Runway · Privacy
Runway privacy policy
Runway does arithmetic on figures you type in. This page states exactly what it stores, where that is, who else ever handles any of it, and how to get it back or delete it.
Who is responsible
Runway is made by Otherpath Ltd, which is the data controller for the personal data described here under UK data protection law. We are registered in England and Wales, company number 17347090, with our registered office at 3 Maple Road, Gravesend, England, DA12 5JR.
For anything about your data — a question, a correction, a copy, a deletion — write to jordan@otherpath.co.uk. That address reaches a person, not a queue. Ask there for a postal address if you need one for a formal request.
Two ways to use Runway
Which of these you choose decides everything else on this page, so it comes first.
On this device only. No account, no sign-in. Your plan is held in the app’s storage on the device you are using — the browser’s own database on the web, the app’s private storage on iPhone. Nothing is sent anywhere. We do not know you exist, and there is nothing for us to hand over, lose or delete on your behalf. The trade is real: clearing your browser data, deleting the app or losing the device loses the plan. Take an export if it matters.
Signed in with Google. Choose this and your plan is stored in your account so it appears on any device you sign in on. That is the only reason the account exists. Everything from What is stored onwards describes this mode.
What is stored when you sign in
-
Your email address
Given to us by Google when you sign in, and stored on your profile record. We never see your Google password, and we do not ask Google for anything else about you.
-
An account identifier
The identifier Firebase issues for your account. It is the storage location of your data and the thing the security rules check. Nothing about you can be worked out from it.
-
A display name, only if you type one
Optional, and used in greetings and reminders. It is not taken from your Google profile — the field starts empty.
-
The figures you enter
Cash balances, debt balances and their APRs, income and expense amounts, your target and deadline, scenario adjustments, and the balances you state at each check-in. This is the substance of the app.
-
The words you type
The goal name, account and debt names, item names and categories, scenario names and descriptions, and any note you write on a check-in.
-
Your settings and reminder preferences
Currency, time zone, payday, the thresholds that grade the forecast, and which reminders you have switched on.
-
A push registration, only if you turn push on
On the web, enabling notifications stores the subscription your browser issues so a reminder can be delivered to it. On iPhone, reminders are scheduled on the device and no registration is stored at all.
That is the complete list. There is no bank connection, no card or payment details, no address, no date of birth, no phone number, no contacts, no location, no photos and no advertising identifier. Runway is free, so there is nothing to bill you for.
Where it is kept, and who can read it
Your data is stored in Google Cloud Firestore, in the Firebase project financial-planner-66ff9, beneath a path belonging to your account. It travels there over an encrypted connection and Google encrypts it at rest.
Access is enforced on Google’s servers by security rules, not by anything in the app. A request that is not signed in as you is refused before it reads a byte, whatever the app asks for. Everything you own lives under that one path, which is what lets the rule be a single check.
Administrative access exists. Otherpath Ltd holds a service credential that can read the database, because the nightly reminder job needs it and because somebody has to be able to fix a fault. It is used for operating the service, not for reading your figures. Nobody else has access, and we have never sold, rented or shared any of it.
What Runway never does
- No bank connection. Nothing logs into your bank. There is no transaction feed, no open banking connection, and no third party is ever given a credential of yours. You type your balances at check-in.
- No analytics. There is no analytics SDK, no crash reporter and no session recording in the app. We do not know which screens you open or how often you use it.
- No advertising and no tracking. No advertising SDK, no advertising identifier, no tracking pixel, and no tracking of you across other apps or websites. Nothing is sold or shared with data brokers.
- No profiling. Nothing decides anything about you automatically. The app states what your own figures imply, and stops.
- No financial figure is ever written to a log. Not a balance, not an account name, not a check-in note, not an email address. The nightly reminder job logs an account identifier, an event type and a delivery channel, which is what is needed to tell whether it worked.
The optional AI explanation
Every figure in Runway is computed by the app itself from your inputs. AI never calculates anything and never changes anything you have stored — at most it rewrites an explanation the app has already produced.
The feature is off unless the deployment has been given an AI key, and even then nothing is sent until you press the button that asks for an explanation. If the key is absent, a request fails, or you never ask, nothing about you reaches an AI provider at all: you get the app’s own written explanation instead.
What is sent, when you ask for one: a computed summary, and only that — your status and the reason for it, days and months remaining, your target, your current cash, the balance projected on each of the three paths, the shortfall or buffer, the required monthly figure, how many complete months of check-ins exist, your spending totals by category, your goal name and your scenario names.
Not sent: your email address, your account identifier, your name, account and debt names, individual items and amounts, and any note you have written. The request carries no identifier at all, so the summary does not arrive attached to a person.
The provider is Anthropic PBC, through the Claude API, acting as our processor for that request. Under Anthropic’s commercial API terms, content sent to the API is not used to train its models. The reply is held in memory on our server for up to twelve hours so an identical question does not go out twice, and is never written to disk.
Your CV, your skills and your free time
If you ask Runway to help you find a way to close a gap, it can work from what you are able to do and when you are free. All of it is optional, all of it is entered or confirmed by you, and the shortlist of ways to earn works without any of it.
What is stored
Skill tags, sector tags, a seniority band, a years-of-experience band and a list of credentials — all chosen from a fixed list built into the app. Plus the hours a week you say you can give, which parts of the week they fall in, and any standing constraints you set.
