YDutySign in →

Privacy Policy

Effective July 25, 2026

This Policy explains what personal data YDuty (the “Service”) collects, how we use it, and the choices you have. It applies to people who use the Service and to the employees an organization manages within it. YDuty is built and operated by YDuty Labs, based in Georgia.

1. Data we collect

  • Account data — name, email, phone and profile photo (both optional), and the password you set (stored only as a secure hash). We also record whether you have confirmed your email address, because confirming it is what unlocks inviting other people.
  • Organization data — teams, branches, roles, schedules, shifts, coverage, leave records, availability and work preferences, shift swaps, and any custom tables your organization builds for itself.
  • Messages and files — in-app chat messages and the files people attach to them.
  • Sign-in and audit records — one row per signed-in device (browser user agent, IP address, expiry) so you can review and revoke your own sessions, plus an audit log of changes made inside your organization: who changed what, when, and from which IP address.
  • Payment and billing data — which plan your organization is on, its trial dates, and the date the current period is paid through. When someone asks to change plan we also keep that request: the plan asked for, how many branches and people the workspace had at the time, any note they wrote, who asked, and the matching audit entry — and the request is emailed to us through our email provider, including the requester’s name and address. No payment processor is connected to the Service today and there is no card field anywhere in it: paid plans are arranged by email, so we hold no card or bank details at all. When we do connect a payment provider, card details will go straight to that provider and never pass through YDuty; we will hold only the billing contact, the plan, and the provider’s reference for each payment. We will name that provider in section 4 before it starts processing anything.
  • Usage data — basic technical logs (e.g. request errors) needed to operate and secure the Service.

Every shift is stored as an exact UTC instant, so the record of when someone worked does not shift when clocks change.

2. How we use it

  • to provide the scheduling features you use;
  • to authenticate you and keep your account secure;
  • to send transactional messages you or your organization trigger (email confirmation, invitations, password reset, notifications);
  • to set up and administer your plan, including the free trial;
  • to diagnose problems and improve the Service.

We do not sell your personal data, and we do not use it for advertising.

3. Who can see your data

Your organization’s owners, administrators, and the managers within your scope can see the schedule and team data relevant to their role. Chat messages and their attachments are visible to the members of the channel they were posted in. We access your data only as needed to operate and support the Service, and outside YDuty we share it only with the providers named in the next section — never with anyone who wants it for their own purposes.

4. Providers we use, and where your data sits

These are all of the outside companies that handle your data today:

  • Hetzner — hosting. The application, the database, and any files uploaded to chat run on a Hetzner server in Germany. That is where your organization’s data lives.
  • Resend — transactional email. Resend receives the recipient’s email address and the contents of each message we send — email confirmation, invitations, password resets, notifications — in order to deliver it.

That is the whole list. We use no analytics, advertising, tracking, or session-recording provider. A payment provider will be added here when paid plans move to self-serve payment, together with what it receives, before it handles anything.

Crossing borders. We are in Georgia, your data is stored in Germany, and email is delivered by a provider that may process it outside both. So your data does leave the country it was entered in. We rely on each provider’s standard data-processing terms for that, we keep the list of providers as short as running the Service allows, and we do not move your data anywhere else for our own convenience.

5. Cookies

YDuty sets exactly one cookie, named yduty-token. It holds the signed token that keeps you signed in. It is httpOnly, so no script on the page can read it; it is marked SameSite=Lax, so other sites cannot ride on it in background requests; and on our hosted service it is sent only over HTTPS. It is valid for at most 7 days: if you check “Keep me signed in” it lasts those 7 days, and if you do not, your browser drops it when you close it. Signing out clears the cookie and revokes the session behind it on our side too.

There are no advertising cookies, no analytics cookies, and no third-party cookies — which is why the Service never asks you to accept any. If you block cookies you can still read our public pages, but you will not be able to sign in: that one cookie is how the Service recognises you from one request to the next.

The app also keeps a few small interface preferences in your browser’s own local storage — things like your initials so the sidebar does not flicker on reload, which branch or team you last looked at, and which hints you have dismissed. Those are not cookies and they are never sent to us.

6. Security

Passwords are hashed, sessions use signed, HTTP-only cookies, and password-reset, invitation and email-confirmation links are stored only as one-way digests. Access to organization data is scoped by role. No system is perfectly secure, but we take reasonable measures to protect your information and continue to strengthen them.

7. Retention

We keep your data for as long as your account or organization is active, and as needed to provide the Service. We do not delete or archive a workspace for being idle.

When the trial ends, or a plan changes. Nothing is deleted. When the 7-day Pro trial runs out, the workspace continues on the free Starter plan with every row of its data intact, and a downgrade works the same way. What changes is what you can do next — the Starter limits are listed in section 10 of the Terms — not what we store. Branches, schedules and history created during the trial stay exactly where they are.

When a person leaves. Deactivating a member stops them using the workspace, but their past shifts, leave and approvals stay in the organization’s records, because that is the business’s own history rather than ours to erase. At the organization’s request we delete or anonymise the personal fields on that account.

When an organization closes. Write to us from an owner’s address and we delete the organization and everything in it — members, schedules, leave, chat messages and uploaded files, custom tables, and the audit log — within 30 days, keeping only what the law requires us to keep. There is no self-serve button that deletes a whole workspace: you ask us, and a person here does it.

A session row lasts at most 7 days, and expired ones are removed the next time that account signs in. The audit log lasts as long as the organization does, because it is that organization’s own record of who changed what.

8. Employee data: who decides what

When a business uses YDuty to schedule its staff, the business decides what employee data goes in and why. In data-protection terms the business is the controller of that data and we are its processor: we handle it on the business’s instructions, not on our own. We do not decide who is in a workspace, what is recorded about them, or how long the business needs to keep it.

We are the controller of the narrow set of data we need to run YDuty itself — the account you sign up with, your sign-in and session records, which plan your organization is on, and whatever you send us when you ask for support.

If your organization needs a data processing agreement covering the above, ask us at privacy@yduty.com and we will sign one.

If you are an employee and want to see, correct, or delete what is held about you, start with your employer. They entered it, they can edit or remove most of it themselves in the app, and they are the ones who decide what their business has to keep. If you write to us first, we will pass the request to your employer and help them act on it, rather than change their records behind their back — unless the law requires us to act ourselves, in which case we will.

9. Your choices

You can view and update much of your profile within the Service. To request access to, correction of, or deletion of your personal data, contact us at the address below and we will respond within a reasonable time. If you were added by an employer, some requests may need to go through that organization as the controller of its own data — see section 8.

10. Changes

We may update this Policy as the Service evolves. Material changes will be communicated through the Service or by email.

11. Contact

Questions or requests about your data? Contact us at privacy@yduty.com. For questions about using the Service, write to support@yduty.com.

The Service is operated by YDuty Labs, Georgia. Registered operator details: [REGISTERED NAME, ADDRESS AND COMPANY NUMBER — TO BE COMPLETED].