My Therapy Shifts
Privacy policy
How information is used for staff scheduling and access.
Last updated September 30, 2026
Information we handle
My Therapy Shifts is a staff scheduling tool. Its protected scheduler stores your name, personal email address, verified sign-in identifier, discipline, employment type, access role, approval status, and account status.
It also stores work dates and hours, shift requests and their comments, manager-recorded time off and its status, monthly scheduling requirements, changes and approvals in the activity log, notification preferences, and notification delivery records. Historical display names or usernames may remain in existing records.
If you report a problem, the scheduler stores your report, the optional screenshot you attach, and manager replies or status updates. Do not include patient information, passwords, verification codes, or medical details in a report, comment, or AI message.
How information is used and shared within the team
Information is used to verify sign-in, manage staff access, coordinate shifts and coverage, review changes and time off, send supported notifications, troubleshoot problems, and maintain a record of scheduling decisions.
Approved active staff can see team scheduling information, including staff names, disciplines, scheduled work, and recorded time-off status. Managers can review staff profiles and email addresses, manage access and scheduling, inspect the activity log, and review team bug reports. Staff can read their own requests and bug reports.
Signing in does not automatically approve an account. Scheduler permissions come from the current staff roster and manager-assigned role.
Services that help the scheduler work
Cloudflare hosting and sign-in
Cloudflare hosts the site and scheduler, stores scheduler records in D1, and handles access verification through Cloudflare Access. Access uses sign-in cookies and processes authentication events. Cloudflare may process technical connection information as part of delivering and protecting the service. The scheduler does not generate, collect, or store email sign-in codes or account passwords.
Google sign-in, when available
If you choose Google as an available sign-in method, Google verifies your identity and shares basic sign-in information with Cloudflare Access, such as your name, email address, and account identifier. The scheduler receives a verified identity from Cloudflare Access. This sign-in integration is for identity verification; it does not request access to your Gmail messages, Google Drive files, contacts, or Google Calendar.
Email notifications
Resend sends upcoming-shift reminders and PTO approval notifications to eligible staff using their personal email. Delivery uses the recipient address and the relevant work or time-off date, hours, and discipline. Private request comments are not included in these emails. Delivery status and provider message identifiers are retained for troubleshooting.
Optional AI drafting
If you use the AI helper, Cloudflare Workers AI processes your submitted date-and-hour messages to prepare an editable draft. Shift drafting also includes the current date, your discipline and employment type, and relevant enabled holiday dates. Manager PTO drafting does not send the selected employee or approval status to the model.
The scheduler does not automatically send its roster, saved assignments, your email address, or sign-in token to the model. Chat text and drafts are held in the page’s memory rather than saved as a chat history in the scheduler database; daily usage counts are stored. Reloading or clearing the page removes that local draft, but does not control a provider’s processing or retention. Review every draft before confirming it.
Providers operate under their own terms and privacy policies: Cloudflare, Google, and Resend.
Retention and your choices
Scheduling history, account and approval records, audit history, delivery records, and bug reports are retained to support scheduling, troubleshooting, and recovery. Moving a staff member to Trash is a recoverable removal, not a permanent erasure: previous days and coverage remain, and a recovery snapshot is saved. The current app does not provide an automatic deletion period or a self-service permanent-delete feature.
You can turn upcoming-shift reminder emails on or off in the scheduler. They are on by default when no preference has been saved. Turning them off does not turn off PTO approval emails or sign-in messages. AI drafting and screenshot attachments are optional.
For corrections, access changes, or a request about your information, contact your scheduling manager through your facility’s usual channel. A request may require review of retained history and recovery records; this policy does not promise immediate deletion from all systems or provider backups.
Public information pages
These public pages contain information about My Therapy Shifts. They have no forms, advertising scripts, analytics scripts, or embedded scheduler data. Opening the staff schedule takes you to the separately protected application. Cloudflare still handles the connection needed to serve these pages.
Questions or concerns
Contact your scheduling manager through your facility’s usual channel for privacy, access, or scheduling questions. Approved staff can use Help → Report a problem for technical issues. This policy may be updated as the service changes; the date above identifies the current version.