Privacy Policy

Effective January 1, 2026

This Privacy Policy describes how Shift Secure (“Shift Secure,” “we,” “us,” or “our”) collects, uses, discloses, and protects information when you use our website, mobile applications, and related services (collectively, the “Service”). By accessing or using the Service, you agree to this Policy. If you do not agree, do not use the Service.

Important. Shift Secure is a workflow productivity tool. It is not a medical device, electronic health record, or clinical decision-support system, and it is not intended to diagnose, treat, cure, or prevent any disease. You are solely responsible for the clinical accuracy of any content you enter and for complying with all laws applicable to your handling of patient information, including HIPAA where applicable.

1. Information We Collect

Account information. When you create an account, we collect your email address, password (stored hashed), display name, and profile details you choose to provide.

Content you submit. Tasks, handoff templates, transcripts, draft SBAR summaries, alerts, and other content you create or upload to the Service.

Subscription & purchase data. Purchases on mobile are processed by Apple or Google. We receive transaction identifiers and entitlement status from RevenueCat. We do not receive or store your full payment card number.

Device & usage data. IP address, device type, OS version, app version, language, crash logs, and basic usage telemetry necessary to operate and improve the Service.

Cookies & similar technologies. The web app uses strictly necessary cookies and local storage for authentication and session management.

2. How We Use Information

  • To provide, maintain, and secure the Service.
  • To authenticate users and enforce access controls.
  • To process subscriptions and manage entitlements.
  • To generate AI-assisted summaries from content you submit.
  • To diagnose issues, prevent abuse, and improve reliability.
  • To communicate service-related notices.
  • To comply with legal obligations.

3. Legal Bases (EEA/UK Users)

Where GDPR applies, we process personal data on the bases of contract performance, our legitimate interests (security, service improvement, fraud prevention), consent (where required), and legal obligation.

4. AI Processing

Transcripts and notes you submit to the SBAR summarization feature are transmitted to our AI inference provider strictly to generate the requested output. We instruct providers not to train their foundation models on your inputs. Do not submit information you are not authorized to share, and de-identify patient data wherever feasible.

5. Sharing & Subprocessors

We do not sell personal information. We share data only with vendors that help us operate the Service under contractual confidentiality and security obligations:

  • Cloud hosting and database (Supabase / Cloudflare).
  • Subscription management (RevenueCat, Apple, Google).
  • AI inference (Google via Lovable AI Gateway).
  • Error and performance monitoring.

We may also disclose information when required by law, to enforce our Terms, or to protect the rights, safety, or property of any person.

6. Data Retention

We retain account and content data for the life of your account and for a limited period thereafter to satisfy legal, tax, and security obligations. You may delete your content at any time and request full account deletion as described below.

7. Security

We use industry-standard safeguards including encryption in transit (TLS), encrypted storage at rest, role-based access controls, and database row-level security. No method of transmission or storage is 100% secure. You are responsible for keeping your credentials confidential.

8. Your Rights

Depending on your jurisdiction, you may have rights to access, correct, port, or delete your personal data, restrict or object to certain processing, and withdraw consent. To exercise any right, email privacy@shiftsecure.app. We will respond within the time required by applicable law.

California residents (CCPA/CPRA): You may request disclosure of categories and specific pieces of personal information collected, deletion, and correction. We do not sell or share personal information for cross-context behavioral advertising.

9. Account Deletion

You may delete your account at any time by emailing privacy@shiftsecure.app from your registered address. Upon verified request, we will delete your account and associated content within 30 days, except where retention is required by law.

10. Children

The Service is intended for users aged 18 and older and is not directed to children under 13. We do not knowingly collect personal information from children.

11. International Transfers

The Service is operated from the United States. If you access it from outside the United States, you consent to transfer of your information to the United States and other jurisdictions where our vendors operate.

12. HIPAA Notice

Shift Secure is not offered as a HIPAA-covered service by default and we do not enter into Business Associate Agreements through the consumer App Store distribution. If you are a covered entity or business associate, you must de-identify patient data before entering it into the Service or contact us to discuss enterprise terms.

13. Changes

We may update this Policy from time to time. Material changes will be communicated through the Service or by email. Continued use after the effective date constitutes acceptance.

14. Contact

Questions about this Policy: privacy@shiftsecure.app.

See also our Terms of Service.