Privacy Policy

Last updated: 26 June 2026

ScheduleLens (schedulelens.com) is operated by Robert Kay. This policy explains what data we collect, how we use it, and the commitments we make to protect your privacy.

What We Collect

  • 1

    Account information

    Email address, display name, and hashed password.

  • 2

    Schedule files

    Uploaded temporarily for analysis, then deleted immediately after processing.

  • 3

    Analysis reports

    Stored encrypted, scoped to your user account, and deletable by you at any time.

  • 4

    Usage data

    Authentication events, upload timestamps, and processing times. No schedule content is ever included in logs.

  • 5

    Payment data

    Handled entirely by Stripe. We never see or store your card numbers.

  • 6

    Bot protection

    The signup and contact forms use Cloudflare Turnstile to block automated abuse. It processes your IP address and a challenge token to tell humans from bots; it does not track you across sites. The site is also served and protected by Cloudflare's network.

What We Never Do

These are non-negotiable commitments we make to every user:

  • Your uploaded schedule files are deleted immediately after processing. (Schedules you add to a Project are kept as an encrypted copy to power the monitoring dashboard — see "Monitored Projects" below; delete them anytime.)

  • Schedule data is never used to train AI models.

  • Schedule data is never shared with third parties other than the selected inference provider for narrative generation.

  • Schedule data is never aggregated, benchmarked, or analysed across users.

  • We do not sell or monetise user data in any form.

  • Only structured analysis findings — never your raw schedule file — are sent to the inference provider for narrative generation.

  • The AI assistant is held to the same line — it only ever sees your computed analysis results, never the raw schedule, and runs on a privacy-first, zero-retention inference provider.

Data Lifecycle

Your data passes through clearly defined stages:

1. Upload

Schedule files are uploaded over an encrypted connection and stored temporarily in encrypted form. Files are deleted immediately after processing completes. A failsafe ensures automatic deletion within 24 hours even if processing fails.

2. Processing

Schedule data is parsed and analysed entirely in memory. Raw schedule content is not persisted to disk during processing and is not written to application logs.

3. AI Narrative Generation

A structured JSON summary of the analysis — activity IDs, dates, float values, and delay findings, but never the raw schedule file — is transmitted over TLS to a third-party inference provider to generate the narrative text for the report. The provider processes the request under its own data-retention policy; your data is not used to train models. If no AI provider is configured, the report falls back to template-generated prose and nothing leaves our server at this stage. You can also switch the AI narrative off at upload: the report is then generated entirely from template prose and no summary is sent to any third-party provider.

4. Report Storage

Completed analysis reports are stored encrypted and scoped to your account. You can delete any report at any time. If you close your account, all stored reports are permanently deleted within 30 days.

5. Monitored Projects Projects only · subscriber

A Project is a monitored programme: when you add a schedule to one, we retain an encrypted copy of that schedule so the dashboard can trend it month over month, re-anchor against whichever baseline you choose, and rebuild a full comparison from a single new upload — without you re-uploading every prior file. Each schedule is compressed and encrypted at rest (AES-256), scoped to your account. One-off analyses that aren't in a Project retain nothing — so for privacy-sensitive work, simply don't add it to a Project. You stay in control: delete any individual retained schedule (Forget), all of them (Forget all), or the whole Project, at any time. This is a security model (encrypted, scoped, deletable), not zero-knowledge: because our server rebuilds the comparison, it can read the schedule.

6. AI Assistant subscribers · optional

Subscribers can ask questions about an analysis they've already run. The assistant answers by querying the computed results of your analysis — it is never given your raw schedule file or the full activity network. So that it can still answer after your uploaded file has been deleted (Stage 1), we keep an encrypted, time-limited copy of the structured results (findings, float paths, delay breakdown — not the source file and not the full logic network, so it cannot reconstruct your programme). This copy is scoped to your account and expires automatically within about three days. Your questions and those structured results are sent over TLS to a privacy-first inference provider (Venice) that operates a zero-data-retention policy. Every figure in an answer comes from our analysis engine, not the AI — the assistant cannot invent numbers about your project. This is stronger data handling than a standard AI API, but it is not zero-knowledge: while generating an answer the provider processes the text in the clear. We therefore describe the assistant as privacy-first and zero-retention — never "private by default".

7. On-Premise Option (V2+)

In a future release, an on-premise deployment option will allow the entire pipeline to run within your own network. Nothing leaves your infrastructure.

Privacy Tiers

Today, every analysis runs on the Standard tier. The higher-isolation options below are planned for future releases and are not yet available. The AI assistant also runs on the Standard tier, using a privacy-first inference provider with a zero-data-retention policy; like every Standard analysis it is not zero-knowledge.

Tier Status Who Sees Data Best For
Standard Live Our server + inference provider (TLS) General use
Self-hosted inference Planned (V2+) Our server only, no third-party AI provider High-sensitivity
On-premise Planned (V2+) Nobody outside your network Defence, classified

Security

We implement the following security measures to protect your data:

  • bcrypt password hashing — passwords are never stored in plain text.
  • Short-lived JWT tokens (15 min) with rotating refresh tokens.
  • User-level data isolation — no cross-user access is possible.
  • HTTPS everywhere — all connections are encrypted in transit.
  • Server-side encryption (AES-256) for all stored files and reports.
  • Rate limiting on all endpoints to prevent abuse.

Your Rights

  • Delete any analysis or report at any time. Deletion is permanent and immediate — there is no recycle bin.
  • Close your account and all associated data will be deleted within 30 days.
  • Export your reports before deletion if you need to retain copies.
  • Contact us for any data-related questions or requests.

Cookies

We keep cookies to the absolute minimum needed for the site to work. We do not use Google Analytics, advertising pixels, or cross-site tracking. For aggregate visitor measurement on our marketing pages we use Plausible Analytics — a privacy-focused, EU-hosted service that sets no cookies, collects no personal data, and does not track you across sites. It is not used inside the signed-in application.

Cookie Set by Purpose Lifetime
Session & refresh tokens ScheduleLens Keep you logged in. Strictly necessary. 15 min (session) / 30 days (refresh)
Stripe checkout cookies Stripe Fraud prevention during payment. Only set on Stripe-hosted checkout pages. Per Stripe's cookie policy

Because ScheduleLens uses only strictly-necessary cookies, no consent banner is required under ePrivacy or GDPR. If you block cookies in your browser, login and payment will stop working — the rest of the site (marketing pages, blog, methodology) is fully usable without any cookies.

Contact

For privacy-related questions or data requests, contact us at privacy@schedulelens.com.