Privacy Policy

Last updated: 27 June 2026

1. Our Privacy Principle

ShiftHawk is local-first by default. Your data stays on your device unless you choose otherwise.

Out of the box, ShiftHawk runs no server that receives your schedule or personal data. Your schedule, your calendar link, and your coworkers' contact details live only on your phone — they never reach us, because we can't see them. (To make the app better for everyone, we do collect a small amount of anonymous, non-identifying usage analytics that can't be traced back to you and never includes your schedule or contacts — described in full in Section 4c.)

This isn't a promise we ask you to take on faith — it's the architecture. By default, there is simply no place on our side for your data to go.

You can bring your schedule in as a calendar link (.ics), a spreadsheet (XLSX), a PDF, or a photo. A spreadsheet (XLSX) you import is read entirely on your phone — it is never uploaded anywhere. A PDF or a photo, on the other hand, is read by a text-recognition step that only happens if you choose Schedule Scan (below) — there, the PDF or image is sent to an OCR service you select to pull out the text, then discarded.

There are two optional exceptions, each off by default and entirely under your control:

  • Team Schedule Sharing — when you opt in, a small, clearly defined slice of your availability is stored on our side so your teammates can see when you're free. Explained in full in Section 4a.
  • Schedule Scan (OCR) — when you choose to read a PDF or a photo of your schedule, that file is sent to a third-party OCR service you select, text is extracted, and the result stays on your device. (An .ics link and a spreadsheet do not use this — those stay on your phone.) The file is not retained by ShiftHawk or by those processors beyond the processing call. Explained in full in Section 4b.

2. Information ShiftHawk Handles (and Where It Lives)

Everything below stays on your device. Nothing here is transmitted to ShiftHawk or any third party unless you activate an opt-in feature: Team Schedule Sharing (see Section 4a) stores a limited slice of your availability so teammates can see it; Schedule Scan / OCR (see Section 4b) sends only a PDF or photo you scan to an OCR processor you choose in order to extract the text (an .ics link and a spreadsheet are read on your device).

  • Your calendar URL — the .ics link to your schedule. Stored securely in the iOS Keychain or Android Keystore on your device. If you turn on Team Schedule Sharing, a copy is also kept on our side in an access-controlled record that your teammates cannot read — it exists only so our relay can fetch your calendar on their behalf (see Section 4a).
  • Your fetched schedule — the shifts read from that calendar. Held in on-device storage only, so the app can search for swaps.
  • Schedule files you import — a spreadsheet (XLSX), a PDF, or a photo of a printed schedule, if that's how you bring your shifts in. A spreadsheet (XLSX) is read entirely on your device. A PDF or a photo is read by an OCR processor you choose only if you use Schedule Scan (see Section 4b); either way, the shifts that come out are stored on-device, and ShiftHawk keeps no copy of the original file on its servers.
  • Colleagues' names and phone numbers — the contacts you enter so ShiftHawk can draft swap messages. Names sit in on-device storage; phone numbers are kept in the Keychain / Keystore.
  • App settings and preferences — your role, rest rules, marked vacations, and similar choices. Stored on-device.

3. What ShiftHawk Does NOT Do

  • No backend collection by default — we operate no server that receives your data, and importing an .ics link or a spreadsheet stays on your device. Two opt-in features change this in a limited, described way: Team Schedule Sharing (see Section 4a) stores a slice of your availability; Schedule Scan / OCR (see Section 4b) sends only a PDF or photo you scan to an OCR processor you select.
  • No analytics service receives your schedule, your calendar link, or your contacts. The anonymous, non-identifying usage analytics we do collect to improve the app are never tied to your name, email, or account — they're described in Section 4c.
  • No selling of your data — ever, to anyone. We do not share your data with third parties except in the opt-in features you control: Team Schedule Sharing (availability data visible to your chosen teammates, see Section 4a) and Schedule Scan / OCR (your schedule image sent to the OCR processor you select, see Section 4b).
  • No ads, and no upselling beyond the in-app purchases you choose.
  • No tracking you across other apps or websites.
  • No PHI (protected health information) — ShiftHawk handles your work schedule, not patient data. It is outside HIPAA's scope by design.

