appears to come from, which is a statement about a company and not about a person. Or, in the United States only, it can resolve a named person — and that requires the customer to have connected their own account with an outside provider that offers it.

Outside the United States, person-level identification is not performed. If the software cannot work out where a visitor is, it refuses the higher tier rather than guessing: an unknown location never unlocks more collection than a known one.

A person-level match is an inference, not a fact
It comes from an outside provider matching a network address against their own data. It can be wrong, and the product treats it as a claim to be weighed rather than as something known.
Being identified does not make you a contact
An identification of this kind does not create a contact record on its own, does not add anyone to a mailing list, and does not start any outreach. Those are separate steps a person at the customer has to take deliberately.
A Global Privacy Control signal stops the person-level tier
If your browser sends the signal, an attempt to resolve you to a named person is refused and recorded as refused. See the section on that signal for everything else it changes.

Why each kind of information is handled

Different information is handled for different reasons, and the reason changes what choice you have. Where the reason is your permission, you can take it back and the handling stops. Where it is not, you can still object and ask for deletion.

Company-level information about a visit
Handled because a business has a genuine interest in knowing which organisations look at its site, and because it describes a company rather than a person. No permission is requested for it, and no banner is shown asking for one.
Person-level identification of a visitor
Only in the United States, only where a customer has connected a provider for it, and never where a Global Privacy Control signal is present. In regions where the rules require permission first, this tier is not offered at all.
What you type into the chat widget
Handled to answer the question you asked. It is not used for marketing unless you separately and explicitly opt in, and opening a chat is never treated as agreeing to anything.
Marketing contact
Only on permission that was actually recorded, never assumed from the fact that we hold your details or that you contacted us. You can take that permission back at any time.
Security and abuse prevention
Session and request information is kept so that abuse of the widget can be detected and stopped. A business has a genuine interest in not having its own systems misused.

Global Privacy Control, and exactly what it does

If your browser sends a Global Privacy Control signal, this product acts on it. It is honoured on its own terms: no lookup of where you are, no check of whether your region requires it, and no way for the company running the site to switch it off.

Because a vague description of this is worse than none, here is precisely what changes.

You are not resolved to a named person
Any attempt to match your visit to a specific individual is refused, and the refusal is recorded as a refusal rather than silently passed over. This is checked before anything about your location is considered.
No third-party person lookup is made about you
The request to the outside provider that performs that matching is not sent. If the software cannot tell whether you sent the signal, it refuses that lookup as well.
Nothing lasting is stored in your browser
No persistent identifier is written. The visit uses a temporary value that is not kept after the page is closed, so you are not recognised on your next visit.
No permission is granted on your behalf
Where the software would otherwise have treated an analytics category as allowed by default, it does not, and it does not go looking for a stored permission for you.
If you send us an enquiry form, it is not tied to your browsing
The enquiry itself still reaches the company you sent it to — you asked them a question and they get it — but the link between that enquiry and your earlier browsing is dropped.
If recording is ever switched on, the signal raises the bar
It would require a separate, explicit yes rather than a notice, and it rules out any secondary use of what was said — no model training, no profile building, no sharing with an identity or advertising partner.
What it does not do
It does not stop the site from counting the visit at all, and it does not stop the organisation a visit appears to come from being resolved — that is a statement about a company rather than about you. If you want no measurement of any kind, a browser content blocker is the tool that achieves it, not this signal.

Where you are changes what happens

The rules that apply to you are not the same everywhere, so the software decides per visit rather than applying one posture to the world. Your location is taken from the hosting platform's own reading of the connection, not from anything your browser claims, so a changed browser setting cannot talk the software into a weaker posture.

In the United States
Person-level identification is possible, if the company running the site has connected a provider for it and you have not sent a Global Privacy Control signal. Where the specific state cannot be read, the most protective United States setting is applied rather than the most permissive.
In the European Economic Area and the United Kingdom
Identification stays at the level of the organisation a visit appears to come from. Person-level identification is not offered.
Everywhere that has not been reviewed
The software refuses rather than guesses. An unreviewed location gets the more protective treatment, and if recording is ever switched on it would not be available there at all.
When no rule can be satisfied
Nothing proceeds. The absence of a known rule is never read as permission, and the outcome is recorded with the reason so it can be checked afterwards rather than looking like nothing happened.

