HemşireM Privacy Policy
Effective Date: July 26, 2026
1. Introduction and Data Controller
HemşireM is a shift and schedule management app (Android and iOS) developed for nurses working in Turkey. This app is a professional tool; it helps you organize shift rosters, keep track of your own shifts, and join the schedules published by the charge nurse.
This Privacy Policy explains what data is processed when you use HemşireM, what it is used for, where it is stored, and what your rights are. The policy has been prepared in line with KVKK (Turkey's Personal Data Protection Law No. 6698) and Google Play policies.
HemşireM is run by an individual (indie) developer. Our approach to privacy is simple: we collect the least data possible, and your data mostly stays only on your own device.
Data Controller: Yakup Habanoğlu (individual developer)
Contact: d.jacopmd@gmail.com
You can reach us at the email address above for any questions about privacy, data deletion, or this policy.
2. The Data We Collect and For What Purpose
HemşireM processes data in only three situations: (a) when you sign in to the app, (b) when the charge nurse publishes a schedule to the cloud, and (c) when you redeem a promotional code. All are explained below.
2.1. Authentication Data (Account)
To sign in to the app, you use one of the Sign in with Google or Sign in with Apple options. This sign-in happens through the Firebase Authentication (Google) infrastructure. The data processed during this step:
- Your email address
- Firebase user ID (UID) — a unique identifier the app assigns to you
Purpose: To create and recognize your account, to match your own shifts with you when you join a published schedule, and to verify that your data belongs only to you.
Important: The app has no community, social feed, or public profile feature. Your real name is never shown to other users anywhere. The UID is used solely to match your own shifts to you.
2.2. Published Schedule Data (Only If the Charge Nurse Publishes)
If you are the charge nurse of the unit and you carry out the "publish" action to share a monthly schedule with your team, the following data is written to the cloud (Cloud Firestore):
- Unit/ward name
- Month and year information
- 6-digit join code
- Team list: for each staff member, their display name, position/title, and whether they are the charge nurse
- Shifts: date, shift type, and time information
Purpose: So that the other nurses on the team can access the schedule using the join code and view their own shifts.
Access rules: Only the charge nurse who published it can modify or delete this schedule. The schedule can be read by signed-in users (accessed via the join code).
2.3. Team Members' Data (People Whose Names Are Entered in the Schedule)
When a schedule is published, the display name, position and shift information of the team members included in that schedule are also written to the cloud. Some of these people may never use the app themselves.
What you need to know:
- The person who enters and publishes the team information is the charge nurse. Informing team members about this sharing is the responsibility of the charge nurse who prepares the schedule and of their institution. HemşireM does not and cannot contact these people directly.
- Entering real names is not mandatory. The app allows you to add team members using initials, nicknames or labels such as "Nurse 1". Where your institution's rules permit, we recommend this approach, so that no identifiable data is sent to the cloud.
- What is never sent: Team members' exemption details, leave reasons, birth/leave dates, experience level and personal notes are never uploaded to the cloud under any circumstances (see 2.4).
- Removal requests: A person named in a schedule who wants their data removed may first contact the charge nurse who published it; the charge nurse can delete the publication. Requests sent directly to d.jacopmd@gmail.com will also be assessed and acted upon.
2.4. Data That NEVER Leaves Your Device (Data Minimization)
In accordance with the data minimization principle, health-related or sensitive planning data is never uploaded to the cloud under any circumstances. This data stays only on your device and includes:
- Exemption information (e.g. pregnancy / maternity status)
- Maternity/leave end dates
- Experience level
- Personal notes
This data is not sent to the cloud even when a schedule is published; technically, these fields do not exist in the cloud data model.
3. What We Do Not Collect (Explicit Statement)
To maintain a strong privacy stance, we deliberately do not collect data that many apps collect. HemşireM does not:
- Collect analytics — we do not measure your usage behavior.
- Collect crash reports (crashlytics).
- Show ads — there are no ads in the app whatsoever.
- Perform tracking — we do not track you across devices or apps; the app contains no third-party advertising SDK.
- Collect location data.
- Access your address book/contacts.
- Send push notifications (FCM) — all notifications are local only (see below).
4. Where Data Is Stored
4.1. On Your Device (Local)
Most of the app's core data is stored only on your device. The data kept on the device (via Hive and shared_preferences):
- Staff list
- Shifts
- Records of schedules you have joined (claims)
- Manual calendar entries
- App settings
- Swap history
This data is not sent anywhere except for the published subset described in 2.2 above.
