Privacy
Block distractions. Don't monitor employees.
Work Mode exists to make shift work less distracting, not to watch people. The employer sees operational status only. This page is the authoritative statement of what that means; the same definitions drive the dashboard, the employee app and the mobile API.
How it works, technically
Precisely what the iPhone app does with Apple's Screen Time frameworks, and what that rules out.
Apple's Screen Time frameworks, nothing else
The iOS app uses FamilyControls, ManagedSettings and DeviceActivity. They let an app shield apps, categories and websites on a schedule. They do not give the app message content, photos, notifications or browsing history.
App choices are opaque tokens
When an employee chooses what to shield, Apple's picker returns opaque tokens that can only be interpreted on the phone that created them. The app stores them in its on-device container; the server receives only the number of categories, apps and websites selected.
Time-based schedules only
Shields are applied and lifted by the app's DeviceActivity extension at the shift and break times synced to the phone. Work Mode registers no usage thresholds and ships no activity-report extension, so it never learns which apps were used or for how long.
Enforcement is local
The server never controls the phone. It supplies the schedule and policy, may send a silent push asking the app to sync, and receives the resulting engine state.
Everything managers see is derived from a short allow-list
The mobile API accepts only the fields listed below, by exact name, and rejects anything else. The dashboard combines those fields with the employer's own shifts, policies and break rules.
What managers can see
Operational status only.
- Whether the employee has joined and their device is connectedThe employee's setup stage (not invited, invited, joined, setup incomplete, connected or deactivated) and whether the Work Mode app is active on their phone.
- Whether Screen Time authorisation is grantedOnly the state of the authorisation: not determined, approved, denied or revoked. Managers see that permission needs attention, never anything the permission gives access to.
- Whether apps have been selected, and how manyWhether the employee has chosen what to shield and how many categories, apps and websites that choice contains. Never which ones: the choice is held on the phone as opaque Apple tokens that neither the employer nor Work Mode's servers can read.
- Whether Work Mode is active right nowThe on-device Work Mode state: off shift, starting soon, working, on break, shift ending, manager override, permission error or sync error. It confirms whether shields are applied, not what the employee is doing on the phone.
- Break start and end times during a shiftWhen a break started and ended and how many breaks were taken, so they can be checked against the Break Rules. Breaks are either started by the employee in the app or scheduled on the shift by the employer.
- When the device last syncedTimestamps of the last device check-in, policy sync and schedule sync, so managers can tell a connected device from one that has not checked in for hours or days.
- App version, iOS version and generic device modelFor support and compatibility only, for example app 1.2.0 on iOS 17.5 on an iPhone. No hardware or advertising identifiers (serial number, IMEI, phone number, advertising ID or vendor ID) are collected.
- Device timezone and clock skewThe timezone setting the phone reports (for example Europe/London) and how far its clock is from server time, so shifts start at the right moment and a wrong clock is flagged. A timezone is a region setting, not a location.
- A timeline of operational eventsEvents from a fixed list, such as joined, setup completed, Work Mode started or ended, break started or ended, and permission needs attention. Each has a time and no free text.
- The shifts, policies and break rules the employer createdThis is the employer's own data, not something observed from the phone. The dashboard combines it with the operational status above to show who should be in Work Mode and whether their phone agrees.
What managers can never see
Block distractions. Don't monitor employees.
- Messages and callsNo iMessage, SMS, WhatsApp, email or call content or history. The Screen Time frameworks Work Mode uses do not expose messaging or calls at all.
- Photos, videos, camera and filesThe app does not request access to Photos, the camera, the microphone or files, so it cannot read any media.
- Browsing history and searchesNo websites visited, search terms or other web activity. Websites an employee chooses to shield are opaque tokens on the phone: counted, never sent.
- App usage, screen time or which apps were openedWork Mode registers time-based schedules only and receives no usage reports. When a shielded app is opened, the shield and its buttons are handled on the phone; nothing about which app, how often or for how long is sent to the server.
- Which specific apps, categories or websites were selectedApple returns the selection as opaque tokens that are meaningless off the phone that created them. They are stored only in the app's on-device container and are never uploaded; the server receives counts only.
- NotificationsNeither the content nor the existence of notifications from other apps is visible to Work Mode.
- LocationThe app does not use Location Services, Wi-Fi or Bluetooth scanning. Like any internet service, the server sees the network address of each request for security and rate limiting; it is not used to locate anyone and is never shown to the employer.
