Privacy
What is collected, and why.
Last updated 12 September 2026
Who this covers
So Fly is a private network for a residency program: a member directory, the didactic calendar, and Running The Board, a multi-patient emergency department simulation the program runs as a teaching session. Running The Board and So Fly are the same application and the same database, reached through two addresses. This policy covers both.
Everything here is scoped to one program. A program’s roster, sessions and scores are visible to that program and to the people who administer it. They are not shared with other programs.
What is collected
From your program. An administrator puts you on the roster before you ever sign in: your name, the email your program has for you, your graduation year (which is what training level is calculated from), and your role. Some people are added by name alone and have no email on file.
From Google, when you sign in. Your email address, your name, and your profile picture. Nothing else. Signing in with an address that is not on a roster does not create an account — it leaves a request for an administrator to review.
From you, if you choose. A photo, a short biography, your interests, your current position, and contact details such as a personal email, a phone number or social links. All of it is optional. Each contact field has its own visibility setting — everyone in the program, program leadership only, or nobody but you and the administrators.
From taking part in a session. Which team you were on, which of the case’s actions your team completed and when, and the team’s score. Scores exist to make the debrief land. They are not an assessment, they are not recorded against you as a trainee, and they do not leave the program.
From asking for the teaching points. After a session, a code on the screen opens a page where you can enter an email address, and optionally a name, to have that session’s summary sent to you. Both are stored so the program knows who asked, and so that an administrator can match the address to a person already on the roster by name.
What it is used for
To decide who may sign in and what they may see; to show the member directory to the rest of the program; to run a session and show its board; and to email you the teaching points you asked for. That is the whole list.
Nothing is sold. Nothing is shared with advertisers. There is no tracking across other websites, and no analytics profile is built about you.
The patients are not real
Every case in Running The Board is written for teaching. The names, vital signs, rhythms and results are invented and describe no real person. No patient information is entered into this application, and it is not a medical record.
Where it is kept
The application runs on Vercel. Data is stored in a Supabase Postgres database in the United States, with access rules enforced in the database itself rather than only in the interface. Sign-in is handled by Google. Email is sent through Resend. Each of these providers processes data on the program’s behalf under its own terms.
The only cookie set is the one that keeps you signed in. There are no advertising or tracking cookies.
How long it is kept, and how to have it removed
Roster and profile information is kept while you are part of the program, and afterwards as alumni unless you ask otherwise. You can edit or empty your own profile at any time, and change who can see each contact field.
To see what is held about you, to correct it, or to have it deleted, write to hello@runningtheboard.com or ask your program director. Deleting your account removes your profile and contact details. Where your participation is part of a record the program keeps — that a session took place and who attended — that record may remain.
Changes
If this policy changes in a way that matters, the date below changes with it and the program is told. This page is always the current version.