Summary
Book’d Off does not operate any servers and does not collect your personal data. Everything you enter stays on your device. There is no analytics, no crash reporting, no advertising, and no tracking.
If you choose to enable cloud backup, your data is sent directly from your device to your own Google Drive account. The developer has no access to it at any point.
This policy covers every version of the app — Android, Wear OS and iOS. They are built from the same code and behave the same way; the handful of places where the platforms differ are named below.
Who we are
Book’d Off is developed and maintained by Allin Software, and is published on Google Play for Android and Wear OS, and on the App Store for iPhone and iPad. For any privacy question, contact contact.allinsoftware@gmail.com.
Data stored on your device
The app stores the information you enter in a database on your device. Depending on which features you use, this can include:
- your shift patterns, shift types, rota, and individual shift entries;
- annual leave records, leave-year settings, and TOIL balances;
- overtime, rest-day working, and bank holiday working, including any pay rates you enter;
- commute mileage, if you use the mileage tracker;
- alarm and reminder settings, and your app preferences.
Pay rates and mileage are stored purely so the app can calculate your own totals. No payment or bank details are ever entered into or held by the app. None of this data leaves your device unless you turn on cloud backup or calendar sharing.
Google user data
Cloud backup and calendar sharing are optional Pro features. They stay off until you unlock them and sign in with Google from within the app. If you never sign in, the app requests no Google data at all. Manual backup and restore to your own device involves no Google account.
What we request, and why
-
https://www.googleapis.com/auth/drive.file— used to create and manage backup and shared-calendar files in your Google Drive. This scope is deliberately narrow: it grants access only to files the app itself creates. Book’d Off cannot see, read, or modify any other file in your Drive. -
openidandemail— used solely to display which Google account you are signed in as, so you can confirm backups are going to the right place.
Backup
Backup files contain the rota data described above and are written to your Drive so you can restore after reinstalling or changing device. They are private to your Google account.
Sharing your calendar with someone else
If you enable calendar sharing, the app creates a file in your Google Drive containing a copy of your shift data and marks that file publicly accessible. You are then given a share code to pass to whoever you choose. Anyone holding that code can read your shared shift data, so treat it like a password and only give it to people you trust.
You stay in control. You can disable sharing at any time, which revokes public access to the file, and you can reset your share code, which permanently invalidates every code you have previously handed out.
Subscribing to someone else’s calendar
If you enter someone else’s share code, the app fetches their shared shift data and stores a copy on your device so their shifts can be displayed alongside your own. That copy is refreshed while the link remains active and is kept locally — it is never sent to the developer or anywhere else. Removing a linked calendar in the app deletes the cached copy from your device.
How your Google data is stored
Your Google credentials are never seen by the app in any form other than a token. Sign-in uses the standard OAuth 2.0 authorization-code flow with PKCE, handled by the system browser. The resulting tokens are held in your device’s own encrypted secure storage — the Android Keystore on Android, the Keychain on iOS — and are used only to talk to Google’s own APIs.
How it is shared
It is not. Google user data obtained through the Drive API is never transferred to the developer or to any third party. There is no backend service to transfer it to.
When you use these features, Google’s own Privacy Policy and Terms of Service also govern how your data is handled within Google’s own services.
Limited Use disclosure
Book’d Off’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Data obtained through Google APIs is used only to provide and improve the backup and calendar-sharing features described above. It is not sold, not transferred to third parties, not used for advertising, and not used to build profiles. No human reads it.
Other network connections
-
GOV.UK bank holidays — the app downloads the public UK bank holiday
calendar from
gov.uk. This is a plain request for a public file; no information about you is sent. - Google Play billing (Android) — Pro features are purchased through Google Play, which handles all payment processing. The app never sees your payment or financial details.
- Apple App Store purchases (iOS) — on iPhone and iPad the same Pro unlock is purchased through Apple’s in-app purchase system, which handles all payment processing. The app never sees your payment or financial details. Apple tells the app only whether the purchase exists, so it knows to unlock the Pro features.
Platform differences
The Android, Wear OS and iOS versions collect the same data — which is to say none of it leaves your device unless you turn on cloud backup or calendar sharing. They differ only in what each operating system asks you for:
- Notifications — both versions ask permission to notify you, so shift alarms and reminders can appear. On Android the app also asks for exact-alarm and full-screen-notification access, which is what lets an alarm wake the screen. iOS has no equivalent, so an alarm there arrives as a time-sensitive notification instead.
- Wear OS — the watch tiles are an Android feature and send your shift data from your phone to your own paired watch. There is no Apple Watch app, so nothing is sent anywhere on iOS.
- Home screen widgets — on both platforms the widgets read the app’s own on-device data. Nothing is uploaded to draw them.
- Apple’s privacy manifest — the iOS build declares no tracking and no collected data types, which is what the App Store privacy label reflects.
Children
Book’d Off is intended for adults managing their working schedule and is not directed at children under 13.
Your choices and how to delete your data
- Stop cloud backup — sign out of Google in the app’s settings. This deletes the stored tokens from your device immediately.
- Stop sharing — disable sharing or reset your share code in the app.
- Revoke access entirely — whichever platform you are on, visit your Google Account permissions page and remove Book’d Off.
- Delete backups — backup and shared files live in your own Drive and can be deleted from Drive at any time, like any other file.
- Delete on-device data — uninstalling the app removes its database from your device, on Android and on iOS alike.
How long data is kept
Because there is no server, we hold nothing and so retain nothing. Your rota data stays in the app’s database on your device for as long as the app is installed, and is removed with it when you uninstall. Backup and shared-calendar files stay in your own Google Drive until you delete them. Sign-in tokens are held in your device’s secure storage until you sign out, which deletes them immediately, or until Google expires them. Nothing is kept anywhere we could reach it, so there is no retention period for us to set and nothing for you to ask us to erase.
Changes to this policy
If this policy changes, the updated version will be posted on this page with a new date at the top.