Privacy Policy

Last updated: 5 September 2026 · Applies to ShiftHawk 2.3.1

The short version. ShiftHawk keeps your schedule on your phone. Nothing about your shifts, your colleagues or your calendar leaves your device unless you switch on a feature that needs it — and each of those is listed below, with what it sends and where it goes. We do not sell your data, we do not show ads, and we do not track you across other apps or websites.

1. At a glance

WhatWhere it lives
Your schedule, your colleagues, your settingsYour device only, by default
Your calendar subscription linkYour device's Keychain / Keystore — copied to our servers only for the sharing features you switch on
Your account (if you create one)Our servers (Supabase, United States)
Sharing features (Team, Handshake, Company, Backup)Our servers, only while switched on
Schedule Scan photosSent to an OCR provider you choose, then discarded
Usage analyticsOff until you say yes — then linked to your ShiftHawk account, not anonymous, and used only to fix and improve the app
Crash reportsScrubbed diagnostics, keyed to a random install identifier
Payment card detailsApple or Google only — we never see them

ShiftHawk is bought and controlled by the person working the shifts. It is not an employer monitoring tool, and no employer can see your data through it.

2. What stays on your device

Unless you turn on one of the features in Section 5, everything below stays on your phone and is never transmitted to us:

  • Your calendar link — the .ics address your shifts come from. It usually contains a private access token, so it is held in the iOS Keychain or Android Keystore.
  • Your shifts — fetched from that link by your phone, directly from your scheduling provider. This also happens periodically in the background so your rota stays current.
  • Files you import — a spreadsheet (XLSX) is read entirely on your device. A PDF or photo only leaves your phone if you use Schedule Scan (Section 5.2).
  • Colleagues you add — their names, abbreviations, and any phone number or email you enter. Phone numbers are held in the Keychain / Keystore.
  • Your search history — the last 40 swap searches, including the colleague names involved.
  • Settings and profiles — rest rules, marked vacations, and any additional profiles you create.

A note on additional profiles. ShiftHawk lets you keep more than one profile — for example, to hold a colleague's schedule alongside your own. Those profiles stay on your device and are kept separate from each other. Only your primary profile is used for the cloud and sharing features.

One honest caveat. Your calendar link is written to secure storage. If the operating system refuses that write, ShiftHawk falls back to ordinary app storage so the app keeps working, and moves it back to secure storage at the next opportunity.

3. Permissions ShiftHawk asks for

PermissionWhy
Calendar (read & write)To show your connected calendars alongside your shifts, to import your personal calendar so ShiftHawk can avoid double-booking you, and — when you confirm a swap — to write that swap into your calendar. Personal event titles read this way are stored on your device only.
CameraOnly to scan a colleague's Handshake QR code, and to photograph a printed schedule. Camera images are never recorded or streamed.
PhotosTo let you pick a photo of your schedule to import.
NotificationsTo send shift reminders and, if you sign in, alerts about swap offers.
ClipboardWhen you are pasting a calendar link, ShiftHawk checks your clipboard so it can offer to paste it for you. It is read at that moment only, and nothing from your clipboard is transmitted or stored.
Reminders (iOS)Not used. iOS requires the permission alongside calendar access.

ShiftHawk does not ask for your location or your contacts.

4. Your ShiftHawk account

You can use ShiftHawk without giving us anything identifying. To hold your token balance and enable the sharing features, the app creates an anonymous account on our servers, identified by a random value rather than by you.

If you choose to sign in — with an email address, or with Sign in with Apple or Google — we then store, on our servers: your email address, and any name, phone number, industry and role you supply. Signing in is what lets you restore purchases and move to a new phone. Sign in with Apple supports Apple's private relay addresses; if you use one, we only ever see the relay address.

If you enable notifications, a push token for your device is stored on your account so we can deliver alerts.

5. Features that send data off your device

Each of these is off until you turn it on. If you never use one, nothing in its section applies to you.

