Privacy Policy
Locumo · Last updated 19 August 2026
Locumo (“we”, “us”, the “app”) is a tool that helps locum practitioners track shifts, manage practices, and create invoices. This policy explains what information we collect, how we use it, who we share it with, and the choices and rights you have. We only collect what we need to run the app for you. We do not sell your data and we do not use it for advertising.
Information we collect
We collect only the information you provide or create while using Locumo:
- Account details: your email address and a password. Your password is never stored in plain text; it is protected using industry-standard salted hashing (scrypt).
- Your work records: shifts (dates, times, pay, mileage and notes), the practices you work at (names, addresses, contact emails and rates), and the invoices you create.
- Your profile & invoice settings: details you enter for your invoices, such as your name, billing address, phone number, contact email, payment/bank details, invoice numbering, and your home address or postcode.
- Location text you enter: your home postcode/address and practice addresses, which are used only to estimate driving mileage. Locumo does not access your device’s GPS or track your location.
We do not use third-party analytics, tracking, or advertising SDKs, and we do not collect device identifiers for tracking.
How we use your information
- To provide the core features of the app: storing your shifts, practices and invoices and syncing them across your devices.
- To create the invoices, summaries and exports you request.
- To estimate driving mileage between your home and a practice, when you ask for it.
- To authenticate you and keep your account secure.
- To send account-related emails you request, such as a password-reset link.
- If you choose to forward a booking-confirmation email to your personal Locumo import address, to read its content and, where we can do so with enough confidence, add it to your calendar automatically. We do not retain the email body beyond this processing. Only the subject line, sender address, and the outcome (e.g. that a shift was created) are kept, as an activity log you can review, for 90 days.
Connected calendars (Google and Microsoft)
If you choose to connect a Google Calendar or a Microsoft (Outlook) calendar, Locumo reads the events in the calendars you select so it can find work shifts you have booked and bring them into Locumo. This feature is optional, is off until you connect a calendar, and you can disconnect it at any time in Settings.
- What we access: the events in the calendars you choose to watch, including their title, location, description, organiser and start and end times. We request read-only access. We never create, edit, or delete anything in your calendar.
- How we use it: we look for events that appear to be work shifts, match them to the practices you have saved, and either add them to Locumo for you or list them for you to review. When an event is unclear, its text may be sent to our AI provider (Anthropic) solely to decide whether it is a shift and to read the practice name.
- What we keep: we do not store the contents of your calendar. We keep only what is needed to avoid importing the same event twice and to notice later changes: the event’s identifier, a one-way fingerprint (hash) of the fields that matter, and the shift records we create at your direction. Event descriptions and bodies are not retained.
- What we do not do: we do not read calendars you have not selected, we do not use your calendar data for advertising, we do not sell it, and we do not use it to train AI or machine-learning models.
- Disconnecting and deletion: disconnecting a calendar in Settings removes our access and deletes the stored access tokens. Deleting your account permanently removes all connection and calendar-related data.
The same applies if you import from your device’s own calendar (the Apple Calendar import in the iOS app). With your permission, the app reads events from the calendars you choose on your device and sends their text (title, times, location and notes) to our server so it can recognise work shifts, with unclear events checked by our AI provider (Anthropic) in the same way as above. This processing is quota-limited, is never used for advertising, and the event text is not kept beyond the activity log described above. Turning the import off, or withdrawing calendar access in your device settings, stops it entirely.
Google API Services User Data Policy
Locumo’s use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use Google Calendar data only to provide and improve the calendar-import features described above, we do not transfer it to others except as necessary to provide those features, we do not use it for serving advertising, and we do not allow humans to read it except with your consent, for security purposes (such as investigating abuse), or where required by law.
Service providers we share data with
We use a small number of trusted providers to operate the app. They process your data only to provide their service to us, under their own privacy and security terms:
- Vercel: application hosting.
- Turso: secure database storage for your account and records.
- Resend: sending transactional emails (e.g. password resets), and, if you use the email-forwarding import feature, receiving the emails you forward to your personal import address so we can read their content. Resend’s own retention of that content is governed by their own terms, separately from Locumo’s. See the note above on what we ourselves keep.
- Google: if you connect a Google Calendar, providing read-only access to the calendar events you select so we can detect shifts. We access only the calendars you choose and never write to them.
- Microsoft: if you connect an Outlook calendar, providing read-only access to the calendar events you select so we can detect shifts. We access only the calendars you choose and never write to them.
- Anthropic: our AI provider. When a forwarded booking email, a connected-calendar event, or a device (Apple) calendar event is unclear, its text is sent to Anthropic solely to decide whether it is a shift and to read the booking details. This automated processing is quota-limited, is used only for that purpose, is not used to train models or for advertising, and the text is not retained by us beyond the activity log described above. Not forwarding emails and not connecting or importing a calendar means nothing is ever sent.
- OpenRouteService: converting the addresses you enter into approximate driving distances for mileage. Only the address text needed for that calculation is sent.
- Google (Routes API): if you turn on leave-time reminders, calculating a live traffic-aware driving time. Only your home and practice coordinates needed for the route are sent, and only while that reminder is enabled.
- Apple Push Notification service (APNs): if you enable notifications in the app, delivering them to your device. We register a device token with Apple, and the notification content (for example a shift or invoice reminder) is transmitted through Apple to reach your device. Notifications are off until you turn them on, and you can disable them at any time.
When you share an invoice or an export from the app, you choose the recipient and the method (for example email or your device’s share sheet). That sharing is initiated by you.
Data retention
We keep your information for as long as your account is active. You can delete individual shifts, practices and invoices at any time. When you delete your account, all of your data, including your profile, settings, shifts, practices and invoices, is permanently removed from our database.
Deleting your account
You can permanently delete your account and all associated data directly in the app: go to Settings → Delete account, confirm with your password, and your account and data will be erased. This action cannot be undone.
Security
Data is transmitted over encrypted connections (HTTPS) and stored on secured, access-controlled infrastructure. Passwords are stored only as salted hashes. While no system can be guaranteed perfectly secure, we take reasonable measures to protect your information.
Your rights
Depending on where you live (including under UK/EU GDPR), you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. You can exercise most of these directly in the app, or contact us using the details below.
Children
Locumo is intended for working professionals and is not directed to children. We do not knowingly collect personal information from children.
Changes to this policy
We may update this policy from time to time. When we do, we will revise the “Last updated” date at the top of this page.
Contact us
If you have any questions about this policy or your data, contact us at kumell@teleop.co.uk.