Scan / My Shift

ScanMyShift Privacy Policy

Effective date: September 6, 2026

Last updated: September 6, 2026

1. Who we are

ScanMyShift is provided by Zhang Biao (张彪), an individual developer based in China ("we", "us", or "our"). We are responsible for the personal information processed for ScanMyShift as described in this policy.

Privacy contact: cherishbingo@gmail.com.

This policy covers the ScanMyShift Android app and our roster-recognition service. ScanMyShift helps you turn work rosters into editable shifts and, after your confirmation, events in a calendar you choose. You do not need a ScanMyShift account. No account does not mean no data processing: cloud recognition, advertising, subscription services and diagnostics involve the providers described below.

Privacy at a glance

This summary highlights the main data flows and does not replace the full policy below:

2. Information stored on your device

The app stores your target employee name, work labels, shift dates and times, work/rest status, job titles, work locations, notes, relevant text extracted from your roster, review flags and import history. It also stores calendar links and write status, time-zone information, settings, consent choices, and local free-scan usage and rewarded-scan balances.

These records use the app's local database and preferences. We do not maintain an account-based cloud copy of your saved shift library or provide our own cross-device roster synchronization. Manual entry does not send the entered shift content to our recognition service. Other enabled SDKs may still communicate with their providers as described below.

The app reads device regional settings and time-zone information to format dates/times and create calendar events. A work location you enter is text, not GPS tracking.

3. Photos and cloud AI recognition

Cloud recognition is optional and requires your in-app agreement. You can instead enter shifts manually. When you select or photograph a roster and start recognition, the app processes its orientation, lets you preview and rotate it, and compresses it for upload. The upload preparation removes source EXIF metadata, including EXIF location metadata. This does not remove information visibly printed in the image.

The recognition request contains the selected image, the target employee name you provide, its image format and a request identifier. It travels over HTTPS to our service running on Cloudflare Workers. Our Worker sends the image and target name, together with extraction instructions, to a contracted AI gateway and the model provider used for that request. The result is returned to the app for your review. We do not send your saved calendar library, advertising ID, subscription credentials or scan-credit balance in this recognition request.

The entire selected image is uploaded, not just the matching employee's row. It may therefore include coworkers' names or other information visible on the roster even though we request results for the target employee only. Only upload material you are authorized to share. Before selecting it, use another editor to remove unnecessary information. Do not upload patient records, medical details, identity documents or other unnecessary sensitive information. This is a scheduling tool, not a patient-record service.

Our Worker does not persist roster images, target names or recognition results in an application database or object store, and does not put that content in its application logs. They are processed to handle the request, and responses instruct clients not to cache them. This is not a promise that every infrastructure or AI provider has zero retention.

The contracted AI gateway and model providers used to fulfill requests also process submitted content. We have not yet verified a single retention period, model-training treatment or deletion process that applies to every provider used on the actual service route. We therefore do not promise provider-wide immediate deletion or exclusion from model training. Current provider details and applicable privacy terms can be requested through our privacy contact.

ScanMyShift does not use roster content for advertising or train its own models with it. AI output may be wrong; you decide what to save and write to your calendar. We do not make employment or eligibility decisions about you from these results.

4. Camera, photos and calendar access

You can revoke camera or calendar permission in Android settings. Without calendar permission, you can keep shifts in the app but cannot perform calendar operations that require access.

If you choose a Google, workplace, shared or other synchronized calendar, that calendar provider may upload events to its own servers or make them visible to people who can access the calendar. Calendar reminders and lock-screen notifications may also reveal event details according to your device settings. Those copies and displays are separate from ScanMyShift's local storage.

5. Advertising and rewarded scans

We use Google AdMob for native and optional rewarded ads. Google Mobile Ads may process IP addresses, device/account identifiers such as an advertising ID or app set ID, ad interactions and diagnostic information for ad delivery, measurement and fraud prevention. IP addresses can be used to estimate general location; this does not require GPS permission. The exact processing depends on privacy choices and SDK configuration. See Google's SDK disclosure and Google's Privacy Policy.

We use Google's User Messaging Platform to obtain applicable advertising choices before requesting ads. Where required, you can reopen Ad privacy options in Settings. You can also use Android's advertising-ID controls. Non-personalized or limited ads do not necessarily mean no data processing.

We do not attach roster images, employee names, shift details, calendar content or notes to ad requests. Rewarded-scan credits are updated locally when the ad SDK reports that a reward was earned; there is no ScanMyShift server-side reward ledger. Google still processes the ad interaction. Firebase Analytics is separate from the data processing needed by advertising services.

6. Subscriptions

Google Play processes purchases, and RevenueCat manages subscription verification, restoration and Pro access. RevenueCat uses an SDK-generated pseudonymous app user identifier and processes purchase records and subscription status, along with relevant app/device metadata. An identifier called "anonymous" by the SDK is not necessarily anonymous under privacy law. See RevenueCat's Privacy Policy and Google Play data disclosure.

The SDK may connect to RevenueCat to check access or available plans even if you have not purchased. We do not pass the target employee name, roster images or calendar content to RevenueCat. We do not receive your full payment-card details. Pro access depends on RevenueCat's entitlement information, not a separate subscription database operated by ScanMyShift.

Deleting the app or clearing local data does not cancel a subscription or erase store/provider transaction records. Manage or cancel your subscription through Google Play.