5.1 Connecting a schedule

Your phone fetches your rota directly from your scheduling provider using the link you supply, including periodically in the background. We are not affiliated with any provider; ShiftHawk simply reads the export you already have access to. Resolving the provider's web address uses Cloudflare's public DNS resolver, which therefore sees the provider's hostname — never your personal link.

If you connect Google Calendar, ShiftHawk talks to Google directly from your phone to read your events and to write confirmed swaps back. Google receives your account email and name as part of signing in.

5.2 Schedule Scan (OCR)

If you import a PDF or a photo, that file is sent to a text-recognition provider you choose, the text is extracted, and the result comes back to your phone:

  • Basic reader — Amazon Textract (United States). PDFs are placed in a temporary storage bucket for processing and deleted within one day; images are passed straight through.
  • AI reader — Mistral AI, whose processing takes place in the European Union.

Neither provider retains your file beyond processing, and ShiftHawk keeps no copy of the original. Only the extracted shifts are stored, on your device. A schedule photo may contain your colleagues' names — please only scan schedules you are permitted to.

5.3 Cloud Schedule Backup

If you turn on backup, a copy of your schedule data — your providers, your cached shifts and their labels, and the calendar links those shifts come from — is stored on our servers so you can restore it on a new device. This is the broadest thing ShiftHawk uploads. Backups are kept for two years and are readable only by ShiftHawk's servers, never by other users. You can remove a backup from inside the app at any time.

5.4 Team Schedule Sharing

Team sharing lets colleagues you invite see when you are free. While it is on, we store your calendar link in an access-controlled record your teammates cannot read, plus the dates you have blocked (as plain dates — no shift details) and a short display label you choose. When a teammate refreshes, a relay fetches your calendar and passes it through to them using an opaque token; the relay does not keep the contents. Teammates never receive your real calendar address. Inviting a teammate by email sends their address to our email provider so the invitation can be delivered.

5.5 Handshake (one-to-one sharing)

Handshake connects you directly with one colleague, usually by scanning a QR code. While a Handshake is active, your calendar link and blocked dates are stored on our servers and your schedule is served to that person through a relay address that reveals nothing about your real link. Either of you can revoke the connection at any time, which deletes the stored link immediately.

5.6 Company

A Company is a shared workspace for one workplace, so your colleagues' real schedules are there from day one. ShiftHawk shows you a summary of everything below, in the app, and you must accept it before you can enter a Company Code.

Anyone holding the Company Code can see the names and shift schedules of everyone in it; your display name and a masked phone number once you claim a schedule as yours; and who added each schedule. Treat the Company Code like a password.

While you are in a Company we hold:

  • Your phone number, verified once and never shown in full. Joining requires a one-time SMS code, so a workplace roster contains real, reachable colleagues. We keep a one-way hash (to recognise a number without storing it in the clear), a masked form showing only the country code and last four digits — for example +1 401 ···· 8842, the only version any member sees — and an encrypted copy of the full number that nothing in the app reads back.
  • Scheduling links, encrypted. Members' apps fetch a schedule through an opaque feed token, never your real calendar address. Our servers refresh these schedules regularly so the roster stays current.
  • The shift events themselves. This is where Company differs from Team sharing: a Company stores the shifts — dates, times and labels — so every member can see the roster. A schedule also carries the display name and, if supplied, an abbreviation, an email address and marked vacation blocks.
  • Membership and audit records — who is in the Company, who is admin, who added or claimed each schedule, removal requests, admin handovers, and Schedule Proof outcomes where a Company uses it.

Schedule Proof. A Company's admin can require new joiners to demonstrate their own live schedule before being admitted, so a roster stays limited to genuine colleagues. It is a joining control, not ongoing monitoring.

Adding a colleague. If you add someone else's schedule to a Company, anything you entered about them — including an email address — is uploaded with it. Please only add colleagues' details where you are entitled to.

5.7 Swap offers, invites and referrals

When you send a swap request or post an open shift, the shift's dates, the people involved and any note you write are stored on our servers so the other person can respond, and a shareable link is created. Anyone with that link can view the offer, so share it only with the person it is meant for. Offers expire automatically.

