Can you own it?
This page is a projection of the one entry record, the Use & modify and Transparency factors that Assess covers. The full verdict is set by all four factors together, floor-weighted so the weakest caps the whole.
- AssessUse & modify + Transparency
- ImplementData control + Doesn't fail you
- UseDoesn't fail you
- SupportTransparency
Data governance - retention, ZDR & training
Read from the binding Terms and Privacy Policy (Runware Ltd, UK), the posture is weak, and it contradicts the marketing.
- Retention is generic, not zero. The Privacy Policy keeps data "as long as necessary" and for the life of the account. There is no auto-purge and no opt-in-storage clause, contrary to the marketed "generated content is auto-purged unless you opt into storage".
- No no-training commitment. The Privacy Policy does not address training at all, and the Terms reference "storing training data and models." Nothing in the binding text stops training on your data.
Data & IP ownership
This is the central finding. Per the read Terms, the customer owns the "Generations" (outputs), but grants Runware a worldwide, perpetual, transferable licence over both inputs and outputs. Nominal ownership sits with you; a perpetual, transferable right to use your prompts and your generated content sits with Runware. That is the opposite of "your data belongs to you and is never reused". The Privacy Policy names only Stripe and Google Analytics as sub-processors, so the processors that actually handle prompt content are not disclosed. The one clean escape is to self-host the same open-weight checkpoints, which removes Runware from the data path entirely.
Data residency & jurisdiction
The Trust page advertises "EU & US" data residency, but no contractual region-pinning document was found, and US CLOUD Act is not addressed anywhere located. The binding legal entity is Runware Ltd (United Kingdom) under UK law and London arbitration, even though the company markets a US (San Francisco) HQ. EU residency is advertised, not guaranteed, so treat this as a UK-jurisdiction provider without a sovereign, EU-only option.
Compliance & attestations
SOC 2 and ISO 27001 appear as badges on the Trust page with no readable report (no
number, issuer, scope, type, or period). No public DPA was located (both runware.ai/dpa and
runware.ai/data-processing-agreement returned 404, so it is likely enterprise-only). GDPR/UK GDPR
is cited without naming SCCs or the EU-US Data Privacy Framework. Request a DPA and the actual
attestation reports before any regulated use.
Security controls
The Trust page carries the SOC 2 / ISO 27001 badges and there is a dedicated vulnerability-disclosure page; models run on Runware's own Sonic Inference Engine hardware. Held short of a strong rating absent a readable attestation report or an independent penetration test.
Pricing & cost model
Pay-as-you-go, usage-based pricing with representative rates read on the pricing page; enterprise plans add dedicated capacity and custom terms.
Reliability posture
A USD 50M Series A (December 2025) and advertised enterprise custom SLAs point to production scale, but no public uptime SLA or status page was found, so availability is asserted rather than independently observable.
How this scores
The ownership factors this domain covers, drawn from the one entry record.
Use and modify freelyCan you use it freely and leave without lock-in?
StrongThe catalogue is open-weight Hugging Face models, so you can run and adapt the same checkpoints elsewhere or self-hosted; the models themselves are fully portable, and self-hosting sidesteps the hosted data terms entirely.
TransparencyAre the binding terms published, legible and independently checkable?
ModerateThe binding Terms and Privacy Policy were read this session, so the data terms are legible - and what they show is unfavourable. Held at moderate, not strong, because the DPA was 404 and the SOC 2 / ISO 27001 reports are badges with no readable report.
Sources
The same evidence records as the entry sheet. Read means the text was verified; unverified means it is known to exist but not yet read.