Privacy Policy
Version 3.1 · Effective 5 October 2026
This policy explains how Cyberinfra Limited ("ScreenJournal", "we", "us") handles personal data in connection with the ScreenJournal service: the desktop app, the web app, the assistant and integrations built on them, and our website (together, the "service"). It tells you what we collect, why, who receives it, how long it is kept and what you can do about it. Where something is done by people following a procedure rather than by software, or is not yet built, we say so.
1. Who we are and whose data this covers
ScreenJournal is a business-to-business workplace-monitoring service. Organisations (our "customers") deploy it on work devices to record and understand work activity. Cyberinfra Limited is a company established in the Isle of Man, at 50 Athol Street, Douglas, Isle of Man IM1 1JB.
This policy covers three groups of people, and our role differs for each:
- Monitored employees and contractors. If your employer (or the organisation you work for) uses ScreenJournal, it is the controller of your monitoring data: the data fiduciary under India's Digital Personal Data Protection Act, 2023, and the personal information controller under the Philippine Data Privacy Act of 2012. It decides what is monitored, which features are on and why. We are its processor: we handle that data on its behalf and on its instructions. Your employer is your first point of contact, and its own notice to you sits alongside this policy.
- Customer administrators and buyers. If you set up, administer or pay for an organisation, we are the controller of your account, sign-in, billing, support and acceptance records.
- Website visitors. If you visit our website, book a demo or use the support chat, we are the controller of the data that creates.
Some data is ours as controller even for monitored employees: your sign-in and session records, your acceptance records (which version of a legal document you accepted or acknowledged, and when), the crash reports your desktop app sends, bug reports you file and the email we send you.
2. Information we collect
The table below lists the categories of personal data processed in connection with the service. Which categories apply to you depends on your role and on the settings your employer has chosen.
| Category | Examples | Where it comes from |
|---|---|---|
| Account data | Name, email address, role, team, organisation details, plan and seat information | Your employer's administrators, you, and our payment provider |
| Device and sign-in data | Sign-in identifiers, session records with IP address and device type, and the country or region and the timezone derived from the IP address at desktop sign-in, stored on the account | Your device and, if used, Google or Microsoft sign-in |
| Screen activity and derived timeline | Short screen recordings uploaded for analysis and deleted after analysis (any temporary copy is removed by a storage lifecycle rule we configure on the bucket), with the cursor position and clicks marked on them; app names, window titles, browser addresses and sites, activity descriptions, 1–5 activity scores, presence and idle signals | The desktop app, analysed automatically |
| Stored screen video | Screen recordings, only where your employer enables Record + Save; video clips kept as evidence for alerts | The desktop app |
| Audio and transcripts | Call, meeting and webinar audio and transcripts, only where your employer turns audio on; this includes other participants on calls and webinars, with each passage attributed to the member or to "other party"; a model-assigned speaker label stored with the transcript, and the member's display name sent with the audio | The desktop app |
| Self-declared entries | Manual time entries, reasons for time away, declared off-screen work, explanations given in response to alerts | You |
| Automated assessments | Productivity scores, weekly ranking position, flags that activity may be simulated, alert matches. These are indicators, not conclusions | Derived automatically from the categories above |
| Pay and timesheet data | Hours, pay rates entered by your employer, computed amounts | Your employer and activity data |
| Conversations with the assistant | Questions, answers and conversation history | The person using the assistant, and activity data |
| Support and error reports | Bug-report text and the reporter's email address; crash reports from the desktop app | You and the desktop app |
| Website visitor data | Analytics collected only after consent, demo requests, support-chat messages | Visitors to our website |
Acceptance records. When someone accepts our terms or acknowledges a notice in the service (for example the Terms of Service when an organisation is created, or the Workplace Monitoring Notice at desktop sign-in), we record the user id, the organisation, their role, where in the service it happened, the IP address, the browser or user agent, the time, and the document and version accepted.
Sources. We obtain this data:
- From you: what you enter when you sign in, set up an organisation, add a reason for time away, answer an alert, ask the assistant a question, file a bug report or write to us.
- From your employer: your name, email address, role and team when you are invited, the monitoring settings that apply to you, pay rates, score corrections and alert rules.
