Who operates NightShifter
NightShifter is operated by Plumios. Contact hello@plumios.com for privacy questions or requests.
Data the app may process
- Account data: email address, Supabase user ID, authentication and account timestamps in production builds. The Android closed-test guest build does not require an account.
- Planning data: shifts, timezone, commute, sleep preferences, constraints, action status, reminders and check-ins that you enter.
- Optional device data: selected sleep records read from Apple Health or Health Connect and calendar events considered as shift candidates after permission. The core planner works without this access.
- Purchase data: store product, transaction status, entitlement, expiry, environment and a pseudonymous app user ID processed by Google Play or Apple and RevenueCat.
- Diagnostics and product events: app version, platform, timezone category, session identifier and allowlisted feature events. We design analytics to exclude employer names, calendar titles, free-text notes and exact health values.
Where data is stored
Core app data is stored in an account-isolated SQLite database on the device. Production account and entitlement records may be stored in Supabase PostgreSQL objects under the nightshifter schema. A Cloudflare Worker verifies authenticated API requests and RevenueCat webhooks. RevenueCat, Apple and Google process subscription data under their own terms.
Why data is processed
We process data to provide and secure the planner, remember choices, deliver requested reminders, restore purchases, answer support requests, prevent abuse and understand reliability. Where consent is required for optional device access, you can withhold or revoke it.
Sharing
We do not sell personal or health data and do not use it for third-party advertising. Service providers receive only the data needed to operate authentication, hosting, subscriptions, app distribution and support. Legal disclosure may occur when required by law or needed to protect rights and safety.
Retention and deletion
Local data remains until removed in the app, cleared through device settings or uninstalled, subject to device backups. Server account and planning data is retained while the account is active and for a limited period needed for security, legal or financial records. Purchase records may need longer retention. Request export or deletion at hello@plumios.com. We will verify identity.
Security
Production user routes require Supabase authentication; user IDs are derived from verified tokens. Database row-level security isolates accounts. Server secrets remain outside the app. No system is completely secure, so we maintain updates and incident response.
Children, international use and changes
NightShifter is not directed to children. Data may be processed in countries where our providers operate, with safeguards required by applicable law. Material policy changes will update the effective date and, when appropriate, be communicated in the app.