ShiftLedger — Privacy Policy
Last updated: 15 September 2026
The short version:
- No server, no account, no login. The developer receives nothing and can't see your data.
- Your schedule, notes, employer names, and pay figures live in a database on your iPhone.
- Your calendar feed address is treated like a password: Keychain only, masked, never in a database, log, export, or error message.
- ShiftLedger only reads calendars you pick, never edits or deletes an event, and reaches the network only for things you set up: your calendar address, your own iCloud (off by default), the share sheet, and Apple for purchases.
- No analytics, ads, tracking, or third-party SDKs. Deleting the app deletes your data.
Who this is from
ShiftLedger is developed by Alan Chang. This policy covers the iPhone app only, not Apple's own services or your calendar provider, which have their own policies (see the Terms of Service for terms of use). There's no backend, account, sign-up, or login, so nothing about your schedule, hours, pay, or calendar address reaches the developer.
What ShiftLedger stores on your iPhone
All of it lives in a local database on your device: shift dates, times, and codes; verbatim calendar-event titles and notes; your notes, dispute notes, and recorded actual times; calendar source, job, and employer names, plus account labels like "iCloud" or "Gmail" (never a raw email); your full pay configuration (base rate, overtime tiers, differentials, holiday rules, stipends); and paycheck amounts, adjustments, and settings. None of it syncs to Apple's servers — the only off-device copy is the optional iCloud backup mirror described below.
Calendar access and your feed address
A calendar feed's web address can be used by anyone who has it to read your whole schedule, so it's kept only in the iOS Keychain, never a database, log, export, or error message — shown masked, and deleted the moment you remove that source.
ShiftLedger only reads calendar events, never creates, edits, or deletes any, and only from calendars you pick (iOS has no separate read-only tier). The prompt reads, verbatim: "ShiftLedger reads the calendars you choose, to import your shifts. It never modifies or deletes calendar events." Per event it reads identifier, title, start/end time, time zone, all-day flag, notes, and status — never location, attendees, organizer, URL, or alarms.
If your Calendar app already has Google or Outlook/365 added, ShiftLedger sees those calendars too, via Apple's EventKit, with no separate sign-in to either company.
When information leaves your iPhone
Four channels, all things you initiate or turn on — never the developer:
- The calendar host you chose. A feed subscription issues a read-only HTTPS request to download your schedule; nothing is uploaded, and the recipient is never the developer.
- Your own private iCloud, only if you turn on the optional backup mirror. Off by default; see "Backups" below.
- Wherever you send an exported file, through the share sheet. CSV, PDF, backup, pay-rules, shift-code preset, or diagnostics.
- Apple, for purchases, handled entirely by StoreKit.
Outside these four, ShiftLedger makes no network connections and shares data with no one.
What ShiftLedger does not do
No analytics, usage tracking, or A/B testing; no advertising or ad identifiers (so no App Tracking Transparency prompt); no crash reporting; no third-party SDKs, only Apple's own frameworks; no profiling; no sale or sharing of personal information, since there's none to sell.
Health information and PHI
ShiftLedger is a work-schedule and pay tool, not a medical app. It doesn't use HealthKit, isn't designed to collect protected health information (PHI), and the developer is not a HIPAA covered entity or business associate.
Be aware, though: calendar titles and notes are stored verbatim, unredacted, and can reach CSV exports and backup files. Don't connect a calendar, or type into a shift's notes, anything identifying a patient or otherwise protected. Treat it like a note-taking app: fine for shift codes, not someone else's health information.
Backups
ShiftLedger keeps versioned backup snapshots locally by default. Settings also has a "Copy to iCloud" toggle, off by default; on, it copies snapshots to your own private iCloud Drive.
A snapshot contains a lot — shifts, verbatim calendar titles and notes, job names, your pay configuration including base hourly rate, and paycheck amounts — as plain, unencrypted JSON, protected only by iOS file protection and your Apple ID. Treat a backup file like a payslip — it has your pay rate and earnings in readable text. A backup never contains your feed address, which is why restoring one asks you to re-enter it.
Sharing and exports
Every export goes through the share sheet, to a destination you choose: CSV, PDF, backup, pay-rules, shift-code preset, or diagnostics. Nothing is ever sent automatically. Anything personal, everything except the shift-code preset, shows a confirmation naming the file's contents, including "Anyone you send it to can see what you're paid," with no "don't ask again."
The shift-code preset, meant for a colleague, skips that: it carries only a code's text, start time, duration, and a not-working flag — never shifts, pay, or your feed address. The diagnostics file carries counts, settings, and version/device strings — never calendar names, your feed address, job names, or amounts.
Purchases and notifications
Purchases — a subscription with a free trial, or a one-time lifetime unlock — are handled entirely by Apple through StoreKit. ShiftLedger never sees your Apple ID, name, email, or payment details, keeping only a small local entitlement record.
ShiftLedger can also schedule a local reminder after a shift ends, showing its code — set by your iPhone itself, no server involved.
Your choices and controls
- Calendar access: revoke anytime in iOS Settings → Privacy & Security → Calendars.
- iCloud backup mirror: turn off in Settings; delete copied files in the Files app.
- Removing a calendar source: deletes its stored feed address from the Keychain.
- Deleting the app: removes the local database, backups, and Keychain entries — iCloud files remain until deleted.
There's no "delete my account" request, since there's no account: deleting the app, plus clearing iCloud if used, removes everything.
Your privacy rights, and children
Regulations like the GDPR, UK GDPR, and CCPA give you rights to access, correct, delete, and port your data. The developer never holds any of it, so there's nothing on that side to act on — the controls above are how you exercise these rights directly, and the developer does not sell or share personal information.
ShiftLedger doesn't ask your age and doesn't collect any. It's a professional tool built for employed adults, not directed at children.
Security
Your feed address is stored in the iOS Keychain; everything else is protected by standard iOS file protection, which depends on your device passcode. Backup snapshots aren't encrypted by the app itself, so anyone who could read one directly could read its contents, pay rate included.
Changes and contact
If this policy changes, the "Last updated" date changes with it, and material changes are reflected here before they take effect in a released version. Questions about this policy or how ShiftLedger handles data: shiftledger@martymail.net.
See the Terms of Service for the terms governing your use of ShiftLedger.
This page is published from the same text reviewed against ShiftLedger's source code. See also the Terms of Service, or get in touch.