How DryRun handles your data
DryRun is built for teams running financially and reputationally sensitive support policies. This page explains exactly what data we collect, how it is stored, and what controls you have over it.
Last updated: August 2026 · Contact: peter@dryrunops.com
What data enters DryRun
DryRun processes two types of data you provide:
- Historical support cases — case identifiers, category, resolution, sentiment, amounts, and any fields you include in your CSV export. DryRun does not require customer names, emails, or contact details; we recommend anonymising before upload.
- Policy definitions — the operational rules and confidence thresholds you author inside the product.
DryRun does not connect to your live support system, does not read real-time tickets, and does not ingest data without an explicit upload action from an authenticated user in your workspace.
Workspace isolation
Every DryRun account maps to an isolated workspace. Cases, policies, simulations, and audit events in your workspace are strictly scoped to your organisation — no other tenant can access or query your data.
Workspace identifiers are deterministic and derived from your authenticated user ID. There is no shared pool of cases or policies across organisations.
Data retention
Your data is retained for as long as your account is active. Specific defaults:
- Cases: retained within your workspace while the account is active; pilot datasets are deleted on request or within 60 days after the pilot ends unless an ongoing agreement states otherwise.
- Simulation runs and results: retained while the workspace is active to preserve reproducibility, subject to the agreed retention schedule.
- Policy versions: all versions are retained to preserve audit history.
- Audit log: immutable; entries cannot be deleted. Retained for the life of the account.
If you require a shorter retention window for contractual or regulatory reasons, contact peter@dryrunops.com to arrange it.
Export and deletion
You own your data. At any point you can:
- Export cases — download all normalised cases in your workspace as CSV from the Cases view.
- Request correction or deletion — use workspace settings or contact us. Raw case content and personal fields are removed; minimised evidence records may be retained where necessary for security, legal claims and accountability.
- Close your account — use workspace settings or email peter@dryrunops.com. The deletion response identifies any minimised evidence that must be retained.
Sub-processors and infrastructure
DryRun is hosted on Cloudflare Workers (globally distributed edge infrastructure). Case and policy data is stored in Cloudflare D1 (SQLite). No data is passed to third-party AI model providers as part of a simulation — simulations run on a local, deterministic evaluation engine with no external API calls.
Authentication is managed by DryRun's own session layer. DryRun does not store passwords.
Security practices
- All traffic is encrypted in transit (TLS 1.2+).
- Data at rest is encrypted by Cloudflare D1's default storage encryption.
- Authentication is delegated entirely to OpenAI's identity system — DryRun never sees or stores credentials.
- Every write to cases, policies, and simulation results generates an immutable audit event with timestamp and actor.
- No live support system integration is possible in the current product — there are no integration credentials to compromise.
Pilot data handling
For founding pilot customers, we treat your case data with additional care:
- Your pilot dataset is isolated in a dedicated workspace and not used for any product development, benchmarking, or demonstration purposes without explicit written consent.
- We recommend uploading anonymised or pseudonymised exports. DryRun does not need personally identifiable information to run a simulation.
- All pilot data will be permanently deleted upon request, or within 60 days of pilot completion if no ongoing agreement is reached.
Questions about a specific pilot data arrangement: peter@dryrunops.com
Contact and governing law
DryRun is a product under development operated by Peter Stockmal, Vinkelstien 14, 4600 Køge, Denmark. For data-related requests — access, correction, deletion, portability, or a DPA — email peter@dryrunops.com. A company registration number will be published when the business has been registered.
This policy is governed by Danish law. Disputes will be resolved by the competent Danish courts.