Privacy Policy
Last updated 4 August 2026.
The short version. Delegyn Shift stores who works where and when. It stores nothing about the people your agency supports — no names, no diagnoses, no support plans, no service notes. There is nowhere in the product to enter that information, which is a deliberate design decision and not a setting you can change.
Who this covers
Delegyn Shift is workforce scheduling software for providers supporting people with intellectual and developmental disabilities. This policy describes what we collect from the agencies who subscribe and from the staff members those agencies invite.
The service is operated by BrightBench LLC, a Nebraska limited liability company. “We”, “us” and “our” below mean BrightBench LLC.
Your agency decides what goes into the product and who may see it. In data-protection terms your agency is the controller of its staff information and we process it on your behalf.
What we store
| Information | Why |
|---|---|
| An email address, if you subscribe to the mailing list on this website | To send you what you subscribed to, and nothing else. Nothing has been sent yet. Ask us to stop and we mark the address as unsubscribed and never send to it — we keep the record of the request rather than deleting the address, so a later import cannot put you back on. Ask us to delete it outright and we will. This is not connected to any agency account. |
| Agency name, time zone, locations and the positions you schedule | To build your schedule. |
| Staff first and last name, position, work locations, hour preferences and availability | To know who can work which shift. |
| Staff email address, for anyone given a login | To sign in and reset a password. Staff without a login need no email. |
| Staff phone number (optional) | So a scheduler can reach someone. Not required, and nothing is sent to it today. |
| Certification names and expiry dates, if your agency turns on certification tracking | To warn a scheduler, or stop them, before somebody is put on a shift after their licence has lapsed. Off unless your agency enables it. We do not verify a certificate, hold a copy of one, or know what any state requires — the record is the name and date your agency entered. |
| Shifts, assignments, time off, call-offs, lateness and no-shows | The schedule itself, and the attendance record your supervisors keep. |
| Password, stored only as a bcrypt hash | To verify a sign-in. We cannot read your password or recover it for you. |
| A session cookie | To keep you signed in. It is the only cookie the product sets. |
| Billing email, invoice history and a Stripe customer reference | To bill a paid account and answer questions about a past invoice. Only on paid accounts. Never a card number — those are entered on Stripe's own pages and we never receive them. |
What we do not store
- Anything about the people your agency supports. No individuals served, no diagnoses, no behavior plans, no incident reports, no service or progress notes. The product has no field for any of it.
- No payroll or banking details, and no Social Security numbers.
- No analytics or advertising trackers. There is no Google Analytics, no advertising pixel, and no third-party script following you between pages.
This is worth stating plainly because it changes what a breach could expose. A serious failure on our side would reveal staff schedules and contact details. It could not reveal anyone's care information, because we never had it.
Who else processes this information
We use a small number of service providers to run the product:
| Provider | What they handle |
|---|---|
| Cloudflare | Hosting, DNS and this website. |
| Neon | The database where your schedule is stored. |
| Nobody — the mailing list has no provider yet | The mailing list. The form on this site posts to our own application and the address is stored in our own database — no third party is involved and no provider has been chosen. When one is, it will be named here before your address is given to it. Ask us to stop and we will. This is separate from your agency account — being on the list does not create one, and holding an account does not put you on the list. |
| Stripe | Payments. If you convert to a paid account, your agency name, billing email and card or bank details are handled by Stripe. Card numbers are entered on Stripe's own pages and never reach us — we hold only a customer reference and the invoice history. |
| Anthropic | The optional assistant. When a scheduler types a request in plain English, that sentence is sent to Anthropic's API, along with the date, the week on screen and the names of your locations and positions, to be turned into a structured instruction. Your staff list is not sent. See below. |
We do not sell your information, and we do not share it with anyone for advertising.
About the assistant
A scheduler can type something like “move Maria to Tuesday at Westmoor” instead of clicking through the grid. What is sent to Anthropic's API is the sentence they typed, today's date, the week on screen, and the names of your locations and positions.
Your staff list is not sent. No roster, no phone numbers, no email addresses, no availability, no hours. The model is given no way to look anybody up — it is asked only to read the sentence and copy any name in it exactly as typed. Matching that name to a person happens afterwards, on our own servers.
So if a scheduler types a person's name, that name travels inside their sentence, in the same way it would if they typed it into any search box. Nothing else about that person goes with it.
The model only ever proposes a change; every change is applied by our own code after the same checks that apply to a change made by hand.
If you would rather no staff names left our systems for this purpose, simply do not use the assistant. Nothing is sent unless a scheduler types a request into the command bar, and the rest of the product works normally without it.
There is no per-agency switch to turn it off today — it is on for every account or none. If a hard guarantee rather than a practice is what your agency needs, tell us before you sign up and we will say plainly whether we can offer it yet.
Who can see what
Within your agency, access follows the role you give someone. Administrators see everything for your agency. Schedulers build and change schedules. Staff see only their own shifts and the openings offered to them — a staff member cannot see an unpublished schedule, cannot see attendance records, and is shown a count of colleagues on a shift rather than their names.
Agencies are separated from one another. No agency can see another agency's staff, schedules or anything else. We can see your data in order to operate and support the product; we do not look at it otherwise.
Keeping it safe
- Encrypted in transit with HTTPS everywhere.
- Passwords stored only as bcrypt hashes, never in a readable form.
- Sign-in links for invitations and password resets are single-use, expire, and are stored hashed rather than in the clear.
- Changing a password ends every existing session for that account.
No system is perfectly secure, and we will not claim otherwise. If we ever discover a breach affecting your information we will tell you without delay and tell you what we know, including what we do not yet know.
How long we keep it
We keep your agency's information for as long as your account is active. If you close your account, tell us and we will delete it; ask before you close it and we will provide an export first. Backups are kept for up to 90 days on Cloudflare R2, in the same account as the hosting above, and a deletion reaches them as those copies age out.
Inside an active account we do not delete old schedules. A shift worked in 2026 is still there in 2030, and that is deliberate: who was in a home on a particular night is the record a licensing review or a payroll question asks for, and several states expect an employer to keep time records for years. Archiving a home or a staff member keeps their history for the same reason — it takes them out of the working lists and destroys nothing. Deleting something outright is a separate, deliberate action, and the app tells you exactly what it will remove before you confirm it.
Your choices
You can ask us for a copy of your agency's data, ask us to correct it, or ask us to delete it. If you are a staff member rather than an administrator, your agency controls your record — ask your administrator first, and contact us if that does not resolve it.
Children
Delegyn Shift is a tool for employers and their staff. It is not directed at children and we do not knowingly collect information from anyone under 16.
Changes
If we change this policy we will update the date at the top, and we will tell subscribing agencies directly about any change that materially affects them rather than relying on you to notice.
Contact
Questions about privacy, or a request about your data: support@delegynshift.com.