Privacy Policy
Run The Board ("we", "us") provides an operating-room scheduling and staffing board for anesthesia teams, available at runtheboard.net and at each customer organization's own address on runtheboard.net (the "Service"). This policy explains what information we collect, how we use it, and the choices you have.
Information we collect
- Account information. A username, a hashed password, and an email address, which you or your organization's administrator provide. If you turn on two-factor authentication, we also store its secret and your recovery codes. One sign-in can belong to more than one organization.
- Signup and agreement records. When an organization signs up, we collect the signer's name, email address, and hospital, plus the details Stripe needs for billing. When anyone accepts these policies — an organization's signer, or a staff member joining through an invitation or a department signup code — we record which versions were accepted, when, and from what IP address and browser. We keep these records as evidence of the agreement.
- Scheduling data. Information your organization enters into the Service to run its board: staff names, aliases, and roles; shift codes; room assignments; break and relief coverage; staff pager, mobile, and office numbers; free-text roster and relief notes; Note Board posts and their authors; phone directory entries; and reference material such as dosing charts. Staff members can also enter or change their own mobile and pager numbers in their account settings. This data belongs to your organization.
- Edit history. The Service records changes made to the board — which account changed which cell, the old and new values, and when — so recent edits can be reviewed. This history cannot be edited from within the Service, and entries are deleted automatically after about seven days.
- Notification records. When your organization sends a staffing notification, we log who it was addressed to, the number or pager address used, which channels were attempted (push notification, text message, or pager), whether each attempt succeeded, and the values needed to reproduce the message text. This lets recipients see the same notification in the app and lets administrators confirm what was sent.
- Uploaded files. Documents and images your organization uploads to its reference library (for example, departmental protocols), stored as files alongside their filename and type.
- Contact and support requests. If you contact us through the form on our homepage, we receive the email address, subject, and message you provide. If you open a support ticket from within the app, we receive what you write, your username and email address, and the diagnostic details the ticket form shows you before you send it.
- Technical information. Server logs, including IP addresses, usernames, and the organization being accessed, used for security (such as rate limiting and abuse prevention) and to diagnose problems. If you use the mobile app, we store a device identifier, a device label (such as the device's name), the app build, and — if you enable notifications — the device's push notification token. Application errors are reported to our error-tracking provider with technical context to help us diagnose faults. We also collect operational metrics (such as request rates and error counts), labelled by organization but not by individual user.
No patient information — the Service is not HIPAA compliant
Run The Board is a staff scheduling tool. It manages clinician assignments, breaks, and relief coverage — not patient records. The Service is not HIPAA compliant, we are not a Business Associate, and we do not sign Business Associate Agreements. It has not been designed, assessed, or certified against the HIPAA Security Rule.
Do not enter patient names, initials, medical record or account numbers, dates of birth, diagnoses, or any other protected health information ("PHI") into the Service. This applies to every field, including free-text ones — roster comments, break and relief notes, Note Board posts, room and surgeon labels, phone directory entries, dosing-chart notes, and support tickets — and to any file uploaded to the reference library. We do not screen, filter, or scan content for PHI, and anything entered is stored, backed up, and processed by our providers like any other data. Room and surgeon labels must identify the resource or staff member, never the patient. See our Terms of Service for the full restriction.
How we use information
We use the information we collect solely to provide, secure, and improve the Service. That means:
- signing users in;
- displaying your organization's board;
- delivering the staffing notifications your organization chooses to send its staff, by push notification to the mobile app, text message, or pager;
- sending account email, such as password resets, invitations, verification codes, email-change confirmations, and notices when an account's permissions change;
- sending billing and account-status notices to an organization's administrators;
- responding to inquiries and support requests.
We do not sell personal information, and we do not use your data for advertising.
Operator access
Our operators can access an organization's data to operate, secure, and support the Service. This includes viewing a board through a read-only support session and copying a limited portion of an organization's data to our own systems to diagnose a problem. We do not access organization data for any other purpose.
Cookies and local storage
We do not use advertising cookies or third-party analytics. The Service uses your browser's local storage for functional preferences (such as theme and navigation layout) and your session token. It sets one functional cookie, which records that you have seen a notice after an organization's address changes.
In the mobile apps, your session token is also stored in the platform's protected credential store: the device Keychain on iOS, or an encrypted store backed by the Android Keystore on Android. The optional biometric app lock (Face ID or Touch ID on iOS, fingerprint or face unlock on Android) is evaluated entirely on the device by the operating system, so no biometric data ever reaches our servers.