4. How Data Leaves Your Device

Setting aside the anonymous analytics described in Section 4c, there are two moments when your own information moves off your phone, and neither one passes through ShiftHawk:

  • Calendar fetches go directly between your device and your scheduling provider. When ShiftHawk refreshes your schedule, your phone talks straight to your provider (Amion, QGenda, MedRez, ShiftAdmin, Symplr, Lightning Bolt, or whoever exports your .ics). We are not in the middle. (If you turn on Team Schedule Sharing, your teammates' refreshes are served by our relay instead — see Section 4a.)
  • Messages you draft are sent by you. ShiftHawk composes a text or email; you read it, approve it, and send it from your own SMS or email app. The app never sends anything on its own and never sends anything you haven't seen.

4a. Team Schedule Sharing (Optional)

This feature is off by default. Everything described in the sections above stays true for you unless you choose to turn Team Schedule Sharing on. If you never enable it, nothing in this section applies to you.

If you do opt in, Team Schedule Sharing lets the teammates you join up with see when you're free — so finding a swap doesn't mean a round of texts. To make that work, and only while sharing is on, three things newly happen on ShiftHawk's side:

  • Your calendar link is stored for the relay — never handed to teammates. Your .ics subscription URL is saved in an access-controlled record on our servers (Supabase). Your teammates cannot read it. It exists for one reason only: so a ShiftHawk relay (a Cloudflare worker) can fetch your calendar on a teammate's behalf using an opaque share token. Teammates receive that one-time relay link, never your real calendar URL.
  • Your blocked dates and a short label are stored so teammates see your availability. The dates you've marked as unavailable or blocked are stored as plain calendar dates (YYYY-MM-DD only — no shift details, no titles, no times), alongside a short display label you set yourself so teammates know whose availability they're looking at.
  • Your schedule passes through the relay in-flight, and is not kept there. When a teammate refreshes, the relay fetches your calendar, passes it through to them, and does not store the schedule's contents. The relay holds only the access-controlled link it needs to make that fetch.

Turning it off is immediate and complete. Switching sharing off in the app, leaving the team, being removed from it, or deleting your account each hard-deletes the stored link and your roster entry right away — so the relay can no longer serve your calendar to anyone, and your blocked dates and label are removed. There is nothing left for teammates to fetch.

4b. Schedule Scan — OCR (Optional)

This feature is off by default, and requires your explicit consent each time before any image leaves your device. Everything described in the sections above stays true unless you choose to use Schedule Scan. If you never use it, nothing in this section applies to you.

Schedule Scan lets you import a PDF of your schedule, or photograph a printed one, and have ShiftHawk read the shifts from it automatically, so you don't have to enter them by hand. To do that, only the schedule image(s) or PDF you choose to scan is sent to a third-party text-recognition (OCR) service, solely to extract the schedule grid — the dates and shift codes — into the app. (A spreadsheet doesn't need this — ShiftHawk reads XLSX files right on your device.) You pick which OCR service is used — ShiftHawk offers two options:

  • Basic reader — AWS Textract (Amazon Web Services, United States — region us-east-1). A standard OCR engine that reads structured documents well. Amazon processes the image on its servers solely to extract text, then returns the result. Amazon's data handling for this service is governed by the AWS Privacy Notice.
  • AI reader — Mistral AI. A large-language-model OCR service better suited for harder-to-read or non-standard schedules. Mistral processes the image on its servers to extract text and returns the result. Mistral's data handling is governed by the Mistral AI Terms & Privacy.

