This policy explains what personal data Rung Coder collects, why, and what rights you have. It covers the Rung Coder desktop application and the website at rungcoder.com.
Controller: Rung Coder, the trading name of an individual trader. The controller's legal identity is given in Section 14. Email: [email protected]
Write to us at [email protected] on any question relating to the processing of your personal data. A postal address is available on request.
| We collect | We do not collect |
|---|---|
| Your email address and, when you use Google or GitHub, the basic profile data that provider makes available | Your CODESYS projects, code, variables or visualisations |
| A hashed hardware identifier and your computer name, to enforce the one-device licence | Any record of what you ask an AI assistant, or what it replies |
| Your subscription status and Creem customer reference | Keystrokes, screen contents or screenshots |
| Version numbers and the time of your last authorisation check | Feature-usage statistics or behavioural analytics |
| Server logs, including IP addresses, at our infrastructure providers | Payment card details — these never reach us |
We do not sell personal data, we do not share it for advertising, and we do not use it to train AI models.
What: your email address and sign-in method. If you sign in with Google or GitHub, we also receive the provider account identifier and any display name or profile picture that provider makes available. If you create an account with email and password, Supabase processes the password for authentication; we do not store it or have access to it.
Why: to create and identify your account and to link it to a subscription.
Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
What: a device identifier — a SHA-256 hash calculated from your processor ID, motherboard serial number and BIOS serial number — plus your computer name, the version of the application, the version of the bundled backend, and the time of your last authorisation check.
Why: to enforce the one-active-device term of the licence, to detect licence sharing, and to help us reproduce faults reported by email.
Legal basis: performance of a contract, and our legitimate interest in preventing unauthorised use of paid software (Art. 6(1)(b) and (f) GDPR). We have assessed that a one-way hash is a proportionate means of achieving this: it identifies a machine without revealing the underlying serial numbers, and it is not used for any other purpose.
Note: your computer name is chosen by you or your employer and may contain your name. You can change it in Windows settings; the new name will be recorded at the next check.
What: subscription status, plan, trial and subscription dates, and the customer and subscription references issued by Creem.
Why: to determine whether your licence is active.
Legal basis: performance of a contract; and legal obligation for the retention of transaction records (Art. 6(1)(b) and (c) GDPR).
Payments are processed by Creem — the trading name of Armitage Labs OÜ, Estonia — which acts as merchant of record and as an independent controller for payment and tax data. We never receive or store your card details. Creem's own privacy policy governs the checkout and everything Creem does with that data afterwards: https://www.creem.io/privacy.
What: each update check discloses your IP address, your operating system and the current version of the application to the update distribution endpoint, which is hosted on GitHub.
Why: to deliver software updates. Checks run at start-up and about every six hours.
Legal basis: legitimate interest in distributing security and functional updates, and — for consumers — our obligation to supply updates for digital content (Art. 6(1)(b) and (f) GDPR).
What: standard server logs at our hosting provider, including IP address, time, requested URL and user agent. If you sign in on the website, a strictly necessary session cookie is set.
Why: to deliver and secure the website and to keep you signed in.
Legal basis: legitimate interest in operating a secure website; the session cookie is strictly necessary for a service you have requested. We do not use advertising or analytics cookies. If we add analytics in future, we will ask for your consent first where the law requires it.
What: the content of emails you send us, including any diagnostic file you choose to attach.
Why: to answer you.
Legal basis: performance of a contract and legitimate interest in providing support.
The following never leaves your device unless you deliberately send it to us:
%USERPROFILE%\.rung-host\diagnostics\. They are not uploaded. You may attach one to a support email; if you do, please open it first — it contains file paths and installed-software information.%USERPROFILE%\.rung-host\session.json.Rung Coder connects CODESYS to an AI assistant that you install and configure. Your project code, the AI's replies and any screenshots the assistant requests travel directly between your computer and that assistant's provider — for example Anthropic, OpenAI or Google.
None of it passes through, or is stored on, our servers.
That provider processes the data under its own terms and privacy policy, over which we have no control. If your projects contain trade secrets or personal data, review that provider's terms before granting access, and consider whether your employer's policy permits it.
We use the following processors and providers. We do not share your data with anyone else except where required by law.
| Provider | Purpose | Where the data is held |
|---|---|---|
| Supabase | Authentication, database, authorisation service | United Kingdom (London region) |
| Sign-in (OAuth) | Google infrastructure; Google is an independent controller for your Google account | |
| Creem (Armitage Labs OÜ) | Payments, invoicing, tax; merchant of record | Estonia (EU); independent controller for payment data |
| Cloudflare | Website hosting and CDN | Global edge network |
| GitHub | Sign-in (OAuth) and distribution of software updates | United States; GitHub is an independent controller for your GitHub account |
A current list is available at any time from [email protected].
Your account, subscription and device data are stored in the United Kingdom, which the European Commission has recognised as providing an adequate level of protection. Sending your data there is therefore permitted without further formalities.
The controller is located in the People's Republic of China and accesses this data from there in order to operate the service and provide support. This is the controller working with data it already holds, not a disclosure to a separate recipient, and it therefore does not require the additional safeguards that Chapter V of the GDPR imposes on transfers to third countries. No personal data is passed to any other recipient in China.
That access is protected by the measures described in Section 10 and, above all, by how little there is to access: we collect no project content and no usage data at all.
Our payment provider, Creem (Armitage Labs OÜ), is established in Estonia, so sharing your subscription details with it does not leave the EU and needs no transfer safeguards.
Transfers to Cloudflare and GitHub in the United States take place under those providers' own transfer mechanisms, including the EU–US Data Privacy Framework and Standard Contractual Clauses where applicable.
| Data | Retention |
|---|---|
| Account and subscription record | For as long as your account exists |
| Device sessions (identifier, computer name, versions) | Deleted within 30 days of account closure |
| Transaction and invoice records | 7 years, to meet tax and accounting obligations |
| Support correspondence | 24 months from the last message |
| Website server logs | As set by our hosting provider, typically under 30 days |
When you close your account we delete the account and device data within 30 days, except for the transaction records we are legally required to keep.
Under the GDPR and UK GDPR you have the right to:
To exercise any of these rights, write to [email protected]. We will reply within one month.
Deleting your account: email [email protected] from the address you signed up with, or use the account-deletion page at https://rungcoder.com/account/delete. Deletion is permanent and ends any active subscription.
We protect your data with encryption in transit (TLS), row-level security in the database so that each account can read only its own records, and access controls on the administrative interface. Access to this data is limited to what is needed for support, billing and abuse prevention.
No system is perfectly secure. If a breach affects your data and is likely to result in a high risk to your rights, we will notify you and the relevant supervisory authority as required by law.
To report a security problem, write to [email protected] with "SECURITY" in the subject line.
Rung Coder is a professional tool and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child has created an account, contact us and we will delete it.
The authorisation check is automated: if your subscription has expired or another device is active, the software will refuse to run. This is a contractual condition, not a decision producing legal effects in the sense of Article 22 GDPR, and it can always be resolved by contacting us.
We may update this policy. The current version is always at https://rungcoder.com/privacy. If we make a material change we will notify you by email or in the application at least 30 days beforehand. Earlier versions are archived and available on request.
Rung Coder is the trading name of YIN QUNJIA, an individual trader, who is the controller for the processing described in this policy. A postal address is available on request.
Questions: [email protected]