Privacy Policy

Effective 18 July 2026

Plain language, no legal fog: we store the minimum needed to run your schedule, we don't sell personal data, and there are no advertising trackers.

What we collect

Cookies & tracking

The app uses browser storage only to keep you signed in. There are no third-party advertising trackers or analytics cookies. The app may display relevant professional announcements (for example, pharmacy conferences); we count impressions and clicks on those in aggregate, and we do not sell or share your personal data with the sponsors.

Who processes data on our behalf

A short list of subprocessors, each used for one job: Supabase (managed database hosting, on AWS, US region), Vercel (application hosting), Resend (transactional email — sign-in codes and notifications), and Anthropic (when a manager imports a schedule file, its contents are processed by an AI service solely to parse the schedule; we do not permit its use for model training). We don't sell data to anyone.

Email

We send transactional email only: sign-in and password-reset codes, and schedule notifications your unit generates. Any optional communications are opt-in and can be turned off.

Retention & deletion

Scheduling data is retained while your organization uses the service, so history and audit needs are met. Managers can export schedules and hours to Excel/CSV at any time. When an organization leaves, we delete its data on request — after giving you the chance to export first.

Your choices

Questions, corrections, export, or deletion: email brantb@justsaywhen.app. If your account was created by your hospital, some changes (like your work email) go through your manager or admin.

Changes to this policy

If this policy changes materially, we'll note it here with a new effective date and tell active organizations directly.