What may be in the file. A printed schedule typically shows shift assignments for a group of clinicians, so the PDF or photo you scan may include your colleagues' names or other identifiers as printed on the schedule grid alongside your own shifts. Because of that, the image is treated as Other User Content — the same category we declare in the App Store's App Privacy details. Only the file you explicitly select and submit is sent — ShiftHawk does not scan your files or camera roll automatically.

What ShiftHawk does with the extracted text. The text extracted by the OCR service is used to populate your in-app calendar. It stays on your device and is not sent to ShiftHawk's servers.

File retention. The image is processed transiently and discarded immediately after the text is extracted. ShiftHawk does not store the raw PDF or image on its servers, and no schedule data or personal identifiers from the scan are kept server-side. The file is transmitted to your chosen OCR processor only for that extraction, and is not retained by that processor beyond the processing call — neither AWS Textract nor Mistral AI retains it as a stored asset after the extraction response is delivered.

You control every scan. Each use of Schedule Scan is a deliberate, per-file action you initiate — there is no background scanning or automatic upload at any time.

4c. Anonymous Analytics & App Improvement

To understand how ShiftHawk is used and to make it faster and easier, the app collects a small amount of anonymous, non-identifying usage data. This is different from the two optional features above: it is not tied to a name, an email, or an account, and it never includes your schedule, your calendar link, or your contacts. Each install is keyed to a randomly generated anonymous identifier — not to you. We use this data only to improve the app. We do not sell it, we do not use it for advertising, and we do not track you across other apps or websites (ShiftHawk does not use Apple's App Tracking Transparency / IDFA).

  • Product analytics — PostHog. Anonymous usage events such as which screens you view, taps and interactions, and app opens, along with your device model, OS version, app version, and performance and latency timings. This is sent to ShiftHawk's own endpoint (analytics.shifthawk.ai) and processed by PostHog, a third-party analytics processor, in the United States. It is keyed to the anonymous identifier described above — never to your identity.
  • Session replay — PostHog. So we can see where the app is confusing or awkward and fix it, ShiftHawk records anonymized replays of the in-app screens you move through. Text you type is masked — input fields are hidden in the recording, so anything you enter (such as a calendar subscription URL, an email address, or a phone number) is not captured. These replays are anonymous, used only to improve the experience, and are never sold or used for advertising.
  • App launch & performance — Expo Insights. Anonymous app-launch timing and app-version metrics, so we can keep ShiftHawk starting up quickly and catch slowdowns. Provided by Expo.
  • Crash & error reporting — Sentry. When something goes wrong, ShiftHawk sends a privacy-first crash or error report so we can find and fix it. These reports are configured to carry no personal data — no schedule, no contacts, no account identifiers. Handled by Sentry.

None of this analytics data can be used to identify you, and none of it contains the contents of your schedule. It exists for one purpose: to help us make ShiftHawk better for everyone who works shifts.

5. Payments & RevenueCat

Subscriptions and in-app purchases are processed by Apple's App Store and Google Play. We use RevenueCat as our purchase broker: it reads the purchase receipt from Apple or Google so the app knows which features you're entitled to. RevenueCat handles receipts and entitlement state — not your schedule, not your contacts.

Apple and Google handle the actual payment, including your card details. ShiftHawk never sees or stores your payment-card information. For how RevenueCat handles its data, see the RevenueCat Privacy Policy.

6. Third-Party Services

ShiftHawk relies on a small, deliberate set of third parties:

