Last updated: September 7, 2026
Thank you for using Shift Management Agent (the “App”). This page explains how BitterSweets-art (the “Developer”), which develops and provides the App, handles the information entrusted to it through the App.
The App is a service for several people at a store or workplace to view and use the same schedule. It is not built to work entirely inside a single device.
Information entered into the App is sent to and stored in a database on Supabase (provided by Supabase, Inc.), a cloud service the Developer uses. The servers that hold it are in the Tokyo region. Stored information is delivered to the devices of the members who belong to the same organization.
Each row in the database is separated by organization, so information belonging to an organization you do not belong to cannot be read.
The App has two sign-in methods.
(a) Registering with an email address
The email address and password are sent to the Supabase authentication service and stored as an account. Passwords are hashed by Supabase before being stored, and the Developer cannot see the password you entered.
(b) Using an account name issued by a manager
For people who do not have an email address, a manager can issue an account by choosing an account name and an initial password. This method handles the following.
This method does not handle email addresses. As the internal identifier in the authentication service, the App uses a string generated mechanically from the account name and the organization code, in a format that uses a domain that does not exist. This identifier is not shown on screen.
These are stored inside your device. They are lost from the device when the App is deleted, but the data on the server remains (see §7).
The Developer does not use the information for any purpose other than those above.
Because the App is a service used at a workplace, the information entered is shared with the members of the same organization.
How hourly wages are set, and to whom they are disclosed, is left to how the managers of that organization operate.
As stated in §1, this is where the data of the App is stored. Server-side processing such as authentication, issuing accounts, and deleting accounts is also carried out here.
Registration verification codes and password reset instructions are sent through the Gmail sending servers provided by Google LLC. On this route, the recipient’s email address and the body of the message pass through Google’s servers.
The App uses Apple’s standard features for the following. This communication takes place with Apple, and the Developer does not receive payment information such as credit card numbers.
Apple’s handling of information follows the Apple Privacy Policy.
If you purchase a paid plan, the service of RevenueCat, Inc. (United States) is used to manage the status of the subscription. What is sent to RevenueCat is the purchase information issued by the App Store (the product purchased, and the status and dates of purchase, renewal, and cancellation), together with an identifier that links the subscription to the account using it.
The contents of shifts, time clock records, and organizations are not sent to RevenueCat, and neither is your name or your email address.
The App does not incorporate an analytics tool (an analytics SDK) for collecting and analyzing how the App is used. Screen view history and operation history are not sent outside the App for the purpose of analysis.
The Developer does not sell the information entrusted to it to third parties.
The provision of information to the external services described in §5 is entrusted processing, within the scope necessary to provide the functions of the App. Apart from this, information is provided to a third party only with your consent obtained in advance, except where required by law.
Uninstalling the App does not delete the data on the server. The information stored inside the device (§2-4) is lost. The records of shifts, time clock entries, and membership remain on the server, and they are shown again when you sign in with the same account.
You can delete your account yourself: in the App, open “Account Settings” and proceed to “Delete account”. Deleting it removes your sign-in information together with the following.
Information that has to remain as a record of the organization stays on the organization’s side, with the information that links it to you removed. Confirmed shift slots that have already been built, and records of approving or rejecting other members’ requests, fall into this category.
Deleting an account cannot be undone. You can register again with the same email address after deleting, but the previous data cannot be restored.
Note that the owner of an organization cannot delete their account while other members remain in that organization. Please remove the remaining members first, or transfer ownership to someone else.
A manager can remove staff who have left from the organization. This operation covers membership and records within that organization; it does not delete the staff member’s own account. Deleting your own account is done with the operation in §7-2.
The App does not request access to the camera, photos, location, contacts, calendar, or microphone. Location is not used for time clock records.
Push notifications are not used either. Announcements are shown only inside the App.
In the feature that lets a manager send an invite code to staff by email, the mail composer of your device opens. You can check and edit the recipient and the body yourself before sending, and that content is not sent to the Developer’s server.
When you get in touch from “Feedback” in the App, the mail app on your device opens. The email address and the content you send this way are used only to respond to the inquiry and to investigate problems.
The App is not directed at children under the age of 13. If information about a child under 13 is obtained unintentionally, it is deleted promptly.
This policy may be updated as functions are added or changed. When there is a significant change, it is announced within the App. The latest text is always published on this page.
Questions and requests regarding this policy can be sent to the following address.
This English page is a translation of the Japanese privacy policy. The Japanese text is the original; if the two differ, the Japanese text applies.