PagerflowBack to app →

Privacy

Privacy Policy

Last updated August 2026

This page explains what PagerFlow stores today, which infrastructure it uses, and where users should go for data-access or deletion requests.

What PagerFlow stores

PagerFlow stores the information needed to run shared schedules and access controls. That includes account details, schedule data, doctor or team records, viewer access settings, generated calendar links, and the device preferences needed to keep the app usable across sessions.

When you use the web app, PagerFlow also stores session data and convenience settings in your browser. Today that includes local storage entries for sign-in state, remembered PIN access, selected schedule groups, install-prompt dismissal, and IndexedDB caches used to speed up schedule loading.

Infrastructure and processors

PagerFlow uses Supabase for authentication and hosted application data. That means account authentication, persisted schedule records, and related access-control data are processed through Supabase-backed services. The application is hosted on Vercel.

PagerFlow also uses these processors for specific features. Google Firebase Cloud Messaging delivers push notifications to the iPhone and Android apps, which means a device notification token and the alert itself pass through Google. Resend sends email, including PIN delivery and schedule-change alerts where an organization has enabled them. Sentry receives error reports so faults can be diagnosed, configured not to send personal data.

PagerFlow does not include advertising SDKs, and does not track users across other companies’ apps or websites. If a processor is added or removed later, this page is updated before that change ships.

The iPhone and Android apps

The PagerFlow apps show the same schedule as the website and store the same information described above. Two things are specific to them. The app keeps a copy of your most recent schedule on the device so it opens instantly, and that copy is removed when you sign out or delete the app. The app can also send notifications, which requires your permission the first time and can be switched off at any point in your phone’s settings.

A notification about your schedule names the shift and the day that changed, for example “Vascular Day Call (8am-5pm) added for Thu, Nov 26”. A notification about a request you filed says what was decided, for example “Your time off was approved”. A change covering many days says how many shifts and the range of dates. The shift name is whatever your hospital calls that shift; we never add anyone else’s name, account, or contact details to it. Because a notification can appear on a locked screen, unusually long shift names are replaced with the words “Scheduled block”, and you can switch previews off entirely in your phone’s own notification settings. The apps do not use the camera, microphone, photos, contacts, or location.

How data is used

PagerFlow uses stored data to authenticate users, load schedules, remember user-selected views, support calendar export links, and provide viewer or PIN-based access where enabled by the organization running the schedule.

PagerFlow does not sell personal data. Data is used to operate the scheduling product, respond to support requests, and maintain service reliability.

Retention and deletion requests

Browser-stored data can usually be removed by signing out, clearing the app’s site data, or removing the installed app from the device. Signing out also removes the device from the notification list, so alerts stop. Organization-managed schedule records remain under the control of the organization account that owns the workspace.

PagerFlow accounts are created and removed by the hospital or group that runs the schedule, not by individual users, so there is no self-service account deletion inside the app. To have your account removed, ask the administrator who issued your access, or contact support below and we will work with them.

For account access, privacy questions, or deletion requests, contact admin@pagerflow.app. Requests should include the organization name, the affected account or schedule, and the action requested so support can verify the request.

Privacy Requests

Use the support address for data-access requests, deletion requests, and questions about how a workspace is configured. For faster handling, include your organization name, the email address used to sign in, and the exact schedule or access flow involved.

Last updated August 2026