Version 2026-08-26
Runway records how much medication you have and works out when you need to reorder. Doing that means holding information about your health, which is treated as a special category of personal data under UK GDPR. This page says exactly what is held, what can be read, and by whom.
Runway is operated by Kieran Holroyd, the data controller for the purposes of UK GDPR. You can reach us at [email protected].
This is the part that matters most, so it is set out plainly rather than summarised. Some of what you enter is encrypted on your own device with a key Runway's servers never receive.
Encrypted — unreadable by Runway:
These are encrypted in your browser before they are sent. The key is derived from your passkey, or from your recovery code, and never leaves your device. Nobody with access to the database — including us, including anyone who compels or steals a copy — can read them.
Not encrypted — readable by Runway:
These stay readable because the reorder calculation runs on the server, including while your browser is closed. That is what allows a reminder to reach you at all. The consequence is that Runway can see that you take something twice a day and when you will run out, but not what it is.
Encryption is often described in a way that promises more than it delivers, so here is the boundary.
It protects against: a stolen or copied database, a stolen backup, a compromised database server, an employee or contractor reading rows, and a legal demand served on us or on our hosting provider. In every one of those cases the medication names are ciphertext and we cannot produce the key.
It does not protect against: a compromise of the Runway web server itself while you are using it. The page that decrypts your data is served by us, so a server serving modified code could capture what your browser decrypts. No browser-based encryption can avoid this. It also does not protect anything if malware is running on your own device.
Because you explicitly consented, under Article 9(2)(a) of UK GDPR. That consent is recorded with the date and the version of this policy you agreed to. You can withdraw it at any time by deleting your account, which erases the data — see below.
Runway does not sell your data, does not share it for marketing, does not profile you, and runs no advertising or third-party analytics.
Runway uses these processors, and no others:
One, called runway_session. It holds a random token that identifies your signed-in
session and nothing else. There are no analytics, advertising or tracking cookies, which is why
Runway does not show you a cookie banner.
Everything is served over HTTPS. Sign-in uses passkeys or a one-time code — Runway has no passwords to lose. Session tokens and IP addresses are stored only as hashes. If a breach ever occurs that is likely to put you at risk, we will tell the ICO within 72 hours and tell you without undue delay.
If this policy changes in a way that affects what is done with your data, you will be asked to agree again before continuing to use Runway.