Contact
Assess · Runware

Can you own it?

Ownership levelPartialnone·limited·partial·substantial·fullAnalytical input D ยท 45.6/100

This page is a projection of the one entry record, the Use & modify and Transparency factors that Assess covers. The full verdict is set by all four factors together, floor-weighted so the weakest caps the whole.

Which domain expands which factor
  • AssessUse & modify + Transparency
  • ImplementData control + Doesn't fail you
  • UseDoesn't fail you
  • SupportTransparency

Data governance - retention, ZDR & training

Read from the binding Terms and Privacy Policy (Runware Ltd, UK), the posture is weak, and it contradicts the marketing.

  • Retention is generic, not zero. The Privacy Policy keeps data "as long as necessary" and for the life of the account. There is no auto-purge and no opt-in-storage clause, contrary to the marketed "generated content is auto-purged unless you opt into storage".
  • No no-training commitment. The Privacy Policy does not address training at all, and the Terms reference "storing training data and models." Nothing in the binding text stops training on your data.

Data & IP ownership

This is the central finding. Per the read Terms, the customer owns the "Generations" (outputs), but grants Runware a worldwide, perpetual, transferable licence over both inputs and outputs. Nominal ownership sits with you; a perpetual, transferable right to use your prompts and your generated content sits with Runware. That is the opposite of "your data belongs to you and is never reused". The Privacy Policy names only Stripe and Google Analytics as sub-processors, so the processors that actually handle prompt content are not disclosed. The one clean escape is to self-host the same open-weight checkpoints, which removes Runware from the data path entirely.

Data residency & jurisdiction

The Trust page advertises "EU & US" data residency, but no contractual region-pinning document was found, and US CLOUD Act is not addressed anywhere located. The binding legal entity is Runware Ltd (United Kingdom) under UK law and London arbitration, even though the company markets a US (San Francisco) HQ. EU residency is advertised, not guaranteed, so treat this as a UK-jurisdiction provider without a sovereign, EU-only option.

Compliance & attestations

SOC 2 and ISO 27001 appear as badges on the Trust page with no readable report (no number, issuer, scope, type, or period). No public DPA was located (both runware.ai/dpa and runware.ai/data-processing-agreement returned 404, so it is likely enterprise-only). GDPR/UK GDPR is cited without naming SCCs or the EU-US Data Privacy Framework. Request a DPA and the actual attestation reports before any regulated use.

Security controls

The Trust page carries the SOC 2 / ISO 27001 badges and there is a dedicated vulnerability-disclosure page; models run on Runware's own Sonic Inference Engine hardware. Held short of a strong rating absent a readable attestation report or an independent penetration test.

Pricing & cost model

Pay-as-you-go, usage-based pricing with representative rates read on the pricing page; enterprise plans add dedicated capacity and custom terms.

Reliability posture

A USD 50M Series A (December 2025) and advertised enterprise custom SLAs point to production scale, but no public uptime SLA or status page was found, so availability is asserted rather than independently observable.

How this scores

The ownership factors this domain covers, drawn from the one entry record.

1

Use and modify freelyCan you use it freely and leave without lock-in?

Strong

The catalogue is open-weight Hugging Face models, so you can run and adapt the same checkpoints elsewhere or self-hosted; the models themselves are fully portable, and self-hosting sidesteps the hosted data terms entirely.

How this scores (AOI sub-dimensions)
Transparency & lock-in4/5how portable it is and how easily you can leaveThe catalogue is open-weight models from Hugging Face, so the same checkpoints run on other providers or self-hosted and the models are fully portable.
Cost4/5how the pricing model compares and how predictable it isPay-as-you-go usage-based pricing with representative rates read on the pricing page, and low cost is a core part of the positioning.
2

TransparencyAre the binding terms published, legible and independently checkable?

Moderate

The binding Terms and Privacy Policy were read this session, so the data terms are legible - and what they show is unfavourable. Held at moderate, not strong, because the DPA was 404 and the SOC 2 / ISO 27001 reports are badges with no readable report.

How this scores
Not a scored AOI dimension. For a hosted provider, transparency is whether the binding terms are published, legible and were actually read - the read/unverified evidence below, not a certification. A strong rating here must trace to a retrieved binding document.
What this means for adoptionYou partly own workloads here, and the split is sharp. The models are open weights, so use, modification and exit stay fully in your hands, and self-hosting the same checkpoints avoids the hosted data terms entirely. But on a hosted basis the binding documents, now read, are weak: the Terms grant Runware a worldwide, perpetual, transferable licence over your inputs and outputs and reference storing training data, the Privacy Policy sets generic retention with no auto-purge and no no-training commitment, and no DPA or readable attestation was reachable. That is the opposite of the marketed 'your data stays yours, never trained on'. Use Runware as a fast, low-cost open-model gateway for non-sensitive work, but self-host the same open checkpoints, or get a negotiated DPA that overrides the standard licence, before putting proprietary or regulated data through it.

Sources

The same evidence records as the entry sheet. Read means the text was verified; unverified means it is known to exist but not yet read.

Terms of serviceread2026-07-26
Runware Terms of Service (Runware Ltd, UK; read 2026-07-26): the customer owns the Generations (outputs) but grants Runware a worldwide, perpetual, transferable licence over inputs and outputs; the Terms reference "storing training data and models per our pricing schedule"; UK governing law and London arbitration; termination at Runware's sole discretion; data deleted on request.
Privacy Policyread2026-07-26
Runware Privacy Policy (Runware Ltd, UK; read 2026-07-26): generic retention ("as long as necessary" / account life) with no auto-purge or opt-in-storage clause; training use not addressed; sub-processors named are only Stripe and Google Analytics; GDPR/UK GDPR referenced without naming SCCs or the EU-US Data Privacy Framework.
Securityunverified2026-07-26
Runware Trust page (read 2026-07-26, partial): "Data residency EU & US" badge with no contractual region-pinning document located; SOC 2 and ISO 27001 shown as badges only with no readable certificate or report; a separate security-disclosure page for vulnerability reporting.
Vendor announcementread2026-07-26
Runware pricing page (read 2026-07-26): pay-as-you-go usage-based pricing with representative rates; enterprise plans add dedicated capacity and custom terms.
Vendor announcementunverified2026-07-26
Runware website ("One API for all AI"): a unified API over a large catalogue of open-weight Hugging Face models run on Runware's own Sonic Inference Engine; low usage-based pricing; markets a US HQ and states data belongs to the customer (marketing framing not supported by the binding Terms/Privacy read this session).
Third-party analysisread2026-07-26
Independent press (SiliconANGLE and others, Dec 2025): Runware raised a USD 50M Series A (Speedinvest and others) to build "one API for all AI"; markets a San Francisco HQ with operations in London and 10+ countries (the binding legal entity is Runware Ltd, UK); inference pods in the US and central Europe; aims to make the broad Hugging Face open-model catalogue addressable behind one schema.