Everything runs on European infrastructure. No transfer outside the EU.
Trust isn't a promise, it's the design.
The app belongs to your employees, not the company. You never see their numbers, check-ins or sick notes, and neither does ShiftRecovery itself. You only get the aggregated team signal.
Because people only share honest signals when they feel safe. That's where it all starts.
Who sees what
Down to the feature: who sees what, and what stays with the user.
| App feature | User | Management | Board | Occ. physician |
|---|---|---|---|---|
Recovery status & sleep debt daily score 0-100 | ||||
Check-in: sleep, energy, stress daily entry | ||||
Log illness & notes complaint, duration, feeling, free note | ||||
Insights & energy trend pattern over time | ||||
Sleep tools & recovery plan exercises, night screen, plan after the doctor | ||||
Own roster & work hours shifts in the app | ||||
Aggregated team energy signal derived, above team threshold, delayed, opt-in | ||||
Roster load (operational) staffing at shift level | ||||
Leave request the request, not the private note | ||||
Profile, account, billing, location name, details, MFA, subscription |
The occupational physician only sees anything if the user seeks help themselves, never the other way around.
Four roles, three boundaries.
The employee
Keeps their own health data. It stays theirs, the employer never gains access to it, not even encrypted or delayed.
The employer
Sees only an anonymised trend at team level. No personal answers, no individual scores.
The occupational physician
Receives a personal signal only when the employee asks for it themselves. Never automatically, never via the employer.
Health data sits in a separated environment that neither the employer nor ShiftRecovery itself can access, regardless of what is asked.
Two separated layers
Workload is about the work. Health is about the person.
We collect two kinds of data with a different status. One may surface sooner; the other stays aggregated and delayed.
May surface sooner
Operational data
- Experienced workload on a shift
- Staffing and rota gaps
- Peaks and under-staffing
About the work, not a person. Not a special category of data.
Stays slow
Health data
- Sleep and recovery
- Energy
- Stress as a personal experience
About the person. Always aggregated, delayed and never individual.
Under the GDPR, health data is a special category with a processing ban. The employer may not even process it, not even with consent. So we make sure they never have to: they see only an anonymised group trend, and that is legally no longer personal data.
When someone drops out
If someone drops out, the team picture freezes.
The risk in a sick note isn't the illness, which is simply reported. The risk is that the picture moves at that moment and the manager links the movement to a person.
So at that moment:
- The counter holds and doesn't drop live.
- The picture keeps moving, but decoupled from that one person.
- The nature or cause of illness never enters the system.
- The individual signal never goes to the manager.
Honest
We don't promise a hundred percent. We make re-identification practically unfeasible.
No system is entirely impossible to re-identify, and promising that would be an empty claim. What we do do: we hide not only who fills something in, but also the surrounding details that would point to a person. The anchor points to tie something to someone simply aren't there. That's stronger than an absolute promise that doesn't hold up.
Every transition from hidden to visible is checked and logged, so it can be reconstructed afterwards that no identifiable signal was shown.
Because we are liable under the GDPR ourselves, this is our first promise, not our fine print.