Analytics on this website, and who receives it

This section is about this website — the pages you are reading now — rather than about the product. Two outside companies are involved, Google and Microsoft, and what each one receives depends on the analytics choice you make in the notice this site shows you.

The notice itself, and the record of what you chose, are ours rather than a third party's. They are served from our own systems, which is why declining still works when you block outside scripts.

Google Analytics, before you decide
Google receives one signal from the page even if you never answer the notice. It carries a flag saying every consent category is denied, sets no cookie, and is not tied to you or to a profile. This is how Google's consent mode is built to behave, and we would rather describe it than let you discover it in a network log.
Google Analytics, after you accept analytics
Google receives the pages you visit and the events this site defines, and may set its own cookies to recognise a returning browser. Accepting marketing as well allows advertising signals; leaving it off keeps them denied while analytics runs.
Microsoft Clarity
Clarity records a replay of how a page was used — pointer movement, clicks, scrolling — and builds heat maps from it. It is not loaded until you accept analytics, so a visitor who declines or never answers sends nothing to Microsoft and downloads none of its code. Text you type into a form field is masked before it leaves the page, in every mode Clarity offers.
Taking analytics back
Reopening the notice and declining stops both. Clarity is told to stop recording and its cookies are cleared, and Google's signals return to denied. A recording already made before you withdrew is Microsoft's to expire on its schedule, which is why the question is asked before anything loads rather than after.
What this does not include
Neither company is sent your name, your email address, or anything you enter into the access application. If you submit that form, what you typed goes to our own database and to the people who read applications.

The AI assistant, and who is actually reading

If you open the chat widget, the replies you get are generated by software. There is no person sitting on the other side reading your messages as you send them and typing back.

That is said first, before anything else about the conversation, because it is the thing most likely to be misunderstood — and because the assistant may be shown with a name and a portrait. The portrait represents the assistant. It is not a photograph of someone replying to you.

A person may read it afterwards
People at the company you were talking to can review conversations later — to answer a question the assistant could not, to check quality, or to follow up. 'No person is reading live' is not the same as 'no person will ever read this', and it would be misleading to let the first imply the second.
Your message text goes to an AI provider
Generating a reply means sending what you wrote to an outside AI provider. Personal details you type into a message are not stripped out before that happens, so treat the box the way you would treat an email to a company you do not know well.
You can ask for a person
At any point. Asking does not require you to justify the request.
Chatting is not agreeing to marketing
Using the widget is never recorded as permission to market to you. That takes a separate, explicit opt-in.

Recorded conversations — not switched on yet

This section describes something that is being built and is not running. No part of this product records audio or video today. The chat widget has no ability to capture your microphone or camera, and there is no route that would accept audio from a visitor.

It is described here rather than left out so that you can see the design before it arrives, and so that this page does not have to be rewritten in secret when it does. When it becomes available, this section will be updated and the version at the top of the page will change.

Current status: not active
Nothing records you. The software that would perform it is present but is not connected to any surface, and it refuses to start for several independent reasons — including that the wording a visitor would be shown has not been approved for use.
The microphone button that exists today does not record you
If your browser offers speech-to-text, the widget can use it. Your browser does the conversion and only the resulting text is sent. No audio reaches this product. Your browser may use its own speech service to do it — that is between you and your browser, and its settings control it.
When it does arrive: you will be asked first
Recording would start switched off. You would be told, before anything could listen, that the other party is software and that the conversation would be recorded and written down. Declining would keep the conversation going as text rather than ending it.
In some places, a notice would not be enough
Where the rules require everyone in a conversation to agree, or where the local regime requires a prior opt-in, it would take a separate explicit yes rather than a notice. Where the location cannot be established, or has not been reviewed, recording would not be offered at all.
Stopping, mid-conversation
You would be able to stop at any point, and stopping would delete the recording of what you had already said rather than merely halting the capture. The conversation would carry on as text. The record that you agreed and then withdrew would be kept — deleting that would destroy the only evidence the software behaved correctly.
How long a recording would be kept
Not decided yet. Rather than print a number that has not been agreed, this page will state the period once there is one. The deletion-on-withdrawal rule above does not depend on it.

