Privacy
What we do with your information.
The short version: your shifts, your hours, your pay rates and anything you read off a pay stub stay on your phone. There is no account, so there is nothing to log into and nothing of yours on a server.
1. Who this is about
ShiftStub is an app for people paid by the hour. You use it to record the shifts you work and to see what your next paycheck should be. This page explains what happens to the information you put into it.
It is written in plain English on purpose. If anything here is unclear, that is a fault in this page — write to support@shiftstub.com and we will fix the wording.
2. What stays on your phone
Everything you enter. Your shifts and hours. Your pay rates and pay rules. Your employers and job names. Your notes. Anything you type in or photograph from a pay stub. All of it is processed and stored on your device.
We do not receive it, so we cannot look at it, share it, sell it, or lose it. There is no account to create, no password, and no server holding your record.
Every screen works with no signal. The pay math runs on your phone, not on ours.
3. What the app does send, and to whom
Five kinds of information are declared to Apple and Google. None of them is linked to you, and none of them is used for tracking. This is the same list, in the same words, as the App Store privacy label and the Google Play Data Safety form.
| Type | What it actually is | What it is for | Optional? |
|---|---|---|---|
| Crash Data | That the app stopped, and whether that was fatal. | App functionality — so a bug that breaks the app on your phone can be found and fixed. | Yes. Off unless you turn it on. |
| Other Diagnostic Data | The error class, the error code, and which screen it happened on. No message text and no stack trace. | App functionality. | Yes. Off unless you turn it on. |
| Product Interaction | Nine counting events, such as “a shift was saved”. Every property is a bucket, never a value: never your hours, never your pay, never a date. | Analytics — to know which parts of the app get used. | Yes. Off unless you turn it on. |
| Device ID | Two random identifiers created when the app is installed. They are not your phone’s ID and they are not linked to you. One groups the diagnostics above; the other is how the store knows which anonymous install bought Pro. | Analytics, and app functionality. | The diagnostics one, yes. The purchase one, no — see below. |
| Purchase History | Which subscription you bought, and whether it is still active. | App functionality — it is how Pro stays unlocked. | No. There is no switch for this, and saying otherwise would be the one false answer on the form. |
The two diagnostics switches
The first three rows above are covered by two switches in Settings. Both are off when you install the app. Nothing is sent unless you turn them on. Turning one off takes effect immediately and throws away anything that was already waiting to be sent.
These are counts, not content. The app records that a shift was saved, not what the shift was. It records that something went wrong on a screen, not what was on it.
Purchases are not optional
If you buy Pro, the purchase goes through Apple's or Google's store, and a service called RevenueCat handles checking that it is still valid. That means RevenueCat receives which subscription you have and whether it is active, tied to a random identifier rather than to your name.
There is no way to switch this off and still have Pro, because it is the mechanism that keeps Pro unlocked. We would rather say that plainly than bury it.
4. Everywhere the app can reach the network
This is the complete list. It was checked call site by call site in the code.
- Diagnostics — to TelemetryDeck, and only when you have turned a diagnostics switch on. There is no analytics SDK in the app; it is a few lines of the app's own code sending a short list of allowed events.
- Purchases — to RevenueCat, whenever the app starts and when it comes back to the foreground, to check whether Pro is active.
- Checking for updates — the app is built with Expo's update service configured, which means it can ask Expo's servers whether a newer version of the app's code is available. That request carries technical details about the build, not anything about you or your shifts.
- Anything you tap that opens a browser — a link like this one hands over to your phone's browser, and from there your browser's rules apply, not ours.
And what is not there: no crash-reporting company, no advertising identifier, no ad networks, no push-notification service, no tracking domains at all. Notifications are generated on your phone by your phone. There are zero marketing notifications, ever — that is a commitment, not a setting you have to find and turn off.
5. Pay stubs
You can photograph a paper stub, share in a PDF from a payroll portal, or type the numbers in yourself. Whichever you choose:
- The text is read on your phone, by your phone's own text recognition.
- Social security numbers, bank account fragments and routing numbers are struck out before anything else touches the text, so only the struck-out version can ever be stored.
- Nothing is saved or compared until you look at it and confirm it.
- The image itself is not kept unless you ask for it to be. Only the confirmed lines are.
- If the reading is poor, the app tells you so and offers manual entry. It does not quietly send your stub to a server instead. There is no such fallback.
6. Backup and sync
Automatic backup is free and is never behind the paywall. It uses your phone's own backup — iCloud on iPhone, Android Auto Backup on Android — so the copy sits in your account with Apple or Google, under their terms, not ours. The app shows you its status so you can see it happened.
Sync across your own devices is a Pro feature. It pairs two of your phones with a QR code — again, no account. What sits on the server is an encrypted blob that only your devices can open. We cannot read it. There are no recovery keys, which is the honest trade: if you lose both devices and your export, nobody can get it back for you. Delete the pairing and the blobs are deleted, with a hard purge within 30 days.
You can also make your own encrypted export file, free, and it moves between iPhone and Android.
7. Keeping and deleting
Because your record lives on your phone, you control how long it lasts. Uninstalling the app removes the local database.
“Delete everything” in Settings wipes the local database, asks the platform to delete the backup, and deletes any sync blobs. It offers you a final export first, so deleting is not the same as losing.
One honest limitation: on Android, Auto Backup copies age out on Google's schedule rather than ours, so a deletion request there is a request. The app states this on screen at the moment you press the button rather than in a document you would have to find.
Edit history dies with the shift it belongs to. If you delete a shift, its history goes with it.
8. The log of everything it has ever sent
Settings contains a list of everything the app has actually sent from your phone. Not a description of what it might send — the list. If this page and that list ever disagree, the list is what happened, and we want to hear about it.
9. Children
ShiftStub is a tool for people who are working for wages. It is not directed at children, it collects nothing that would identify anyone, and it has no accounts, no messaging and no user-generated content that anyone else can see.
10. Where you are
Version 1 is for the United States, in US English, and its pay rules are US labour law. Nothing here is designed around the rules of another country. If you are outside the US, this is worth knowing before you install it.
11. Changes to this page
If what the app does changes, this page changes first. Material changes will be noted here with a new date, and the app will point at the updated page. A change that would mean the app sends something new would also mean a new choice for you, not a quiet update to a document.
12. Getting in touch
Questions about any of this go to support@shiftstub.com. There is no account to verify, so ask plainly and we will answer plainly.