Privacy Policy
ShiftSum · Effective date: 2026-07-19 · Version 1.0
This policy describes exactly what ShiftSum (“the app”) does with your information. It is written to match the app’s actual behavior — if the app’s data practices change, this page changes first.
The short version
- Your work record — jobs, shifts, breaks, rates, notes, and earnings — is stored only on your device. It never leaves your device unless you export or back it up yourself.
- There is no account and no sign-in.
- The app collects anonymous usage statistics (for example, “a timer was started”) to understand which features are used. You can turn this off at any time in Settings → Privacy.
- Crash reports reach the developer only through Apple’s built-in crash reporting, and only if you have allowed sharing with app developers in your iPhone settings.
- Purchases are made through Apple; purchase validation is processed by RevenueCat under an anonymous app user ID. We never see your payment details.
- No advertising. No tracking across apps or websites. No sale of data.
What the app stores, and where
| Data | Where it lives | Who can see it |
|---|---|---|
| Jobs, shifts, breaks, pay rules, notes, earnings estimates | Your device (protected by iOS data protection) | Only you |
| App preferences (currency, week start, display options) | Your device | Only you |
| Purchase/entitlement status (Free or Pro) | Your device; purchase validation and the purchase record are processed by RevenueCat under an anonymous app user ID (payment itself is handled by Apple) | You; RevenueCat processes the receipt anonymously; Apple holds the payment record |
| Encrypted backup files | Wherever you choose to save them (your Files app, your iCloud Drive, etc.), protected by your passphrase | Only you |
| Anonymous usage signals | TelemetryDeck’s servers | The developer, in aggregate form |
| Crash reports | Apple’s servers, shared with the developer through App Store Connect | The developer, if you opted in on your device |
Anonymous usage analytics
The app sends a small, fixed set of usage signals to TelemetryDeck, a privacy-focused analytics service, so the developer can see which features are used and where people get stuck. The complete set of signals is fixed in the app’s code and covers only product interactions, such as:
- onboarding started or completed;
- first job created (with the pay-period type, e.g. “weekly”);
- first timer started or stopped (with a coarse bucket like “3–5 shifts” — never the real count);
- first manual shift, first break, first earnings breakdown viewed, first overtime rule configured, first export completed;
- paywall viewed; purchase started, completed, or restored (with the plan type — “annual” or “lifetime” — never a price);
- backup enabled or restored.
Each signal is associated with a randomly generated, hashed installation identifier that is not linked to your name, email, device, or Apple ID. The signals are used for analytics only and are never used to track you across other apps or websites.
These signals never include your work or earnings content. The app is built so that job names, notes, rates, amounts, shift dates, and exported files cannot be attached to a signal — this restriction is enforced and tested in the app’s code, not just promised here.
You can turn analytics off at any time: Settings → Privacy → “Share anonymous usage analytics”. No signals are sent while it is off.
Crash reports
If you enable “Share with App Developers” in your iPhone’s Privacy & Security settings, Apple may share anonymized crash logs with the developer through App Store Connect. The app does not include any third-party crash-reporting software. Apple’s sharing is governed by your device settings and Apple’s privacy policy.
Purchases
Pro subscriptions and lifetime purchases are paid through the App Store — Apple holds your payment information and manages billing, renewal, cancellation, and refunds. Purchase validation and entitlement status are processed by RevenueCat under an anonymous, randomly generated app user ID (no account, nothing linked to your name, email, or device). RevenueCat receives only App Store receipt data — never your jobs, shifts, rates, or earnings, which never leave your device.
The app receives only what you are entitled to (Free or Pro), which it stores on your device so Pro works offline. We never see your card number, Apple ID password, or billing address.
What the app does not do
- No account, email, or phone number required.
- No GPS or location access. No access to your contacts, calendar, photos, microphone, or camera.
- No advertising, and no use of your data for advertising.
- No tracking across other companies’ apps or websites.
- No sale or rental of any data to anyone.
- No itemized work or earnings data in analytics (see above).
Your choices and your data
- Export everything: Settings → Your data → Export data produces a CSV copy of your record at any time, free, with or without a subscription. PDF reports are a Pro feature.
- Back up and restore: Settings → Your data → Backup & restore creates an encrypted backup file protected by a passphrase you choose.
- Delete everything: Settings → Privacy → Delete all data erases the app’s local record permanently.
- Uninstalling the app deletes its local data from your device. Backup files you saved elsewhere remain yours to keep or delete.
Data retention
Your work record stays on your device until you delete it or uninstall the app. Anonymous usage signals are retained by TelemetryDeck in aggregate form; because they are not linked to you, they cannot be traced back or deleted per person. Crash reports are retained by Apple under Apple’s policies.
Children
The app is not directed at children under 13, and we do not knowingly collect personal information from children.
About pay estimates
All pay values are estimates based on rules entered by the user. The app must not claim to calculate legally authoritative wages, payroll, taxes, deductions, benefits, or net pay.
Changes to this policy
If the app’s data practices change, this page is updated before the change ships, and the effective date above is revised. Material changes are also noted in the app’s release notes.
Contact
Questions about privacy: [email protected].