- Generated by the service: the screen activity the desktop app captures and everything derived from it, including descriptions, scores, rankings, flags and reports.
- From our payment provider: Paddle, our merchant of record, tells us about subscriptions, plans, seats and transactions.
- From the sign-in provider: your name, email address and an account identifier, if you choose to sign in with Google or Microsoft.
- From your browser: device and usage data on our website, and analytics and advertising identifiers only if you consent to them.
We do not buy personal data from data brokers, and we do not combine monitoring data with data from outside the service.
3. The desktop app's permissions
The desktop app is the part of the service that captures activity. It runs on Windows and macOS, and it is visible in the menu bar or system tray while it runs. At sign-in it shows a notice that it may record your screen and, where your organisation turns it on, meeting audio. On macOS it asks for the permissions below once after sign-in; Windows has no equivalent permission step.
| Permission | What it is used for |
|---|---|
| Screen Recording | While tracking is on, the app captures every connected display as short video segments, by default at one frame per second. The cursor position and clicks are painted into the recording as markers. Applications and sites on the organisation's exclusion list are not captured. |
| Accessibility | Used to read window titles and browser-tab addresses so excluded applications and sites can be left out of capture. |
| Microphone | Used only where your employer enables audio. Audio is then captured whenever a listed meeting or calling application uses the microphone. Where listen capture is enabled, it records entire meetings or webinars, including every other participant, even if you never speak. |
While audio is recording, the app shows "Recording from" and the application's name. Unless your organisation's policy locks them, you can see and change the list of meeting applications and turn meeting capture off in the app's settings. The app does not announce a recording to the other people on a call or webinar; telling them, and obtaining any consent the law requires, is the responsibility of the organisation that turned audio on.
What the app cannot do:
- record the content of your keystrokes or read your clipboard;
- use your webcam or take photographs;
- use the microphone outside the listed meeting and calling applications, or record ambient sound when no listed application is using the microphone;
- capture anything while you are signed out, or while tracking is stopped;
- track your location, beyond the country or region derived from your network address when you sign in;
- perform face recognition, voiceprints or emotion recognition.
Transcripts attribute each passage to the member or to the other party. The transcription model also separates the voices it hears and may label a passage with a name spoken in the conversation; that label is stored with the transcript, and the Audio page shows only the member's name or "Other party". We do not match voices against voiceprints or identify anyone biometrically.
Your employer's policy decides whether you can stop tracking, pause, sign out or quit the app. A timed pause is always available.
4. How we use data
We use personal data only for the purposes below. For monitoring data, your employer is the controller and chooses the lawful basis; the bases shown are the ones that usually apply, and we process that data only on its instructions. For the other rows we are the controller. We give the lawful-basis notes as information, not legal advice.
| Purpose | Data | Lawful basis note |
|---|---|---|
| Providing activity timelines, scores, rankings, alerts, review and reports to your employer | Screen activity and derived timeline; stored screen video; audio and transcripts; self-declared entries; automated assessments | Employer as controller. India DPDP: the employer's legitimate uses for employment purposes under section 7, or consent where it applies. Philippines DPA: contract and legitimate interests under section 12; section 13 conditions for any sensitive personal information. UK/EEA: legitimate interests, and in some cases legal obligation. |
| Timesheets and pay calculation | Pay and timesheet data; activity data | Employer as controller. India DPDP: employment purposes under section 7. Philippines DPA: contract under section 12. UK/EEA: performance of a contract and legal obligation. |
| The assistant and AI tools the organisation connects | Conversations with the assistant; activity data within the user's access | Employer as controller. India DPDP: section 7 legitimate uses, or consent where it applies. Philippines DPA: legitimate interests under section 12. UK/EEA: legitimate interests. |
| Accounts, sign-in, sessions and security | Account data; device and sign-in data | ScreenJournal as controller. India DPDP: the purpose for which you provided the data, under section 7. Philippines DPA: contract and legitimate interests under section 12. UK/EEA: performance of a contract and legitimate interests in keeping the service secure. |
| Billing | Account data; plan, seat and payment-provider identifiers | ScreenJournal as controller. India DPDP: section 7. Philippines DPA: contract and legal obligation under section 12. UK/EEA: performance of a contract and legal obligation. |
| Support, bug reports and crash diagnosis | Support and error reports | ScreenJournal as controller. India DPDP: the purpose for which you provided the data, under section 7. Philippines DPA: legitimate interests under section 12. UK/EEA: legitimate interests. |
| Service email: sign-in links, invitations, reminders and reports | Email address, name and message content | ScreenJournal as controller; reports are sent on the employer's instruction. India DPDP: section 7. Philippines DPA: contract under section 12. UK/EEA: performance of a contract. |
| Website, demo booking and support chat | Website visitor data | ScreenJournal as controller. India DPDP: consent, or the purpose for which you provided the data. Philippines DPA: consent and legitimate interests under section 12. UK/EEA: consent for analytics and marketing cookies; legitimate interests for answering your questions. |
| Meeting legal obligations and responding to lawful requests | Any of the above, as required | India DPDP, Philippines DPA and UK/EEA: legal obligation. |
Where consent is the basis, note that an employee's consent in an employment relationship is often not freely given, because of the imbalance of power. Employers should rely on another basis where one is available, and should not treat a click-through at sign-in as the basis for monitoring.
