ScanMyShift Privacy Policy
Effective date: September 6, 2026
Last updated: September 6, 2026
1. Who we are
ScanMyShift is provided by Zhang Biao (张彪), an individual developer based in China ("we", "us", or "our"). We are responsible for the personal information processed for ScanMyShift as described in this policy.
Privacy contact: cherishbingo@gmail.com.
This policy covers the ScanMyShift Android app and our roster-recognition service. ScanMyShift helps you turn work rosters into editable shifts and, after your confirmation, events in a calendar you choose. You do not need a ScanMyShift account. No account does not mean no data processing: cloud recognition, advertising, subscription services and diagnostics involve the providers described below.
Privacy at a glance
This summary highlights the main data flows and does not replace the full policy below:
- Your saved shift library is primarily stored on your device. We do not provide a ScanMyShift account or our own cloud shift synchronization.
- Only when you choose cloud recognition do we send the entire selected roster image, target employee name and request identifier through our Cloudflare Worker to a contracted AI gateway and the model providers it uses. You can use manual entry instead.
- AdMob, Google Play, RevenueCat and Firebase process advertising, subscription, app/device, usage or diagnostic information for their respective functions. We do not attach roster images, employee names or calendar content to those services.
- We do not use roster content for ad targeting or to train our own models. This does not mean that every third-party provider promises zero retention or no model training; see Sections 3, 5–10 for the applicable boundaries.
- Clearing local data, deleting calendar events, cancelling a subscription and requesting provider deletion are separate actions. See Sections 10–11 for available controls and deletion boundaries, or contact our privacy email.
2. Information stored on your device
The app stores your target employee name, work labels, shift dates and times, work/rest status, job titles, work locations, notes, relevant text extracted from your roster, review flags and import history. It also stores calendar links and write status, time-zone information, settings, consent choices, and local free-scan usage and rewarded-scan balances.
These records use the app's local database and preferences. We do not maintain an account-based cloud copy of your saved shift library or provide our own cross-device roster synchronization. Manual entry does not send the entered shift content to our recognition service. Other enabled SDKs may still communicate with their providers as described below.
The app reads device regional settings and time-zone information to format dates/times and create calendar events. A work location you enter is text, not GPS tracking.
3. Photos and cloud AI recognition
Cloud recognition is optional and requires your in-app agreement. You can instead enter shifts manually. When you select or photograph a roster and start recognition, the app processes its orientation, lets you preview and rotate it, and compresses it for upload. The upload preparation removes source EXIF metadata, including EXIF location metadata. This does not remove information visibly printed in the image.
The recognition request contains the selected image, the target employee name you provide, its image format and a request identifier. It travels over HTTPS to our service running on Cloudflare Workers. Our Worker sends the image and target name, together with extraction instructions, to a contracted AI gateway and the model provider used for that request. The result is returned to the app for your review. We do not send your saved calendar library, advertising ID, subscription credentials or scan-credit balance in this recognition request.
The entire selected image is uploaded, not just the matching employee's row. It may therefore include coworkers' names or other information visible on the roster even though we request results for the target employee only. Only upload material you are authorized to share. Before selecting it, use another editor to remove unnecessary information. Do not upload patient records, medical details, identity documents or other unnecessary sensitive information. This is a scheduling tool, not a patient-record service.
Our Worker does not persist roster images, target names or recognition results in an application database or object store, and does not put that content in its application logs. They are processed to handle the request, and responses instruct clients not to cache them. This is not a promise that every infrastructure or AI provider has zero retention.
The contracted AI gateway and model providers used to fulfill requests also process submitted content. We have not yet verified a single retention period, model-training treatment or deletion process that applies to every provider used on the actual service route. We therefore do not promise provider-wide immediate deletion or exclusion from model training. Current provider details and applicable privacy terms can be requested through our privacy contact.
ScanMyShift does not use roster content for advertising or train its own models with it. AI output may be wrong; you decide what to save and write to your calendar. We do not make employment or eligibility decisions about you from these results.
4. Camera, photos and calendar access
- Camera: used when you choose to photograph a roster. The app's camera capture does not record audio.
- Photos: the picker gives the app access to the image you select; the app does not scan or upload your photo library in the background.
- Calendar: with your permission, the app lists calendars and their account labels so you can choose a destination. It reads linked events and creates, updates or deletes events as needed for actions you request. It stores calendar/event identifiers locally to maintain those links. We do not upload your calendar list, account labels or unrelated calendar events to our recognition service or use them for ad targeting.
You can revoke camera or calendar permission in Android settings. Without calendar permission, you can keep shifts in the app but cannot perform calendar operations that require access.
