Privacy Policy

Last updated: 9 October 2026

ScheduleLens (schedulelens.com) is operated by Robert Kay trading as ScheduleLens (ABN 41 580 709 632), Western Australia. This policy explains what we collect, what we keep and for how long, who can see it, and your rights. We follow the Australian Privacy Principles in the Privacy Act 1988 (Cth).

The short version

Your uploaded file is deleted after analysis. Your reports, programme view and any schedules we keep are encrypted by ScheduleLens itself (AES-256) on top of our storage provider's encryption, tied to your account, and served only to you after you sign in. There are no public or shareable links.

The app has no way for anyone at ScheduleLens to open your reports, programme or schedules. Our only access is the infrastructure access needed to fix faults, and we never open customer content unless you ask us to.

What We Collect

  • 1

    Account information

    Email address, display name, and hashed password. If you sign in with Google, we receive your name, email address and an account identifier from them, and nothing else: no contacts, files or other account data, and no password is created.

  • 2

    Schedule files

    Uploaded for analysis and deleted when it finishes. What we keep afterwards is listed under “What We Keep” below.

  • 3

    Analysis results

    Reports, the programme view and summary figures for your dashboard, all scoped to your account.

  • 4

    Usage data

    Sign-in events, upload times, processing times and error reports. Application logs record identifiers and timings, not schedule content.

  • 5

    Payment data

    Handled by Stripe. We never see or store your card number.

  • 6

    Bot protection

    The signup and contact forms use Cloudflare Turnstile to block automated abuse. It processes your IP address and browser signals to tell people from bots.

  • 7

    Emails and messages

    Copies of the emails we send you, which can name your schedule and its finish date, and anything you send us through the contact or feedback forms. Email copies are encrypted, and each time one is opened for a support question the access is logged.

We collect this to run the service you signed up for: to analyse your schedules, deliver reports, bill you, answer support questions and keep the service secure. You can use the marketing pages and free tools without an account.

What We Keep, and For How Long

All of it is available only to your account. Files, programme views, retained schedules, assistant data, email copies and backups are encrypted by ScheduleLens itself; account and billing records sit in our database on an encrypted disk.

What How long
Your uploaded schedule file Deleted as soon as the analysis finishes. A comparison waiting for you to confirm its completion milestone keeps the file for up to 7 days. An analysis that fails or stalls is cleared within 45 minutes.
Reports (HTML, PDF, Excel) Until you delete them or close your account. A health report's Excel appendix lists every activity with its logic, so a report holds your programme's content.
Programme view 30 days after the analysis runs, so you can open the schedule in your browser. It holds activities, WBS and logic links, not the source file, calendars or resources.
Schedules you add to a Project (subscribers) Until you remove them, or 90 days after your subscription ends. We email you 30 days before that deletion.
One-off copy (subscribers) 90 days, so you can add the upload to a Project later. Untick “Keep a copy for 90 days” when uploading and no copy is kept.
AI assistant data (subscribers) About 3 days, then deleted. It holds the computed results of an analysis (findings, float paths, delay breakdown), not the source file.
Copies of emails we send you Until you close your account, so a support question about an email can be answered.
Account and billing records Until you close your account. Stripe keeps its own payment records under its own obligations.
Database backups One a day, the last 8 kept. Anything you delete leaves the backups within 8 days.

Delete your account and everything above is deleted straight away, apart from the backups, which age out within 8 days.

What We Never Do

  • Use your schedule data to train AI models.
  • Sell, rent or monetise your data in any form.
  • Aggregate, benchmark or analyse schedule data across customers.
  • Send your source schedule file to an AI provider. Only structured analysis results go to the AI provider, and only when the AI features are on.
  • Share your data with anyone other than the service providers listed below, unless the law requires it.

How Your Data Is Protected

  • Encrypted by ScheduleLens: every file we keep (reports, programme views, retained schedules, assistant data, email copies and backups) is encrypted with AES-256 by our own application before it is stored, on top of the storage provider's encryption. Each stored item is bound to its own location, so a copy moved elsewhere will not decrypt.
  • Only yours: reports, programme views and retained schedules are served only to the signed-in account that created them. There are no public or shareable links. An automated test tries every customer route as a different account on every release.
  • Encrypted database disk: the database runs on an encrypted volume.
  • Passwords: hashed with bcrypt, never stored in plain text.
  • Short-lived sign-in: access tokens last 15 minutes, with rotating refresh tokens that last 7 days.
  • HTTPS everywhere: every connection is encrypted in transit.
  • Rate limits: on sign-in, sign-up, password reset, the contact form and the AI assistant, plus a daily cap on free analyses.

