Privacy Policy
Effective: August 30, 2026 · Controller: Codeholics LLC (New York, United States)
Codeholics LLC ("we") operates DENOFFs, a shift-schedule app ("the Service"). This policy
explains what information the Service collects, why, and how it is stored, shared, and deleted.
1. What we collect
- On account creation (automatic): a random account identifier. You start anonymously,
with no sign-up form.
- When you link a social login: your provider account identifier (Google, Apple), email
address, and name if the provider shares it.
- As you use the Service: your shift schedule (shift type per date), custom shift types
(name, color, hours), display name, friend connections, team membership and team rosters,
shift change/swap/cover requests, and shift preferences.
- If you subscribe (team features): payments are processed by Stripe — we never hold
your card details. We keep only Stripe customer/subscription identifiers and seat counts.
- Automatically (operations): standard server access logs (IP address, request logs) needed
to operate the Service.
- When you use notifications (Android and iOS app): your device notification token and which
platform it is. It is registered only if you allow notifications and are signed in — never while
notifications are off or while you use the app anonymously — and the web version neither sends
notifications nor collects a token.
- When you send feedback (optional): the feedback text you write, an optional reply email address
you may provide, and app/device info for diagnosis (platform, device model, OS/app version, language).
Sending is your choice.
- Product analytics (improvement & error diagnosis): app usage events (e.g., screen views,
feature usage counts), errors and crashes, and device/environment info (device model, OS/app
version, language, coarse region). This excludes personally identifying information such as
name, email, or shift contents, and is linked only to an opaque account identifier. You can
turn this off (see below).
We use no advertising identifiers, no ad-purpose behavioral tracking, and no cookies,
and we never use personal data for advertising. We use one product-analytics tool
(PostHog, EU region) solely to improve the Service and diagnose errors, collecting only the
non-identifying data above. You can opt out anytime in Account → Share usage data. The web
version also uses browser localStorage to keep you signed in.
2. Why we use it
- Providing the Service: storing schedules, syncing across devices, sharing within the scope you choose
- Account management and security (sign-in, linking/unlinking, abuse response)
- Billing for paid subscriptions
- Service notices (account, security, billing — never marketing)
- Sending notifications: a team roster is published, shift-preference collection opens, someone asks to
join or is approved for your team, and friend requests and acceptances. We never send marketing
pushes, and you can turn notifications off in your device's operating-system settings.
- Responding to your inquiries and feedback, and fixing bugs
- Improving the Service and diagnosing errors (product analytics excluding personally identifying information) — you can opt out
- Legal compliance
3. Who can see your schedule
- Friends: controlled by your sharing setting — everything / days off only (default) / private.
- Teams: rosters published to your team are visible to team members.
- Calendar subscription: accessible only via the link you generate; you can regenerate
(revoke) it at any time.
We do not sell personal information, and we do not share it for advertising.
4. Retention and deletion
- Your data is deleted promptly when you delete your account (Account → Delete account in
the app). This removes your server-stored data — schedules, friends, teams, and requests.
- Deleted data disappears from disaster-recovery backups when the backup retention cycle expires.
- Feedback text and any reply email are kept for up to 90 days and are deleted when you delete your account.
- Product-analytics and error data are stored under an opaque identifier without your name or
email, and are deleted when you delete your account. You can also request deletion at
[email protected], or turn off collection entirely in
Account → Share usage data.
- Your device notification token is released when you sign out and deleted with your account,
and it is removed automatically once the delivery service reports it is no longer valid.
- Records that law requires us to keep (e.g., contract and payment records) are retained for the
legally required period, stored separately, then destroyed.
5. Processors and international transfer
We are a U.S. company and use the following processors to operate the Service. Transfers occur
over the network as you use the Service, as necessary to perform our contract with you.
| Processor | Location | Purpose | Data |
| Google Cloud (Google LLC) | U.S. entity · data stored in Seoul, South Korea | Servers and database | Service data in §1 |
| Cloudflare, Inc. | U.S. (global edge) | Web hosting, network security | Access logs (IP), transit traffic |
| Stripe, Inc. | U.S. | Payment processing | Payment details (cards held by Stripe only), email |
| Google LLC | U.S. | Social sign-in, support email | Sign-in identifiers, email, inquiries |
| Resend, Inc. | U.S. | Service email delivery | Email address, notice content, feedback reply email (only if we reply) |
| PostHog, Inc. | U.S. entity · data stored in the EU (Germany) | Product usage statistics and error diagnosis | App usage events, error records, device/environment info, opaque account identifier (no personally identifying information) |
| Google LLC (Firebase Cloud Messaging) | U.S. (global) | Push notification delivery | Device notification token, notification title and body (may include a team name and another person's display name) |
| Apple Inc. | U.S. (global) | Sign in with Apple, iOS push delivery (APNs) | Sign-in identifiers, device notification token, notification title and body |
6. Your rights
- Access and correction: view and edit your data directly in the app.
- Deletion: Account → Delete account in the app, or contact us below. See how to delete your account.
- Sharing scope: change anytime in Account → Sharing.
- Opt out of product analytics: turn it off anytime in Account → Share usage data.
- Questions and requests: [email protected]
7. Security
- TLS encryption for all data in transit
- Least-privilege access controls and two-factor authentication on operational infrastructure
- Data minimization by design (e.g., no card details held)
8. Children
The Service is not directed to children under 14, and we do not knowingly collect their
information. If we learn we have, we delete it promptly.
9. Breach notification
If a breach of personal information is confirmed, we will notify affected users and report to
the relevant authorities without undue delay, as required by law.
10. Changes
Changes to this policy will be posted on this page; significant changes will also be announced
in the Service.
11. Contact
Privacy team, Codeholics LLC
Email: [email protected]
Codeholics LLC, New York, United States