If you choose a Google, workplace, shared or other synchronized calendar, that calendar provider may upload events to its own servers or make them visible to people who can access the calendar. Calendar reminders and lock-screen notifications may also reveal event details according to your device settings. Those copies and displays are separate from ScanMyShift's local storage.
5. Advertising and rewarded scans
We use Google AdMob for native and optional rewarded ads. Google Mobile Ads may process IP addresses, device/account identifiers such as an advertising ID or app set ID, ad interactions and diagnostic information for ad delivery, measurement and fraud prevention. IP addresses can be used to estimate general location; this does not require GPS permission. The exact processing depends on privacy choices and SDK configuration. See Google's SDK disclosure and Google's Privacy Policy.
We use Google's User Messaging Platform to obtain applicable advertising choices before requesting ads. Where required, you can reopen Ad privacy options in Settings. You can also use Android's advertising-ID controls. Non-personalized or limited ads do not necessarily mean no data processing.
We do not attach roster images, employee names, shift details, calendar content or notes to ad requests. Rewarded-scan credits are updated locally when the ad SDK reports that a reward was earned; there is no ScanMyShift server-side reward ledger. Google still processes the ad interaction. Firebase Analytics is separate from the data processing needed by advertising services.
6. Subscriptions
Google Play processes purchases, and RevenueCat manages subscription verification, restoration and Pro access. RevenueCat uses an SDK-generated pseudonymous app user identifier and processes purchase records and subscription status, along with relevant app/device metadata. An identifier called "anonymous" by the SDK is not necessarily anonymous under privacy law. See RevenueCat's Privacy Policy and Google Play data disclosure.
The SDK may connect to RevenueCat to check access or available plans even if you have not purchased. We do not pass the target employee name, roster images or calendar content to RevenueCat. We do not receive your full payment-card details. Pro access depends on RevenueCat's entitlement information, not a separate subscription database operated by ScanMyShift.
Deleting the app or clearing local data does not cancel a subscription or erase store/provider transaction records. Manage or cancel your subscription through Google Play.
7. Usage analytics and crash diagnostics
Configured production releases use Firebase Analytics and Firebase Crashlytics to understand feature usage and diagnose reliability problems. The app does not provide separate Firebase collection switches in Settings. Firebase processing is separate from cloud-recognition agreement and advertising privacy choices.
We send predefined feature events, bounded counts and timing information. Crash reports include technical failure categories and sanitized app-generated stack traces. The SDKs can additionally process installation identifiers, app version, device and operating-system metadata, crash timestamps and native diagnostics. We do not attach names, photos, roster text, shift details, calendar identifiers or purchase credentials to these reports. The app disables Analytics advertising-ID collection, ad-storage consent, ad-user-data consent, ad-personalization signals and automatic screen reporting. See Firebase privacy information.
Firebase may queue or retain information under its service configuration. Clearing ScanMyShift's local data, uninstalling the app or changing an advertising privacy choice does not retract information already sent to Firebase.
8. Service security and support
Cloudflare processes network information, including IP addresses, to deliver and protect the recognition endpoint. We use the edge-provided IP address for rate limiting. Our application logs contain request/trace identifiers, status and error categories, and processing duration—not roster content or raw request bodies. Cloudflare can also keep service/security metadata, such as request time, method, URL and network information, under its own service arrangements. See Cloudflare's Privacy Policy.
If you contact us, we process your email address, message and any information you choose to send to respond and resolve the issue. Do not include payment-card details or unredacted rosters in support messages. We may ask for an app version, approximate request time or transaction reference where needed, rather than unnecessary identity documents.
9. Why we process information and who receives it
We process information to provide requested scheduling and recognition features, verify subscriptions, operate advertising, understand feature usage, improve reliability, answer support requests, and protect the service. The recipients are the providers described above and the calendar service you choose. Our contracted AI gateway may use different model providers to fulfill AI requests. We may also disclose information we hold when legally required or necessary to address fraud, security incidents or legal claims, subject to applicable law.
Where EEA/UK data-protection law applies, the intended bases include consent for optional cloud uploads; performing our service agreement for requested local/calendar and subscription functions; legitimate interests in understanding use, maintaining secure and reliable services, diagnosing failures and handling support; and compliance with applicable legal obligations. Where applicable law requires consent before analytics or diagnostic collection, we will request it through a separate region-appropriate flow before collection. Advertising uses consent where required and the applicable privacy choices. These bases do not give you or us permission to upload somebody else's sensitive information without an appropriate basis.
We do not sell your roster content. Advertising-related identifier processing can nevertheless constitute "sharing", "sale" or targeted advertising under some laws. Where applicable, you may opt out through the provided advertising privacy controls or contact us to exercise your rights; we do not treat a general acceptance of this policy as consent to such processing.