AI participants in meetings — not switched on yet

This product is being built to let a company send an AI participant into its own video meetings: a notetaker that listens and writes things down, and a teammate that can also speak when spoken to. They are separate, and a company chooses per meeting whether either joins. Neither runs today — no bot joins any call, and the software that would do it refuses to start for several independent reasons, including that the words it would say on arrival have not been approved for use.

As with recorded conversations above, the design is described here before it arrives so that it can be argued with now. When it becomes available, this section will be updated and the version at the top of the page will change.

Current status: not active
No meeting has ever been joined. The joining software exists behind a gate that requires approved wording, established agreement, and a reviewed jurisdiction before it will start, and there is no runtime connected to it.
It would arrive as itself
The participant would be named as an AI in the meeting's participant list, would say out loud on arrival that it is software and may record, transcribe, and speak, and would post the same notice into the meeting chat. The notice is both spoken and written because either channel alone leaves someone out — spoken misses people who are deaf or hard of hearing, written misses people who are blind.
Where everyone must agree, agreement comes before the join
In places where the rules require every participant to agree to recording, the design treats joining — not recording — as the thing that needs the agreement, because a bot that enters first and asks second has already heard the room. Without the agreement, it stays out. Where a location is unknown or has not been reviewed, the stricter reading applies and it stays out too.
Leaving is part of the design
A bot that is admitted but does not obtain what it needs to operate leaves after a short, fixed time rather than sitting in the room. A meeting that ends up containing only notetaking software gets left as well.
No voiceprints unless that is separately agreed
Working out who said what from the sound of a voice creates a biometric identifier. That is off by default: without a separate agreement covering it, a transcript records what was said without naming speakers by voice.
Recordings would stay on our own systems
Audio and transcripts would be processed on infrastructure we run rather than passed to an outside transcription service, and deletion on withdrawal reaches the stored recording itself, not only the text made from it.
How long a recording would be kept
Not decided yet — the same honest answer the recording section gives. The period will be stated here once there is one; the deletion-on-withdrawal rule above does not depend on it.

How long any of this is kept

The honest summary is that some deletion is on a fixed timer and some is not yet, and this page distinguishes the two rather than rounding both up to the reassuring answer.

The content of a conversation: 90 days after it is closed
Messages, attachments, and the stored copies of messages that arrived from another platform are deleted 90 days after the conversation is marked closed. This runs automatically. If a conversation is never closed, that timer never starts — so an abandoned conversation can sit longer than 90 days.
Everything else: as long as it is needed, then deleted
Account records last as long as the account. Visit and session records are kept while they are useful for measurement and for spotting abuse. Some of these deletion steps are still carried out on request rather than on a timer; where that is the case, asking us is what makes it happen, and we would rather tell you that than imply a schedule that is not running.
Records that deliberately survive a deletion
If you ask not to be contacted, the record of that request is kept — otherwise we would have no way to keep honouring it, and you would end up back on a list. The same applies to the record of a permission being given and taken back, and to accounting records we are separately required to hold.
A legal hold pauses deletion
If information is subject to a legal hold, deletion is blocked and the request is reported as blocked rather than quietly skipped. Silently keeping something after you asked for it to go is the failure worth guarding against.

What you can ask for, and how

Depending on where you live you may have rights to see what is held about you, to correct it, to have it deleted, to object to how it is used, or to take it elsewhere. Rather than list rights in the abstract, here is which of them you can exercise directly today and which need a person to act on.

