01 / Boundary

Nothing leaves the machine.

Not a policy but an architecture. Anything touching a secret runs locally; live introspection talks only to the credential's own issuer.

Stays local

Credentials, prompts, tool arguments, file contents, customer records. The CLI holds a token in memory for one call and never writes it down.

Would ever leave

Nothing today. When a hosted dashboard exists it receives derived metadata only: what tool, what authority, whether it was reversible, with payloads hashed in place.

Read-only Scans introspect scopes. They never exercise a permission, and never request a write-scoped credential to run.
Auditable Pure Python standard library. No dependency tree to review before you point it at your own keys.
02 / This website

And what ranwhat.com collects.

The section above is about the tool. This one is about the site you are reading, which is a separate question with a shorter answer.

Who Cenner, obrt za računalno programiranje… Reachable at [email protected], which is also how you exercise anything below.
Full registered details

Cenner, obrt za računalno programiranje i ostale usluge, vl. Matija Mikulinec

Mikulinci 8, Zagreb, Croatia

OIB 23152585818 · MB 99210363

Cookies None. No analytics, no tracking pixels, no consent banner, because there is nothing to consent to.
Forms The contact page has no backend. It opens a message in your own mail app, so nothing is submitted to this site and nothing is stored here.
Server logs Cloudflare sits in front of the site and GitHub Pages serves it. Both log request metadata, including your IP address, to deliver pages and absorb abuse. That is our legitimate interest in running a website, and neither log is used to profile anyone.
Third parties None in the page itself. Typefaces are served from this domain rather than Google Fonts, so rendering a page sends your IP address to nobody but the host above.
Email If you write to us we keep the message and your address for as long as the conversation is useful, and delete it when it is not. We do not add you to any list.

Your rights

Under the GDPR you can ask what we hold about you, correct it, have it deleted, or object to it being processed at all. Write to the address above. If we handle that badly you can complain to AZOP, the Croatian data protection authority.

Changes

When this notice changes the commit history shows exactly what changed and when, which is more than most privacy pages can offer. It lives in the same public repository as the site.

The install is not tracked

Installing or running ranwhat sends us nothing. There is no licence check, no version ping, no crash reporter. We do not know how many people use it, which is occasionally inconvenient and entirely the point.