Privacy policy
Pilot version. This policy describes the service as it works today, in its invitation-only pilot. It will be reviewed again before the public launch.
Effective date: October 9, 2026
Who we are
Runnext is run by Binj App Inc. Below we call it "the service". It helps US small business owners decide what to post.
To ask us anything about privacy, write to help@runnext.app.
What this covers
The service's website during its pilot, as the code works today: business owners with an account, creators whose public videos appear in trend searches, and anyone who reads its public pages (the front page, this policy, the Terms and the creator opt-out page).
What we collect from owners
- Account. Your email address and a password. We store the password only as an Argon2 hash. We keep when you signed up and last signed in, and your Monday email choice. Signing up means agreeing to the Terms and this policy: for an account made on or after 2026-10-07 we keep which version you agreed to, and when. Older accounts have no such record.
- Your website. The address you give us. We read up to five of its pages and draft your business profile and buyer reading from the text. We store the address, both drafts, your edits to them, and your answers to questions the website left open.
- What we write for you. Weekly post ideas ("angles") and what you open or buy: full angles, video scripts, static briefs and prompt sets.
- Trend searches. Your question, the search terms, progress lines and results. While a search runs we also hold a record of how far it has got (counts and our own numbers, with no creator named); it is removed when the search ends. We keep when you first watched a search run or played it back, so the replay starts by itself only once.
- Ratings. Thumbs up or down, any note you add, and which version of our instructions made the thing you rated.
- The pilot's question. Under a paid piece or a finished search we may ask "Could you have gotten this from a free chatbot?" Answering is optional. We keep your answer (yes, no or not sure), what it was about, and which version of our instructions made it.
- Tips. Which of the three first-run tips you have dismissed.
- Checklists. Which things on an idea's "You'll need" list you have ticked off, so the ticks are there on your phone and your laptop. We also keep whether the filming page has yet made each of its two one-time moves for you, so each happens once.
- Your own posts (optional). Where the "Your posts" feature is switched on and you add your own TikTok handle, we read the public counts on your own recent posts, the same way we read any creator's: logged out, with no access to your TikTok account. We keep your handle and, for each recent post, its link, date, the start of its caption and its view count, and work out your own usual views from them. We read them when you add the handle and once a week after. Removing the handle deletes them. Without a handle none of this happens.
- Wallet. Credit added, credit you asked for, holds, charges, and any note we wrote when adding credit. No card or bank details: the pilot takes no payments.
- Activity. Each action that costs us money: what it was, when, how it ended, its price, your charge and our own cost. We also count your free actions each day.
- Technical records. The server's request log holds each request's network address, page and time; our host holds it, not our database. One-time links (a password reset, an admin's inbox check) are cut out of it. To limit guessing and abuse, tries are counted against a scrambled network address, in memory only.
What we collect about creators of public videos
Trend searches cover public TikTok videos in the US. For an account that has it switched on, they also cover public YouTube Shorts, read through YouTube API Services (see "YouTube" below).
For each creator a search shortlists (up to 30), we keep the handle, platform IDs, follower count and "usual views": the middle value of the views on their recent posts, our own calculation.
For each video on a results page (up to ten a search), we also keep:
- the link to the original post, the video's ID, caption, length and posting date
- public counts (views, likes, shares, comments, saves) and when we read them. The counts are deleted after 30 days, and the creator's usual views on that card with them (see "How long we keep things").
- our notes from watching it: the opening, the structure, a short summary of what is said (we ask for at most two short quotes), the main on-screen text, the kind of sound, and how many people appear. The model is told not to describe anyone's body, looks, age or race.
- our write-up of why it worked, and a timing tag: "Timeless" or "Trending".
The owner who ran the search sees these, always with a link to the original. If another owner runs the same search within 24 hours, we reuse the facts, notes and tags and write the explanation afresh. Our pilot ranking comparison also keeps these public facts, without the notes, for each ranking method's top ten, for 30 days.
Creators' choices. Any creator can ask to be left out at /opt-out, with no account. Give your handle or profile link and where you post. An email address and a note are optional. We then leave that handle out of every later search. We delete its usual-views record, its videos on every stored results page (with those searches' summary lines) and its rows in our ranking comparison.
