Privacy policy
Effective 17 September 2026
Whon is a staff-scheduling service used by hospital departments. This policy explains what information Whon holds, why, and who can see it. It applies to the Whon website, web application and mobile app.
What Whon holds
- Account and identity: your name, work email address, role (for example cardiologist, practice manager) and the department you belong to. Accounts are created by your organization's administrator by invitation; there is no public sign-up.
- Schedule information: your published assignments, time-off (PTO and CME) requests and balances, call-swap proposals and their outcomes, and your acknowledgements of schedule changes.
- Activity records: an audit history of scheduling actions (who published, requested, approved, swapped or acknowledged what, and when), kept so that the schedule can be trusted.
- Sign-in security: a password and a one-time-code (TOTP) factor, both stored in protected form by our authentication provider.
Whon does not hold patient information of any kind, and it must not be used to enter it.
Why Whon uses it
Only to run the schedule for your department: publishing it, showing you your own assignments, recording and checking requests, applying approved changes, and notifying the people affected. Whon does not use your information for advertising, profiling, or any purpose unrelated to scheduling, and does not sell it.
Who can see what
- Department administrators (practice manager, chief) see the whole department's schedule, requests and audit history.
- Physicians see their own schedule and requests. When colleagues are away, Whon shows only that they are unavailable — never the type of leave, the reason, or any private note.
- Notification-only recipients receive schedule emails but have no access to Whon.
Tracking and analytics
Whon uses no advertising trackers and no third-party analytics. The mobile app contains no analytics or advertising software. Whon does not track you across other apps or websites.
Where it is stored and how it is protected
Whon runs on cloud infrastructure in the United States (application hosting and a managed database with authentication). Data is encrypted in transit; sign-in requires a password and a one-time code; every scheduling action is recorded in an unalterable audit history.
Retention and deletion
Schedule and audit records are kept for as long as your organization uses Whon, because past schedules are a record the department relies on. Your account is created and removed by your organization's administrator. To request removal of your account or to ask what Whon holds about you, contact your administrator or write to privacy@whon.ai.
Children
Whon is a workplace tool for clinical staff and is not directed at children.
Changes and contact
If this policy changes, the effective date above will change and the current version will always be at this address. Questions: privacy@whon.ai.