Not stored: any employer you have worked for, any school or university you attended, any job title you have held, and any date — no start dates, no end dates, no graduation years. There is no field for them. A CV cannot be reconstructed from what is kept.
If you upload a CV or a LinkedIn export, the file is not stored. It is read once, on our server, turned into the tags above, and discarded. It is never written to a database, never cached and never logged. You are then shown what was read and asked to correct it before anything is saved — nothing is used to suggest anything to you until you have confirmed it is right.
Reading the document is done by Anthropic PBC through the Claude API, acting as our processor for that one request, under the same commercial terms described above: content sent to the API is not used to train its models. The structured answer it can return is limited to the fixed lists of tags, so it has no way to send back an employer or a date even if the document contained one.
If you connect a calendar
Calendar access is read-only and is asked for only when you choose it. Your events are read on your device and turned into free periods there. No event ever leaves your device — not its title, not its time, not its location, and attendees are not read at all.
What is kept is the shape of your week: “Tuesday evening”. When the coach is asked for suggestions, that is the level of detail it receives — a part of a day, never a time and never a date.
You can view, edit and clear all of this at any time in Settings, and “delete my data” removes it with everything else.
Reminders and email
Reminders are off until you turn them on, and you choose which kinds you get. A reminder can quote figures from your own plan, because a reminder that cannot say what changed is not worth sending.
- On iPhone, reminders are scheduled by iOS on the device. They do not travel through us or through Apple’s push servers.
- On the web, a reminder is delivered to the browser subscription you registered, through the push service your browser provider operates.
- The email fallback, if you switch it on and the deployment has email configured, sends the same short text to your email address through Resend, our delivery processor. That text can name a figure from your plan. Leave the fallback off and no email is ever sent.
Server logs and abuse prevention
When the app talks to our server — asking for an AI explanation, registering a browser for push — our hosting provider records the request, including the IP address it came from, in the way every web server does. Those records are short-lived operational logs and are not joined to your plan.
To stop one machine looping on the AI endpoint, a value derived from the IP address is held in memory for up to twenty-four hours. It is never written to disk, never linked to your account, and it disappears whenever the server restarts.
Who else handles your data
-
Google — Firebase Authentication and Cloud Firestore
Signs you in and stores your plan. Only when you sign in.
-
Vercel
Hosts the web app and its server routes, and therefore handles requests to them.
-
Anthropic PBC
Writes the optional AI explanation, reads an uploaded CV into skill tags, and suggests ways to earn. Only when the feature is configured and you ask, and only from the computed summary and the tag list described above. Uploaded documents are not stored by us or used to train its models.
-
Resend
Delivers reminder emails. Only when the email fallback is configured and you have switched it on.
Each is bound by its own data processing terms and acts on our instructions. All four are US companies, so some processing happens outside the UK; those transfers rely on the standard contractual protections each provider offers for UK and EU data. There is nobody else. Apple distributes the iPhone app and never receives your plan.
How long it is kept
Until you delete it. Nothing expires on a timer, because a savings plan with a deadline eighteen months out and a check-in history behind it is the product — quietly discarding part of it would break the forecast.
Two exceptions, both housekeeping: a browser push registration is removed when the push service reports it dead, and the record of which reminders have already been sent is pruned once it is old enough that it can no longer cause a duplicate.
Getting your data out, and deleting it
-
Export it
Settings → Backup and portability → Export gives you your entire plan as a JSON file: every account, debt, item, scenario and check-in. It is yours to keep, and you can import it into a fresh install.
-
Delete everything
In the same place. Removes your plan, check-ins and scenarios from your account, on every device, and puts you back at the start. You have to type DELETE to confirm, because it cannot be undone.
-
Delete your account
Also in Settings. Deletes the plan, then the profile record that holds your email address and display name, then the sign-in account itself. Nothing of yours is left behind. It is immediate and permanent, so take an export first if you want a copy.
-
On this device only
Nothing ever reached us, so there is nothing to ask us for. Clear the data from Settings, or delete the app.
After a deletion, a copy can persist for a short period in our storage provider’s routine infrastructure backups before it ages out. It is not accessible through the app and we do not restore from it to bring anything back.
Your rights under UK GDPR
You have the right to ask for a copy of your data, to have it corrected, to have it erased, to receive it in a portable format, to restrict or object to how it is used, and to withdraw consent for anything you consented to. Two of those you can exercise yourself, right now, without asking anyone: export is the portability right, and delete your account is the erasure right.
The legal bases are short. Storing your plan and running the app is performance of our agreement with you. Reminders and the AI explanation rest on your consent, given by switching one on or pressing the button, and withdrawn just as easily. Keeping the service up and unabused — the rate limit above — is our legitimate interest.
To exercise any of these, write to jordan@otherpath.co.uk. We answer within one month, and usually within a few days. If you are unhappy with the answer, you can complain to the Information Commissioner’s Office at ico.org.uk — though we would rather you told us first, so we can fix it.
Children
Runway is for adults planning their own money. It is not directed at children, we do not knowingly store data about anyone under 13, and if we learn we have, we delete it.
Changes to this policy
If what the app does changes, this page changes with it and the date at the top moves. A material change will be described here in plain terms rather than buried in a diff. The version you agreed to is the one you can read.
Related: terms of use and support. The privacy notice for this website, which is a separate thing, is at otherpath.co.uk/privacy.