Shiftby Granvure

Your data, clearly explained

Privacy Policy

Shift is built to help shift workers plan with confidence. Core schedules, calendar views, pay estimates, search, and Local Quick Questions work on your device. Cloud features are optional.

Effective September 1, 2026

1. Scope

This policy explains how Granvure LLC handles information through Shift’s mobile app, cloud services, and support experience. “Shift,” “we,” and “us” refer to Granvure LLC as the operator of Shift.

You can use the core local planner without creating an account. Creating an account enables optional account-based features such as sharing, purchase restoration, data requests, and Cloud Ask. A planner created for or explicitly bound to an account remains stored on that installation but is locked to the same verified account; binding does not upload or synchronize the planner.

2. Information we handle

Information stored on your device

Shift stores your work profiles, schedule versions, exceptions, extra shifts, pay settings and estimates, personal calendars and events, reminders, preferences, and pending synchronization changes in its local app storage. Shift also stores a local custody record that says whether the planner is anonymous or account-bound; an account-bound record contains the account’s internal identifier so the app can prevent another account on the same installation from opening it. Secure device storage may retain the same internal identifier as a last-verified local owner proof so an already-bound planner can remain available during a network outage. That proof is cleared on explicit sign-out, account switch, or deletion and cannot authorize cloud or purchase actions. Local search and Local Quick Questions run on-device.

Account and cloud information

If you create an account or enable account-based features, we process your email address, account identifier, authentication state, sharing invitations and relationships, revision metadata, entitlement state, Cloud Ask quota/audit metadata, and account export or deletion requests. Wage rates and estimated earnings are financial information when you choose to store or process them with an enabled cloud feature. Shift does not collect payment-card details; Apple processes App Store payments.

Calendar and notification information

With your permission, Shift can read events from calendars you select, write only after a separate choice, and schedule local reminders. Device-calendar information is normally processed locally. If you deliberately ask Cloud Ask a question that depends on calendar context, a minimized relevant tool result may be processed to answer that request. Local notification content does not contain wage or pay totals.

Ask Shift

Local Quick Questions use deterministic tools on your device and do not use cloud AI or Cloud Ask quota. Cloud Ask is an optional Shift Pro feature. When you choose Cloud Ask, your question is sent through Shift’s server to OpenAI so the model can select a deterministic Shift tool and explain its structured result. The model is not permitted to calculate authoritative schedules, dates, durations, availability, hours, or pay.

Shift does not store raw Cloud Ask prompts or responses in its application database and requests that OpenAI not store the response as product application state. We retain limited audit metadata—such as a request identifier, selected tool, outcome, and timestamps—for up to 30 days. Privacy-minimized provider-attempt records containing identifiers, stage, and timestamp may remain for up to 35 days so monthly security, abuse-prevention, and cost limits cannot be erased by a retry or refund. OpenAI states that API data is not used for training by default unless the account owner opts in. Its default abuse-monitoring logs may retain request and response content for up to 30 days, and supported GPT-5.6 requests may use encrypted prompt-cache tensors that expire within 24 hours, unless Granvure’s production project is approved and configured for Zero Data Retention or Modified Abuse Monitoring. The applicable production setting must be verified before release.

Product analytics and diagnostics

If configured and not opted out, PostHog receives a limited catalog of coarse feature events and app/device metadata. Shift disables PostHog session replay, automatic event/error capture, and IP-based geolocation. Shift does not send schedule values, pay values, calendar content, locations, partner data, email addresses, or Ask prompts to product analytics. You can opt out in More → AI & privacy. Sentry may receive privacy-scrubbed crash, device, and app-version diagnostics; performance tracing is disabled. Shift removes default personal identifiers, request bodies, breadcrumbs, and sensitive exception messages before sending reports.

3. How we use information

  • Provide, secure, and troubleshoot Shift.
  • Authenticate accounts and prevent unauthorized access.
  • Calculate deterministic schedules and pay estimates.
  • Deliver reminders and user-requested calendar actions.
  • Maintain subscription access and restore purchases.
  • Provide read-only sharing that excludes pay information.
  • Enforce Cloud Ask entitlement, rate, and quota limits.
  • Measure coarse product reliability and improve the app.
  • Complete account export and deletion requests.

We do not sell personal information, serve advertising, use IDFA, broker data, or authorize cross-company tracking.

