Privacy Policy
What Cuna collects, why we need it, who helps us process it, and the choices you have.
Effective
Scope and controller
This Privacy Policy explains how Cuna collects, uses, discloses, retains, and protects personal information when you visit getcuna.com, create an account, join the waitlist, schedule onboarding, or use the Cuna console, machines, and related services (together, the Service).
Cuna Labs (Cuna, we, or us) is the controller of the account, website, and service-administration data described here. If an organization uses Cuna to process personal information in its own code, files, or workflows, that organization remains responsible for its instructions and legal basis. Cuna does not currently offer a Data Processing Addendum for that content. Do not use the Service for processing that requires a controller-processor agreement until one has been signed.
Privacy questions and requests may be sent to angel@getcuna.com or contact@getcuna.com.
Information we collect
Depending on how you use the Service, we collect:
- Account and identity data: your email address, account identifier, and the basic name, avatar, and profile data Google or another sign-in provider returns with your permission.
- Access and onboarding data: workspace assignment, waitlist and onboarding status, booking details, and related timestamps.
- Machine and usage data: machine names and identifiers, agent selection, requested capacity, lifecycle state, run time, estimated usage or cost, token measurements, and service events.
- Workspace and run content:instructions, commands, repository references, files, prompts, model responses, and artifacts that you or an agent place in a machine. Runtime and model providers may process the full content. Cuna's hardened audit records keep safe action summaries and operational metadata while omitting command text, paths, URLs, request bodies, and credential names and values.
- Credentials and secrets:when you use an approved credential workflow, Cuna's edge receives the value only as needed to send it to the runtime provider. Cuna records the action and its outcome without the credential name or value. Runta stores and processes the credential as needed to operate the machine and may return redacted metadata for display.
- Communications: messages you send us, scheduling information, transactional email status, and delivery events such as delivered, delayed, bounced, or reported as spam. We retain a digest of signed email webhook payloads rather than the full provider payload.
- Technical data: IP address, browser and device information, request metadata, timestamps, security events, and diagnostic logs collected by Cuna and its hosting providers.
We do not ask you to place government identifiers, health data, payment-card data, or other regulated sensitive personal information in the Service. Do not put that data—or secrets and credentials outside an approved workflow—into prompts, files, or machines.
Where information comes from
We receive information directly from you, automatically from your browser and use of the Service, from Google or another sign-in provider you choose, from Calendly when you book onboarding, and from the infrastructure and model or developer services involved in a run.
If you use Cuna for an organization, an administrator or colleague may also provide account or workspace information about you.
How and why we use information
We use personal information to:
- authenticate you and maintain your account and session;
- assign capacity, operate machines, execute requested workflows, and keep the activity record;
- manage the waitlist, onboarding, service email, and support;
- meter usage, understand reliability, troubleshoot failures, and improve the Service;
- detect abuse, protect users and infrastructure, enforce our Terms, and investigate security incidents; and
- comply with law and establish or defend legal claims.
- Contract: account creation, authentication, workspace assignment, machine execution, service records, onboarding, support, and transactional email.
- Legitimate interests: security, fraud and abuse prevention, diagnostics, reliability, capacity planning, and internal product and usage measurement, balanced against your rights.
- Legal obligation: lawful requests, required records, and establishing or defending legal claims.
- Consent: optional marketing, non-essential cookies, or another purpose when we specifically ask. Cuna does not currently send marketing email.
You may withdraw consent at any time, but withdrawal does not affect processing already carried out lawfully.
Agents and automated decisions
AI agents process the instructions and workspace content needed for the task you start. AI output is probabilistic and may be inaccurate or unsafe; you remain responsible for reviewing it before relying on or deploying it.
As of the effective date, Cuna does not operate a program that uses your workspace content to train a Cuna general-purpose AI model. A model or developer service that you choose may process content under its own terms and privacy notice.
Workspace and waitlist assignment may occur automatically according to available capacity. Cuna does not use personal information to make solely automated decisions that produce legal or similarly significant effects about you.
Disclosures and service providers
We disclose information only as needed to operate the Service, follow your instructions, protect the Service, complete a business transfer, or comply with law. Current provider categories include:
- Google for sign-in; Supabase for authentication and the service database; Vercel for the website and console;
- Fly.io for the edge API and runtime gateway, and Runta for cloud machine infrastructure;
- Resend for transactional email and Calendly for onboarding scheduling; and
- source-control, model, agent, or other services you deliberately connect or direct Cuna to use.
These providers process information under their own contracts and privacy terms. Their notices are available from Google, Supabase, Vercel, Fly.io, Runta, Resend, and Calendly.
Cuna does not sell personal information and does not share it for cross-context behavioral advertising. We do not provide customer records, mandates, or activity to data brokers or advertisers.
International transfers
Cuna uses providers with infrastructure in the United States, Canada, and other countries. Your information may be processed outside the country where you live. Providers describe their own transfer mechanisms in their privacy notices and contractual terms. Cuna does not currently make a separate Data Processing Addendum or a complete set of provider transfer agreements available to early-access users. Contact us before using Cuna for regulated processing that requires one.
Retention and deletion
We keep account, workspace, machine, usage, onboarding, email delivery, and activity records for as long as needed to provide and secure the Service, maintain the record you requested, troubleshoot delivery, resolve disputes, and meet legal obligations. Receiving access does not by itself delete waitlist, onboarding, or email history.
Retention depends on the type of data, whether your account or machine remains active, the sensitivity of the data, provider backup cycles, and legal or security needs. As of the effective date, Cuna does not run a general automatic expiry job for every service record. An account-deletion request requires coordinated cleanup across Cuna, Supabase, Runta, and other providers. Some data may remain where required by law, for security, to establish or defend legal claims, or until a provider backup cycle completes.
Security
Cuna uses encrypted transport, encrypts its own Runta tenant tokens at rest, separates workspaces, restricts database records by user, and omits secret values from Cuna audit records. Agents receive only the access made available to their machine and task. A runtime provider may apply its own storage and security controls to credentials and content processed in a machine.
No service can guarantee absolute security. Protect your account, use only systems you are authorized to access, keep backups, review agent actions, and notify angel@getcuna.com promptly if you suspect unauthorized access.
Your rights and choices
Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a portable copy of personal information, withdraw consent, and appeal or complain to a competent authority. In Mexico, these include rights of access, rectification, cancellation, and opposition (ARCO), revocation of consent, and limiting the use or disclosure of personal information. California residents may also have rights to know, correct, delete, and receive equal service when exercising applicable rights.
Send a request to angel@getcuna.com or contact@getcuna.com. State the account email and the right you want to exercise. We may ask for information needed to verify your identity and authority. We will respond within the period required by applicable law and will not discriminate against you for making a request. For a valid Mexican ARCO request, we will communicate our determination within 20 days and, if granted, act within the following 15 days, subject to extensions and exceptions allowed by law. The same emails are the mechanism for withdrawing consent or asking us to limit use or disclosure.
Children, changes, and contact
The Service is for adults and is not directed to children. You must be at least 18 years old and legally able to enter an agreement. If the age of legal majority where you live is higher, you must have reached that age. Contact us if you believe a child provided personal information.
We may update this Policy as the Service or law changes. We will post the revised Policy here, change the effective date, and provide additional notice when a change materially affects your rights or our use of personal information.
For privacy questions or requests, email angel@getcuna.com or contact@getcuna.com.
