Health Schedule LLC Privacy Policy
Health Schedule LLC (“Health Schedule,” “we,” “us,” or “our”) provides workforce scheduling software for healthcare organizations and clinical teams. This Privacy Policy explains how we collect, use, disclose, and protect information when you use our website, application, services, and related communications, collectively, the “Services.”
By using the Services, you acknowledge the practices described in this Privacy Policy.
1. Scope of This Privacy Policy
This Privacy Policy applies to information we collect through:
- Our website, healthschedule.app;
- The Health Schedule web application;
- Customer support and business communications;
- Billing and account administration; and
- Other interactions related to the Services.
Health Schedule is intended for use by healthcare organizations and their authorized personnel, including administrators, physicians, physician assistants, clinicians, and scheduling staff. The Services are not intended for patients or children.
2. Important Notice: Do Not Enter Patient Information or PHI
Health Schedule is a workforce scheduling platform. We do not position the Services as HIPAA-compatible, and the Services are not intended to collect, store, process, or transmit protected health information (“PHI”) or patient information.
Customers and users must not enter patient names, diagnoses, medical record numbers, treatment information, insurance information, patient contact details, or any other patient-identifying health information into the Services.
The Services may include free-text fields, including leave reasons, notes, comments, scheduling notes, and administrative notes. Users should not enter sensitive personal information, patient information, PHI, or unnecessary medical details into these fields. If a leave reason or note is required, users should keep it brief and work-related, such as “vacation,” “conference,” “personal leave,” or “unavailable.”
If we later offer features intended to support HIPAA-regulated use cases, we will update our legal documentation and make appropriate contractual arrangements before doing so.
3. Information We Collect
We collect information in the following categories.
3.1 Account and Profile Information
When users create or manage accounts, we may collect:
- Name;
- Email address;
- Phone number;
- Organization name;
- Job title, clinician type, or role;
- User permissions and account type;
- Login credentials or authentication information;
- Account status; and
- User settings and preferences.
Clinicians and other authorized users may create their own accounts. Organization administrators may also invite, approve, manage, or administer user accounts depending on the configuration of the Services.
3.2 Scheduling and Workforce Information
Customers and users may enter information related to workforce scheduling, including:
- Shift assignments;
- Availability;
- Leave requests;
- Leave reasons or notes;
- Scheduling preferences;
- Clinician type or role, such as physician or physician assistant;
- Facility, department, or site assignments;
- Schedule history;
- Staffing rules, constraints, or notes;
- Administrative comments related to scheduling; and
- Audit history or activity related to schedule changes.
This information is generally work-related and is used to provide scheduling, staffing, availability, and administrative functionality.
3.3 Billing and Payment Information
If you purchase a subscription or paid service, we may collect billing-related information, including:
- Billing contact name;
- Billing email address;
- Company or organization name;
- Billing address, if provided;
- Subscription plan;
- Payment status;
- Invoice history; and
- Transaction metadata.
If payment processing is enabled, payment card information will be processed by a third-party payment processor. We do not intend to store full payment card numbers on our own systems.
3.4 Communications and Support Information
If you contact us, request support, submit feedback, or communicate with us, we may collect:
- Your name;
- Email address;
- Phone number, if provided;
- Organization;
- Message content;
- Support requests;
- Feedback; and
- Any other information you choose to provide.
3.5 Usage, Device, and Log Information
When you use the Services, we and our service providers may automatically collect technical and usage information, including:
- IP address;
- Browser type;
- Device type;
- Operating system;
- Referring pages;
- Pages or features accessed;
- Dates and times of access;
- Session activity;
- Error logs;
- Performance logs;
- Security logs;
- Audit logs; and
- Approximate location inferred from IP address.
3.6 Cookies, Local Storage, and Similar Technologies
We use cookies, browser local storage, and similar technologies to operate and improve the Services. The list below describes the specific items we store and why.
Essential storage (always active)
These items are required for the Services to function. They are stored regardless of cookie consent choices.
- Authentication session cookie (
ms_refresh) — an HTTP-only refresh-token cookie set by our server to keep you signed in securely. It is not accessible to browser JavaScript. The short-lived access token is kept in browser memory and is not stored in a cookie or local storage. - Session activity (
idle:lastActivity) — tracks recent activity across browser tabs to support automatic session timeout for security. - Authenticated display profile (
clinician) — stores a limited display-only profile containing your identifier, name, email address, and organization identifier so the application loads quickly after sign-in. Authorization and role information are always reloaded from the server. - Cookie consent preference (
consent:preferences) — stores your cookie consent choice so we do not show the consent banner on every visit. - Preference ownership (
preferences:last-owner) — separates locally stored preferences by organization and user so one account does not inherit another account's settings.
