SHIFT Privacy Policy
Last updated: July 11, 2026
This policy describes the current SHIFT iOS app and the public pages at useshift.app. SHIFT is a race-weekend activity, hydration and preparation app. The current App Store candidate uses email authentication and does not offer a connected-fitness-provider flow.
Information SHIFT Collects
- Account and profile information: email address, display name, role and account identifiers used for sign-up, sign-in, verification, account management and private crew features.
- Fitness information: activity type, duration, distance, pace or speed, calories when entered, workout notes and saved session history.
- Health and wellness information: hydration logs and user-entered recovery, readiness, nutrition or goal information where those controls are used.
- User content: goals, private crew or challenge setup content, workout notes, support reports and questions submitted to Ask Coach.
- Subscription information: Apple subscription product, purchase, restore and entitlement history linked to the signed-in SHIFT user identifier through RevenueCat. SHIFT never receives the user's payment-card details.
- Security and reliability information: Supabase-hosted authentication and API logs may record the user identifier, authentication action, timestamp, IP address, user agent, requested API route, response status and country-level network metadata. SHIFT uses this information for authentication, abuse prevention, troubleshooting and service reliability, not advertising.
Location and Device-Only Information
If you start a tracked Run, Ride or Walk and allow foreground location, SHIFT uses raw coordinates on the device to calculate distance, pace or speed and draw a private route preview. Raw coordinates are not uploaded, synced or shared in the current candidate; background location and live location sharing are not enabled. Only the resulting fitness values, such as distance and duration, may be saved to your SHIFT account.
Network requests can expose an IP address and country-level network metadata to SHIFT's hosting provider as described above. This is security and diagnostic logging, not the app's precise-location feature.
If you choose a profile photo, SHIFT resizes it and keeps it only inside the app on that device. The current candidate does not upload or share the photo. It is removed from that device when account-bound local data is cleared, the account is deleted, app storage is cleared or the app is uninstalled.
How SHIFT Uses Information
SHIFT uses information to authenticate users, save private progress, show history and passport state, operate private crew features, prevent abuse, provide support, manage subscriptions and keep the service reliable. Health, fitness and user-entered goal information may also personalize the preparation suggestions that a user asks SHIFT to provide. RevenueCat uses the signed-in user identifier and purchase history for entitlement functionality, fraud prevention, customer history and subscription analytics. SHIFT does not sell personal data or use health, fitness, location or user content for advertising.
AI Features
Before the first Ask Coach request, SHIFT presents a point-of-use notice describing the data that will leave the device and asks for consent to the current notice. When a signed-in user then submits a question, SHIFT sends that question and a compact context containing recent SHIFT activity, hydration, goals and Cups state to OpenAI through a SHIFT server function. The request excludes the device-only profile photo, exact route coordinates and connected-provider data.
SHIFT requests that OpenAI not persist Responses API application state. OpenAI may still retain API content in abuse-monitoring logs for up to 30 days under its API data controls, or longer where legally required. If you do not submit Ask Coach, SHIFT does not send coaching context to OpenAI. Withdrawing Ask Coach consent in Settings blocks future AI requests; it cannot reverse provider retention that has already begun for an earlier request.
Service Providers and International Processing
- Supabase: authentication, database, private storage, security logs and server functions.
- RevenueCat and Apple: subscription product lookup, purchase, restore, entitlement, fraud prevention and subscription history.
- OpenAI: generation of a response only after a user submits Ask Coach under the current consent notice.
- Web hosting and email providers: delivery of public policy/support pages and support correspondence.
These providers may process data in the United Kingdom, European Economic Area, United States or other locations where they operate. SHIFT requires service providers acting for SHIFT to protect user data to standards at least equivalent to those described in this policy, subject to their contracts and applicable law, and does not authorize advertising or unrelated use of the data.
Retention and Deletion
- Account, profile, activity, hydration, private crew and user-entered content is kept while the account is active and is removed from live SHIFT account systems when in-app deletion completes, unless a specific legal obligation requires limited retention.
- Supabase-hosted authentication and API logs for the current production plan are normally available for up to 7 days. A security incident record extracted for investigation may be kept only as long as needed to resolve and document that incident or meet a legal obligation.
- Daily database backups may retain a deleted record for up to 7 days before rotation. A restoration process must reapply completed deletion requests before restored data is returned to service.
- OpenAI abuse-monitoring retention for an Ask Coach request may last up to 30 days as described above.
- Support correspondence is kept for up to 12 months after the request is resolved, unless a longer period is required for a dispute, fraud prevention or legal obligation.
- A completed deletion request may leave a minimal, de-identified status and timestamp record for up to 24 months so SHIFT can demonstrate completion; the completed record does not retain the account email or user identifier.
- Apple and payment-service records are controlled by those providers and may be retained for their legal, tax, fraud-prevention and platform obligations. Deleting SHIFT does not cancel an Apple subscription.
Your Choices
- Decline or revoke foreground location in iOS Settings and use the timer/manual passport path instead.
- Decline Ask Coach or withdraw Ask Coach consent in SHIFT Settings to stop future AI requests.
- Correct editable account information in the app, or contact support for access or correction help.
- Delete the account in SHIFT Settings. If you cannot sign in, use the instructions at useshift.app/delete-account.
- Clear phone-only data from Settings or remove the app to clear device-only information.
Children
SHIFT is not directed to children under 13. A parent or guardian should review use of SHIFT by a minor, and a minor must not use Ask Coach without the consent required in their country and by the applicable AI-service terms.
Contact
For privacy or support questions, contact SHIFT at sam@useshift.app.