Break Schedule — Privacy Notice
Effective: September 22, 2026 · Last updated: September 22, 2026
The short version
- The schedules you upload come from the scheduling or workforce-management software you already use (UKG, Deputy, or whatever your stores run on today). We process that export just long enough to build your break schedule, then discard it — no employee names, hours, or shift times are kept on our servers.
- The account email and beta-request details you give us directly are kept, so we can run access to the Service.
1. Who we are
Break Schedule ("we", "us") provides a decision-support tool that computes meal-period and rest-break schedules for hourly retail employees. Questions about this notice or your data: legal@breakschedule.com.
2. Where your roster data comes from
Break Schedule doesn't replace the scheduling or workforce-management software your stores already run — it reads an export from it. The employee names, shift times, and other roster details in that export originate in your existing system, not in Break Schedule; that system's own privacy policy governs how it collected and retained that data before you exported it. This notice covers only what happens to that data once you upload it here. You're responsible for confirming you have the right to export that data and share it with us (see the Terms of Service).
3. Two kinds of data
Roster data (processed, never stored). When you upload a work-schedule export, we decode it in memory to produce a break schedule. This can include employee names and shift times. We do not write your upload or the derived schedule to disk, a database, a cache, or a session. It exists only for the duration of the request that processes it, and the working schedule you edit lives in your browser's memory — a page refresh or tab close discards it. When you download your result, the downloaded files are the only record; we keep none.
Contact data (stored). To run access to the Service we keep:
| Data | Why | Where |
|---|---|---|
| Email address | identify your waitlist request and account, send sign-in and approval emails | Neon (database), Clerk (auth) |
| Beta-request qualifiers — scheduling tool used, California-retail attestation, optional store name and headcount | judge fit for the beta | Neon |
| Account and invite status | manage beta access | Neon, Clerk |
| Anonymous processing metadata — column counts, row counts, a one-way file "fingerprint", and reusable column-mapping settings | speed up and improve automatic reading of your exports | Neon |
The processing metadata contains no cell values and no recoverable personal data from your uploads. The fingerprint is a one-way digest, not reversible into your schedule.
4. Automated ("AI") reading of unrecognized exports
If we do not recognize your export format, we use an AI model to propose how your columns map. When this happens, the only data sent to the model provider is: the sheet name, the header row, and up to five sample rows with likely personal values masked before sending (names and IDs replaced with placeholders). We never send your full file or the finished schedule.
We send that real (masked) sample data only to a provider under a zero-data-retention agreement — OpenAI or Anthropic, whichever is under contract with us on those terms at the time — so the provider does not store or train on it. If no such agreement is in force, the AI path runs on synthetic sample data only, and an unrecognized real export is reported as "couldn't read automatically" instead of being sent.
5. Service providers (subprocessors)
We share the data above only with providers that operate the Service:
- Neon — database hosting (Contact data + anonymous metadata), U.S. region.
- Clerk — authentication (email address only).
- OpenAI or Anthropic — automated column-mapping, under zero-data-retention terms, and only the masked sample described in §4.
- Cloudflare Turnstile — bot protection on the request-invite form.
6. Where data is processed
The Service runs on infrastructure in the United States (our application region is San Francisco, California; Neon stores Contact data in a U.S. region). We do not currently serve users outside the United States.
7. How long we keep it
- Roster data: not retained — discarded when each request ends.
- Contact data: kept while your waitlist request or account is active. If your request is declined or your account is closed, we delete or anonymize it within 90 days, except where we need to keep limited records longer to comply with law, resolve disputes, or enforce our agreements.
8. Your California privacy rights
If you are a California resident, the CCPA/CPRA gives you rights to know, access, correct, and delete the personal information we hold about you, and to not be discriminated against for exercising them. Because we do not retain uploaded schedule data, requests concern your Contact data only. To make a request, email legal@breakschedule.com from the address on your account or waitlist request (so we can verify it's you); we'll respond within 45 days. We do not sell or "share" personal information for cross-context behavioral advertising.
9. Security
We use TLS for data in transit, restrict database access to least-privilege credentials, and keep all secrets out of client code and the repository. No security measure is perfect; we cannot guarantee absolute security.
10. Children
The Service is for business use by adults and is not directed to children.
11. Changes
We may update this notice. Material changes will be signposted here with a new "last updated" date; where a change materially reduces your rights, we will also email accountholders.
12. Contact
legal@breakschedule.com