ListRunning Privacy Policy

Last updated: April 22, 2026

ListRunning ("we", "our", or "us") is a task management application designed for medical teams. This Privacy Policy explains how we collect, use, store, and protect your personal data when you use our web application and mobile apps (collectively, the "Service").

We are committed to protecting your privacy and complying with applicable data protection laws, including the EU General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act (CCPA), and HIPAA where applicable.

Contents
1. Data Controller
2. Data We Collect
3. Lawful Basis for Processing
4. How We Use Your Data
5. Data Storage and Security
6. Data Sharing and Third Parties
7. Data Retention
8. Your Rights
9. HIPAA Compliance
10. Cookies and Tracking
11. Children's Privacy
12. International Data Transfers
13. Changes to This Policy
14. Contact Us

1. Data Controller

The data controller responsible for your personal data is:

ListRunning
Email: raheembell2021@gmail.com

2. Data We Collect

We collect and process only the minimum data necessary to provide the Service:

Data CategorySpecific DataPurpose
Account InformationEmail address, display name, profile photo (optional)Authentication and identification
Task DataTask descriptions, categories, lab values, I/O values, timestamps, completion statusCore service functionality
Team DataTeam name, membership, assigned rolesTeam collaboration features
Room DataRoom numbers (numeric only), building identifiersOrganizing tasks by location
Usage DataLogin timestamps, feature usage patternsService improvement and security
Payment DataTransaction ID only (payment details handled by Stripe)Processing purchases
What we do NOT collect: We do not collect patient names, diagnoses, treatment details, medical record numbers, social security numbers, or any Protected Health Information (PHI). Our app actively blocks entry of such data through automated PHI detection.

3. Lawful Basis for Processing (GDPR)

Under the GDPR, we process your personal data based on the following lawful bases:

Processing ActivityLawful Basis
Account creation and authenticationContract - necessary to provide the Service you requested
Storing and syncing task dataContract - core functionality of the Service
Team collaboration featuresContract - enabling shared team workflows
In-app notifications (overdue tasks, lab alerts)Legitimate Interest - ensuring clinical task awareness
Data retention and automatic cleanupLegitimate Interest - maintaining data hygiene and system performance
Service improvement and analyticsLegitimate Interest - improving the user experience
Marketing communicationsConsent - only sent with your explicit opt-in

4. How We Use Your Data

We use the data we collect to: provide and maintain the ListRunning service, allow you to create, manage, and track tasks and clinical values, enable real-time team collaboration, send in-app notifications about overdue tasks and clinical alerts, process payments through our payment provider (Stripe), and improve the app experience.

5. Data Storage and Security

Your data is stored securely using Google Firebase services, including Firebase Authentication and Cloud Firestore. We implement the following security measures:

All data is transmitted over encrypted connections (HTTPS/TLS). Firestore security rules restrict data access to authorized users only. Passwords are never stored in plain text (handled by Firebase Authentication). Profile photos are stored as compressed data URIs within your user document. We do not store data on local devices beyond browser session data.

Data Processing Agreement

We maintain a Data Processing Agreement (DPA) with Google (Firebase/Google Cloud) as our data processor, ensuring they handle your data in compliance with GDPR requirements. Google's DPA is available at cloud.google.com/terms/data-processing-addendum.

6. Data Sharing and Third Parties

We do not sell, trade, or rent your personal information to third parties. We share data only with:

Third PartyPurposeData Shared
Google FirebaseData storage, authenticationAll app data (encrypted)
StripePayment processingEmail, transaction data only
VercelWeb app hostingNo personal data (static hosting only)

We may also disclose data if required by law, court order, or to protect the safety of our users.

7. Data Retention

We follow a structured data retention policy:

Data TypeRetention Period
Active account dataRetained while your account is active
Soft-deleted tasks and roomsAutomatically purged after 30 days
In-app notificationsAutomatically purged after 30 days
Lab and I/O value historyRetained while account is active or until manually deleted
Account data after deletion requestPermanently deleted immediately upon request

8. Your Rights

Under GDPR, CCPA, and other applicable data protection laws, you have the following rights:

Right to Access

You can download a complete copy of all your personal data at any time from the Profile > Data & Privacy > Export My Data section in the app. The export includes your account information, tasks, team memberships, room data, and notifications in JSON format.

Right to Deletion (Right to Be Forgotten)

You can permanently delete your account and all associated data from the Profile > Data & Privacy > Delete My Account section. This action is immediate and irreversible. It removes your user profile, all tasks you created, all notifications, and your membership from all teams.

Right to Rectification

You can update your personal information (name, profile photo) at any time from the Profile page.

Right to Restrict Processing

You may request that we restrict the processing of your data by contacting us at the email below.

Right to Data Portability

The Export My Data feature provides your data in a standard, machine-readable JSON format that you can transfer to another service.

Right to Object

You can object to processing based on legitimate interests by contacting us. We will cease processing unless we have compelling legitimate grounds.

Right to Withdraw Consent

Where processing is based on consent (such as marketing communications), you can withdraw consent at any time without affecting the lawfulness of prior processing.

Right to Lodge a Complaint

If you believe your data protection rights have been violated, you have the right to lodge a complaint with your local data protection authority (supervisory authority).

9. HIPAA Compliance

ListRunning is designed with HIPAA awareness in mind. While the app is a task management tool (not an Electronic Health Record), we take the following precautions:

We actively prevent entry of Protected Health Information (PHI) through automated detection. Room identifiers are numeric only (no patient names). Task descriptions are monitored for potential PHI patterns. Users must acknowledge our HIPAA compliance guidelines before using the app. No patient names, diagnoses, or treatment details are stored in our system.

Important: ListRunning is designed as a task tracking tool, not a medical records system. Users should never enter patient-identifiable information into the app. Our PHI detection is a safeguard, not a guarantee.

10. Cookies and Tracking

ListRunning uses only essential cookies and local storage required for authentication and app functionality. We do not use advertising cookies, third-party tracking pixels, or analytics services that track individual users. Firebase Authentication uses session tokens stored in browser local storage to maintain your login state.

11. Children's Privacy

ListRunning is intended for use by medical professionals and is not directed at children under the age of 16 (or 13 in the US). We do not knowingly collect personal information from anyone under these ages. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.

12. International Data Transfers

Your data is stored on Google Cloud servers which may be located outside your country of residence. When data is transferred outside the European Economic Area (EEA), we ensure appropriate safeguards are in place through Google's Standard Contractual Clauses and their compliance with applicable data protection frameworks.

13. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated through the app or via email. The "Last updated" date at the top indicates the most recent revision. Continued use of the Service after changes constitutes acceptance of the updated policy.

14. Contact Us

For any questions, concerns, or requests related to this Privacy Policy or your personal data, please contact us at:

Email: raheembell2021@gmail.com

We aim to respond to all data-related requests within 30 days, as required by GDPR.


ListRunning v1.0 | listrunning.com