EvidentlyApp support
Evidently Staff

Your information.

Privacy notice for the Evidently Staff app.

Updated 26 September 2026

Who is responsible

Evidently Staff is operated by CHUKWUDE HOLDINGS LTD, 128 City Road, London EC1V 2NX, United Kingdom. Contact hello@evidently.care about app privacy or security.

Your care organisation decides how your employment records and the records of people receiving care are used. It is the data controller for those records; Evidently processes them on its instructions. Your organisation's staff and care privacy notices also apply. CHUKWUDE HOLDINGS LTD is responsible as controller for information it uses to operate its own support and service-security activities.

What the app handles

The information available depends on your organisation, role and the features you use. It can include:

Information comes from you, your organisation and authorised users working with your organisation. Only enter information needed for your work.

Why it is used

Your organisation uses these records to organise care, document visits, manage employment and training, communicate with staff and meet its responsibilities. It explains its legal bases, including any conditions for health or other sensitive information, in its own privacy notices.

For our own support and security activities, we rely on legitimate interests in answering requests, protecting accounts, investigating misuse and keeping the service reliable. We also use information when necessary to meet legal obligations. We do not use the app for advertising tracking or sell personal information.

Your phone permissions

Location: precise location is requested when recording visit attendance, such as clock-in or clock-out. The app does not continuously track your location in the background.

Photos, files and microphone: these support uploads and optional dictation. Information you submit becomes part of the relevant work record. Speech recognition uses your device or platform's speech service, subject to its settings and privacy terms.

Notifications: a device token enables work notifications through Apple's push service on iPhone or Google Firebase Cloud Messaging on Android. You can change notification permissions in your phone's Settings.

Biometric sign-in: Face ID, Touch ID or Android biometric verification is handled by your device platform. Evidently receives the verification result, not your face image, fingerprint or biometric template. Remembered sign-in information and preferences may be stored on your device.

Ada is optional

Ada can draft visit notes and briefings, interpret shift-log text and read dates from documents. Before these features run in the installed app, a disclosure explains the sharing and asks for your permission.

If you allow Ada, relevant visit text, recorded tasks and checks, recent care notes or uploaded documents can be sent to Anthropic, the AI provider, for the requested feature. Anthropic's API terms do not permit using this information to train its models by default. Check and edit drafts before saving them. You can leave Ada off and enter information yourself, or turn it off in Me under your settings on this phone.

Giving the app permission to use Ada does not replace your organisation's responsibility to have a lawful basis for processing care information. Care and employment decisions remain with people.

Who receives information

Authorised staff in your organisation can access information according to their role. Care records you write may also be shared by your organisation with authorised care recipients or representatives under its own access and consent arrangements.

Service providers support delivery: Supabase provides the database, file storage and backend services; Vercel hosts web services; Resend delivers service emails; Apple delivers iPhone push notifications; Google Firebase Cloud Messaging delivers Android push notifications; and Anthropic processes requests when Ada is used. Device speech services may process speech when you use dictation. Relevant information may also be disclosed where required by law.

The primary Supabase backend is hosted in Ireland. Other providers may process information outside the UK or EEA, including in the United States. Our provider agreements include the applicable data-protection and international-transfer terms. Where required, transfers rely on recognised adequacy arrangements or contractual safeguards, including applicable UK transfer provisions. Contact us for information about the safeguards relevant to your data.

How long information is kept

Your organisation determines retention of care, employment, payroll and training records according to its obligations and retention schedule. Closing app access does not necessarily delete records it must retain. Ask your office for the periods that apply to your records.

We retain our own support and security information for as long as needed to resolve the issue, protect the service, investigate incidents and meet applicable legal obligations. Retention depends on the purpose, sensitivity of the information, unresolved disputes and any legal requirement to preserve it. Provider backup and deletion cycles can also affect when all copies are removed.

Request data or account deletion

You can review your information in the app, ask your office to correct records and use Me → Delete my account to request account deletion. To request deletion without opening the app, email hello@evidently.care with the subject “Evidently Staff deletion request”. Include your organisation name and the email address on your staff account, and say whether you want to close your account or delete particular information. We may need to verify your identity and involve your organisation. Please do not send identity documents or care records in an initial email.

When a request is approved, app access and account identifiers can be removed, together with profile information, optional uploads and other records that no longer need to be kept. Care, employment, payroll, training and security records may need to be retained for legal obligations, safeguarding, unresolved disputes or service security. Your organisation determines the applicable record-specific retention periods; we will explain any retained data and the applicable period when responding to your request. Closing your account does not automatically erase records your organisation must retain.

Your other privacy rights

Depending on the circumstances, you have rights to access, correct or erase information, restrict or object to its use, and receive certain information in a portable form. Where processing relies on consent, you can withdraw it without affecting earlier lawful processing. Some rights have exceptions, including necessary legal retention.

You can change phone permissions in your phone's Settings and turn Ada off in the app. If a required work feature needs information you choose not to provide, contact your office about an alternative process.

You can complain to the UK Information Commissioner's Office. You can also contact us first so we can try to resolve your concern.

We may update this notice when the app or its processing changes. The date above identifies the current version.