Functional storage (active when you accept preferences)
Stored items remember your display and filter preferences. If you reject non-essential storage, stored preferences will reset each session.
- Appearance — follows your operating system light or dark setting by default. If you use the in-app theme toggle, the choice applies only to the current page session and is not stored.
- Calendar view and display settings (
calendar:view-mode,calendar:density,calendar:text-size,calendar:month-layout,calendar:filter-sidebar-open,calendar:show-facility,calendar:military-time, andcalendar:shade-dimension) — remembers your preferred calendar layout, density, shift text size, time format, shading, and sidebar state. - Calendar filters (
calendar-applied-filters) — remembers which clinician, facility, and shift filters you have applied so they persist across page loads. - Import mode (
settings:import-mode) — remembers which import tab (users, templates, or schedule) you last used in the settings area. - Selected clinician (
availability_physician_*andstats_physician_*) — remembers which clinician an administrator last viewed in availability and statistics pages. - Workload display settings (
stats_workload_multipliers_*) — remembers custom workload multipliers used in the statistics view. - Browser analytics storage — when you accept all, PostHog may create cookies or local-storage entries containing analytics consent, device, session, and usage identifiers. These are disabled when consent is pending or rejected.
You can control cookies through your browser settings. Some parts of the Services may not function properly if cookies or local storage are disabled.
4. Analytics
We use PostHog to understand how visitors and users interact with our website and Services. PostHog may process product usage events, account or organization identifiers, pages and features accessed, web performance measurements, device and browser information, approximate location, referring pages, and usage patterns.
We use analytics to improve the Services, understand product usage, troubleshoot issues, and make better product decisions. Browser-side PostHog analytics are disabled while your non-essential storage choice is pending and when you reject non-essential storage. Server-generated product events, security records, and operational logs may still be processed as necessary to provide, secure, and improve the Services.
We do not use targeted advertising or retargeting pixels.
5. How We Use Information
We use information to:
- Provide, operate, and maintain the Services;
- Create and manage user accounts;
- Authenticate users;
- Display, manage, and update schedules;
- Process availability, leave requests, and shift assignments;
- Save user preferences, including filters and interface settings;
- Provide administrative tools to customer organizations;
- Process billing, subscriptions, payments, and invoices;
- Provide customer support;
- Send service-related notices;
- Send product updates or optional marketing communications;
- Monitor performance and troubleshoot errors;
- Improve product functionality and user experience;
- Analyze website and product usage;
- Maintain security and prevent misuse;
- Create audit logs and security records;
- Enforce our agreements and policies;
- Comply with legal obligations; and
- Develop new features and services.
We may also use aggregated or de-identified information for analytics, product improvement, research, benchmarking, or business purposes. Aggregated or de-identified information does not identify a specific individual.
6. How We Share Information
We do not sell personal information in the ordinary sense of exchanging it for money. We also do not use targeted advertising or retargeting pixels.
We may share information in the following circumstances.
6.1 With Your Organization
If your account is associated with an organization, information in your account and information you enter into the Services may be visible to authorized administrators and other authorized users within that organization. For example, administrators may be able to view users, schedules, leave requests, availability, shift assignments, phone numbers, notes, and audit history.
6.2 With Service Providers
We may share information with vendors and service providers that help us operate the Services. These may include:
- Amazon Web Services (AWS), for application hosting, managed databases, caching, logging, security, and backups;
- PostHog, for product analytics, usage events, web performance measurements, and operational telemetry;
- Sentry, for error monitoring, performance monitoring, and debugging; and
- Resend, for transactional email delivery.
These service providers may process information on our behalf as necessary to provide their services to us.
6.3 Business Transfers
If Health Schedule is involved in a merger, acquisition, financing, reorganization, bankruptcy, sale of assets, or similar transaction, information may be transferred as part of that transaction.
6.4 Legal, Safety, and Security Reasons
We may disclose information if we believe it is necessary to:
- Comply with applicable law;
- Respond to legal process;
- Protect the rights, property, or safety of Health Schedule, our customers, users, or others;
- Detect, investigate, or prevent fraud, abuse, security incidents, or technical issues;
- Enforce our agreements or policies; or
- Maintain the security and integrity of the Services.
6.5 With Your Consent or Direction
We may share information with your consent or at your direction.
7. Customer Data and Our Role
Health Schedule provides software to organizations. In many cases, the customer organization controls the information entered into the Services by administrators, clinicians, and other authorized users.
Where we process information on behalf of a customer, we do so according to our agreement with that customer and the customer’s instructions. If you are an end user of an organization using Health Schedule and have questions about information your organization controls, you may need to contact your organization directly.