Inviting a colleague sends the email address or phone number you enter to our servers so the invitation can be delivered. Please only enter someone else's details where you are entitled to.

6. Analytics and crash reports

To fix bugs, catch errors we would otherwise never see, and make future versions better, we would like to collect a small amount of usage data — but only if you say yes. Analytics is off when you install ShiftHawk, nothing is sent until you accept the one-time request the app shows you, and you can turn it back off at any time in Settings › Account › Privacy. We do not sell it, we do not use it for advertising, and we do not track you across other apps or websites — ShiftHawk does not use Apple's App Tracking Transparency or an advertising identifier.

  • Usage analytics — PostHog, only if you opt in. Which screens you open, taps, app opens, device model, OS and app version, and performance timings. This is off by default: the app asks you once, plainly, and captures nothing unless you agree — and you can withdraw at any time in Settings › Account › Privacy, which stops collection from that moment. Once you agree, your usage events carry your ShiftHawk account identifier, so they are linked to your account, not anonymous; if you have signed in, that account holds your email address, so the analytics can be connected to you. We do not send PostHog your name, email or phone number themselves. Sent to our own endpoint (analytics.shifthawk.ai) and processed by PostHog in the United States.
  • Session replay — switched off. ShiftHawk previously recorded replays of the screens you moved through. We turned that off on 3 September 2026, because a replay of your roster would also have captured colleagues' names — people who never installed ShiftHawk and never agreed to be recorded. Recording is now disabled on our analytics account itself, so it is off for every version of the app, including older ones already installed. We no longer record your screen at all.
  • Crash and error reporting — Sentry. Reports are configured to carry no personal data: web addresses, email addresses and access tokens are stripped before sending, and reports from the most sensitive areas discard their message entirely. Reports are labelled with a random install identifier, not with your account. If you use the in-app "report a problem" form, the text you write is sent as you wrote it.
  • App launch and updates — Expo. Anonymous launch-timing metrics, and a check for over-the-air updates each time the app starts, which sends only your app and update version.
  • This website — PostHog. Anonymous page views, clicks, referring page, browser and device type. There is no session replay on the website either. A first-party cookie holds a random identifier to recognise a repeat visit; it contains no name, email or account, is never used for advertising, and you can clear or block it at any time.

Your choices. Analytics is yours to switch on or off whenever you like, in the app under Settings › Account › Privacy. We would rather you said yes — it is how we find what is broken — but it is entirely your call, and saying no changes nothing about how ShiftHawk works for you. Switching it off stops collection from that moment. If you would also like the events already collected erased, email [email protected] and we will do it — see Section 14.

7. Payments

Subscriptions and in-app purchases are processed by Apple's App Store and Google Play, who handle your card details. ShiftHawk never sees or stores your payment-card information. We use RevenueCat as our purchase broker: it reads the receipt from Apple or Google so the app knows what you are entitled to. To stop the same free allowance being claimed repeatedly, we keep a one-way hash of your store account identifier — see Section 10.

8. Who else is involved

ShiftHawk relies on a small, deliberate set of service providers. Each one is bound by a contract that permits it to use your data only to provide its service to us. Everything marked opt-in is only involved if you use that feature.

ProviderWhat it doesWhat it receives
Apple App Store / Google PlayDistribution and paymentsPurchase and payment details
RevenueCatPurchase brokerReceipts and entitlements only
Your scheduling providerSource of your rotaA request from your phone for your own schedule
Supabase (United States)Accounts and all server-side storageAccount details, and the data for whichever sharing features you enable
CloudflareCalendar relay, analytics endpoint, DNSCalendars in transit (not stored); the provider hostname; a hashed IP address for anti-abuse
Twilio (opt-in)Sends the Company verification codeYour phone number
Amazon Web Services (opt-in)Basic Schedule Scan readerThe schedule image or PDF you submit
Mistral AI (opt-in, European Union)AI Schedule Scan readerThe schedule image you submit
Google (opt-in)Sign-in and Google CalendarYour account email and name; the calendar events read and written
Apple (opt-in)Sign in with AppleYour Apple ID identifier and email, possibly via private relay
ExpoPush delivery, app updates, launch metricsYour device push token; app version
Resend (opt-in)Sends invitation and account emailsThe recipient's email address and the invitation contents
PostHog (United States)Product analytics — in the app, only if you opt inUsage events; your account identifier once you have opted in
SentryCrash and error reportingScrubbed diagnostics

None of these are advertising networks, and we do not disclose your personal information to anyone for their own marketing purposes.

