Information stored on your device
DutyNest stores the information you enter in a local SQLite database on your device. This can include your display name, workplace, role, contracted hours, shifts, rota patterns, notes, colleague or crewmate names, overtime and payroll codes, leave, TOIL, reminders, preferences and locally cached subscription status.
You do not need to create a DutyNest account. Free rota features continue to work locally without signing in. Backups and exports are only created when you choose to save or share them.
Your device operating system may include app data in a device or iCloud backup according to your system settings. Android cloud backup is disabled by DutyNest. KSJ Growth cannot access operating-system backups.
Optional DutyNest account and Premium sync
If account and sync features are available in your build and you choose to enable them, DutyNest uses Supabase to authenticate your email address, maintain the account and store an encrypted-in-transit cloud copy of the rota data needed to keep your own signed-in devices up to date. This can include your work profile, shifts, rota patterns, workplaces, notes, colleague or crewmate names, overtime and payroll codes, leave, TOIL and related histories.
A Premium rota owner may invite one household viewer. The read-only viewer receives a separate limited calendar view containing shift or leave dates, times, labels, rest days and leave status. Notes, colleague or crewmate names, overtime codes, payroll codes and balance records are not included in that shared view.
Sync is offline-first. Local changes may remain in a queue on the device until a connection is available. Supabase processes account and synced data on behalf of KSJ Growth. DutyNest does not use synced data for advertising or sell it.
Subscriptions and information processed off-device
If a production build is configured for subscriptions, DutyNest uses Apple App Store or Google Play billing and RevenueCat to display products, validate purchases, restore purchases and determine whether Premium is active.
RevenueCat receives an automatically generated anonymous app-user identifier while DutyNest is used without an account. If you sign in for Premium sync, DutyNest links RevenueCat to the random account UUID so the entitlement can follow your devices. DutyNest does not send RevenueCat your email address, rota, notes, work profile, leave, TOIL, colleague names or advertising identifier.
RevenueCat processes purchase or subscription transaction information for app functionality, fraud prevention, entitlement management and subscription analytics. It is not used by DutyNest for advertising or cross-app tracking. Apple, Google and RevenueCat process this information under their own privacy terms and retention practices.
Permissions and device services
Shift reminders are optional. DutyNest asks for notification permission only when you enable reminders and schedules them through the device operating system. Denying permission does not prevent rota use.
When you choose an import, backup or export action, DutyNest uses the operating-system file picker or share sheet. The destination you select may receive the exported information and will apply its own privacy practices.
What DutyNest does not do
- No advertising, behavioural analytics or third-party tracking SDK is included.
- DutyNest does not request your contacts, precise location, photos, microphone, camera or health data.
- DutyNest does not sell personal information.
- DutyNest does not upload rota or report data unless the user deliberately enables an available account and sync feature.
Retention, access and deletion
Local information remains on the device until you edit or delete it, use Delete all local data, clear the app’s storage or uninstall the app. Backups and exports remain wherever you save or share them until you delete them there.
The Data and privacy screen lets you create a complete backup, export a readable copy of your local information and delete all local DutyNest data. Deleting app data does not cancel an App Store or Google Play subscription. Store subscriptions must be cancelled through the relevant store account.
A request concerning RevenueCat purchase information may require the anonymous subscription identifier and must be handled through the published DutyNest support contact. Apple and Google provide their own controls for store-account and transaction information.
The Account and sync screen lets a signed-in user permanently delete the DutyNest cloud account and its associated synced data. Local information remains on the device until separately deleted in Data and privacy. Deleting a cloud account or local data does not cancel an App Store or Google Play subscription.
Security
DutyNest relies on the security controls of your device and operating system. Keep your device passcode and software up to date. Exported JSON backups are readable, unencrypted files so you should save them only in a location you trust.
Subscription and optional sync traffic is encrypted in transit. Authentication sessions are protected using device secure storage on supported native devices. No method of storage or transmission can be guaranteed completely secure.
Children
DutyNest is designed for people managing work rotas and is not directed to children. Do not enter information about another person unless you are permitted to keep it on your device.
Changes and contact
This policy may be updated when DutyNest features or service providers change. The updated date will appear at the top of the policy. Material changes will be reflected in the app and store disclosures.
KSJ Growth is responsible for DutyNest. Use the Support screen or the published support link on the DutyNest store listing for privacy questions or data requests.
KAI website assistant
Website assistant notice added 9 August 2026. If you choose to use KAI, the text you deliberately submit is sent through this website to OpenAI to generate a reply. KAI cannot access the DutyNest app, your account, rota, subscription, backups or any other records. Do not include confidential workplace information, colleague names, payroll details, passwords, payment details or other sensitive personal information.
WordPress does not save the conversation transcript. A signed, limited conversation context is returned to and held by your browser while the chat is in use so KAI can follow the conversation. The website keeps only temporary security and rate-limit metadata and aggregate, non-content health counters; question and reply text is not included in those records. KAI does not add analytics or advertising tracking.
OpenAI processes the submitted text to provide the reply. OpenAI's own terms and retention arrangements apply to that processing; this notice does not claim that the provider deletes submitted text immediately or within a particular period.