8. Data Retention
We retain information for as long as reasonably necessary to provide the Services, comply with legal obligations, resolve disputes, enforce agreements, maintain security, and support legitimate business purposes.
Retention periods may vary depending on the type of information, customer configuration, subscription status, contractual requirements, legal obligations, backup retention practices, and operational needs.
Customers may request deletion or export of certain organization data, subject to our agreements, legal obligations, backup retention practices, and technical limitations.
9. Security
We use reasonable administrative, technical, and organizational safeguards designed to protect information from unauthorized access, loss, misuse, alteration, or disclosure.
These safeguards may include access controls, logging, monitoring, encryption where appropriate, vendor security controls, and other measures designed to protect the Services.
However, no method of transmission or storage is completely secure. We cannot guarantee absolute security of information.
Users are responsible for maintaining the confidentiality of their login credentials and for promptly notifying us of any suspected unauthorized account access.
10. Your Privacy Choices and Rights
Depending on your location and relationship to Health Schedule, you may have certain rights regarding your personal information, such as the right to:
- Request access to personal information;
- Request correction of inaccurate personal information;
- Request deletion of personal information;
- Request a copy of personal information;
- Object to or restrict certain processing;
- Opt out of certain communications; or
- Appeal a decision we make regarding a privacy request, where required by law.
To make a privacy request, contact us at:
We may need to verify your identity before fulfilling a request. If your information is controlled by your organization, we may direct you to contact that organization.
11. Colorado Privacy Notice
If the Colorado Privacy Act applies to Health Schedule or to a particular processing activity, Colorado residents may have rights to access, correct, delete, and obtain a portable copy of certain personal data, as well as rights to opt out of certain types of processing such as targeted advertising, sale of personal data, or certain profiling activities.
Health Schedule does not use targeted advertising or retargeting pixels and does not sell personal information in the ordinary sense of exchanging it for money.
You may submit Colorado privacy requests by contacting:
If we deny your request, you may have the right to appeal our decision by replying to our response or contacting us again at the same email address with the subject line “Privacy Appeal.”
12. Communications Preferences
We may send service-related communications, such as account notices, security alerts, billing messages, administrative updates, password reset emails, product functionality notices, and other transactional messages. These communications are necessary for the Services and may not be fully opt-outable while you maintain an account.
We may also send optional marketing or product update communications. You may opt out of marketing emails by using the unsubscribe link in the email or by contacting us at privacy@healthschedule.app.
13. Cookies and Tracking Preferences
We use cookies, browser local storage, and similar technologies for authentication, security, functionality, and preferences. A full description of what we store and why is provided in Section 3.6.
Cookie consent banner
When you first visit the site, a banner asks whether you would like to accept or reject non-essential storage. Your choice is remembered so the banner does not appear on subsequent visits.
- Accept all — essential and functional storage are active, and browser-side PostHog analytics are enabled. Your preferences are saved between sessions.
- Reject non-essential — browser-side PostHog analytics are disabled, and functional preference storage is cleared and disabled. Essential storage for authentication, session security, limited display caching, preference ownership, and your consent record remains active. Server-generated security records, product events, and operational logs also continue. The Services remain fully functional; optional preferences reset to defaults each session.
To change your choice, clear your browser's local storage for healthschedule.app (specifically the consent:preferences key) and reload the page. The consent banner will reappear.
Browser controls
You can also control or clear cookies and local storage through your browser settings. Disabling cookies or local storage entirely may affect the availability or functionality of certain features, including sign-in.
Health Schedule does not use cookies for targeted advertising, retargeting pixels, or selling personal information. If we use those technologies in the future, we will update this Privacy Policy and provide any legally required choices.
14. Third-Party Services and Links
The Services may contain links to third-party websites or integrations with third-party services. We are not responsible for the privacy practices of third parties. Their privacy policies govern how they collect, use, and share information.
15. International Users
Health Schedule is operated from the United States. If you access the Services from outside the United States, your information may be transferred to, stored in, or processed in the United States or other jurisdictions where our service providers operate.
By using the Services, you understand that your information may be processed in the United States, where privacy laws may differ from those in your location.
16. Children's Privacy
The Services are not intended for children under 13, and we do not knowingly collect personal information from children under 13. If we learn that we have collected such information, we will take reasonable steps to delete it.
17. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will provide notice as appropriate, such as by updating the effective date, posting a notice in the Services, or sending an email.
Your continued use of the Services after an updated Privacy Policy becomes effective means you acknowledge the updated Privacy Policy.
18. Contact Us
For questions about this Privacy Policy or our privacy practices, contact us at: