Trust

Trust isn't a promise, it's the design.

The app belongs to your employees, not the company. You never see their numbers, check-ins or sick notes, and neither does ShiftRecovery itself. You only get the aggregated team signal.

Because people only share honest signals when they feel safe. That's where it all starts.

Who sees what

Down to the feature: who sees what, and what stays with the user.

App featureUserManagementBoardOcc. physician

Recovery status & sleep debt

daily score 0-100

Check-in: sleep, energy, stress

daily entry

Log illness & notes

complaint, duration, feeling, free note

Insights & energy trend

pattern over time

Sleep tools & recovery plan

exercises, night screen, plan after the doctor

Own roster & work hours

shifts in the app

Aggregated team energy signal

derived, above team threshold, delayed, opt-in

Roster load (operational)

staffing at shift level

Leave request

the request, not the private note

Profile, account, billing, location

name, details, MFA, subscription

Full accessAggregated, not traceable to an individualOnly if the user shares it themselvesNo access, ever

The occupational physician only sees anything if the user seeks help themselves, never the other way around.

Four roles, three boundaries.

The employee

Keeps their own health data. It stays theirs, the employer never gains access to it, not even encrypted or delayed.

The employer

Sees only an anonymised trend at team level. No personal answers, no individual scores.

The occupational physician

Receives a personal signal only when the employee asks for it themselves. Never automatically, never via the employer.

Health data sits in a separated environment that neither the employer nor ShiftRecovery itself can access, regardless of what is asked.

Two separated layers

Workload is about the work. Health is about the person.

We collect two kinds of data with a different status. One may surface sooner; the other stays aggregated and delayed.

May surface sooner

Operational data

  • Experienced workload on a shift
  • Staffing and rota gaps
  • Peaks and under-staffing

About the work, not a person. Not a special category of data.

Stays slow

Health data

  • Sleep and recovery
  • Energy
  • Stress as a personal experience

About the person. Always aggregated, delayed and never individual.

Under the GDPR, health data is a special category with a processing ban. The employer may not even process it, not even with consent. So we make sure they never have to: they see only an anonymised group trend, and that is legally no longer personal data.

When someone drops out

If someone drops out, the team picture freezes.

The risk in a sick note isn't the illness, which is simply reported. The risk is that the picture moves at that moment and the manager links the movement to a person.

So at that moment:

  • The counter holds and doesn't drop live.
  • The picture keeps moving, but decoupled from that one person.
  • The nature or cause of illness never enters the system.
  • The individual signal never goes to the manager.

Honest

We don't promise a hundred percent. We make re-identification practically unfeasible.

No system is entirely impossible to re-identify, and promising that would be an empty claim. What we do do: we hide not only who fills something in, but also the surrounding details that would point to a person. The anchor points to tie something to someone simply aren't there. That's stronger than an absolute promise that doesn't hold up.

Everything runs on European infrastructure. No transfer outside the EU.

Every transition from hidden to visible is checked and logged, so it can be reconstructed afterwards that no identifiable signal was shown.

Because we are liable under the GDPR ourselves, this is our first promise, not our fine print.