runtheboard
← Back to home

Privacy Policy

Effective date: October 7, 2026

Run The Board ("we", "us") provides an operating-room scheduling and staffing board for anesthesia teams, available at runtheboard.net and at each customer organization's own address on runtheboard.net (the "Service"). This policy explains what information we collect, how we use it, and the choices you have.

Information we collect

No patient information — the Service is not HIPAA compliant

Run The Board is a staff scheduling tool. It manages clinician assignments, breaks, and relief coverage — not patient records. The Service is not HIPAA compliant, we are not a Business Associate, and we do not sign Business Associate Agreements. It has not been designed, assessed, or certified against the HIPAA Security Rule.

Do not enter patient names, initials, medical record or account numbers, dates of birth, diagnoses, or any other protected health information ("PHI") into the Service. This applies to every field, including free-text ones — roster comments, break and relief notes, Note Board posts, room and surgeon labels, phone directory entries, dosing-chart notes, and support tickets — and to any file uploaded to the reference library. We do not screen, filter, or scan content for PHI, and anything entered is stored, backed up, and processed by our providers like any other data. Room and surgeon labels must identify the resource or staff member, never the patient. See our Terms of Service for the full restriction.

How we use information

We use the information we collect solely to provide, secure, and improve the Service. That means:

We do not sell personal information, and we do not use your data for advertising.

Operator access

Our operators can access an organization's data to operate, secure, and support the Service. This includes viewing a board through a read-only support session and copying a limited portion of an organization's data to our own systems to diagnose a problem. We do not access organization data for any other purpose.

Cookies and local storage

We do not use advertising cookies or third-party analytics. The Service uses your browser's local storage for functional preferences (such as theme and navigation layout) and your session token. It sets one functional cookie, which records that you have seen a notice after an organization's address changes.

In the mobile apps, your session token is also stored in the platform's protected credential store: the device Keychain on iOS, or an encrypted store backed by the Android Keystore on Android. The optional biometric app lock (Face ID or Touch ID on iOS, fingerprint or face unlock on Android) is evaluated entirely on the device by the operating system, so no biometric data ever reaches our servers.

Some pages load content from third parties:

Service providers

We rely on a small number of providers to operate the Service:

These providers process data only as needed to deliver their services to us. We also keep a standby copy of the database on a server we operate ourselves. It is refreshed nightly from our backups and used only for disaster recovery.

Data retention and deletion

Scheduling data is retained for as long as your organization uses the Service. When an organization's tenancy ends, we notify the organization and delete its data after a notice period. Deletion is a deliberate, confirmed step, not something that happens automatically on the day access ends. Some records are not part of that deletion:

Backups. We take nightly backups of the database to protect against data loss. They are stored in Cloudflare R2, which encrypts them at rest. Backups are deleted on a rolling basis after about 30 days, though the seven most recent are always kept, so data removed from the Service can persist in backups for about 30 days, or longer if backups have not been running. Backups and the standby copy are used only for disaster recovery.

Delete your account

Run The Board is provided to your organization (a hospital or clinical group). Your account is a membership in that organization, created by its administrator or by you through an invitation or your department's signup code. There is no in-app "delete my account" button.

To request deletion of your account or personal information:

Scheduling data you contributed as part of your organization's board (for example, shift assignments) is organization data and is deleted when your organization's tenancy ends, per the retention terms above. Notification records and Note Board posts that name you are also organization data. As with all deletions, removed data may persist in backups for about 30 days before aging out.

Security

All traffic is encrypted in transit with TLS. Passwords are stored using salted, one-way hashing (scrypt), and you can turn on two-factor authentication with an authenticator app. Access to boards is controlled by per-organization accounts and role-based permissions. See our security.txt for how to report a vulnerability.

Your rights

You may request access to, correction of, or deletion of your personal information by contacting us. If your account was created by your organization, some requests may need to be handled through your organization's administrator.

Changes to this policy

If we make material changes to this policy, we will update the effective date above and post the revised version on this page.

Contact

Questions about this policy? Reach us through the contact form on our homepage, or email [email protected] for security-related matters.