We do not sell personal data. We do not use monitoring data for advertising, and we do not use it for any purpose of our own beyond running, securing and supporting the service.
5. Automated processing
The service draws five kinds of automated inference about the people it monitors:
- an activity score from 1 to 5 for each recorded segment of screen activity;
- a productivity percentage, measured against the working day;
- a position in a weekly ranking of the organisation's members;
- flags that activity may be simulated, for example by a mouse-jiggling device;
- matches against alert rules written by the organisation.
Segment scores and descriptions are produced by a Google Gemini model accessed through Google Vertex AI, and alert evaluations by a Google Gemini model accessed through Google's Gemini API, from screen content and activity signals such as presence and idle time. The productivity percentage and the weekly ranking are calculated from those scores. Simulated-activity flags come from the same model reviewing the segment's screen recording, on which the desktop app marks the cursor position and clicks; fixed checks in our code then discount the device's own idle periods and apply minimum thresholds before a flag is set. These outputs are probabilistic. They can be wrong, and they describe what was on screen, not the quality or value of anyone's work.
ScreenJournal makes no employment decision. Any decision about a person, whether on pay, performance, discipline or anything else, is made by your employer's managers, who are responsible for it.
The following human-review surfaces exist today:
- the Review page, where managers can examine flagged segments, and the alerts inbox, where a manager approves or rejects a member's explanation;
- corrections, where the organisation's administrators change a segment's score;
- Add a reason, where a member, or a manager on the member's timeline, explains a paused, offline or away stretch (when the organisation's policy allows manual entries);
- the member's own Activity timeline, which shows their segments, descriptions and scores.
If you disagree with a score, flag or ranking, ask your employer first. Your employer can correct the record or redact a time range. If your employer does not respond, contact support@screenjournal.ai.
A flag that activity may be simulated is an indicator that calls for human judgement. It is never proof of misconduct, and it should not be relied on without a person reviewing the underlying activity.
An organisation can shape these outputs: correction rules override scores for chosen applications or sites, alert prompts define what an alert looks for, and suppression rules stop alerts it does not want. The documents the service produces, from timelines to rankings and flags, describe indicators, not decisions.
6. Who receives data
The service runs on one server operated by Hetzner in Germany, with Cloudflare in front of it for traffic protection and encryption in transit. Account and organisation records, monitoring metadata and report data are held in a PostgreSQL database on that server, and generated reports are cached in a MongoDB database on the same server. The server also runs other applications we operate, in separate containers. We do not currently keep database backups.
