Privacy
What we do with your information.
The short version: your shifts, your hours, your pay rates and anything you read off a pay stub stay on your phone. There is no account. Purchase services and optional diagnostics are explained below.
1. Who this is about
ShiftStub is an app for people paid by the hour. You use it to record the shifts you work and to see what your next paycheck should be. This page explains what happens to the information you put into it.
It is written in plain English on purpose. If anything here is unclear, that is a fault in this page — write to majesticbits01@gmail.com and we will fix the wording.
2. What stays on your phone
Everything you enter. Your shifts and hours. Your pay rates and pay rules. Your employers and job names. Your notes, and every figure you type in off a pay stub. All of it is processed and stored on your device.
We do not receive it, so we cannot look at it, share it, sell it, or lose it. There is no account to create, no password, and no server holding your record.
Every screen works with no signal. The pay math runs on your phone, not on ours.
3. What the app does send, and to whom
Five kinds of information are declared to Apple for the iOS app. None of them is linked to you, and none of them is used for tracking. This list corresponds to the App Store privacy label.
| Type | What it actually is | What it is for | Optional? |
|---|---|---|---|
| Crash Data | That the app stopped, and whether that was fatal. | App functionality — so a bug that breaks the app on your phone can be found and fixed. | Yes. Off unless you turn it on. |
| Other Diagnostic Data | The error class, the error code, and which screen it happened on. No message text and no stack trace. | App functionality. | Yes. Off unless you turn it on. |
| Product Interaction | Nine counting events, such as “a shift was saved”. Every property is a bucket, never a value: never your hours, never your pay, never a date. | Analytics — to know which parts of the app get used. | Yes. Off unless you turn it on. |
| Device ID | Random identifiers, not your phone’s ID. One groups diagnostics and is created only when you enable diagnostics. RevenueCat creates another to identify the anonymous install and check whether Pro is active. | Analytics, and app functionality. | The diagnostics one, yes. The purchase one, no — see below. |
| Purchase History | Which subscription you bought, and whether it is still active. | App functionality — it is how Pro stays unlocked. | No. There is no switch for this, and saying otherwise would be the one false answer on the form. |
The two diagnostics switches
The first three rows above are covered by two switches in Settings. Both are off when you install the app. Nothing is sent unless you turn them on. Turning one off takes effect immediately and throws away anything that was already waiting to be sent.
These are counts, not content. The app records that a shift was saved, not what the shift was. It records that something went wrong on a screen, not what was on it.
Purchases are not optional
ShiftStub asks the store whether Pro is active on this phone every time you open the app and every time you come back to it. That question goes through RevenueCat, the company that handles Pro subscriptions for us, whether or not you have ever bought anything.
What goes with it: a random identifier RevenueCat makes for this install, whether Pro is active, and the store receipt after a purchase so it can be checked. No hours, pay amounts, name or email from your ShiftStub record are sent.
There is no way to switch this off and still have Pro, because it is the mechanism that keeps Pro unlocked. We would rather say that plainly than bury it.
Two things accompany every diagnostics signal
A random identifier marks one run of the app and is discarded when the app closes. The time is rounded down to the minute. Neither is a figure from your work record.
4. Everywhere the app can reach the network
This is the complete list. It was checked call site by call site in the code.
- Diagnostics — to TelemetryDeck, and only when you have turned a diagnostics switch on. There is no analytics SDK in the app; it is a few lines of the app's own code sending a short list of allowed events.
- Purchases — to RevenueCat, whenever the app starts and when it comes back to the foreground, to check whether Pro is active.
- Anything you tap that opens a browser — a link like this one hands over to your phone's browser, and from there your browser's rules apply, not ours.
And what is not there: no third-party crash-reporting SDK, no advertising identifier, no ad networks, no push-notification service, no tracking domains at all. Notifications are generated on your phone by your phone. There are zero marketing notifications, ever — that is a commitment, not a setting you have to find and turn off.
5. Pay stubs
You type the figures off your stub yourself. There is no camera in the app, it cannot open a PDF from a payroll portal, and no picture of your stub is taken, stored or sent.
- Social security numbers, bank account fragments and routing numbers are struck out before text is stored, and the app refuses to store a line that has not passed that step.
- Nothing is saved or compared until you look at it and confirm it.
- Only the confirmed figures are kept.
6. Backup and moving to a new phone
Automatic backup is free and is never behind the paywall. It uses your phone's own backup — iCloud on iPhone, Android Auto Backup on Android — so the copy sits in your account with Apple or Google, under their terms, not ours. The app tells you whether your hours are included in that backup. It cannot tell you when the backup last ran, because neither Apple nor Google tells an app that.
There is no ShiftStub server, and nothing of yours sits on one. Moving your record between phones is done with the export file below, which you make and carry yourself.
You can also make your own encrypted export file, free, and it moves between iPhone and Android.
7. Keeping and deleting
Because your record lives on your phone, you control how long it lasts. Uninstalling the app removes the local database.
“Delete everything” on the Backup screen erases shifts, corrections, history and job settings from this phone, then reclaims the space. You must type a phrase to enable the button. The app warns you to export a file first; deletion cannot be undone.
This reaches only what is on your phone. Copies already held by iCloud or Google's backup are outside ShiftStub's reach. Clear those copies from your phone's own settings. The app states this limit on the same screen.
Edit history dies with the shift it belongs to. If you delete a shift, its history goes with it.
8. The recent diagnostics log
The Privacy screen shows the last 25 diagnostics entries, newest first, with the time each one went. Both diagnostics switches start off, so the list can be empty. It does not include RevenueCat or App Store requests and is not a complete network log. This log stays on your phone and is never sent anywhere itself.
Contacting support
If you email majesticbits01@gmail.com, your email address, message and any attachments are sent to our Gmail mailbox and processed by Google to deliver and store that correspondence. We use the information you choose to send to answer your request and investigate reported problems. Please do not include sensitive details that are not needed for support. You can contact the same address to request deletion of support correspondence, subject to applicable recordkeeping requirements.
9. Children
ShiftStub is a tool for people who are working for wages. It is not directed at children, it collects nothing that would identify anyone, and it has no accounts, no messaging and no user-generated content that anyone else can see.
10. Where you are
Version 1 is for the United States, in US English, and its pay rules are US labour law. Nothing here is designed around the rules of another country. If you are outside the US, this is worth knowing before you install it.
11. Changes to this page
If what the app does changes, this page changes first. Material changes will be noted here with a new date, and the app will point at the updated page. A change that would mean the app sends something new would also mean a new choice for you, not a quiet update to a document.
12. Getting in touch
Questions about any of this go to majesticbits01@gmail.com. There is no account to verify, so ask plainly and we will answer plainly.