Privacy Policy
Last updated August 2, 2026
ShiftPilot is a work-schedule app. This policy explains exactly what it stores, why, and how to delete it. Plain language, no surprises.
What we store
- Your shifts and workplaces — dates, times, roles, job names, and any pay rates, tips or tip-out you choose to enter.
- An account identifier — a random key generated on your device. If you use Sign in with Apple, we also store the anonymous user ID Apple gives us, so your data can be restored on a new device. We never receive your Apple password.
- Schedule emails you forward — if you turn on automatic import, emails sent to your personal import address are parsed into shifts. We store the resulting shifts. We do not keep the email itself, with three exceptions.
First, if we fail to read it, we keep a short excerpt so we can fix the problem.
Second, if your schedule comes from a system we don't recognise yet, we have to fall back to AI to read it — and in that case we keep a short excerpt too. That is how we learn the format well enough to write a proper reader for it, which makes your imports faster and more reliable and means the AI is no longer involved. This applies only to emails, never to photos you scan.
Both excerpts are truncated, and have email addresses, phone numbers and long account numbers stripped out automatically before they are stored.
Third, if a schedule arrives while automatic import isn't active on your account (a Pro feature), we hold that email so it can be imported if you upgrade — it is stored, not read, and is automatically deleted after 60 days. All of these are deleted immediately if you delete your account. - Notification token — only if you enable notifications, so we can alert you when a new schedule arrives.
- Bug reports and feature requests — if you send one, we store what you wrote along with your app version and device model so we can reproduce the problem. To track the work, the report text is also copied to our private issue tracker; it is labelled with a random reference, never your name, email or account identifier.
- Anonymous usage analytics — which screens you open and which features you use, plus your app version, device model and rough counts (for example how many jobs you have, never which). We use this to see which features are worth keeping and which aren't. It is deliberately stripped of content: no shift dates or times, no job, workplace or role names, no coworker names, no pay rates, tips or totals, and no notes. Events are tied to a random account handle, never to your email or your login credential. You can turn this off completely in Settings → Share usage data.
What we do not do
- We do not sell or rent your data. Ever.
- We do not show third-party ads or use advertising trackers.
- We do not track you across other apps or websites, and we do not record your screen or your taps.
- We never connect to your email account or read your inbox. Automatic import only sees messages you deliberately forward to your import address.
Service providers
We use a small number of processors purely to run the service: a cloud host and database for storage, an inbound email provider to receive forwarded schedules, a push notification service, an AI provider used only to read schedule formats we don't recognize, and a product-analytics provider (PostHog) that receives only the anonymous usage events described above. Email content sent for parsing is used to extract shifts and is not used to train models.
Deleting your data
You can delete your account and everything in it from inside the app: Settings → Account → Delete account. This permanently removes your profile, shifts, workplaces, any stored requests, and the bug reports you filed. It cannot be undone, and it does not require contacting us.
Retention
Your data is kept while your account exists. When you delete your account it is removed from the live database immediately; routine encrypted backups roll off shortly after.
Children
ShiftPilot is not directed at children under 13, and we don't knowingly collect their data.
Changes
If this policy changes materially, the date above changes and the app will point to the updated version.
Contact
Questions or a data request: devauxprod0@gmail.com