Data Retention & Deletion Protocol
Version 2.0 · Effective 5 October 2026
This protocol explains how long Cyberinfra Limited ("ScreenJournal", "we") keeps each kind of data processed by the ScreenJournal service, and how that data is deleted. Where a step is done by people following a procedure rather than by software, we say so.
1. Scope and how to read this page
This page covers all personal data the service processes: monitoring data about the members of a customer organisation (screen activity, timelines, scores and, where enabled, audio), the entries members write themselves, and the account, billing and support data we hold about the people who use the service. It is the public statement of our operational retention schedule: it describes what happens today, not what we plan to build.
For monitoring data, the employer is the controller and we process the data on its instructions. The employer decides which features are on, and it can delete data earlier than this schedule allows. For account, sign-in, support and crash-report data, we are the controller.
Three phrases are used throughout:
- Retained for the subscription term means the data is kept while the employer's subscription continues, unless it is deleted earlier on a verified request, by the employer, or by a redaction where the organisation allows redaction. It does not mean a fixed number of days.
- Automated expiry means software that deletes data on its own when a period ends. For most categories this is not yet built, and the table says so row by row. Where it is not built, deletion is carried out by our operational procedure in sections 3 and 4.
- Retained for (true today) describes current practice, not a target.
2. Retention schedule
Data is retained for the term of your employer's subscription unless it is deleted earlier on a verified request or by your employer. Where Record + Save is enabled, stored screen video is kept for up to three months by policy. Automated expiry is not yet built; deletion is carried out by our operational procedure.
The table below sets out each category. Where a period is set by the organisation, it is the organisation's choice, within the limits stated.
| Data | Retained for (true today) | How deletion happens today | Automated expiry |
|---|---|---|---|
| Screen video in the default capture mode, with the analysis result for each segment | Deleted after analysis; any temporary copy is removed by a storage lifecycle rule we configure on the bucket | Removed after the timeline is derived; the bucket lifecycle rule clears any temporary copy | Bucket lifecycle rule, configured outside code, not yet verified in production |
| Screen recordings kept on the member's device | The period the organisation sets, up to three months | The desktop app removes them from the device | The desktop app removes local copies after the configured period |
| Record + Save video, where the organisation enables it | Up to three months by policy; not enforced by an automated process | Removed by a member's redaction request where redaction is enabled; otherwise by our operational procedure on request or at termination | Not yet built |
| Alert evidence clips, with the alert message, decision and reply | Window configurable by the organisation; the shipped default keeps them until deleted | By our operational procedure on request or at termination; the clips are not removed by a member's redaction request | Not yet built |
| Audio recordings and transcripts, where the organisation turns audio on | Retained for the subscription term; audio is stored only where the organisation chooses Record + Save for audio (otherwise it is used for transcription and any temporary copy is removed by a storage lifecycle rule we configure on the bucket); transcripts are kept in both modes; managers can download stored audio, and downloaded copies are outside our control | By our operational procedure on request or at termination | Not yet built |
| Activity timelines, descriptions and scores, including productivity figures, rankings and flags that activity may be simulated | Retained for the subscription term | Removed by redaction for the redacted range; otherwise by our operational procedure | Not yet built |
| Self-declared entries: manual time entries, away reasons, declared off-screen work and explanations given for alerts | Retained for the subscription term; a member cannot delete them | A member can edit an entry's reason; deletion is by our operational procedure on request or at termination | Not yet built |
| Pay rates, computed pay, timesheets and generated reports (the report cache is a MongoDB database on our server with no expiry) | Retained for the subscription term | By our operational procedure on request or at termination | Not yet built |
| Assistant conversations | Retained for the subscription term unless the user deletes a conversation | The user can delete a conversation; otherwise by our operational procedure | Not yet built |
| Redaction audit records: who asked, which range, the reason and when | Kept as evidence of the request; not deleted on redaction | By our operational procedure at termination | Not yet built |
| Account and organisation data, sign-in data and session records, including the country or region and timezone derived from the sign-in IP address | For the life of the account | By our operational procedure on request or at termination; cancelling a subscription does not delete them automatically | Not yet built |
| Access granted to AI tools the organisation connects | Until the organisation revokes the connection; data a connected tool has already received is outside our control | The organisation revokes the connection | Not yet built |
| Support and crash reports | Bug reports forwarded to our staff through Telegram are kept in the staff chat without a retention window (to be confirmed); desktop crash reports are kept under Sentry's settings (to be confirmed) | By our operational procedure on request, as far as those services allow | Not yet built |
| Operational logs | No fixed window yet | No removal procedure yet | Not yet built |
| Website visitor data and records held by Resend and Google Workspace, our email providers | Under each vendor's settings; no fixed window on our side | See the Cookie Policy for website data | Not yet built |
Before 17 September 2026 the service also stored images of pointer movement. None are collected now; any already stored are kept on the same terms as activity timelines until deleted.
