Privacy Policy
Kwilio Scheduling is a workforce scheduling app: a desktop app for managers and a mobile app for staff. This page describes what it collects, what it deliberately does not, and what you can ask us to do with it.
Contents
1. Who this covers
Kwilio Scheduling is operated by Kwilio ("we", "us"). This policy covers the desktop app, the mobile app, the API they talk to, and this website.
Your data is organised into an organisation, which is your employer or the business that runs the schedule. The organisation controls who has an account, what each person can see, and whether it continues to exist. If you are a staff member, your employer, not us, decides those things and is the first place to go about data concerning your work. We act on their behalf in running the service.
2. What we collect
Your account
Your name, your email address, and a hash of your password. We store a hash
produced by argon2, not the password, so we cannot read it, tell
you what it is, or give it to anyone who asks.
Scheduling information
What your organisation puts in to run its schedule: staff profiles (name, contact details, employment type, skills, availability, pay rates), clients and their contact details and addresses, locations, services, shifts and assignments, open-shift claims, swap requests, time-off requests, and notes attached to any of these. This is your organisation's content. We store it so the apps can show it back to the people it is shared with. We do not read it except where needed to fix a fault you have reported.
Clock-in and clock-out
When staff clock in, start or end a break, or clock out in the mobile app, we record the event, its time, the shift it belongs to, and an identifier for the device. Location is optional and controlled by your employer. Where your employer turns on on-site checks, the app reads your position at the moment you clock, compares it with the workplace, and stores those coordinates with that clock event. It does not track your location at any other time, and it does not run in the background. If you lose signal, clock events are held on your phone and sent when you are back online.
Notifications
If you allow push notifications, we store the token Apple gives the app for your device, and use it to send shift alerts such as new shifts, changes, cancellations and start reminders. You choose which alerts you want, and you can turn notifications off in the app or in your phone's settings.
A record of actions
The app keeps an audit log inside your organisation: who changed what, and when. It records the action and the affected item. It does not record your IP address or your device.
Addresses you search for
When a manager types an address while setting up a location, the text they type is sent, through our API, to Photon, a public OpenStreetMap geocoding service, to suggest matching addresses. Only the search text is sent. It is not linked to your account.
Billing status
If your organisation subscribes, we store which plan it is on, whether it is active, and the subscription identifier PayPal gives us. See Payments and email.
3. What we don't collect
These are absences by design, not omissions from this page:
- No analytics and no tracking. The apps contain no analytics SDK, no session recorder and no advertising code.
- No continuous location. Location is read only when you clock, and only where your employer has enabled it.
- No cookies on this website. It is static HTML. It sets nothing and stores nothing in your browser.
- No profiles, no data sales, no sharing with advertisers. We do not sell or rent personal data, and we have never done so.
Two honest qualifications. This website loads its typeface from Google Fonts, which means your browser makes a request to Google and Google sees your IP address in the ordinary way any web request is seen. And our hosting providers keep their own standard server logs, which include IP addresses, for security and abuse handling.
4. AI features
On-device shift parsing. On a Mac with Apple Intelligence, the desktop app can turn a sentence into a draft shift. This runs on the device using Apple's on-device model. The text does not leave your computer for this feature.
Office Agents. Organisations can optionally hire AI agents that help with scheduling tasks. When one runs, the relevant scheduling context and instructions are sent from our API to the AI model provider we have configured for that agent, which may be a hosted provider such as OpenAI or a model we run ourselves. Their privacy policy governs the text they receive. Every run and every action an agent takes is logged, with an undo where one applies, so your organisation can see and reverse what it did. If your organisation does not hire an agent, nothing is sent to a model.
We do not train models on your data. We have no model of our own to train, and we use providers' API products, not their consumer products.
5. Payments and email
Subscriptions are handled by PayPal. Payment details are entered on PayPal's own pages and go to PayPal, not to us. We never see or store them. What we receive back is a subscription identifier, a status, and the dates of the current period. PayPal's privacy policy governs their side.
We send email only when something you did calls for it: a code to verify your address, a code to reset your password, invitations to join an organisation, and replies to support requests you send us. There is no mailing list and no marketing email.
6. Updates and this website
The desktop app checks for updates at launch by requesting a small file from our download host. As with any web request, that reveals your IP address and the app version to our provider (Cloudflare) in its logs. Downloading and installing an update is your decision. If the check fails, the app carries on silently.
7. Where your data lives
We use a small number of providers, each doing one job:
| Provider | What it holds |
|---|---|
| Supabase (PostgreSQL) | The application database, holding your account and your organisation's scheduling data. |
| DigitalOcean | Runs the API and serves this website. |
| Cloudflare | DNS and the desktop installer downloads. |
| Apple (APNs) | Delivers push notifications to iPhones. It receives the notification text and your device token. |
| PayPal | Payments. |
| Mailtrap | Delivers verification, password-reset and support emails. It handles your address and the message. |
| Photon (OpenStreetMap) | Address suggestions. It receives only the text of the address search. |
| An AI provider, if your organisation hires an agent | Only the context of the tasks the agent runs. |
Data is stored in the United States. If you are in the UK or EEA, that is a transfer outside your region, made under the providers' standard contractual clauses.
8. Keeping and deleting
We keep your organisation's data for as long as the organisation exists, because a past shift and its clock events are the record of who worked when. Sign-in sessions expire after 24 hours.
When someone leaves a team they are deactivated rather than deleted: they lose access, and their name stays on past shifts so the timesheet history remains accurate. If you want your personal details removed as well as your access, ask us or your employer and we will do it, subject to any records an organisation is legally required to keep.
An owner can ask us to delete an entire organisation. We remove it from the live database within 30 days; encrypted backups age out on their own cycle after that.
9. Security
- Everything travels over TLS.
- Passwords are stored as
argon2hashes. - Sessions use signed tokens that expire after 24 hours.
- The desktop and mobile apps hold no database credentials. They can only ask the API for what your account is allowed to see, so a lost laptop or phone is not a route into anyone else's data.
- Access is checked on the server on every request, against your role in the organisation (owner, manager, scheduler, office user or staff).
No system is perfect. If you find a vulnerability, please tell us before telling anyone else. The contact details are below.
10. Your rights
Depending on where you live, you may have the right to see the personal data we hold about you, correct it, have it deleted, take a copy elsewhere, or object to how we use it. Ask us and we will do it. We do not charge for this and we will not make it difficult.
Because your employer decides what is recorded about your work, we may need to refer your request to them. We will tell you if we do.
11. Changes and contact
If we change this policy in a way that matters, we will change the date at the top and say so in the app. Continuing to use Kwilio Scheduling after that means the new version applies.
Questions, requests, or a vulnerability to report: [email protected].