What encryption does and does not mean. Our server decrypts your data to show it to you and, for Projects, to rebuild comparisons, so this is a security model (encrypted, scoped to you, deletable), not zero-knowledge encryption. The encryption key is held in our hosting provider's secret store, separate from the stored files.

AI Narrative and AI Assistant

AI narrative. To write the report's narrative, a structured summary of the analysis (activity IDs and names, dates, float values and delay findings, never the source file) is sent over TLS to Venice.ai. Venice's published privacy policy says it does not store prompts or responses on its servers. That is Venice's commitment and we cannot verify it independently. The narrative is on by default. You can switch it off for one upload or as your account default (Account → Report preferences), and the report is then written entirely from templates with nothing sent to an AI provider. The model and its limits are described on our AI transparency page.

AI assistant (subscribers). The assistant answers questions about an analysis by querying its computed results, never the source file. Your questions and the results it looks up go to Venice in the same way. Every figure in an answer comes from our analysis engine, not the AI. While generating an answer the provider processes the text in the clear, so we describe the assistant as privacy-first, never “private by default”.

Projects subscribers

A Project tracks one programme over time. When you add a schedule to a Project we keep an encrypted copy of it, so the dashboard can trend it month by month, re-anchor against the baseline you choose, and rebuild a full comparison from one new upload. Free accounts and one-off purchases keep no copy of the schedule itself, only the report and the 30-day programme view.

You stay in control: remove one retained schedule (Forget), all of them (Forget all), or the whole Project (Delete on the project page; your analyses and reports stay), at any time. For sensitive work, use One-off with “Keep a copy for 90 days” unticked, and delete the analysis once you have downloaded your report.

Service Providers and Overseas Storage

ScheduleLens runs on the providers below. Your data is stored and processed outside Australia, mainly in the United States. Each provider handles data under its own terms and only to provide its service to us.

Provider What for Where
Fly.io Hosting, application servers and database USA (Virginia)
Tigris Data Encrypted file storage (reports, programme views, retained schedules, backups) USA
Stripe Payments and invoices USA and other countries
Venice.ai AI narrative and AI assistant (summaries and questions, never the source file) USA
Resend Sending email USA
Sentry Error reports (error type, message and code location; request contents and program variables are stripped before sending) USA
Cloudflare Website delivery, bot protection (Turnstile) and cookieless visitor counts Global network
Google Sign-in, only if you choose “Sign in with Google” USA

Analytics and Cookies

We count visits with Cloudflare Web Analytics, which sets no cookies and does not track you across sites. We do not use Google Analytics, advertising pixels or cross-site tracking.

ScheduleLens sets no cookies. Your sign-in is kept in your browser's local storage: an access token that lasts 15 minutes and a refresh token that lasts 7 days. Signing out removes them. Stripe sets its own cookies on its hosted checkout pages, for fraud prevention, under Stripe's cookie policy. Cloudflare Turnstile, on our forms, processes browser signals to detect bots.

Your Rights

  • Delete any analysis or report: at any time from your dashboard. Deletion is immediate and permanent, apart from the backups, which age out within 8 days.
  • Delete your account: under Account → Delete my account. Your data is deleted straight away and any subscription is cancelled.
  • Download your reports: before deleting them if you want to keep copies.
  • Access and correction: ask for a copy of the personal information we hold about you, or for it to be corrected, by emailing us. We reply within 30 days and do not charge for it.

Complaints

If you think we have mishandled your personal information, email us with the details. We will acknowledge it within 7 days and respond within 30 days. If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au or on 1300 363 992.

Higher-Isolation Options

Every analysis today runs on our hosted service described above. Two higher-isolation options are on the roadmap and not yet available: self-hosted AI inference, so no third-party AI provider sees any data, and an on-premise deployment that runs the whole pipeline inside your own network.

Changes to This Policy

We update the “Last updated” date whenever this policy changes, and email registered users before a change that reduces your protections takes effect.

Contact

For privacy questions, access or correction requests, or complaints, email privacy@schedulelens.com.