  • Apple App Store / Google Play — app distribution and payments.
  • RevenueCat — subscription and purchase management (receipts and entitlements only).
  • Your scheduling provider — your device fetches your calendar directly from it. ShiftHawk is not affiliated with any scheduling provider; it simply reads the .ics export you already have access to.
  • Supabaseonly if you turn on Team Schedule Sharing. Stores the access-controlled calendar link and your blocked dates (see Section 4a), hosted in the United States. Only ShiftHawk has server-side access to these records; your teammates cannot read them.
  • Cloudflareonly if you turn on Team Schedule Sharing. Operates the relay that fetches your calendar for your teammates. Your schedule passes through it in-flight and is not stored there (see Section 4a).
  • AWS Textract (Amazon Web Services)only if you use Schedule Scan and select the Basic reader. Receives the schedule image you submit, extracts the text, and returns it. The image is not retained beyond the processing call. Governed by the AWS Privacy Notice (see Section 4b).
  • Mistral AIonly if you use Schedule Scan and select the AI reader. Receives the schedule image you submit, extracts the text, and returns it. The image is not retained beyond the processing call. Governed by the Mistral AI Terms & Privacy (see Section 4b).
  • PostHog — anonymous product analytics and anonymized session replay (with the text you type masked out), used only to improve the app. Reached through ShiftHawk's own endpoint (analytics.shifthawk.ai) and processed in the United States. Not sold, not used for advertising, no cross-app tracking. Governed by the PostHog Privacy Policy (see Section 4c).
  • Expo — anonymous app-launch and performance telemetry (Expo Insights), so the app stays fast. Governed by the Expo Privacy Explained notice (see Section 4c).
  • Sentry — privacy-first crash and error reporting, with no personal data attached. Governed by the Sentry Privacy Policy (see Section 4c).

Each of these has its own privacy policy that governs the data it handles.

7. Data Retention & Deletion

By default, your data lives on your device, so you control all of it and we hold nothing to delete on your behalf. If you used Schedule Scan, the raw image was not stored by ShiftHawk or retained by the OCR processor — only the extracted text remains, on your device, as part of your calendar data. To remove your on-device data:

  • Delete the app. Removing ShiftHawk from your phone deletes its on-device storage, including your schedule and saved colleagues.
  • Clear data inside the app. Use the in-app reset or clear options to wipe saved colleagues, settings, and cached schedule data without uninstalling.
  • Revoke your calendar URL. Remove or replace the calendar link in the app's settings to stop ShiftHawk from fetching your schedule. The stored URL is cleared from the Keychain / Keystore when you do.

Securely stored items (your calendar URL and colleagues' phone numbers in the Keychain / Keystore) are removed when you clear them in-app or uninstall the app, following the platform's secure-storage rules.

If you turned on Team Schedule Sharing (see Section 4a), the limited slice of data we hold on our side — your access-controlled calendar link and your blocked dates — is removed the moment you do any of the following, with no need to contact us:

  • Turn off sharing in the app. Switching Team Schedule Sharing off immediately hard-deletes your stored link and roster entry and disables the relay for all your teammates.
  • Leave the team, or be removed from it. Either one immediately hard-deletes your stored link and roster entry, so the relay can no longer serve your calendar.
  • Delete your account. Deleting your ShiftHawk account immediately removes everything we hold for you, including the stored link and roster entry.

If you'd like anything else removed, or want confirmation that it's gone, email us at [email protected] and a real person will take care of it.

8. Children's Privacy

ShiftHawk is a professional tool for people who work shifts and is not directed at children. We do not knowingly collect information from anyone under 13 (or under 16 where local law sets that age). The app is meant for working adults managing their own work schedules.

9. Your Rights

Privacy laws such as the GDPR and CCPA give you rights to access, correct, and delete your personal data. With ShiftHawk you already have all of that, directly: by default your data is on your device, under your control, and you can view, edit, or delete it at any time using the steps in Section 7. By default we hold no copy to hand over or erase. If you turned on Team Schedule Sharing (see Section 4a), the limited data we hold on our side is yours to erase at any time — turning off sharing, leaving the team, or deleting your account each removes it immediately, as Section 7 describes. If you have a question about your rights, email us at [email protected].

10. Changes to This Policy

If we change how ShiftHawk handles data, we'll update this page and revise the "Last updated" date above. Because our model is on-device by design, any change that affected it would be significant — and we'd flag it clearly in the app.

11. Contact

Questions about your privacy? Email [email protected]. A real person reads every message.