This Privacy Policy explains how the Rún application (“Rún”, the “App”) handles information. The App is provided by Vikstrom Group AB (“we”, “us”). Contact: run@vgab.eu.
Rún ships in more than one build, and two sections below differ between them. If you are unsure which you have, it is the F-Droid/direct build unless you installed from Google Play.
Neither the messaging itself nor anything in section 3 changes between builds: messages are end-to-end encrypted and routed over Tor in every case.
We do not ask for, collect, or store:
The following is created and kept locally on your device, inside an encrypted vault, and is never transmitted to us:
You control this data entirely. It is destroyed when you wipe the vault, when the App's automatic safeguards trigger (repeated incorrect PIN entry or long inactivity), or when you uninstall the App.
To deliver messages between two people who are not online at the same time, Rún sends and retrieves messages through a relay server we operate. The relay is deliberately “dumb”: it stores sealed, fixed-size (padded) ciphertext addressed to randomly generated, opaque inbox identifiers.
The relay keeps no logs. It does not record access logs, request logs, IP addresses (it cannot see them — connections arrive over Tor), inbox-access history, or timing/metadata about who fetched or posted what. It maintains no user accounts and no profiles.
What the relay cannot see or do:
The only data the relay holds at any moment is the set of currently-undelivered encrypted blobs and their opaque inbox identifiers. To route a message it transiently processes that identifier and ciphertext in memory, but it persists none of it beyond storing the pending blob until delivery.
Retention: a message blob is removed from the relay once it has been delivered to its recipient; inboxes that are never used expire automatically after a long period of inactivity. Because the relay keeps no logs, nothing about your activity persists on our servers beyond pending, unreadable ciphertext.
Notifications are disabled by default. Out of the box Rún reaches the network only while you have it open, and on the Google Play build the Firebase SDK's automatic start-up is switched off in the app manifest, so it does not contact Google at launch or register your device merely because the app is installed.
If you do turn notifications on:
Turning notifications off revokes the registration, and a vault wipe also asks Google or Apple to invalidate it — that last request needs a working network connection, so on an offline device it is best-effort. It makes no practical difference: a wipe destroys the vault and the inbox a notification would have pointed at, so a surviving registration has nothing left to signal about.
Because this involves Google's or Apple's services, their handling of the registration and the wake-up signal is governed by their own privacy policies, not ours. The F-Droid/direct build has no notification capability at all.
Rún routes its connection to the relay through the Tor network so that the relay (and any network observer) cannot learn your IP address. Tor is operated by the Tor Project and independent volunteers; it is a third-party network and its use is subject to the Tor Project's terms and privacy practices. Rún uses Tor solely for its own connection to our relay — it is not a general-purpose proxy or VPN and does not route any other app's traffic.
Support for the project is entirely optional and there are two ways to give, neither of which is enabled or opened unless you choose it.
Rún does not include crash-reporting or diagnostics SDKs. If you have separately opted in, at the operating-system level, to share diagnostics with developers, Apple or Google may provide us aggregated, anonymised crash information. This is governed by Apple's or Google's privacy policies, is outside Rún's control, and never includes message content.
We do not sell, rent, trade, or share your information with third parties for any purpose. We have no personal data to share. We may disclose information only if required by valid legal process — but because we keep no logs, hold no accounts, receive no IP addresses, and store only unreadable ciphertext addressed to opaque identifiers, there is effectively nothing identifying for us to disclose.
Rún is built around strong, standard cryptography: end-to-end encryption of messages (AES-256-GCM, with keys exchanged in person and the text channel additionally protected by a Double Ratchet so that past messages stay secret even if a later key is compromised), on-device vault encryption, message padding to resist size analysis, and connectivity over Tor.
Opening your vault requires two things together — your PIN or passphrase, and a device key held by the platform keystore (Android Keystore or Apple Keychain). Neither alone can decrypt it. We want to be precise about the limit of that, because it is easy to overstate: the device key is tied to that specific handset and cannot be copied off it, but by default it is not held inside a dedicated secure chip while the app is running, so on a device that is powered on and already unlocked the practical strength of your vault rests on your PIN or passphrase — which is why the higher protection levels require a long passphrase rather than a short PIN. Enabling the optional biometric binding adds a hardware barrier that must be satisfied on the device itself before the vault key can be used at all.
No system is perfectly secure, and you are responsible for safeguarding your device and your PIN or passphrase.
Rún is not directed to children under 13 (or the minimum age required in your country), and we do not knowingly collect information from children. As the App collects no personal data, it does not gather information from any user.
Privacy laws such as the GDPR and CCPA give you rights to access, correct, or delete personal data a service holds about you, and not to have it sold. Because we operate no accounts and do not collect or hold personal data about you, there is generally nothing for us to access, correct, delete, or sell on our side. You already hold and control all of your data on your own device and can erase it instantly. We do not sell personal information.
Rún is available internationally. Strong encryption may be regulated in some jurisdictions; you are responsible for ensuring your use of the App is lawful where you are.
We may update this Privacy Policy from time to time. We will revise the “Last updated” date above and, where appropriate, note changes within the App or on https://vgab.eu/privacy.html.
Questions about this Privacy Policy or Rún's privacy practices: run@vgab.eu