4. Service providers

Supabase

Database, authentication, authorization, Edge Functions, sharing, Cloud Ask controls, and account-request records.

RevenueCat and Apple

Subscription offerings, transactions, entitlement state, renewal, restoration, and purchase management. Apple handles payment credentials.

OpenAI

Optional Pro Cloud Ask intent interpretation and explanation of deterministic tool output. Provider access is server-side only.

PostHog

Privacy-minimized product analytics when enabled. Session replay, automatic capture, and IP-based geolocation are disabled.

Sentry

Privacy-scrubbed crash diagnostics used to keep Shift reliable. Performance tracing is disabled.

These providers process data only to perform services for Shift under their applicable agreements and safeguards. Shift's current reminders are scheduled locally on the device; Shift does not register a remote push token.

5. Partner and family sharing

You choose whether to invite another Shift account. Launch sharing is read-only. Availability-only sharing exposes working/free/busy windows; schedule-detail sharing exposes only the details you authorize. Pay, wage, notes, and private personal-event details are never included in shared projections. You can revoke access in the app.

6. Your choices

  • Use an anonymous local planner without creating an account.
  • When signing in over an anonymous planner, explicitly bind it locally, export it, sign back out and keep it anonymous, or erase it.
  • Decline calendar or notification permission and keep using eligible core features.
  • Choose which device calendars Shift may display or write to.
  • Use Local Quick Questions without Cloud Ask.
  • Decline or disable Cloud Ask processing.
  • Opt out of product analytics in More.
  • Revoke a sharing relationship.
  • Export a device-planner archive or separately export cloud account data in More → Data controls.
  • Request immediate cloud-account deletion or choose a seven-day delay.
  • Manage or cancel an App Store subscription through Apple.

7. Retention and deletion

Planner and Calendar Core information is device-local in this release. Anonymous data remains available locally; account-bound data remains on the installation but is hidden after sign-out or account mismatch until the same account is verified or you explicitly erase it. Shift does not automatically erase, release, or reassign planner custody. Local information otherwise remains until you explicitly erase or release it, clear app data, or uninstall Shift, subject to platform backup behavior. Cloud account records are retained while your account is active and as needed to provide requested services. A cloud export is stored privately for up to 48 hours; each authorized download link lasts about five minutes.

After recent password verification, you may queue cloud-account deletion immediately or choose a seven-day delay. A request can be cancelled only before processing claims it; sharing is revoked when the request is accepted and is not automatically restored by cancellation. Bounded processing removes supported Shift cloud records, deletes the RevenueCat customer before and after Supabase Auth deletion, and preserves an opaque completion receipt plus hashed provider replay/security metadata for up to 90 days. The receipt does not contain the deleted account identifier. Isolated backups are not used for ordinary processing and expire through the service’s backup-rotation schedule. AI audit metadata expires after 30 days; privacy-minimized provider-attempt accounting expires after 35 days.

Cloud-account completion does not automatically erase the device planner or copies you explicitly wrote to Apple, Google, or Exchange Calendar. After verified completion and local session removal, the app asks whether to keep eligible matching planner data anonymously—while removing deleted-account subscription cache and Cloud Ask consent—or erase it. If the receipt is missing or unreadable, Shift keeps content, export, binding, and release locked but still permits a separately confirmed permanent local erase. External calendar copies must be removed in that calendar. Deleting Shift does not cancel an App Store subscription. Shift does not claim per-user deletion from PostHog, Sentry, or OpenAI where no such deletion call is implemented; legal or security records may be retained only as disclosed or required.

8. Security

Shift uses encryption in transit, secure session storage, local planner custody checks, least-privilege access, database row-level security, server-side authorization, effective-dated history, privacy-minimized logs, and idempotent mutation handling. Before showing planner content, the app verifies both the signed-in account and the matching local custody record. It clears Shift widgets and notifications during owner transitions so an earlier account’s data does not reappear for another account. No online service can promise absolute security. Please contact support if you believe your account or data is at risk.

9. Children and geographic scope

Shift is designed for workers and is not directed to children under 13. The initial public release is intended for the United States in English with USD estimates. If you access Shift elsewhere, local laws may provide additional rights.

10. Contact and changes

For privacy questions, contact hello@granvure.com. Account export and deletion are available in More → Data controls after sign-in.

We may update this policy as Shift changes. We will publish the revised effective date and provide additional notice when required.