10. Retention and deletion
- Local shifts and settings: retained until you delete them, successfully clear the relevant app data, or remove the app's storage through Android. Clear unfinished drafts leaves confirmed shifts and settings. Clear all local data removes app-managed shifts/history, target name, settings and local scan balances. It is not a complete erasure of all third-party SDK records or caches.
- Calendar events: remain unless you explicitly choose to delete them. The app can attempt to delete events for which it still has valid links and permission. If deletion fails, it retains affected linked shifts and settings to allow a retry and reports the partial result. After clearing links or uninstalling, you may need to delete events in your calendar app. Shared copies, calendar trash and provider backups follow that provider's rules.
- Images: preview and processing copies are temporary; the app releases its normalized previews when no longer needed and cleans leftover preview files on initialization. Camera/picker caches may remain until Android or you clear them. Clearing local shift records does not delete original photos from your gallery. Our Worker does not create a persistent roster archive; provider retention is separate.
- Security and operational logs: ScanMyShift application outcome logs in Cloudflare Workers Logs are retained for no longer than seven days under the current service limits. Cloudflare may separately retain security and service metadata under its terms. Incident-specific records are kept only as long as reasonably needed for investigation, abuse prevention or applicable legal obligations.
- AI-provider records: retention and deletion are governed by the contracted AI gateway and the model provider used for the request. Because the route can use different providers, we do not promise a single provider-wide deletion time. Local deletion cannot retract an already submitted request; contact us to ask about the provider applicable to a request or to make a deletion request.
- Firebase Analytics and Crashlytics: Analytics data follows the active Firebase/Google Analytics project retention settings and deletion controls. Crashlytics describes a 90-day retention period for crash traces and associated identifiers before removal from live and backup systems begins; that is not immediate erasure. See Firebase's retention information. You can contact us to request the current Analytics setting or applicable deletion assistance.
- Subscriptions and support: subscription records are kept as needed to verify access, restore purchases, manage transactions and meet legal requirements under Google Play and RevenueCat arrangements. Support messages are ordinarily retained while the request is handled and for up to 12 months afterward for follow-up, security and dispute handling, unless a longer period is legally required or you successfully request earlier deletion.
We cannot remotely read or delete a shift library stored only on your device. For information held by us or providers acting for us, contact our privacy email. We will assess the request, use proportionate verification and assist with applicable deletion requests; we will explain any legal retention requirement or technical limitation. We do not promise that clearing the app erases provider records.
11. Your choices and rights
You may choose manual entry instead of cloud recognition, stop starting new scans, revoke camera/calendar permissions, change available ad privacy choices, edit/delete local shifts and contact us about data we process.
The current app does not provide a standalone cloud-consent-off switch. To reset its stored cloud-recognition agreement, you can successfully complete Clear all local data, which also deletes the other local information described above. You do not need to clear your shifts merely to stop future uploads—stop using recognition and use manual entry. Contact us if you wish to withdraw processing consent or request deletion of already submitted information. Withdrawal does not undo processing that was lawful before withdrawal.
Depending on your location and applicable law, you may have rights to access, correct, delete or receive a portable copy of personal information, restrict processing, withdraw consent, and complain to a data-protection authority. You may also have the right to object to processing based on legitimate interests and to opt out of targeted advertising or legally defined sale/sharing. Contact us using the privacy email; we will respond within applicable legal time limits and will not penalize you for exercising protected rights. Some features necessarily depend on the data needed to provide them.
12. International processing and security
Our providers operate across countries, so information may be processed outside your country, where privacy laws can differ. Where applicable law requires transfer safeguards, we rely on the safeguards made available under the relevant provider arrangements and will provide available information on request. Contact us for information about the providers and safeguards applicable to your request. Accepting this policy alone is not treated as authorization for a transfer where the law requires another basis or safeguard.
Recognition requests use HTTPS. Provider secrets stay on the server, not in the app. Local records use Android app-private storage; the app disables Android's standard app backup setting. The local database and preferences do not use additional app-level database encryption. Protect your device with its security controls. No storage or transmission method is perfectly secure.
13. Children and policy changes
ScanMyShift is designed for people managing work shifts and is not directed to children. If you are below the age at which you may consent to this processing in your location, use the app only with authorization from a parent or legal guardian. If you believe a child has provided information inappropriately, contact us so we can investigate and take appropriate action.
We may update this policy as the app or its providers change. We will update the date and give additional notice or request renewed consent where required. A policy update alone does not authorize a new use that requires your consent.
14. Contact
For privacy questions or requests, email cherishbingo@gmail.com, identifying ScanMyShift and the request. You do not need to create a ScanMyShift account to contact us.