Activity time-series data is stored in Amazon S3 in Mumbai, India (the ap-south-1 region). Since August 2026 all new screen and audio media is stored in Google Cloud Storage (region to be confirmed); older media remains readable in Amazon S3 in Mumbai. The AI analysis of screen recordings and audio runs on Google Gemini models through Google's Vertex AI service at its global endpoint. Report and timesheet narratives, alert evaluation and the assistant use Google Gemini models through Google's Gemini API, as does the support chat on our website.
| Vendor | Purpose | Location |
|---|---|---|
| Hetzner | Server hosting and database | Germany |
| Cloudflare | Domain name service, encryption in transit, protection against attacks | Global, including the United States |
| Amazon Web Services | Activity time-series storage; read-only access to older media | India (Mumbai, ap-south-1) |
| Media storage (Google Cloud Storage); AI processing (Vertex AI for screen and audio analysis; the Gemini API for reports, alerts, the assistant and the website chat) | Storage region to be confirmed; Vertex AI (global endpoint); Gemini API (Google-operated, no fixed region) | |
| Paddle | Billing, as merchant of record | United Kingdom, European Union, United States |
| Resend | Sign-in links, invitations, reminders and alert emails | United States |
| Google Workspace (Gmail) | Report emails | Google's data centres |
| Sentry | Crash reports from the desktop app | United States (to be confirmed) |
| Telegram | Forwarding bug reports to our staff | Netherlands for accounts registered in the UK or EEA, per Telegram's privacy policy (section 4.1); Telegram does not publish the location for other accounts, and its group companies are in Dubai and the British Virgin Islands |
| Vercel | Hosting the web app and our website | United States (to be confirmed) |
| DeepInfra | Transcription fallback: not used in normal operation; available as a fallback and would be enabled only with notice | United States |
| OpenAI | Model fallback: not used in normal operation; available as a fallback and would be enabled only with notice | United States |
| MaxMind | A local database used to derive country or region from an IP address at sign-in; it sends nothing to MaxMind | Not applicable |
| Google and Microsoft sign-in | Sign-in, if you choose it; they act as independent controllers | United States |
| AI tools the organisation connects through the integration feature | The organisation's own analysis; these are recipients chosen by the organisation, not our processors | Chosen by the organisation |
Within your organisation. What people at your employer can see depends on their role: managers see the people they manage, and organisation-wide roles see everyone. You can see your own timeline.
Connected AI tools. Your employer, or a member with access, may connect an AI tool through the integration feature. The tool reads organisation data, within that person's access and read-only, on their instruction. The organisation chooses the tool and is responsible for it; we are not responsible for how that tool handles the data it receives. The connection lasts until it is revoked. Our Subprocessors page lists the third parties that process data on our behalf and explains why connected tools are not among them.
Platform staff support access. Our platform staff may sign in to an account to investigate a support issue. When they do, the session is shown as an impersonation in that member's session list. This access is not yet centrally logged.
Law enforcement and legal requests. We disclose personal data to a public authority only where it presents a valid legal process, and we notify the organisation concerned where the law allows.
Beyond the recipients described in this policy, we do not share personal data with third parties.
7. International transfers
Cyberinfra Limited, as controller and as processor, is established in the Isle of Man, a jurisdiction the European Union and the United Kingdom recognise as providing adequate protection for personal data. The service's server and database are hosted in Germany.
Some data is transferred onward from there: to India, where Amazon Web Services stores activity time-series and older media in its Mumbai region; to the United States, where Vercel hosts the web app and website (to be confirmed), Sentry receives desktop crash reports (to be confirmed) and Resend sends our sign-in, invitation and reminder emails; to Google Workspace, which sends report emails; and to Google, whose Vertex AI service is reached through its global endpoint and whose Gemini API serves reports, alerts and the assistant, so AI processing may take place in any country where Google operates it. Google Cloud Storage's region, Vercel's and Sentry's locations and every other location marked "to be confirmed" in section 6 have not yet been confirmed. These transfers take place under each vendor's standard terms.
India's law allows personal data to be transferred outside India except to countries the central government restricts. Philippine law holds the personal information controller accountable for personal data transferred abroad; we support our customers in meeting that duty.
8. Retention
Data is retained for the term of your employer's subscription unless it is deleted earlier on a verified request or by your employer. Where Record + Save is enabled, stored screen video is kept for up to three months by policy. Automated expiry is not yet built; deletion is carried out by our operational procedure.
The table condenses our Retention & Deletion Protocol, which sets out, category by category, how deletion happens today.
| Data | Retained for |
|---|---|
| Screen video in the default capture mode | Deleted after analysis; any temporary copy is removed by a storage lifecycle rule we configure on the bucket |
| Screen recordings on your device | The period your organisation sets, up to three months |
| Record + Save video | Up to three months by policy; not yet enforced automatically |
| Alert evidence clips | Until deleted; an organisation can set a window, but nothing yet acts on it |
| Audio recordings, only where your organisation chooses Record + Save for audio | The subscription term; otherwise audio is used for transcription and any temporary copy is removed by a storage lifecycle rule we configure on the bucket |
| Transcripts, kept whenever audio is on | The subscription term |
| Timelines, descriptions, scores and automated assessments | The subscription term |
| Self-declared entries | The subscription term; you can edit an entry's reason but not delete it |
| Pay, timesheets and reports | The subscription term |
| Assistant conversations | The subscription term, unless the user deletes a conversation |
| Records of each redaction | Kept as evidence of the request |
| Acceptance records | Kept for as long as a claim could be brought about the agreement they evidence |
| Account, sign-in and session data | The life of the account |
| Support and crash reports | Under the settings of the services that hold them (to be confirmed) |
| Operational logs | No fixed window yet |
| Website visitor data and email records | Under each vendor's settings |
When an organisation's subscription ends, we delete its data within sixty days, unless a contract or the law requires otherwise. Where your organisation allows redaction, a redaction removes the activity data for the chosen range, including any Record + Save video. Alert evidence clips are not removed by a member's redaction request.
Our servers are not the only place screen video is kept. In the default capture mode, the desktop app keeps recordings on your own device for the period your organisation sets, up to three months, and then removes them.
Because we do not currently keep database backups, there are no backup copies for a deletion to reach. Copies that have left our systems, such as audio a manager downloaded or data a connected AI tool received, are outside our control.
9. Security
We protect personal data with measures appropriate to the service, including encryption in transit, provider-managed encryption at rest in object storage, organisation-scoped access, signed short-lived access tokens, optional two-factor authentication and the exclusion of sensitive applications before capture. Sensitive-category exclusions (banking, payroll, HR, health and adult content) are on by default, and an organisation's administrators can change them. Before analysis output is stored, an automated filter removes secrets and certain identifiers, such as card numbers, from descriptions and window titles; names, email addresses and web addresses are kept.
Not everything is built yet: we keep no database backups, there is no central access log, and disk encryption on the database host has not yet been verified. We track our security controls in Vanta and are preparing for a SOC 2 audit. No SOC 2 report or ISO 27001 certificate has been issued.
If a breach affects personal data, we notify the affected organisations without undue delay, and regulators and individuals where the law requires. Our Security page describes every measure and gap, and our Vulnerability Disclosure Policy explains how to report a vulnerability.
10. Your rights
Your rights depend on the law that applies to you.
- India (Digital Personal Data Protection Act, 2023): access to a summary of your data and its processing, correction, completion, updating and erasure, grievance redressal, withdrawal of consent where consent is the basis, and nomination of someone to exercise your rights if you die or become incapacitated. Some DPDP rights and the Board's complaint route commence in stages; the substantive duties commence on 13 May 2027.
- Philippines (Data Privacy Act of 2012): the rights to be informed, to access, to object, to rectification, to erasure or blocking, to damages, to data portability, and to complain to the National Privacy Commission.
- UK and EEA: access, rectification, erasure, restriction, portability, objection, and the right not to be subject to a decision based solely on automated processing that has legal or similarly significant effects. ScreenJournal makes no such decisions; see section 5.
If you are a monitored employee, your employer controls your monitoring data, so please ask your employer first. If you write to us directly, we pass the request to your employer and help it respond. We may not be able to act on monitoring data without its instruction.
What you can do yourself:
- see your own timeline, with its descriptions and scores, in the desktop app;
- add a reason for paused, offline or away time, where your organisation's policy allows manual entries;
- answer an alert addressed to you with an explanation;
- redact a time range from your timeline, where your employer has enabled redaction for your role;
- turn meeting capture off, unless your organisation's policy requires it;
- review your signed-in sessions and revoke any of them;
- turn on two-factor authentication;
- delete your conversations with the assistant, if you use it.