- Contacts, calendar, health, passwords, keystrokes or screenshotsWork Mode requests none of these permissions and contains no keyboard, screen-recording or screenshot capability.
- What happens on the phone outside shiftsShields lift when the shift ends. Off shift the app only performs routine sync check-ins, which carry the same operational fields as always and nothing about how the phone is used.
What employees are told
Work Mode blocks distracting apps during your shifts. Your employer sees operational status only: whether the app is set up and working, when you take breaks, when your phone last synced, and basics such as the app version and your timezone. They cannot see your messages, photos, browsing history, notifications, what you do on your phone, or which apps you chose to block. Your app choices stay on this device.
What the device sends
The mobile API accepts only the fields below, by their exact request field names. Request schemas are strict: unknown fields are rejected. Adding a field means changing the shared privacy statements, which regenerates this list, so the allow-list and this page cannot drift apart.
| What | Fields | Why |
|---|---|---|
| Join details |
| Sent only when joining: the company code, the optional employee invite code, and the first and last name the employee types, used only to find the employee record the employer already created. |
| Permission state |
| Screen Time authorisation state: NOT_DETERMINED, APPROVED, DENIED, REVOKED or UNKNOWN. |
| Selection state and counts |
| Whether a selection exists (NONE or CONFIGURED) and three numbers: how many categories, apps and websites it contains. Never the tokens, names or bundle identifiers of what was selected. |
| Engine state |
| The on-device Work Mode state (also attached to some events): OFF_SHIFT, SHIFT_STARTING_SOON, WORKING, ON_BREAK, SHIFT_ENDING, MANAGER_OVERRIDE, PERMISSION_ERROR, SYNC_ERROR or UNKNOWN. |
| App and OS version |
| The Work Mode app version (for example 1.2.0) and the iOS version (for example 17.5.1). |
| Platform and generic device model |
| The platform (IOS) and the generic model family iOS reports, such as iPhone or iPad. Never the device's name, serial number or any other per-device identifier. |
| Applied policy and schedule versions |
| Which policy version and schedule version the device has applied (both were issued by the server). The server records when it receives them; that is the last policy and schedule sync time managers see. |
| Timezone |
| The phone's IANA timezone setting, for example Europe/London. |
| Local time (clock skew) |
| The phone's clock reading when it checks in. The server keeps only the difference from server time, in whole seconds. |
| Break start and end |
| Starting or ending a break: an idempotency id generated by the app, the phone's time when the break was requested, the requested length in minutes, and the time it ended (with an enumerated end reason). |
| Enumerated events |
| Operational events from a fixed list, each with an idempotency id generated by the app, the time it happened and optional metadata limited to the fields on this list, server-issued ids and an UPPER_SNAKE_CASE reason code; no free text. The event types are SETUP_COMPLETED, PERMISSION_GRANTED, PERMISSION_NEEDS_ATTENTION, SELECTION_CONFIGURED, WORK_MODE_STARTED, WORK_MODE_ENDED, BREAK_STARTED, BREAK_ENDED, BREAK_EXPIRED, SCHEDULE_SYNCED, POLICY_SYNCED. |
| Push token |
| The Apple Push Notification token for this app install and whether it belongs to Apple's sandbox or production service. Stored encrypted and used only to ask the app to sync. It identifies the app install to Apple, not the person. |
Not listed, because they carry no information about the employee or the phone: authentication tokens, ids the server itself issued (employee, shift and break ids), and structural fields such as the request containers and the date window of a schedule request.
Data handling
- Push tokens and workforce-integration credentials are encrypted at rest with AES-256-GCM.
- Audit logs record what managers do (who changed a policy, who created an override), not what employees do on their phones.
- Leaving the workplace from the app removes Work Mode's shields and schedules from the phone and deletes its local copy of the schedule. A manager deactivating an employee or device revokes that device's access, so it can no longer sync.
- Employees can revoke Screen Time access at any time in iOS Settings. The dashboard then shows that the device needs attention, and nothing more.
- Workforce integrations (Planday, Deputy, 7shifts, When I Work, Rotaready and Homebase) are not available yet. When they are, they will only bring employees, teams, locations, shifts and clock events into Work Mode; nothing about the phone will be sent to them.
Questions about privacy? Email support@workmode.app.
Show your team this page
Employees read the same statements in the app before they join. Book a demo and bring your questions.
Block distractions. Don't monitor employees.