Stop marketing email — immediate, no account needed
Every marketing message has a one-click unsubscribe. There is also a preferences page reached from those messages where you can change what you receive. Opening either does nothing on its own; the change happens when you choose it.
Stop being tracked — immediate, no account needed
The tracking used on a customer's site can be withdrawn from the site itself, which clears the identifier stored in your browser. A Global Privacy Control signal achieves the identification part of this automatically and permanently.
See, correct, or delete what is held about you
Ask the company whose website you were on. They hold the relationship and they can act on it. Their staff have tools in this product to find your record, export it, and erase it, and an erasure reports honestly on anything it could not reach rather than reporting success.
If you were only ever an anonymous visitor
There is currently no self-service way to file a deletion request for someone who never became a contact, because there is no verified record to attach the request to. Contact the company whose site you were on and they can act on it. We would rather state this gap than describe a form that does not exist.
Complain
You can raise a concern with your local data protection authority. Doing so does not require you to have contacted us first.

Outside providers, and how to find out which ones

Some things are done by other companies on our behalf — generating an AI reply is the main one, along with hosting, sending email, and telephony where a customer uses it.

Which AI provider processes a given conversation depends on how the product is configured, and it is becoming a customer-selectable choice. So rather than print a vendor name here that could be wrong for your situation, the published provider list is generated from the configuration that is actually in force. It names each provider, what they do, and how long they keep what they receive.

Where to look
The providers page linked from the footer of this site. If you are dealing with a specific company using this product, ask them which providers their configuration uses — the answer is theirs to give and it may differ from the default.
What we do not claim
We are not going to tell you an agreement is signed that this page cannot verify. If you need the contractual terms covering a provider's handling of your data, ask for them directly rather than treating this page as evidence of them.

Where in the world this data goes

This product runs on hosting and provider infrastructure that is not confined to any one country. If you are outside the United States, assume your information is processed there and in other countries where our providers operate.

There is no option to keep data in a particular region, and no region selector. If your situation requires one, this product does not offer it today and you should know that before choosing it rather than after.

What we are not claiming
This page does not claim any particular transfer mechanism, certification, or audit. We hold no security certification that we are asserting here, and we would rather say that than let a reader assume one from silence.

How a customer's own settings change this

This product is installed and configured by the company whose website you were on. Several things on this page are theirs to turn on or off, so the accurate answer for any specific site is 'this, as that company configured it'.

Whether person-level identification happens at all
It requires the customer to connect their own account with an outside provider. Most of what this page describes about that tier does not apply if they have not.
Whether the chat widget is on the site, and what it looks like
Including the assistant's name and portrait. The portrait represents software; it is not a photograph of a person replying to you.
Which outside providers process what you type
See the section on outside providers below.
What the customer does with the result
Whether anyone is contacted, and how, is the customer's decision and their responsibility. Ask them directly what they hold about you.

Who is responsible for this, and how to reach them

The organisation behind this product is established in the Republic of Korea, so Korean privacy law applies to it directly. That law requires a named person to be responsible for how personal data is handled, and requires that you be told how to reach them.

Privacy requests go to privacy@runtheworld.ai. Use it to ask what is held about you, to have something corrected, to have something deleted, or to complain. It is a working address rather than a formality, and a request sent to it is answered.

If a company used this product on their website and your question is about what that company holds, they will usually be able to answer faster — they decide what is collected on their site. Either route works; that one is often shorter.

개인정보 보호책임자
Privacy requests and complaints: privacy@runtheworld.ai. The designated officer is the representative of SHMAPLEX, named on the terms page.
How long a request takes
Korean law allows ten days to answer a request to see what is held about you. If something will take longer than that, you are told why rather than left waiting.
If you are not satisfied
You can raise it with the Korea Internet & Security Agency's privacy complaint centre (privacy.kisa.or.kr, 118) or the Personal Information Protection Commission. Saying so here is not an invitation to skip us — it is a route you have whether or not we mention it.

How to reach us about this

If a company used this product on their website and you want to ask what they hold about you, ask that company first. They decide what is collected on their site and they can answer for it; this product is the software they run.

If you want to reach us directly about this statement, use the address in the section above. We would rather answer a question than have you guess from this page.