We keep the request: handle, platform, date, and any email and note. We cannot check who is asking, so we honour every request. An idea an owner already built from your video stays theirs, but we remove the video's ID and the line describing the original.
YouTube
The service uses YouTube API Services to find public YouTube Shorts and read their public details. Using the service means agreeing to the YouTube Terms of Service. Google's own policy applies to YouTube: see the Google Privacy Policy.
- We never touch your YouTube or Google account. The service has no "Sign in with Google", asks for no access to anyone's account, and reads only what YouTube makes public. So there is no access for you to revoke.
- What we read from YouTube. For a search: the public videos that match the search terms, and for each one its ID, title, the start of its description, tags, length, posting date, and its view, like and comment counts. For each video's channel: its ID, name and handle, its subscriber count where the channel shows it, and the view counts of its recent Shorts.
- What we store, and for how long. For each video on a results page (up to ten a search): its link, ID, title, length and posting date; its public counts and when we read them; the channel's handle and subscriber count; and the channel's "usual views", the middle value of the views on its recent Shorts. Everything read from YouTube is deleted within 30 days of being read: a stored Short leaves its results page whole, and a channel's usual views go 30 days after we read them.
- How we use it. To show the owner who ran the search which Shorts did far better than their channel usually does, with a link to each video on YouTube and YouTube's own player. The multiple ("12× this creator's usual views") and "usual views" are our own calculations from those public counts at the time shown. They are not YouTube's figures, and each page that shows them says so. We do not combine YouTube data across owners to study YouTube, and we do not sell or share it.
- Who else gets it. The companies listed under "Companies that process data for us", only to write the results: the video's public details go to our writing model, and nothing about you goes to YouTube beyond the search terms.
- Thumbnails and players. A results page loads each video's thumbnail, and its player when you open it, from YouTube itself (and from TikTok for a TikTok video). YouTube and TikTok may see that visit and may set their own cookies when a player loads.
What we never keep
Video files, audio, frames or full transcripts. To watch a video, our server holds it in memory, passes it to the watching model, and drops it. Nor the text of your website: it is held in memory only, between the two onboarding steps, and dropped after 30 minutes. Nor your password itself.
How we use it
To run your account, draft your profile and buyer reading, write what you ask for, find and explain public videos, run your wallet and email you. Costs, ratings and answers to the pilot's question help us set prices and improve the service. In the pilot we also compare two ways of ranking videos.
The pages carry no advertising, analytics or tracking scripts. The only scripts are our own, served from our own server: they draw a search while it runs and play it back, step through a video script, light up parts of a results page and set an idea beside the video it came from. While a search runs, its page asks our server for progress every two seconds. Nothing in the code sells data or shares it for advertising.
Companies that process data for us
- Anthropic (writing and planning). Gets your website's text, your profile and buyer reading (with your edits and answers), your search question and the ideas being built on. For trend searches: video ids, captions, hashtags, creator handles, posting dates, counts, our usual-views figures and our watch notes. Never your account email or password.
- Google Gemini (watching videos). Gets each public video being watched, with our instructions and a request not to store it. Nothing about you.
- Apify (TikTok search). Gets search terms, region and time window, and the IDs or handles of creators whose recent posts we read. We ask it to delete each result set once read. Nothing identifying you.
- TikTok. Our server fetches each video file from the address the search results give, normally TikTok's own servers.
- YouTube (Google). Where Shorts are switched on, YouTube API Services get our search terms and the IDs of the videos and channels we read. Nothing identifying you.
- Resend (email). Gets your email address and the email's text, which can include your business name or search question. Our emails are sent from an address on our own domain; a reply goes to help@runnext.app.
- Fly (hosting, US East). Runs the service and holds the server log.
- Neon (database, in the US). Stores everything listed here.
The fonts are our own files, served from our own server. No page loads a font or a script from Google.
Our administrators can see account emails, sign-up dates, onboarding status, credit figures, last activity date, credit requests, rating notes and search questions. They see answers to the pilot's question only as totals, not by account.
Cookies
Two, both needed:
- session keeps you signed in for 30 days. It is a random token; we store only its hash.
- gate shows this browser entered the pilot passcode. It lasts 14 days and holds nothing about you.
A demonstration account's guided tour keeps a third, tour, holding only which stop of the tour it is on; it is gone when the browser closes.