An organisation can set a retention window for alert evidence clips. Today that setting records an intended expiry date, but no process yet acts on it, so clips stay stored until they are deleted under our operational procedure.
Where each category is stored is set out on the Security page and the Subprocessors page.
3. Deletion on request
Who asks. If you are a member of an organisation, your employer controls your monitoring data, so please make an erasure request to your employer first. We act on your employer's verified instruction, and we pass to your employer any request we receive from you directly. Customer administrators, and anyone whose account, support or crash-report data we hold, can ask us directly. Our Privacy Policy explains your rights.
How it works today. Deletion on request is a manual procedure:
- A request reaches us at support@screenjournal.ai, and we verify that it comes from the organisation's authorised administrator or from the person whose data it is.
- We locate the data in scope across every storage location the service uses: the database, activity time-series storage and media storage. Copies on the member's own device are outside this procedure; they expire under the organisation's local setting (up to three months).
- We delete it, then check the result and repeat the deletion if any step fails.
- We confirm to the requester when the deletion is complete. We aim to complete deletions within thirty days.
There is no self-service "delete my data" button. Copies already outside our systems are outside this procedure: audio a manager downloaded, data an organisation's connected AI tool received, and reports held by Telegram or Sentry beyond what those services let us delete.
Redaction. Where an organisation allows it, members or managers can redact a time range themselves. A redaction removes the activity data for that range, including timelines, descriptions, scores and any Record + Save video. Alert evidence clips are not removed by a member's redaction request. We keep a record of each redaction (who asked, which range, the reason and when) as evidence of the request. If removing a stored file fails during a redaction, the failure is logged on our side; ask support@screenjournal.ai and we will repeat the deletion.
4. Deletion on termination
When an organisation's subscription ends, we delete its data within sixty days, unless a contract with the organisation says otherwise or the law requires us to keep it. Deletion at termination uses the same manual procedure as section 3, applied to the whole organisation.
Two things are excluded:
- Billing records held by Paddle, our merchant of record, which Paddle keeps under its own legal obligations. Our Refund Policy covers payments.
- Support correspondence with us, which we keep as a record of what was asked and answered.
5. Backups
We do not currently keep database backups. When we introduce them, this section will state how long backup copies persist after a deletion.
6. What is not yet automated
These items are on our roadmap. They are plans, not commitments, and we will update this page when any of them is in place:
- A retention sweeper: software that deletes each category automatically when its period ends, including the alert evidence window an organisation sets and the three-month Record + Save limit.
- A fixed retention window for operational logs.
- Backup propagation rules: how long a deletion takes to reach backup copies, once backups exist.
The Security page lists these and our other gaps in one place. Questions about this page: support@screenjournal.ai. Our other legal documents are on the Legal page.
Changes and previous versions
- 5 October 2026v2.0: schedule rebuilt per data category; evidence clips and self-declared entries added; no automated expiry stated plainly.
Questions about this document: support@screenjournal.ai. Canonical URL: /legal/retention-deletion-protocol.