VitalScheduler

Privacy Policy

Version 2026-09-15 · Effective 15 September 2026

This policy explains what VitalScheduler collects, who handles it, who can see it, and how it is deleted. We do not sell it, and we never run analytics inside the app.

1. Who we are

VitalScheduler is operated by Viereck Group LLC, a Pennsylvania limited liability company based in Phoenixville, Pennsylvania ("we," "us"). This policy covers our public website and everyone who uses the app. Schedule information an organization enters belongs to that organization, and we handle it on its behalf. If your group entered your details, raise questions about them with your group first. For account, billing, and website information, we are responsible ourselves.

2. What we collect

  • Account: your name, email address, and password (stored only as a one-way hash), when the account was created, your organizations and roles, and which version of our terms you accepted and when. Signing in creates a session: a random token in a cookie, with a matching server record that expires after 30 days.
  • Organization: its name, settings (such as weekend days, work-hour limits, and whether AI features are on), creation date, and billing status.
  • Schedule data: the provider roster (name, initials, email address, FTE, groups, an optional level label, and whether active); rotations and rules; schedules and assignments; holidays; time-off requests (dates, type, status, optional note); swap requests (shifts, providers, status, optional notes, and any reason for declining); invite codes; and calendar feed tokens. Imported spreadsheets are read to create entries and are not stored.
  • Billing: Stripe customer and subscription identifiers, subscription status, and active provider count. Card details go directly to Stripe.
  • Technical: counts of recent failed sign-ins (by IP address and by email address) and of signups (by IP address), kept in server memory for at most one hour. Our hosting provider's request logs record IP addresses, times, and the addresses requested.
  • Email you send us.

3. How we use it

We use it to run the Service (schedules, calendar feeds, exports, and notifications), keep it secure, bill for it, and provide support; to understand in aggregate how people find our website; to tell administrators about changes; and to comply with the law. To run the business, we see signup counts and a list of recent signups with organization names, user names and email addresses, signup dates, and provider counts.

4. What we do not do

We do not sell personal information or schedule data. We do not share it with advertisers or data brokers, and we do not use it to train AI models or build products for anyone else. There are no analytics or advertising trackers anywhere inside the app.

If we ever want to use your organization's data for another purpose, we will ask your organization first.

5. Who can see what

  • Administrators and schedulers see all of the organization's data, including time-off notes, all swap requests, and any provider's calendar feed link. Only administrators see billing.
  • Providers see rotations, holidays, and schedules, including unpublished drafts; colleagues' time-off dates, type, and status, but not notes; swaps they are part of; and only their own row of the work-hour report. Any signed-in member can also see every provider's name, initials, FTE, level, groups, and whether they are active. Roster email addresses are shown only to administrators and schedulers.
  • Other organizations see nothing of yours. Every request is checked on the server.
  • Viereck Group accesses production data only to operate, support, and secure the Service. Today that access is limited to the company's founder.

6. Service providers

Each receives only what its role needs.

  • Render hosts the app and its database in the United States.
  • Stripe processes payments. It receives the organization name, the subscribing administrator's email address, and the active provider count, and collects card details directly.
  • Anthropic powers the optional AI features (section 7).
  • Google provides website analytics (section 9) and hosts our email.
  • An email delivery provider will send schedule emails once email sending is switched on.

We may also disclose information where the law requires, to protect the rights or safety of others, or in a merger or sale of our business, in which case this policy keeps applying.

7. AI features

Data goes to Anthropic only when a scheduler uses an AI feature. Drafting rotations sends the description, the organization name, each active provider's internal id number, name, and groups, and each active rotation's code, name, day or block setting, and eligible groups. Turning a pasted list into roster entries sends the pasted text, exactly as pasted, and the organization's provider groups. Neither feature sends schedules, time off, swaps, or roster email addresses.

We do not store the text sent. Nothing is saved until a scheduler saves the draft. Anthropic processes the data under its commercial terms. To turn AI features off for your organization, email us.

8. Emails and calendar feeds

When a schedule is published, the Service can email each active provider, at their roster address or, if there is none, their login address, with the organization name, the schedule's name and dates, and the provider's name. Until email sending is switched on, each message's recipient and subject are written to our server log instead. The app sends no marketing email.

A provider's calendar feed holds their shifts in published schedules and their approved time off, leaving out anything that ended more than 90 days ago, with the organization and provider names. Drafts are never included. The link works without a password, so treat it like one, and email us to replace a link shared by mistake.

9. Cookies and analytics

The app sets one cookie, ps_session, to keep you signed in. Page scripts cannot read it, it is sent only over HTTPS, and it lasts up to 30 days or until you sign out. The app also saves one display preference in your browser: whether conflict warnings are shown.

Google Analytics 4 measures visits to the home page, /demo, and pages under /for/ when you are signed out, and to /security for everyone. It sets its own cookies and collects pages viewed, the referring site, device and browser details, and approximate location from your IP address. It never runs on the sign-in page, on the Terms of Service or this Privacy Policy, or inside the app, and it is switched off before any app page is shown. We use no advertising cookies, and the site works normally if you block analytics.

10. Keeping and deleting information

  • Data is kept until someone deletes it. Providers and rotations used in past schedules are deactivated rather than deleted, so those schedules stay intact.
  • An administrator can permanently delete the organization from the Billing page. This removes all of its data, and the login and sessions of every user who belongs to no other organization. To delete only your own login, email us and we will do it within 30 days.
  • Deleted data can remain in our hosting provider's database backups, and request logs in its log storage, for a limited period.
  • Sessions are deleted when you sign out. Records of sessions that simply expired remain until the login or organization is deleted.
  • Stripe keeps billing records under its own policies, and we keep them as tax law requires. Deleting an organization cancels its subscription but does not delete its Stripe customer record.
  • Google keeps website analytics data under our Google Analytics retention setting.

11. Security

All traffic uses HTTPS. Every request is checked on the server against the signed-in user's organization. Passwords are stored only as one-way hashes, sign-in is limited after repeated failures, and card details never reach our servers. If a security incident affects your organization's information, we will notify its administrators without undue delay, and others as the law requires.

12. No patient information

VitalScheduler is not designed to hold protected health information, and we do not sign business associate agreements. Our Terms of Service prohibit entering patient information. If it is entered, tell us and we will help remove it.

13. Your requests

Email us from your account address to access, correct, delete, or get a copy of your personal information, or to change the name or email address on your login. We may confirm your identity, and we respond within 30 days. For information your organization entered about you, we may refer you to your organization and follow its instructions. We will not treat you differently for asking.

14. Children and location

VitalScheduler is for medical organizations in the United States and is not directed to anyone under 18. Information is stored and processed in the United States.

15. Changes to this policy

Each version is dated, and earlier versions are kept. We announce material changes to administrators by email or in the Service before they take effect.

16. Contact

Viereck Group LLC, Phoenixville, Pennsylvania. Email matthew@vitalscheduler.com.

Terms of ServiceSecurityContact usBack to VitalScheduler

VitalScheduler is made by Viereck Group LLC.