Myrosta is a rostering tool for Emergency Department consultants. It holds no patient or clinical‑record data — only the staff information needed to build and share a roster.
What we hold
Staff name, work email, work mobile, contracted hours (EFT) and payroll/employee number
Roster assignments, leave (type and dates), and shift‑swap requests
Internal admin/staff messages and an audit log of key actions
We do not hold patient or clinical data, passwords, or salaries / bank / financial data.
Where it's held
Data is stored in a secure, encrypted database hosted in Australia (Sydney), aligned with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. All connections use HTTPS/TLS.
Access & security
Passwordless sign‑in — a one‑time 6‑digit code by email or SMS; no passwords stored.
Approved access only — an allow‑list enforced in the database; unlisted emails are refused even with a valid login.
Roles — staff see only their own profile; admins manage the roster.
Audit log — every approval, edit and change is recorded.
Service providers we use
Supabase (database, on AWS Sydney) — stores the roster data described above, in Australia.
Resend (email) and Twilio (SMS) — deliver your one‑time sign‑in code to your email address or mobile number. They handle only the delivery details, never the roster.
Netlify (website hosting) — serves the app itself and keeps standard access logs; no roster data is stored there.
Retention
Data persists until removed by an administrator. Backups are kept by the database provider. Retention is aligned with the health service's records‑management policy.
If something goes wrong
If a data breach likely to cause serious harm ever occurs, we will notify affected staff and the OAIC in line with the Notifiable Data Breaches scheme, and act promptly to contain it.
A fuller technical and information‑governance summary is available to your hospital IT / privacy office on request. Questions about your own data — including access or correction? Contact your roster administrator — see Support. Last updated: 4 July 2026.