Privacy notice
Who we are
Shyft is made by Credefolio. In this notice, "we" and "us" mean Credefolio, and "Shyft" means the Shyft app, its servers and this website. Shyft is in beta, and this notice describes what the beta does with your data today.
The short version
- Your shifts, receipts, photos and reports are stored on your phone, encrypted.
- Cloud backup is off by default. If you turn it on, your records (not yet your photos) are encrypted on your phone before upload, with a key made from a recovery code only you hold. We can't read your backups.
- Our servers only see what they need to: receipt images while Shyft reads them, emails you forward to your Shyft address, and alerts that your calendar changed.
- Calendar access is read-only. Shyft can't create, edit or delete events.
- If you turn on the recruiter availability profile (off by default), an anonymous summary of your availability is shared with our servers. It never includes your name or contact details.
- If you join the waitlist, we keep your email, organization and role only to contact you about Shyft.
- We don't sell your data, show ads or use trackers. This website sets no cookies and runs no analytics.
- You can export your records or delete your account at any time from Settings. Exports don't include photos yet.
What stays on your phone
Your ledger lives on your device: hospitals, assignments, shifts, receipts and their photos, mileage trips, your filtering and matching rules, and the reports you generate. It is encrypted with AES-256-GCM. The encryption key is held in the Android Keystore on your phone and never leaves the device.
If you turn on the app lock, Shyft asks for your fingerprint, face unlock or device PIN when it opens. Biometric checks are done by your phone's operating system; Shyft never receives your face or fingerprint data.
Unless you turn on encrypted cloud backup, your ledger exists only on this phone, and we can't recover it if you lose it. With a backup, you can restore your records on a new phone with your recovery code. We can't do that for you, because we never see the code. Settings → Export all data also saves your records as a file. Neither includes photos yet.
Encrypted cloud backup
Cloud backup is off until you turn it on in Settings → Cloud backup. Shyft then shows a 27-character recovery code once, and you confirm you saved it before backup starts. A backup is made each time you tap Back up now.
- Encrypted on your phone. Each backup is encrypted with AES-256-GCM before it leaves your phone, using a key made from your recovery code. The recovery secret is kept in the Android Keystore on this phone. Our servers receive only the encrypted backup, its size and date, and a hashed identifier derived from the code. We can't read your backups, and we can't reset or recover your code. Anyone who has your code can restore your backups, so keep it private.
- What's included: hospitals, assignments, shifts, receipt details, mileage trips, time off, credentials, CME activities, timesheets, offers, card transactions, deposits, invoice contacts and billing details, receipt drafts and matches, your rules and tax settings, your recruiter profile answers, and records you deleted in the last 90 days, marked as deleted so the deletion carries over.
- Not included yet: photos (receipt images, credential and CME certificates, and tax-home evidence). Settings tied to this phone, such as your calendar connection, sign-in and app lock, are never backed up.
- Restoring: on a new phone, install Shyft, open Settings → Cloud backup and enter your recovery code. You see what will change before anything is restored, and restoring merges the backup into the phone without deleting anything on it. Your recruiter profile comes back with sharing off; you turn it on again yourself.
- How long we keep it: the newest 3 backups, each up to 5 MB encrypted. Once there are three, each new backup replaces the oldest. Turning backup off stops new backups and keeps the stored ones, so you can still restore. To delete them, delete your account in Settings, which deletes the backups uploaded from this phone, or email beta@credefolio.com. Backups another phone uploaded with the same code are deleted when that phone's account is deleted, or once three newer backups have replaced them.
What reaches our servers
| Data | Why | How long we keep it |
|---|---|---|
| An anonymous account ID and access token | To tell your device apart from others. The token is stored only as a hash. | Until you delete your account. |
| Your personal forwarding address, approved senders and forwarding addresses | So forwarded receipts reach you, and only from senders you've approved. We send a confirmation email to verify a forwarding address. | Until you remove them or delete your account. |
| Emails you forward to Shyft, and the receipt details read from them | To create receipt drafts in your app, and to re-read an email if you ask. | Until you delete your account. |
| Receipt photos you scan | To read the merchant, date and total from the image. | Not stored. The image is processed in memory and the text is sent back to your phone. |
| Calendar change alerts | Google or Microsoft notify our servers that your calendar changed, so your phone knows to check. The alert contains no event details. | Until the alert channel expires, you disconnect the calendar or delete your account. |
| Your AI setting and a daily request count | To respect your choice and apply fair-use limits. | Until you delete your account. |
| Encrypted cloud backups, only if you turn them on | So you can restore your records on a new phone. We receive only encrypted data we can't read, its size and date, and a hashed identifier derived from your recovery code. See cloud backup. | The newest 3 backups, until you delete your account; turning backup off keeps them. To delete them sooner, email beta@credefolio.com. |
| Your anonymous availability profile, only if you turn it on | So verified hiring teams can send you relevant offers once the recruiter beta opens. See availability profile. | While sharing is on. Turning it off or deleting your account deletes it. |
| Waitlist signups: email, organization, role, and the date and version of the consent you gave | To contact you when the recruiter beta or the physician app beta has a spot for you, or when a new Android build ships if you signed up for updates. See the waitlist. | Until you ask us to remove it, or until we close the waitlist. |
| Standard request logs (IP address, time, request path) | To keep the service secure, rate-limit abuse and fix problems. | Up to 7 days in Cloudflare Workers Logs, then deleted automatically. |
Recruiter availability profile (opt-in)
Shyft can let hospitals, agencies and recruiters send you structured offers. This is off by default. It starts only when you turn on sharing in Settings → Credentials → Get offers and confirm, and you can turn it off at any time.
