Runway

Privacy Policy

Version 2026-08-26

Runway records how much medication you have and works out when you need to reorder. Doing that means holding information about your health, which is treated as a special category of personal data under UK GDPR. This page says exactly what is held, what can be read, and by whom.

Who is responsible

Runway is operated by Kieran Holroyd, the data controller for the purposes of UK GDPR. You can reach us at [email protected].

What Runway stores, and what it can read

This is the part that matters most, so it is set out plainly rather than summarised. Some of what you enter is encrypted on your own device with a key Runway's servers never receive.

Encrypted — unreadable by Runway:

  • The name of each medication
  • Its strength
  • Any notes you add

These are encrypted in your browser before they are sent. The key is derived from your passkey, or from your recovery code, and never leaves your device. Nobody with access to the database — including us, including anyone who compels or steals a copy — can read them.

Not encrypted — readable by Runway:

  • Your email address
  • How many units you take per day, how many arrive per order, and when you last ordered
  • Any hand counts you record, and the dates of them
  • How many days' notice you want, and whether each item is paused
  • The form — tablet, capsule, liquid and so on
  • Your time zone, display name, colour, and notification preferences
  • When your account was created and last used

These stay readable because the reorder calculation runs on the server, including while your browser is closed. That is what allows a reminder to reach you at all. The consequence is that Runway can see that you take something twice a day and when you will run out, but not what it is.

What this protects you against, and what it does not

Encryption is often described in a way that promises more than it delivers, so here is the boundary.

It protects against: a stolen or copied database, a stolen backup, a compromised database server, an employee or contractor reading rows, and a legal demand served on us or on our hosting provider. In every one of those cases the medication names are ciphertext and we cannot produce the key.

It does not protect against: a compromise of the Runway web server itself while you are using it. The page that decrypts your data is served by us, so a server serving modified code could capture what your browser decrypts. No browser-based encryption can avoid this. It also does not protect anything if malware is running on your own device.

Why Runway is allowed to hold this

Because you explicitly consented, under Article 9(2)(a) of UK GDPR. That consent is recorded with the date and the version of this policy you agreed to. You can withdraw it at any time by deleting your account, which erases the data — see below.

Runway does not sell your data, does not share it for marketing, does not profile you, and runs no advertising or third-party analytics.

Who else touches it

Runway uses these processors, and no others:

  • Railway — hosting and the database. Holds everything above, with the medication names encrypted.
  • Amazon Web Services (SES) — sends your sign-in codes and reorder reminders. Receives your email address and the message. No message Runway sends ever contains the name of a medication.
  • Google, Apple or Mozilla — whichever operates the push service for your browser, if you turn on notifications. They relay the notification, which is encrypted end to end and contains only a count. They can see that your browser receives messages from Runway.

How long it is kept

  • Your medication data: until you delete it, or until your account is deleted.
  • Inactive accounts: deleted after 24 months without a sign-in. We email you twice before that happens.
  • Sign-in codes: ten minutes, then deleted within a day.
  • Sessions: 30 days, or until you sign out.
  • Backups: up to 30 days after deletion, after which the data is gone from those too.

What you can do

  • See it or take it elsewhere. Settings has an export that produces a JSON file. It is assembled in your browser, with the names decrypted, because the server cannot produce a complete copy.
  • Correct it. Everything is editable in the app.
  • Erase it. Deleting your account removes every row, immediately and irreversibly. There is no soft delete and no recovery period.
  • Complain. If you think Runway has mishandled your data you can complain to the Information Commissioner's Office at ico.org.uk.

Cookies

One, called runway_session. It holds a random token that identifies your signed-in session and nothing else. There are no analytics, advertising or tracking cookies, which is why Runway does not show you a cookie banner.

Security

Everything is served over HTTPS. Sign-in uses passkeys or a one-time code — Runway has no passwords to lose. Session tokens and IP addresses are stored only as hashes. If a breach ever occurs that is likely to put you at risk, we will tell the ICO within 72 hours and tell you without undue delay.

Changes

If this policy changes in a way that affects what is done with your data, you will be asked to agree again before continuing to use Runway.