1. Who We Are
RunCabin ("we", "us", "our") is an AI-agent-enabled website platform operated by Ryan Mergen, based in Baltimore, MD. We can be reached at hello@runcabin.com.
2. Information We Collect
When you use the AI builder, publish a Cabin, or otherwise interact with the Service we collect:
- Account info - email address, name, and (if you ask us to register a domain) the registrant details required by ICANN: name, postal address, phone number.
- Build conversations - the messages you exchange with our AI builder ("Stony"), uploaded images, and the resulting generated pages. We store these so you can come back to your draft and so we can debug failed builds.
- Cabin contents - the pages, images, schema, and data you publish on your Cabin. This lives in your Cabin's container and a corresponding Postgres schema.
- Usage records - Cabin token debits, AI API calls made by your Cabin's agent, request timestamps, and approximate model cost. Stored so we can bill accurately and show you a usage breakdown.
- Payment metadata - handled by Stripe. We receive your Stripe customer ID, the last 4 digits of your card, billing zip, and payment history. We never see or store your full card number.
3. How We Use Your Information
We use the information described above to:
- Operate the AI builder and your published Cabin;
- Bill monthly publishing fees and debit Cabin tokens for AI usage;
- Send transactional emails (publish confirmations, low-balance alerts, payment receipts, support replies);
- Debug failures, improve the platform, and detect abuse;
- Comply with legal obligations (tax records, registrar requirements, lawful requests).
We do not sell your data. We do not share your data with third parties for marketing purposes.
4. Sub-processors
We use the following third-party services to deliver the Service. Each is bound by its own privacy policy and processes only the data necessary for its specific function:
- DigitalOcean (US) - hosting infrastructure for the orchestrator, your Cabin's container, and the underlying Postgres database.
- Anthropic (US) - Claude models. Receives the message contents sent to your Cabin's agent and to Stony during the design phase.
- OpenAI (US) - used for image generation (
gpt-image-1). Receives the image prompts you or your Cabin visitors submit.
- Stripe (US) - payment processing for publishing fees, Cabin token top-ups, and domain registration pass-through.
- Porkbun (US) - domain registrar, when you ask us to register a domain on your behalf. Receives your registrant details.
- Resend (US) - outbound transactional email delivery (your publish receipts, low-balance alerts, etc.).
- GitHub (US) - hosts the private repository containing your Cabin's source code.
- Plausible Analytics (EU) - cookieless website analytics for runcabin.com. Receives anonymized page views; no personal data, no cross-site tracking.
5. Email Communications
By creating an account, you agree to receive transactional emails related to your Service: publish confirmations, payment receipts, low-balance and zero-balance alerts, security-relevant notices, and support replies. We do not send marketing newsletters or promotional blasts. If we ever introduce optional marketing email, it will be strictly opt-in.
6. Cookies & Analytics
We use only the cookies needed to operate the site. We do not use third-party advertising cookies, Google Analytics, Facebook Pixel, or any cross-site tracking pixels.
Functional cookies (always on while signed in):
aibuild_slug - keeps your AI build draft tied to you across page loads. 30-day expiry, HttpOnly, first-party.
aibuild_dash - signed-in dashboard token for managing your published Cabin. 30-day expiry, HttpOnly, first-party.
tax_session - sign-in token for tax-services customers (if applicable). HttpOnly, first-party.
These are strictly necessary to keep you signed in and are exempt from consent requirements under GDPR and ePrivacy rules. If you refuse them you will not be able to stay signed in.
Analytics: We use Plausible Analytics, which is cookieless - no persistent identifiers, no cross-site tracking, no personal data leaves the EU. You can still opt out via our cookie banner ("Essential only").
You can re-open the banner at any time by clicking cookie preferences.
7. Data Storage & Retention
Your data is stored on infrastructure operated by the sub-processors listed in Section 4, primarily in the United States. Retention:
- Draft AI builds - retained while your account is active; purged 90 days after last edit if never published.
- Published Cabin content and database - retained for the life of your subscription, plus 30 days after cancellation for restoration.
- Usage records (Cabin token ledger, AI call logs) - retained for 24 months for billing reconciliation and dispute resolution.
- Stripe billing data - retained as long as legally required for tax and audit purposes.
- GitHub repository - remains in your possession indefinitely (see Terms §8).
8. AI Agent Conversations
When your Cabin's AI agent talks to a visitor, the conversation is sent to the upstream model provider (Anthropic by default) so the model can generate a reply. We keep a record of those calls - token counts, timestamps, and (for debugging) the message content for a limited window - so we can show you usage and investigate failures. If your Cabin asks visitors for personal data, you are the data controller for that data; RunCabin processes it on your behalf.
9. AI Assistant & Connector Access (MCP)
You can connect AI assistants (such as Claude) and coding agents to your RunCabin account through our MCP connector or API keys. When you do:
- Sign-in and consent - the assistant is authorized via OAuth: you sign in on our own page and approve access before it can act. We never share your password with the assistant, and you can revoke access at any time by emailing us.
- What the assistant can do - create and deploy sites on your account, check domain availability, and start a domain order. It can never charge you by itself: every purchase requires you to review the order and pay on our checkout.
- What we store - the sites and files the assistant deploys for you, domain orders it starts, and access credentials (stored only as cryptographic hashes - we cannot read them back). We log tool calls (timestamps, the acting account) to bill accurately, debug failures, and detect abuse.
- What we do not receive - your conversation with the assistant stays between you and the assistant's provider. We only receive the specific tool requests it sends us (for example "create a site with this HTML").
10. Your Rights
You have the right to:
- Request a copy of the data we hold about you;
- Request correction of inaccurate data;
- Request deletion of your data at any time (subject to records we are legally required to retain);
- Export your Cabin's content and database, or have your GitHub repository transferred to your own account.
To exercise any of these rights, email hello@runcabin.com. We will respond within 30 days.
11. Changes to This Policy
We may update this policy from time to time. Material changes will be communicated via email or a notice on your dashboard at least 30 days before taking effect. The "Last updated" date at the top of this page always reflects the current version. Continued use of the Service after changes constitutes acceptance of the updated policy.