7. Usage analytics and crash diagnostics

Configured production releases use Firebase Analytics and Firebase Crashlytics to understand feature usage and diagnose reliability problems. The app does not provide separate Firebase collection switches in Settings. Firebase processing is separate from cloud-recognition agreement and advertising privacy choices.

We send predefined feature events, bounded counts and timing information. Crash reports include technical failure categories and sanitized app-generated stack traces. The SDKs can additionally process installation identifiers, app version, device and operating-system metadata, crash timestamps and native diagnostics. We do not attach names, photos, roster text, shift details, calendar identifiers or purchase credentials to these reports. The app disables Analytics advertising-ID collection, ad-storage consent, ad-user-data consent, ad-personalization signals and automatic screen reporting. See Firebase privacy information.

Firebase may queue or retain information under its service configuration. Clearing ScanMyShift's local data, uninstalling the app or changing an advertising privacy choice does not retract information already sent to Firebase.

8. Service security and support

Cloudflare processes network information, including IP addresses, to deliver and protect the recognition endpoint. We use the edge-provided IP address for rate limiting. Our application logs contain request/trace identifiers, status and error categories, and processing duration—not roster content or raw request bodies. Cloudflare can also keep service/security metadata, such as request time, method, URL and network information, under its own service arrangements. See Cloudflare's Privacy Policy.

If you contact us, we process your email address, message and any information you choose to send to respond and resolve the issue. Do not include payment-card details or unredacted rosters in support messages. We may ask for an app version, approximate request time or transaction reference where needed, rather than unnecessary identity documents.

9. Why we process information and who receives it

We process information to provide requested scheduling and recognition features, verify subscriptions, operate advertising, understand feature usage, improve reliability, answer support requests, and protect the service. The recipients are the providers described above and the calendar service you choose. Our contracted AI gateway may use different model providers to fulfill AI requests. We may also disclose information we hold when legally required or necessary to address fraud, security incidents or legal claims, subject to applicable law.

Where EEA/UK data-protection law applies, the intended bases include consent for optional cloud uploads; performing our service agreement for requested local/calendar and subscription functions; legitimate interests in understanding use, maintaining secure and reliable services, diagnosing failures and handling support; and compliance with applicable legal obligations. Where applicable law requires consent before analytics or diagnostic collection, we will request it through a separate region-appropriate flow before collection. Advertising uses consent where required and the applicable privacy choices. These bases do not give you or us permission to upload somebody else's sensitive information without an appropriate basis.

We do not sell your roster content. Advertising-related identifier processing can nevertheless constitute "sharing", "sale" or targeted advertising under some laws. Where applicable, you may opt out through the provided advertising privacy controls or contact us to exercise your rights; we do not treat a general acceptance of this policy as consent to such processing.

10. Retention and deletion

We cannot remotely read or delete a shift library stored only on your device. For information held by us or providers acting for us, contact our privacy email. We will assess the request, use proportionate verification and assist with applicable deletion requests; we will explain any legal retention requirement or technical limitation. We do not promise that clearing the app erases provider records.

11. Your choices and rights

You may choose manual entry instead of cloud recognition, stop starting new scans, revoke camera/calendar permissions, change available ad privacy choices, edit/delete local shifts and contact us about data we process.

The current app does not provide a standalone cloud-consent-off switch. To reset its stored cloud-recognition agreement, you can successfully complete Clear all local data, which also deletes the other local information described above. You do not need to clear your shifts merely to stop future uploads—stop using recognition and use manual entry. Contact us if you wish to withdraw processing consent or request deletion of already submitted information. Withdrawal does not undo processing that was lawful before withdrawal.

Depending on your location and applicable law, you may have rights to access, correct, delete or receive a portable copy of personal information, restrict processing, withdraw consent, and complain to a data-protection authority. You may also have the right to object to processing based on legitimate interests and to opt out of targeted advertising or legally defined sale/sharing. Contact us using the privacy email; we will respond within applicable legal time limits and will not penalize you for exercising protected rights. Some features necessarily depend on the data needed to provide them.

12. International processing and security

Our providers operate across countries, so information may be processed outside your country, where privacy laws can differ. Where applicable law requires transfer safeguards, we rely on the safeguards made available under the relevant provider arrangements and will provide available information on request. Contact us for information about the providers and safeguards applicable to your request. Accepting this policy alone is not treated as authorization for a transfer where the law requires another basis or safeguard.

Recognition requests use HTTPS. Provider secrets stay on the server, not in the app. Local records use Android app-private storage; the app disables Android's standard app backup setting. The local database and preferences do not use additional app-level database encryption. Protect your device with its security controls. No storage or transmission method is perfectly secure.

13. Children and policy changes

ScanMyShift is designed for people managing work shifts and is not directed to children. If you are below the age at which you may consent to this processing in your location, use the app only with authorization from a parent or legal guardian. If you believe a child has provided information inappropriately, contact us so we can investigate and take appropriate action.

We may update this policy as the app or its providers change. We will update the date and give additional notice or request renewed consent where required. A policy update alone does not authorize a new use that requires your consent.

14. Contact

For privacy questions or requests, email cherishbingo@gmail.com, identifying ScanMyShift and the request. You do not need to create a ScanMyShift account to contact us.