How to contact us. Email support@screenjournal.ai with the subject line "Data protection request". We verify who you are before we act, normally through the sign-in email on your account, and we acknowledge every request. Our Data Protection Contacts page explains how we route, verify and answer requests, how agents and nominees are handled, and where you can complain.
11. Staff access
Our platform staff may access an account to investigate a support issue. When they do, it is shown in your session list as an impersonation, so you can see that it happened. We have no central access log yet, so apart from that marker we keep no separate record of what our staff view. Staff may access monitoring data only to support the organisation, acting as its processor.
12. Children
The service is a workplace tool and is not directed at anyone under 18. We do not knowingly collect personal data from children. Employers must not deploy the service on a device used by a minor unless they have a lawful basis to do so. If you believe a child's data has reached us, contact support@screenjournal.ai.
13. Marketing, cookies and Global Privacy Control
Our Cookie Policy lists the cookies and similar technologies on our website and how to control them. Google Tag Manager, the Meta Pixel and Microsoft Clarity load only after you consent through the cookie banner, and you can change your choice at any time. Clarity's session replays in the web app are recorded with Strict masking: text and images are masked in your browser before anything is sent, so Microsoft receives layout and interaction data only. With your consent, the Meta Pixel on our website shares visitor data with Meta for advertising measurement; you can withhold or withdraw that consent in the cookie banner. Demo and trial requests open a WhatsApp chat with us; the interactive demo page sends your messages to an automation workflow we run on our own server in Germany, which keeps the conversation for the session and its execution log for about 14 days. The support chat on our website is answered by a Google Gemini model through Google's Gemini API; we do not save the conversation to our database.
We do not use monitoring or customer data for advertising. The email we send is service email: sign-in links, invitations, reminders and the reports an organisation has set up. We do not yet read Global Privacy Control browser signals automatically; use the cookie banner to withhold or withdraw marketing consent.
14. California and other US states
For monitoring data and other data we process for a customer, we act as a service provider (or processor) to that customer. We do not sell personal information. Where consent-based website tags would count as "sharing" under California law, you can opt out through the cookie banner. We do not yet read Global Privacy Control browser signals automatically; use the cookie banner to withhold or withdraw marketing consent. We do not use monitoring or customer data for advertising.
Depending on your state, you may have the right to know what personal information we hold about you, to delete it and to correct it, and to appeal if we refuse. We will not discriminate against you for exercising these rights. If you are an employee of a customer, your employer handles your requests about monitoring data, and we help it respond. For data we hold as controller, contact support@screenjournal.ai. The categories of data, their sources and the purposes we use them for are set out in sections 2 and 4.
15. EEA and UK
Our home regime is the Isle of Man's data protection law, which applies the GDPR with local adaptations. We have not appointed an EU or UK representative; contact support@screenjournal.ai.
You can complain to the Information Commissioner of the Isle of Man, our home regulator (inforights.im). You also have the right to lodge a complaint with the data protection authority where you live or work, or where you believe the law was broken; in the UK, that is the Information Commissioner's Office.
16. Changes
This policy is versioned, and the version and effective date are shown at the top. We list every change on the Legal page with its effective date and, where practicable, post material changes before they take effect. Earlier versions remain available in the Legal archive. Our other terms, including the Terms of Use and the Refund Policy, are on the same page.
17. Contact
For questions about this policy or your personal data, email support@screenjournal.ai, with the subject line "Data protection request" for rights requests. We route each message to the right role, including our Data Protection Officer role and our Grievance Officer role for India.
Post: Cyberinfra Limited, 50 Athol Street, Douglas, Isle of Man IM1 1JB.
If you are not satisfied with our answer, you can complain to the Information Commissioner of the Isle of Man or to the authority where you live, as described in section 15.
Changes and previous versions
- 5 October 2026v3.1: acceptance records added to the data we collect and the retention table.
- 5 October 2026v3.0: full rewrite — data categories, automated processing and human review, current vendors and hosting in Germany, retention stated as operated, staff access, EEA/UK and US-state sections.
Questions about this document: support@screenjournal.ai. Canonical URL: /privacy-policy.