Privacy Policy – ShiftMate

Last updated: 31 August 2026

This Privacy Policy explains how ShiftMate ("the App") accesses, uses, stores, and shares data when you use the app.

Data controller: Eros Fava, an individual
Address: Via Fontana di Papa 33, Ariccia (RM), Italia
Project / developer name: Mety° (not a separate legal entity)
Contact: contact@mety.app
No data protection officer (DPO) has been appointed.

1. Scope

This Privacy Policy applies to ShiftMate and its related services and features, including shift calendar management, notes, voice notes, file and image import, shared calendars, backup, premium features, in-app feedback, and optional AI-related features.

1.1 Purposes and legal bases

Account management, synchronization, imports, requested AI responses, backup and purchase entitlement checks are used to provide the features you request (GDPR Article 6(1)(b)). Required data may be needed to provide the selected online feature; declining an optional feature does not require you to upload its content. Security and abuse prevention rely on the legitimate interest in protecting the service (Article 6(1)(f)); compliance with legal obligations and rights requests relies on Article 6(1)(c). General support correspondence is handled to answer your enquiry, on a contractual basis where related to the service or otherwise on the legitimate interest in responding.

Google Analytics is optional and relies on your consent (GDPR Article 6(1)(a)), collected during onboarding as described in section 6.1 for the planned release. Advertising choices are described in section 7. Temporary OCR quality checks are separate from the processing strictly necessary to fulfil an import; their legal basis must be assessed before final publication, as must any processing of special-category data under GDPR Article 9. An Android permission, a pre-enabled switch or merely using the app must not be represented as consent to an unrelated purpose.

2. Data stored locally on your device

ShiftMate is primarily designed to store your work-related information locally on your device. Depending on the features you use, the app may store data such as:

Unless you explicitly use a feature that sends data off your device, this information is stored locally in the app on your device.

3. Permissions the app may request

Depending on the features you choose to use, ShiftMate may request permissions such as:

These permissions are requested only for the related app features and are not intended for surveillance, background listening, or unrelated data collection.

Health Connect readings are used on the device to display activity, sleep and shift-related comparisons. The reviewed Health Connect feature does not send those readings to the developer's server, advertising or Analytics. You can revoke access in Health Connect/Android settings; this does not delete the source records held by Health Connect. The dashboard is not a medical service. Calendar notes, leave reasons and uploaded rosters can also reveal health information or data about other people: do not include unnecessary sensitive information, and remove unrelated names or details before uploading or sharing a document.

4. Microphone and voice notes

If you choose to record a voice note, ShiftMate uses the microphone only for that purpose. Audio recording starts only when you explicitly begin a recording inside the app.

Voice notes are stored on your device and are not automatically uploaded to external servers unless you explicitly use a backup, export, or another feature that includes them.

5. When data may leave your device

Some features require certain data to be transmitted off your device. This happens only when relevant to the feature you use.

5.1 AI chat and AI-powered features

AI features send the content needed for your request, such as chat text and the shift/calendar context included by the selected feature, through the developer's backend to Google's Gemini API. Do not include confidential or unnecessary personal information. Responses can be inaccurate and should be checked; they are not used by the developer to make employment, medical or other decisions with legal or similarly significant effects about you.

5.2 PDF and image import

If you use PDF or image import, the selected document is uploaded to the developer's backend for text extraction and recognition. Depending on the import, document content may also be sent to Google's Gemini API. This can include names, schedules and any other information visible in the document.

5.3 Shared calendars

Shared calendars are stored in Cloud Firestore and made available to the people with whom you share them. This includes shared calendar content, shifts and dates, calendar and user identifiers, invitations and member permissions. Share only information you are entitled to disclose. Recipients may retain their own exports or copies; revoking a share does not erase copies already made outside ShiftMate.

5.4 Feedback and support

The in-app feedback form sends the report type, title and description, optional email address and reply preference, together with account identifier, timestamp, app and Android versions, device model/manufacturer, language and screen context where available. Reports are stored in Firestore for support and issue resolution. If you choose to send attachments using your email app, that message and its attachments are also processed by the email providers involved; they are not the same as an attachment stored in the feedback record.

5.5 Backup and restore

You can create a local backup or use your Google Drive account. Drive backups use the app's dedicated storage area and encrypted archives protected by the backup password you choose. Calendar content, notes, attachments and preferences may be included, depending on the backup. Protect your password and account: the developer cannot recover a forgotten backup password. Backup retention and deletion are managed by you, including any automatic backup options you enable.

5.6 Accounts and authentication

Firebase Authentication manages an account identifier (UID), including an anonymous identifier where used, and, for a registered account, the email address, display name, sign-in provider and verification status. Email/password sign-in or Google sign-in is handled through the relevant authentication service. An anonymous account identifier is still an identifier, not a guarantee of anonymous data. Authentication and security services also process connection and device-related technical information.

