Last updated: April 22, 2026
ListRunning ("we", "our", or "us") is a task management application designed for medical teams. This Privacy Policy explains how we collect, use, store, and protect your personal data when you use our web application and mobile apps (collectively, the "Service").
We are committed to protecting your privacy and complying with applicable data protection laws, including the EU General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act (CCPA), and HIPAA where applicable.
The data controller responsible for your personal data is:
ListRunning
Email: raheembell2021@gmail.com
We collect and process only the minimum data necessary to provide the Service:
| Data Category | Specific Data | Purpose |
|---|---|---|
| Account Information | Email address, display name, profile photo (optional) | Authentication and identification |
| Task Data | Task descriptions, categories, lab values, I/O values, timestamps, completion status | Core service functionality |
| Team Data | Team name, membership, assigned roles | Team collaboration features |
| Room Data | Room numbers (numeric only), building identifiers | Organizing tasks by location |
| Usage Data | Login timestamps, feature usage patterns | Service improvement and security |
| Payment Data | Transaction ID only (payment details handled by Stripe) | Processing purchases |
Under the GDPR, we process your personal data based on the following lawful bases:
| Processing Activity | Lawful Basis |
|---|---|
| Account creation and authentication | Contract - necessary to provide the Service you requested |
| Storing and syncing task data | Contract - core functionality of the Service |
| Team collaboration features | Contract - enabling shared team workflows |
| In-app notifications (overdue tasks, lab alerts) | Legitimate Interest - ensuring clinical task awareness |
| Data retention and automatic cleanup | Legitimate Interest - maintaining data hygiene and system performance |
| Service improvement and analytics | Legitimate Interest - improving the user experience |
| Marketing communications | Consent - only sent with your explicit opt-in |
We use the data we collect to: provide and maintain the ListRunning service, allow you to create, manage, and track tasks and clinical values, enable real-time team collaboration, send in-app notifications about overdue tasks and clinical alerts, process payments through our payment provider (Stripe), and improve the app experience.
Your data is stored securely using Google Firebase services, including Firebase Authentication and Cloud Firestore. We implement the following security measures:
All data is transmitted over encrypted connections (HTTPS/TLS). Firestore security rules restrict data access to authorized users only. Passwords are never stored in plain text (handled by Firebase Authentication). Profile photos are stored as compressed data URIs within your user document. We do not store data on local devices beyond browser session data.
We maintain a Data Processing Agreement (DPA) with Google (Firebase/Google Cloud) as our data processor, ensuring they handle your data in compliance with GDPR requirements. Google's DPA is available at cloud.google.com/terms/data-processing-addendum.
We do not sell, trade, or rent your personal information to third parties. We share data only with:
| Third Party | Purpose | Data Shared |
|---|---|---|
| Google Firebase | Data storage, authentication | All app data (encrypted) |
| Stripe | Payment processing | Email, transaction data only |
| Vercel | Web app hosting | No personal data (static hosting only) |
We may also disclose data if required by law, court order, or to protect the safety of our users.
We follow a structured data retention policy:
| Data Type | Retention Period |
|---|---|
| Active account data | Retained while your account is active |
| Soft-deleted tasks and rooms | Automatically purged after 30 days |
| In-app notifications | Automatically purged after 30 days |
| Lab and I/O value history | Retained while account is active or until manually deleted |
| Account data after deletion request | Permanently deleted immediately upon request |
Under GDPR, CCPA, and other applicable data protection laws, you have the following rights:
You can download a complete copy of all your personal data at any time from the Profile > Data & Privacy > Export My Data section in the app. The export includes your account information, tasks, team memberships, room data, and notifications in JSON format.
You can permanently delete your account and all associated data from the Profile > Data & Privacy > Delete My Account section. This action is immediate and irreversible. It removes your user profile, all tasks you created, all notifications, and your membership from all teams.
You can update your personal information (name, profile photo) at any time from the Profile page.
You may request that we restrict the processing of your data by contacting us at the email below.
The Export My Data feature provides your data in a standard, machine-readable JSON format that you can transfer to another service.
You can object to processing based on legitimate interests by contacting us. We will cease processing unless we have compelling legitimate grounds.
Where processing is based on consent (such as marketing communications), you can withdraw consent at any time without affecting the lawfulness of prior processing.
If you believe your data protection rights have been violated, you have the right to lodge a complaint with your local data protection authority (supervisory authority).
ListRunning is designed with HIPAA awareness in mind. While the app is a task management tool (not an Electronic Health Record), we take the following precautions:
We actively prevent entry of Protected Health Information (PHI) through automated detection. Room identifiers are numeric only (no patient names). Task descriptions are monitored for potential PHI patterns. Users must acknowledge our HIPAA compliance guidelines before using the app. No patient names, diagnoses, or treatment details are stored in our system.
ListRunning uses only essential cookies and local storage required for authentication and app functionality. We do not use advertising cookies, third-party tracking pixels, or analytics services that track individual users. Firebase Authentication uses session tokens stored in browser local storage to maintain your login state.
ListRunning is intended for use by medical professionals and is not directed at children under the age of 16 (or 13 in the US). We do not knowingly collect personal information from anyone under these ages. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
Your data is stored on Google Cloud servers which may be located outside your country of residence. When data is transferred outside the European Economic Area (EEA), we ensure appropriate safeguards are in place through Google's Standard Contractual Clauses and their compliance with applicable data protection frameworks.
We may update this Privacy Policy from time to time. Material changes will be communicated through the app or via email. The "Last updated" date at the top indicates the most recent revision. Continued use of the Service after changes constitutes acceptance of the updated policy.
For any questions, concerns, or requests related to this Privacy Policy or your personal data, please contact us at:
Email: raheembell2021@gmail.com
We aim to respond to all data-related requests within 30 days, as required by GDPR.
ListRunning v1.0 | listrunning.com