While sharing is on, your phone sends our servers an anonymous summary built from the profile you review before sharing. It contains only:
- your specialty and board status,
- the states where you hold a current license, with each expiry to the month,
- the weeks you're open over the next six months (a week counts only if it has at least three open days, and exact dates are never sent),
- the shift times and lengths you prefer, and your minimum rate,
- your home state, how far you're willing to travel (100, 250 or 500 miles, or anywhere) and any other states you'd work in.
It never includes your name, email, phone, sign-in identity, city or address, the hospitals and agencies you work with, your assignments or shift titles, exact dates, income, receipts, taxes or credential numbers. Your name and contact details are shared with a hiring team only when you tap Interested on one of their offers.
This is the one part of your ledger that doesn't stay only on your phone, and only while you've chosen to share it. We keep one copy per account and replace it whenever you edit your profile. Turning sharing off deletes it from our servers (if the deletion can't reach us right away, the app retries the next time you open Settings), and deleting your account deletes it too.
Recruiter accounts and search aren't open yet, so no hiring team can see profiles today. This section will be updated before they are.
The waitlist
Hospitals, staffing agencies, recruiters and physicians can join the waitlist on this website without an account. When you submit the form, your browser sends what you typed straight to our servers on Cloudflare. We store:
- your email address,
- your organization, if you gave one,
- the role you chose (hospital, agency, recruiter or physician),
- when you signed up and which version of the consent text you agreed to.
We don't store your IP address or browser details with the entry. Your request passes through standard request logs like any other (see the table above), and to limit abuse your IP address is kept in a separate signup counter for one hour, then removed by a daily cleanup.
We use these details only to contact you about the beta you signed up for. We don't send newsletters, share the list or add it to any marketing tool. Signing up again with the same email keeps your first entry unchanged. To see, correct or remove your entry, email us at the address under Contact.
Your calendar
When you connect a calendar, you sign in with Google or Microsoft directly. Shyft requests read-only access only:
- Google:
calendar.calendarlist.readonlyandcalendar.events.readonly - Microsoft Outlook:
Calendars.Readandoffline_access(to stay signed in for background sync)
Events are fetched by your phone and stay on your phone. Sign-in tokens are kept in your phone's secure storage. You choose which calendars Shyft reads, and nothing becomes a shift until you accept it. You can disconnect at any time in Settings, and you can also revoke access from your Google or Microsoft account.
AI receipt reading
AI receipt reading is off by default, and it isn't enabled on our servers yet, so today every receipt is read by Shyft's own text recognition and rules. Before it is, we'll name the AI processor under Service providers, with its retention and training terms, and you'll still choose whether to use it. You can turn it off again at any time.
Service providers
We use a small number of providers to run Shyft, each only for the purpose listed:
- Resend, to receive forwarded emails and send confirmation emails.
- Cloudflare, to run our servers and database, store the data listed above, and serve this website.
- An AI processor, only once AI receipt reading is switched on and you choose to use it. We'll name it here first.
Google and Microsoft handle calendar sign-in under their own privacy policies. The Android app is downloaded from shyft.credefolio.com, not from Google Play.
Patient information
Shyft is for your own business expenses. It is not designed to store protected health information. Please don't photograph or forward documents that include patient details.
Export and delete
- Export: Settings → Export all data saves your records as a file you can keep or share. Photos aren't included yet.
- Delete: Settings → Delete account deletes your server account, including stored emails, drafts and calendar alert channels. It also deletes the cloud backups this phone uploaded, disconnects your calendar, and erases your ledger, photos, encryption key and backup recovery secret from your phone. This can't be undone.
Deleting the app without deleting your account removes your ledger from the phone but leaves the server records listed above. Email us and we'll delete them.
This website
shyft.credefolio.com is a static page. It sets no cookies, loads nothing from third parties and runs no analytics. A small script on the page switches between the physician and hiring views, opens the menu on small screens, checks /download/android/latest.json for the latest Android build, and sends the waitlist form only when you submit it. The view you pick is kept in the page address (?for=hiring), not in a cookie. Cloudflare, which serves it, processes standard connection data such as IP addresses to deliver the page and protect it from abuse.
Children
Shyft is built for practicing physicians and is not intended for anyone under 18.
Changes
If we change how we handle your data, we'll update this page and the date at the top. Planned changes include account sign-in, photos in cloud backups and optional sync between devices; this notice will be updated before any of them launches.
Contact
Shyft is made by Credefolio. Questions, corrections or deletion requests go to beta@credefolio.com.