6. Third-party services and external platforms

Depending on the build and the features enabled, ShiftMate may use third-party services such as:

These services may process limited categories of data such as device identifiers, IP address, diagnostic information, app interaction data, account-related identifiers, and content explicitly submitted by the user when required to provide the selected feature.

During onboarding, ShiftMate asks for your specific, optional consent to use Google Analytics for Firebase to understand and improve the app. Analytics collection stays disabled until you explicitly accept. You can refuse or skip this choice and continue using the app without enabling Analytics. This choice is separate from advertising consent and from simply acknowledging this privacy notice.

If you consent, Firebase Analytics collects usage events such as screens or tools opened, interactions, import/backup outcomes, purchase-flow events, preferences and app version, alongside SDK-generated installation/device and usage information. A user property named pref_worker records the selected profession category to understand which groups use the app. It is not the name of your employer. These app events are not designed to include calendar entries, notes, attachments, voice recordings, imported files or AI prompt content. This collection is not described as anonymous.

Your choice is remembered, and you can change it at any time using the Google Analytics option in ShiftMate Settings. Disabling it withdraws your consent, stops future collection and resets Analytics data on that device; it does not by itself erase events already sent to Google or affect the lawfulness of processing based on consent before withdrawal. For data-rights requests, contact contact@mety.app.

6.2 Processing locations and international transfers

Aruba hosting is in Italy. The Firestore database uses the European multi-region eur3: Belgium and the Netherlands, with a witness region in Finland (Firestore locations). This setting does not apply to every Google service. Firebase Authentication runs in the United States; other services may process data globally (Firebase privacy information). Applicable safeguards may include standard contractual clauses or an adequacy decision such as the EU–US Data Privacy Framework for covered transfers; see Google's transfer safeguards. You may contact the controller for details and copies of applicable safeguards.

Google describes separate rules for Gemini content and security retention in its Gemini API terms. Those provider rules are not replaced by the controller's 24-hour OCR deadline. This notice does not promise that all provider copies are deleted within 24 hours or that all processing takes place in Europe. Availability in a country is different from the location where data is processed.

7. Advertising and monetization

ShiftMate may show advertisements through Google AdMob and may also offer premium purchases through Google Play Billing.

ShiftMate may display ads through Google AdMob. Depending on the user’s region, consent choices, and applicable law, ads may be personalized, non-personalized, or limited. Ad-related data processing may include device identifiers, IP address, app interactions, and diagnostic information, as handled by Google and related advertising technologies.

Ad-related processing, where applicable, is handled through the relevant advertising platform and subject to the consent and privacy settings available to the user and required by law. The app uses Google's User Messaging Platform for the advertising choices available in your region. Non-personalized ads do not necessarily mean no identifiers or no processing. See Google advertising privacy information. Google Play processes payment details; ShiftMate receives the purchase identifiers/tokens and subscription or entitlement status needed to manage premium access, not your full payment card details.

8. Data sharing

ShiftMate does not sell personal data.

Data may be shared only in the following situations:

9. Data retention

Local calendar data, notes, images, and audio remain on your device until you delete them, clear the app data, uninstall the app, or overwrite them through normal use.

Retention depends on the category of data:

10. Deletion and user controls

You can control and delete a substantial part of your data directly from the app or from your device settings. For example, you may:

If you cannot access the app, use the ShiftMate account deletion page to submit a request. Deletion of the account and associated data under the controller's management is completed within 30 days of the request. If you contact us by email, we may need proportionate information to verify account ownership. Deleting a ShiftMate account does not automatically cancel a Google Play subscription, which must be managed separately in Google Play.

Service-provider backup deletion can follow a separate technical cycle. For example, Firebase states that Authentication data is removed from its live and backup systems within 180 days after the developer initiates user deletion. This is distinct from the controller's 30-day deadline for carrying out your request. Any records retained for a specific legal obligation must be limited to that purpose and its required period.

10.1 Your data-protection rights

Under GDPR Articles 15–22, where applicable, you may request access, rectification, erasure, restriction or portability and object to processing based on legitimate interests. Where processing relies on consent, you may withdraw it without affecting the lawfulness of processing before withdrawal. Contact contact@mety.app. Rights requests normally receive a response within one month, subject to justified GDPR extensions. You may complain to the Italian data protection authority or the competent supervisory authority where you live or work.

11. Security

The developer takes reasonable measures to protect data processed by ShiftMate. However, no method of storage or transmission can be guaranteed to be completely secure.

12. Minimum age

ShiftMate is intended for people aged 18 or older, not for minors. If you believe a minor has supplied personal data, contact the controller so the situation can be assessed and the data removed where appropriate.

13. Changes to this Privacy Policy

This Privacy Policy may be updated from time to time. Any changes will be published on this page with an updated "Last updated" date.

14. Contact

If you have any questions about this Privacy Policy or the app's data handling, contact:

Eros Fava — Mety° / ShiftMate
Via Fontana di Papa 33, Ariccia (RM), Italia
Email: contact@mety.app

Website privacy notice · ShiftMate website