The page of a running search may also keep one item in your browser's session storage (the address of that page, kept if its drawing could not start). It is never sent to us and goes when you close the tab.
Thumbnails and players. Viewing a results page loads each video's thumbnail, and its player when you open it, from TikTok and YouTube themselves, which may see that visit. We ask their embed service for the thumbnail's address each time and never keep the picture.
The platforms' players. A video's player (TikTok's, or YouTube's for a Short) loads only when you press play on its thumbnail or open its "Play it here" section. The platform then gets your network address and browser details and may set its own cookies. Links to a post open the platform in a new tab.
Emails and how to stop them
- A password reset link, when asked for.
- A weekly notice that your Monday drop is ready. Turn it off on your account page; each email links there.
- A notice that a trend search you started is ready, or did not finish. It has no off switch.
Administrators get a notice when you ask for credit; it includes your email address. The code sends no marketing email.
How long we keep things
- Sessions stop working after 30 days, or when you sign out or reset your password. Changing your password on your account page ends every session except the one you changed it in. Reset links work once, for 60 minutes, and stop working when the password is reset or changed. Each night, sessions that have run out are deleted, and so are one-time links a day past their hour.
- Usual views are used for 7 days, refreshed overnight while the creator keeps appearing in recent searches, and deleted after 30 days without a refresh.
- Video counts (views, likes, shares, comments, saves) are deleted 30 days after we read them, unless we read them again. Nothing reads them again today, so they go 30 days after the search. With them goes everything the view count could be worked out from again: the creator's usual-views figure on that card, and any sentence of our write-up that states a count. What stays of the card: the link, the caption, the creator's handle and follower count, our notes, the rest of our write-up, and how far the video beat its creator's usual views (the multiple), shown with the date the counts were read. Where a creator's usual views were under 1,000 the multiple itself would give the count back, so it is deleted too. The ranking comparison's rows are deleted whole after the same 30 days. A YouTube Short's card is deleted whole at 30 days.
- Drops, angles and searches are kept for 12 months after they were made, then deleted, each counted from its own date. A drop that still holds a newer angle waits for it. With an angle goes everything written for it: the full angle, scripts, briefs and prompt sets. With a search go its question, search terms, progress lines and results. The check runs each night.
- What stays after that: the wallet entries and activity log for what you bought or ran (kind, date, price, charge, our cost and how it ended; the log keeps the deleted item's internal id, which leads nowhere), your ratings, your answers to the pilot's question, and the verdict of any ranking comparison on the search (its note is blanked). An angle you made within the year from a video in a deleted search stays yours.
- Everything else of yours is kept until you delete your account: the account and the version of the Terms you agreed to, your business profile and buyer reading, ratings, answers to the pilot's question, wallet entries, the activity log and your daily counts.
- Opt-out requests are kept with no end date.
Deleting your account
Delete it on your account page, with your password. It cannot be undone. This removes your account, sessions, business profile, buyer reading, drops, angles, everything written for them, searches and results, ratings, answers to the pilot's question and daily counts. Any credit left is lost.
What stays, with nothing linking it to you:
- wallet entries: amounts, kinds and dates (notes are blanked)
- the activity log and its cost lines: kind of action, outcome, price, charge, our cost and times. Error text is blanked; what you typed was never in the cost lines.
- credit requests: amount, status and dates
- the verdict of any ranking comparison on your search (its note is blanked)
- a keyed, one-way fingerprint of your email address. It cannot be turned back into the address. It only stops the same address getting the starting credit twice.
Security
In our database, passwords, sign-in tokens and reset tokens are held only as hashes. The site is served over HTTPS only. The pilot sits behind a passcode: only the front page, this policy, the Terms and the creator opt-out page are open without it. Wrong passwords and passcodes are limited to 10 an hour per connection.
Children
The service is for business owners, not for anyone under 18. We do not knowingly collect children's data.
People outside the US
The service is built for US businesses and searches US videos only. Our server and database are in the US.
Changes
We may update this policy. The new version will carry a new effective date. An account made on or after 2026-10-07 records the version it agreed to at sign-up. Older accounts have no record.
Contact
Binj App Inc. Write to us about privacy, or anything else, at help@runnext.app.
See also the Terms.