9. Categories of information we collect

Set out in the categories used by California's privacy law, so you can compare this policy with others. We collect the following, from you and from your device, in order to run the features described above, and we keep each for the periods in Section 10.

CategoryExamples in ShiftHawkDisclosed to
IdentifiersAccount identifier, email address, phone number, name, device push token, hashed IP addressService providers in Section 8
Commercial informationSubscription and token purchasesApple, Google, RevenueCat
Internet or network activityScreens opened, taps, app version, performance timings — in-app analytics are collected only if you opt in, and carry your account identifier once you doPostHog, Sentry, Expo
Professional or employment informationYour work shifts, role, industry and employer roster where you use CompanyService providers in Section 8; other members of a Company or team you join
Other information you provideColleagues' names and contact details you enter; free-text notes and problem reportsService providers in Section 8; recipients you choose

We do not collect: precise geolocation, contacts from your address book, biometric identifiers, government identifiers, racial or ethnic origin, religious beliefs, union membership, sexual orientation, or the contents of your messages or email. We do not collect information that California law classifies as sensitive personal information, and therefore have nothing to limit the use of. ShiftHawk handles your work schedule, not patient data — it is outside HIPAA's scope by design, and you should never enter patient information into it.

We do not use your information to make any decision that produces a legal or similarly significant effect about you, and we do not profile you.

10. How long things are kept

DataKept for
Everything on your deviceUntil you clear it or uninstall
Team Sharing / Handshake link and blocked datesDeleted the moment you stop sharing, leave, or delete your account
Cloud Schedule BackupTwo years, or until you remove it
Swap offers, invitations, referralsExpire automatically, typically within days
Company schedules and cached shiftsUntil the schedule is removed or the Company closes
Company membership history and encrypted phone numberRetained after you leave — see below
Hashed store-account identifier (free-allowance anti-abuse)Retained indefinitely — see below
Hashed IP addresses used for rate limitingPurged regularly, typically within hours
Usage analytics (only if you opted in)Per PostHog's retention settings; linked to your account identifier
Crash and error reportsPer Sentry's retention settings; keyed to a random install identifier, not to your identity

Two things outlive your account, and we would rather say so than imply otherwise.

  • Company history. Leaving a Company is immediate: your schedule stops being served, its access token is revoked, and the Company's data is cleared from your device. But the Company keeps a record that your membership existed and when it ended, the encrypted copy of the verified phone number, and the audit entries for schedules you added or claimed. A shared roster has to be able to answer "who added this schedule" after someone has gone, and the number history is what stops a removed member rejoining immediately. None of it is visible to members as an active roster entry.
  • Free-allowance protection. A one-way hash of your Apple or Google account identifier is kept so the free starter tokens cannot be claimed repeatedly by deleting and recreating an account. It cannot be reversed into your identity, and it is not used for any other purpose.

Both are retained for fraud prevention and security, which US privacy laws permit us to keep even after a deletion request. If you would still like either erased, ask us and we will do it — see Section 14.

11. Deleting your data

  • Delete the app — removes all on-device data, including your schedule and saved colleagues.
  • Clear data inside the app — wipes saved colleagues, settings and cached schedules without uninstalling.
  • Remove your calendar link — stops ShiftHawk fetching your schedule and clears the link from secure storage.
  • Turn off a sharing feature, or leave a team — immediately deletes the link and roster entry we hold for it.
  • Delete your account — from inside the app, or at shifthawk.ai/delete-account. This removes your account and the data attached to it, with the two exceptions in Section 10.