Some pages load content from third parties:
- Our web pages and the web app load fonts from Google Fonts, which receives your IP address and browser information when a page loads.
- The contact and signup forms use Cloudflare Turnstile to prevent spam, which receives your IP address.
- The signup page loads Stripe's payment form, which may set cookies for fraud prevention.
Service providers
We rely on a small number of providers to operate the Service:
- Cloudflare — content delivery, network security, bot protection (Turnstile), and R2 object storage for uploaded reference files and database backups.
- Neon — managed PostgreSQL database hosting (United States).
- Fly.io — application hosting (United States).
- Upstash — managed Redis, used for rate limiting (keyed by IP address and username), short-lived session and presence data (who is viewing a board), and relaying real-time updates between servers.
- Amazon Web Services (SES) — outbound email delivery: account email, billing notices, contact-form notifications, and staffing notifications sent to pager email gateways.
- Twilio — outbound SMS delivery, where your organization enables text notifications to staff mobile numbers.
- Your organization's paging provider — where your organization enables pager notifications, they are emailed to that provider's pager gateway address.
- Apple — push notification delivery (APNs) to the iOS app, where enabled.
- Google (Firebase Cloud Messaging) — push notification delivery to the Android app, where enabled.
- Google Fonts — web font delivery.
- Stripe — subscription billing and payment processing for paying organizations.
- Sentry — application error and crash reporting, used to diagnose faults.
- Axiom — server log storage, used for security and diagnosing faults; logs are kept for 30 days.
- Grafana Cloud — operational metrics.
- Zoho Desk — support ticketing, where you open a support ticket from within the app.
- Proton Mail — our inbound email, including contact-form submissions and messages you send us.
These providers process data only as needed to deliver their services to us. We also keep a standby copy of the database on a server we operate ourselves. It is refreshed nightly from our backups and used only for disaster recovery.
Data retention and deletion
Scheduling data is retained for as long as your organization uses the Service. When an organization's tenancy ends, we notify the organization and delete its data after a notice period. Deletion is a deliberate, confirmed step, not something that happens automatically on the day access ends. Some records are not part of that deletion:
- Signup and agreement records are kept as evidence of the agreement.
- Edit history ages out on its own seven-day schedule.
- Billing records held by Stripe, and data held by our other providers, follow those providers' own retention. Server logs, for example, are kept for 30 days.
Backups. We take nightly backups of the database to protect against data loss. They are stored in Cloudflare R2, which encrypts them at rest. Backups are deleted on a rolling basis after about 30 days, though the seven most recent are always kept, so data removed from the Service can persist in backups for about 30 days, or longer if backups have not been running. Backups and the standby copy are used only for disaster recovery.
Delete your account
Run The Board is provided to your organization (a hospital or clinical group). Your account is a membership in that organization, created by its administrator or by you through an invitation or your department's signup code. There is no in-app "delete my account" button.
To request deletion of your account or personal information:
- Ask your organization's administrator to remove your membership. This deletes your account in that organization and signs out your devices. Your name and contact numbers on the organization's staff roster are organization data; ask the administrator to remove those too.
- Your sign-in itself — username, email address, password, and two-factor settings — is not deleted when a membership is removed, because it can belong to more than one organization. To have it deleted, contact us through the contact form on our homepage or by emailing [email protected]. We will process the request or route it to your organization's administrator as needed.
Scheduling data you contributed as part of your organization's board (for example, shift assignments) is organization data and is deleted when your organization's tenancy ends, per the retention terms above. Notification records and Note Board posts that name you are also organization data. As with all deletions, removed data may persist in backups for about 30 days before aging out.
Security
All traffic is encrypted in transit with TLS. Passwords are stored using salted, one-way hashing (scrypt), and you can turn on two-factor authentication with an authenticator app. Access to boards is controlled by per-organization accounts and role-based permissions. See our security.txt for how to report a vulnerability.
Your rights
You may request access to, correction of, or deletion of your personal information by contacting us. If your account was created by your organization, some requests may need to be handled through your organization's administrator.
Changes to this policy
If we make material changes to this policy, we will update the effective date above and post the revised version on this page.
Contact
Questions about this policy? Reach us through the contact form on our homepage, or email [email protected] for security-related matters.