This policy explains how HLR Studio processes information when you use Orde. The app calculates your schedule primarily on your device. We do not sell your personal data or broker your information.
1. Data Controller & Contact
HLR Studio is the controller of personal data. For privacy questions, access, or rights requests, contact hello@hlrstudio.dev.
2. Data Stored Locally on Your Device
Without creating an account, your schedule data is stored locally in your phone's database (using SQLite/drift). This includes shift patterns, types, exceptions, vacation days, sick leaves, reminders, settings, and personal notes. The calendar is calculated privately on the phone.
An account is optional. If you choose to sign in, we use secure authentication with Google or Apple via Firebase Authentication. Firebase receives the account identifier and basic profile details (name and email) provided by Google or Apple.
3. Cloud Backup
If you sign in and enable backup, Orde saves a copy of your data in Cloud Firestore (encrypted at rest by Google, like the rest of the database) at users/{uid}/backup/current. The database is hosted in the European multi-region eur3. This backup is used solely to restore your schedules when switching phones or reinstalling the app.
4. Local Device Calendar Writing
If you choose to enable the calendar sync option in Settings, Orde can write your shifts (date, shift name, and hours, excluding personal notes and leave reasons) to a dedicated calendar named “Orde” on your phone's native calendar (Apple Calendar or Android Calendar).
This operation is performed strictly on your local device: this data never leaves your phone and is never sent to our servers. You can turn this off and remove the “Orde” calendar anytime directly from the app's Settings.
5. Shared Links
When you create a share link, Orde publishes a token-protected, read-only calendar view in Firestore. To publish it without asking you for an account, the app creates an anonymous Firebase Authentication session with no name or email; if you later sign in with Google or Apple, that session is linked to your account. Anyone with the unique link can view your shift schedule in a web browser.
By strict privacy design, the shared web view never shows personal notes, sick leave reasons, or coworker names. Certain sensitive leaves appear only as “Unavailable”. You can revoke and delete any share link anytime from the app's Settings.
6. Analytics & Crash Reporting
We use Google Analytics for Firebase to analyze aggregate feature usage (tied to a pseudonymous install identifier, never to your name or email) and Firebase Crashlytics to diagnose unexpected application crashes. These services process technical device identifiers and error stacks. Analytics is never used to read the content of your personal notes or leaves.
7. Advertising & In-App Purchases
The free version of Orde may display banner ads served by Google AdMob on the Month and Hours screens only (never in Today or home widgets). Required consent is gathered via Google UMP (and Apple's ATT prompt on iOS) before serving personalized ads. The Pro version is completely ad-free.
Orde Pro purchases and subscriptions are handled by RevenueCat alongside Google Play Billing (Google LLC) and Apple In-App Purchases (Apple Inc.). RevenueCat receives technical receipt information necessary to validate purchases and link them to your app account.
8. Service Providers
We rely on trusted enterprise infrastructure: Google Cloud / Firebase (Authentication, Firestore in eur3, Analytics, Crashlytics, and Hosting), Google AdMob, RevenueCat, Google Play Store, and Apple App Store. Each provider handles data under its respective privacy terms.
9. Your Rights & Account Deletion
You can export your schedule anytime to a portable JSON file. You can revoke share links, sign out, or permanently delete your account and remote data from the Account section. For complete instructions, visit our Account & Data Deletion page.
10. Updates to this Policy
We may update this policy to reflect product improvements. Changes will always be published on this page with the revision date clearly stated.