4.2. In the Cloud (Firebase / Google)
Only the following data is stored on Google's servers:
- Authentication data: email and UID (Firebase Authentication)
- Published schedule data (Cloud Firestore) — only if you published it
- Pro access status (Cloud Firestore): If you redeemed a promotional code, your account record stores the code used, the platform (Android/iOS) and, if applicable, the expiry date of the access. This record exists so that your access is preserved when you change devices.
5. Notifications
All notifications sent by HemşireM are local only (generated on the device). Push notifications sent from a server (FCM) are not used. Your data is not transmitted to any server for notifications.
6. News Feature
The in-app news feed is pulled read-only from the Sağlık Aktüel and Anadolu Ajansı RSS sources. During this process:
- No user data is sent — only publicly available news content is read.
- When you tap a news item, it opens in your device's external browser.
7. Third Parties and International Transfer
HemşireM uses only the following service providers to perform its functions:
- Google (Firebase) — Firebase Authentication (authentication) and Cloud Firestore (published schedule data). This data is processed and stored on Google's servers.
- Apple — only for authentication when you use the "Sign in with Apple" feature.
No data is shared with any third party other than these; your data is not sold or transferred for marketing purposes.
International transfer: Google and Apple are companies with global infrastructure. For this reason, the data specified above may be stored and processed on servers outside Turkey or the European Union. This transfer is necessary in order to provide the service and is carried out within the framework of KVKK Article 9.
Consent: When you first start using the app, you confirm on the sign-in screen that you have read and accepted this Privacy Policy, the KVKK Disclosure Notice and the Terms of Use. This consent is obtained once; it is not requested again for each publishing action.
7.1. Purchases
Subscriptions for charge-nurse tools are purchased through Google Play or the App Store. Your payment details (card information, etc.) are processed directly by the relevant store; this information is never transmitted to us and is not visible to us. The app only learns from the store whether a subscription is active.
8. Retention and Deletion
Device data: The data kept on your device is retained until you delete the app. When you remove the app from your device, this local data is also deleted from your device.
Cloud data: Published schedules and your account are retained in the cloud until you delete them.
To delete your account and your cloud data:
- From within the app: Follow Settings > "Delete account." This action permanently deletes your published schedules in the cloud, your join codes, and your Firebase Authentication account.
- By email request: You can request deletion by writing to d.jacopmd@gmail.com.
9. Security
Reasonable technical measures are taken to protect your data. Cloud data is protected by authorization rules: a published schedule can only be modified or deleted by the charge nurse who published it; the data can only be read by signed-in users. Authentication is carried out through the secure infrastructure of Google and Apple. That said, we remind you that no transmission of data over the internet or electronic storage can be 100% secure.
10. Children's Privacy
HemşireM is a professional tool designed for adult healthcare workers (nurses) and is intended only for users aged 18 and over. The app is not directed at children, and we do not knowingly collect data from children.
11. Your Rights (KVKK)
Under Article 11 of KVKK (Turkey's Personal Data Protection Law No. 6698), by applying to the data controller you have the following rights:
a) To learn whether your personal data is being processed,
b) To request information if it has been processed,
c) To learn the purpose of processing and whether the data is used in accordance with that purpose,
ç) To know the third parties, domestic or abroad, to whom the data is transferred,
d) To request correction if the data has been processed incompletely or incorrectly,
e) To request deletion or destruction within the framework of the conditions set out in KVKK and the relevant legislation,
f) To request that the actions taken under paragraphs (d) and (e) be notified to the third parties to whom the data was transferred,
g) To object to a result that arises to your detriment as a consequence of the processed data being analyzed exclusively by automated systems,
ğ) To request compensation for damages if you suffer harm due to unlawful processing.
To exercise these rights, you can contact us at d.jacopmd@gmail.com. You can also delete your account and your cloud data yourself at any time using the "Delete account" feature within the app.
12. Changes
This Privacy Policy may be updated from time to time. When significant changes occur, we make the current version available through the app and/or the publishing page. The most up-to-date version of the policy is always located at this address. The effective date is indicated at the top of the page.
13. Contact
For any questions or requests regarding this policy, your data, or privacy:
Email: d.jacopmd@gmail.com
*HemşireM — Developed for nurses in Turkey.*