12. How we protect your information

Your calendar link is held in your device's Keychain or Keystore. Traffic between the app and our servers is encrypted in transit. On our servers, the links that Company schedules are built from are stored encrypted, phone numbers are stored hashed and masked rather than in the clear, and the tables holding shared data are not readable by other users — only by ShiftHawk's own server code. Access to production systems is limited to those who need it.

No system is perfectly secure, and we will not pretend otherwise. If a breach affects your personal information we will notify you and the relevant authorities as required by Delaware and other applicable state law.

13. Where your information is processed

ShiftHawk is operated from the United States and our servers are located there. If you use the AI Schedule Scan reader, that one request is processed by Mistral AI in the European Union. If you are outside the United States, using ShiftHawk means your information is transferred to and processed in the United States, which may have different privacy protections than your own country.

Where we transfer personal data out of the UK, EU or EEA, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum) with the provider concerned, together with a data-processing agreement covering security and confidentiality.

14. Your privacy rights

Depending on where you live, you may have the right to:

  • Know and access the personal information we hold about you, and the categories in Section 9;
  • Correct inaccurate personal information;
  • Delete your personal information;
  • Obtain a copy of it in a portable format;
  • Opt out of any sale or sharing of personal information, and of profiling — neither of which we do;
  • Not be discriminated against for exercising any of these rights. We will never degrade ShiftHawk or charge you more because you made a privacy request.

These rights are available to residents of California, Delaware, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana and other states with comprehensive privacy laws, and — for access, portability, restriction and objection — to people in the UK, EU and EEA. Most of them you can exercise yourself using Section 11, because your data is on your device.

We do not sell your personal information, and we never have. We do not share it for cross-context behavioural advertising, and we do not process it for targeted advertising or profiling. Because we do not sell or share in this sense, there is nothing for a browser opt-out signal to switch off; we nonetheless honour Global Privacy Control signals on our website.

How to make a request. Email [email protected]. We will confirm receipt promptly and respond within 45 days, extending once by a further 45 days if a request is complex, and we will tell you if we need the extra time. To protect your account we will ask you to verify your identity — usually by replying from the email address on the account, or by confirming details only the account holder would know. We will not ask for more information than we need to do that.

Authorised agents. Someone may make a request on your behalf if they provide your written permission; we may still ask you to confirm it directly.

If we say no. You may appeal any refusal by replying to our decision with the word "appeal". We will review it and respond in writing within 60 days, explaining our reasoning. If we still decline, you may contact your state Attorney General — in Delaware, the Department of Justice's Consumer Protection Unit. If you are in the UK, EU or EEA you may complain to your local data protection authority.

Why we are allowed to process your data. For people in the UK, EU or EEA: we process your data to perform our contract with you (running the app and the features you switch on), on the basis of your consent where you opt in to analytics, to a sharing feature or to the AI reader — which you may withdraw at any time by switching it off — and on the basis of our legitimate interest in keeping the service secure and preventing abuse.

15. Children's privacy

ShiftHawk is a professional tool for people who work shifts. It is not directed to children, and we do not knowingly collect personal information from anyone under 13, or under 16 where local law sets that age. If you believe a child has provided us with personal information, email [email protected] and we will delete it promptly. We do not knowingly sell or share the personal information of anyone under 16 — and we do not sell or share anyone's.

16. Changes to this policy

If we change how ShiftHawk handles data we will update this page and revise the date at the top. Anything that materially changes what leaves your device will also be flagged in the app before it takes effect, and where the law requires it we will ask for your consent.

17. Who we are, and how to reach us

ShiftHawk is operated by ShiftHawk LLC, a multi-member limited liability company formed in Delaware, United States. ShiftHawk LLC is the controller — and, under California law, the business — responsible for the personal information described in this policy.

PostShiftHawk LLC, 8 The Green STE B, Dover, Kent County, DE 19901, United States
Email[email protected]
Phone(302) 493-5075

Questions about your privacy, or a request under Section 14? Email us and a real person will read it.