# Shiftly data handling

Last reviewed: 2026-10-06

This is a plain-language summary of current product behavior, not a complete legal privacy notice.

## Private workspaces

A signed-in workspace stores information needed for scheduling: employee names and roles, availability, time off, staffing rules, generated schedules, and any optional cost figures. Exact wages are not required; relative cost signals are available. Employee email addresses are optional.

## Uploads and AI interpretation

Uploaded images and spreadsheets are read for the requested interpretation; the original file is not retained as an uploaded file. For manager review and troubleshooting, Shiftly stores submitted or extracted text, the filename, the structured interpretation, and error details in encrypted audit fields. If cloud interpretation is selected, the content needed for that request is sent to the currently configured AI provider. Avoid uploading unrelated or unnecessary personal information.

## Anonymous demo and traffic records

The demo uses an HTTP-only browser cookie to keep each visitor's sample workspace separate. That cookie expires after 24 hours. Operational traffic records can include IP address, browser user-agent, requested page or endpoint, response status, referrer host, and campaign tags. These records are not visible to other visitors. Access-log records older than 180 days are deleted when a new access is recorded or an administrator opens the access-log view.

The administrator's product-learning view derives session activity, AI outcomes and API errors from existing first-party demo and operational records. The per-action demo audit trail used by this view is automatically deleted after 180 days when the learning data is next read. Funnel percentages use one group of newly created demo sessions; AI and API rates count parse attempts and requests, not people, and are shown with their denominators. These rates may include signed-in use and should not be compared as though they were the same cohort. The summary does not copy IP addresses, browser strings, employee details, wages, rosters, upload content or typed requests. Automated-traffic classification is a browser-string heuristic and cannot verify that other sessions are people. An administrator may manually add a sanitized summary of customer or manager feedback, then record a testable hypothesis, owner role and success measure. Hypotheses and review notes are encrypted and visible only in the platform admin area. Improvement records are automatically deleted 365 days after creation the next time the admin learning data is read. Avoid names, contact details and other private information even in encrypted notes.

## AI assistant connections

An MCP-compatible assistant can connect only after a signed-in manager approves the requested access and explicitly selects one or more store workspaces. The assistant may receive staff names, roles, availability, time off, rules and schedule context from only those selected stores as needed for the task. Exact hourly pay is omitted, although a preview may show an aggregate labor-cost estimate. Usage events are linked internally to the signed-in account for aggregate counts and contain the connected-client label, tool name, outcome and time. This agent-usage view does not copy MCP prompts, tool results, roster content or uploads. Usage events are deleted after 180 days when the admin panel is next refreshed. General operational HTTP logs may separately contain IP address, browser user-agent, endpoint and response status; access-log records older than 180 days are deleted when a new access is recorded or an administrator opens the access-log view.

Managers can review approved assistants in Connection settings and disconnect an assistant at any time. Once disconnected, its access token is rejected by the service.

The separate `shiftly:feedback` permission allows an assistant to send a generalized product note. Feedback is encrypted, visible only to platform administrators and deleted after 180 days when the admin panel is next refreshed. The service rejects common email, phone and wage patterns, but filters cannot identify every private detail. Do not include names, contact details, wage amounts, exact shifts, uploaded text or private store information. An assistant cannot change saved settings, confirm a roster or publish it. A public product link is provided only if a user asks what Shiftly is or asks to share it; assistants are instructed not to promote it unsolicited.

The separate public agent demo needs no account and uses only fictional sample teams. Its signed demo ID contains a sample-industry identifier and expiry, not a merchant identity; it is signed but not encrypted. The sample workspace is reconstructed when needed and is not saved as a server-side workspace. The ID expires after two hours. Demo instructions and generated schedules are returned to the calling assistant and are not stored in the demo workspace or MCP usage metrics. Aggregate demo tool/outcome counts and a daily count of natural-language demo requests may be recorded without their contents; the daily cap resets at 00:00 UTC. Natural-language instructions and relevant fictional scheduling context are sent to the currently configured scheduling parser; this may involve a cloud AI provider, whose privacy practices also apply. Send sample details only, never real employee, customer or store information. Standard operational access logs may separately include IP address, browser user-agent, endpoint and status; records older than 180 days are deleted when a new access is recorded or an administrator opens the access-log view.

## Contact and billing

Contact form details (name, email, and optional phone, store name, and message) are stored so the team can reply. When a form is submitted, the first and most recent source, campaign, referring site and entry page are also attached to the request to understand how people find Shiftly. New contact requests are not linked to anonymous demo sessions by an IP-derived visitor code; older requests may still contain a pseudonymous visitor code from the previous setup. Billing choices and subscription events are recorded to operate checkout and understand which plan was selected. First- and last-visit campaign details are kept in the browser for up to 180 days, and billing funnel events are retained for 180 days. Submitted contact requests, including their source labels, do not yet have a published deletion schedule. Card details are entered in Stripe Checkout; do not send card numbers by email.

## Practical guidance

- Do not upload identity documents, bank details, or unrelated personal conversations.
- Use employee names only when needed; employee email is optional.
- Use relative cost levels if you do not want to enter actual pay.
- Review extracted text and rules before applying them to a schedule.

The anonymous demo cookie expires after 24 hours; access logs, billing attribution and funnel events have a 180-day limit. Access logs are cleaned when a new access is recorded or an administrator opens the access-log view. Demo action details and MCP usage/feedback records are deleted after 180 days when their admin panel is next read, and product-improvement notes are deleted 365 days after creation when the admin learning data is next read. Other contact, workspace, demo-session and audit records do not yet have a published, product-wide deletion schedule. For questions or data requests, email [support@zhiyong.dev](mailto:support@zhiyong.dev); requests are reviewed manually.

## Links

- [Open Shiftly](https://easyshiftplan.zhiyong.dev/)
- [Pricing](https://easyshiftplan.zhiyong.dev/pricing)
- [FAQ](https://easyshiftplan.zhiyong.dev/faq)
- [AI assistant connection guide](https://easyshiftplan.zhiyong.dev/for-ai-assistants)
