Gialdyn Privacy Policy
Gialdyn helps a worker and individually invited people record shift intentions and check agreed gap and duration limits against registered records. It is an engineering preview awaiting independent reviews. Publishing this policy does not mean the app has been publicly released.
Personal records on your device
Personal mode works offline. Duty labels, times, time zones, observations, local history and drafts are stored in an encrypted local database. Android Keystore protects the local encryption key. An optional app lock can use a locally chosen PIN or Android biometric verification. Gialdyn does not receive your biometric template. The app does not include advertising or analytics SDKs.
Android system backup is disabled for the app. You choose where to save an encrypted export through Android's file picker. A chosen storage provider may receive that file under its own terms. Keep the export and its recovery code separately: someone who has both can read the export and, for a shared recovery export, replace the authorized device.
What sharing sends
Sharing uses a Cloudflare Worker and Durable Object service. Requests contain device public keys, opaque ledger and relationship identifiers, encrypted records, cryptographic commitments and proofs, signatures, policy values, revisions and request times. The service processes network metadata such as IP addresses to deliver requests. Cloudflare may process operational and security data under its own policies.
Duty labels and exact times are encrypted for the relevant participants. An invited person can read the records shared with that relationship, rather than your other employers' plaintext records. The service can see metadata, including relationship and record counts, changes and request timing. Proof results and the order of commitments can reveal limited relationships between times. This is not anonymous communication or protection against every inference.
A complete, consistent service is part of the trust model. A successful check concerns the registered records and selected limits at that revision. It does not establish actual attendance, complete disclosure of all work, legal compliance, fitness for work or medical safety. A device signature does not establish a person's legal identity.
Reports and safety
A report deliberately discloses its category, your note, your own relationship and item references, and only the duty details you explicitly choose to include. Reports are held in a separate restricted review inbox with decisions and appeals. The developer cannot generally scan end-to-end encrypted schedules. Do not include information about children, patients or care recipients in duty labels or reports. See the Child Safety Standards.
Retention
- Device records and exported files remain until removed by you; uninstalling the app does not remove files you exported elsewhere.
- Unaccepted offers expire after 72 hours. The service removes their retained payloads within the following 24 hours.
- Active registered constraints remain until eligible retirement or ledger deletion. Superseded and retired service assertions are retained for 90 days. Minimal retry records are retained for 90 days.
- Reports, decisions and appeal records are retained while open and for 90 days after closure. Reopening an appeal extends that period.
Deletion and your choices
You can stop sharing with an individual, export your records, or close your shared ledger from the app. Closing the ledger revokes its devices and removes its service ciphertexts, with a signed closure receipt. Reports are handled separately under the retention period above. Historical copies already downloaded by participants and your exported files cannot be erased remotely. Removing a record does not cancel real-world duties.
Request deletion or help without the app. We verify ownership before acting on requests affecting a ledger. Never email a PIN, private key, recovery code or complete recovery export.
Permissions and changes
Network permissions support sharing and service checks. Biometric access supports optional device-local unlocking. File import and export use the system picker rather than broad storage access. Gialdyn does not request contacts, location, camera or microphone access. This policy will be updated when the app's actual practices change.