ScreenJournal

Data Retention & Deletion Protocol

Version 2.0 · Effective 5 October 2026

This protocol explains how long Cyberinfra Limited ("ScreenJournal", "we") keeps each kind of data processed by the ScreenJournal service, and how that data is deleted. Where a step is done by people following a procedure rather than by software, we say so.

1. Scope and how to read this page

This page covers all personal data the service processes: monitoring data about the members of a customer organisation (screen activity, timelines, scores and, where enabled, audio), the entries members write themselves, and the account, billing and support data we hold about the people who use the service. It is the public statement of our operational retention schedule: it describes what happens today, not what we plan to build.

For monitoring data, the employer is the controller and we process the data on its instructions. The employer decides which features are on, and it can delete data earlier than this schedule allows. For account, sign-in, support and crash-report data, we are the controller.

Three phrases are used throughout:

  • Retained for the subscription term means the data is kept while the employer's subscription continues, unless it is deleted earlier on a verified request, by the employer, or by a redaction where the organisation allows redaction. It does not mean a fixed number of days.
  • Automated expiry means software that deletes data on its own when a period ends. For most categories this is not yet built, and the table says so row by row. Where it is not built, deletion is carried out by our operational procedure in sections 3 and 4.
  • Retained for (true today) describes current practice, not a target.

2. Retention schedule

Data is retained for the term of your employer's subscription unless it is deleted earlier on a verified request or by your employer. Where Record + Save is enabled, stored screen video is kept for up to three months by policy. Automated expiry is not yet built; deletion is carried out by our operational procedure.

The table below sets out each category. Where a period is set by the organisation, it is the organisation's choice, within the limits stated.

DataRetained for (true today)How deletion happens todayAutomated expiry
Screen video in the default capture mode, with the analysis result for each segmentDeleted after analysis; any temporary copy is removed by a storage lifecycle rule we configure on the bucketRemoved after the timeline is derived; the bucket lifecycle rule clears any temporary copyBucket lifecycle rule, configured outside code, not yet verified in production
Screen recordings kept on the member's deviceThe period the organisation sets, up to three monthsThe desktop app removes them from the deviceThe desktop app removes local copies after the configured period
Record + Save video, where the organisation enables itUp to three months by policy; not enforced by an automated processRemoved by a member's redaction request where redaction is enabled; otherwise by our operational procedure on request or at terminationNot yet built
Alert evidence clips, with the alert message, decision and replyWindow configurable by the organisation; the shipped default keeps them until deletedBy our operational procedure on request or at termination; the clips are not removed by a member's redaction requestNot yet built
Audio recordings and transcripts, where the organisation turns audio onRetained for the subscription term; audio is stored only where the organisation chooses Record + Save for audio (otherwise it is used for transcription and any temporary copy is removed by a storage lifecycle rule we configure on the bucket); transcripts are kept in both modes; managers can download stored audio, and downloaded copies are outside our controlBy our operational procedure on request or at terminationNot yet built
Activity timelines, descriptions and scores, including productivity figures, rankings and flags that activity may be simulatedRetained for the subscription termRemoved by redaction for the redacted range; otherwise by our operational procedureNot yet built
Self-declared entries: manual time entries, away reasons, declared off-screen work and explanations given for alertsRetained for the subscription term; a member cannot delete themA member can edit an entry's reason; deletion is by our operational procedure on request or at terminationNot yet built
Pay rates, computed pay, timesheets and generated reports (the report cache is a MongoDB database on our server with no expiry)Retained for the subscription termBy our operational procedure on request or at terminationNot yet built
Assistant conversationsRetained for the subscription term unless the user deletes a conversationThe user can delete a conversation; otherwise by our operational procedureNot yet built
Redaction audit records: who asked, which range, the reason and whenKept as evidence of the request; not deleted on redactionBy our operational procedure at terminationNot yet built
Account and organisation data, sign-in data and session records, including the country or region and timezone derived from the sign-in IP addressFor the life of the accountBy our operational procedure on request or at termination; cancelling a subscription does not delete them automaticallyNot yet built
Access granted to AI tools the organisation connectsUntil the organisation revokes the connection; data a connected tool has already received is outside our controlThe organisation revokes the connectionNot yet built
Support and crash reportsBug reports forwarded to our staff through Telegram are kept in the staff chat without a retention window (to be confirmed); desktop crash reports are kept under Sentry's settings (to be confirmed)By our operational procedure on request, as far as those services allowNot yet built
Operational logsNo fixed window yetNo removal procedure yetNot yet built
Website visitor data and records held by Resend and Google Workspace, our email providersUnder each vendor's settings; no fixed window on our sideSee the Cookie Policy for website dataNot yet built

Before 17 September 2026 the service also stored images of pointer movement. None are collected now; any already stored are kept on the same terms as activity timelines until deleted.

An organisation can set a retention window for alert evidence clips. Today that setting records an intended expiry date, but no process yet acts on it, so clips stay stored until they are deleted under our operational procedure.

Where each category is stored is set out on the Security page and the Subprocessors page.

3. Deletion on request

Who asks. If you are a member of an organisation, your employer controls your monitoring data, so please make an erasure request to your employer first. We act on your employer's verified instruction, and we pass to your employer any request we receive from you directly. Customer administrators, and anyone whose account, support or crash-report data we hold, can ask us directly. Our Privacy Policy explains your rights.

How it works today. Deletion on request is a manual procedure:

  1. A request reaches us at support@screenjournal.ai, and we verify that it comes from the organisation's authorised administrator or from the person whose data it is.
  2. We locate the data in scope across every storage location the service uses: the database, activity time-series storage and media storage. Copies on the member's own device are outside this procedure; they expire under the organisation's local setting (up to three months).
  3. We delete it, then check the result and repeat the deletion if any step fails.
  4. We confirm to the requester when the deletion is complete. We aim to complete deletions within thirty days.

There is no self-service "delete my data" button. Copies already outside our systems are outside this procedure: audio a manager downloaded, data an organisation's connected AI tool received, and reports held by Telegram or Sentry beyond what those services let us delete.

Redaction. Where an organisation allows it, members or managers can redact a time range themselves. A redaction removes the activity data for that range, including timelines, descriptions, scores and any Record + Save video. Alert evidence clips are not removed by a member's redaction request. We keep a record of each redaction (who asked, which range, the reason and when) as evidence of the request. If removing a stored file fails during a redaction, the failure is logged on our side; ask support@screenjournal.ai and we will repeat the deletion.

4. Deletion on termination

When an organisation's subscription ends, we delete its data within sixty days, unless a contract with the organisation says otherwise or the law requires us to keep it. Deletion at termination uses the same manual procedure as section 3, applied to the whole organisation.

Two things are excluded:

  • Billing records held by Paddle, our merchant of record, which Paddle keeps under its own legal obligations. Our Refund Policy covers payments.
  • Support correspondence with us, which we keep as a record of what was asked and answered.

5. Backups

We do not currently keep database backups. When we introduce them, this section will state how long backup copies persist after a deletion.

6. What is not yet automated

These items are on our roadmap. They are plans, not commitments, and we will update this page when any of them is in place:

  • A retention sweeper: software that deletes each category automatically when its period ends, including the alert evidence window an organisation sets and the three-month Record + Save limit.
  • A fixed retention window for operational logs.
  • Backup propagation rules: how long a deletion takes to reach backup copies, once backups exist.

The Security page lists these and our other gaps in one place. Questions about this page: support@screenjournal.ai. Our other legal documents are on the Legal page.

Changes and previous versions

  • 5 October 2026v2.0: schedule rebuilt per data category; evidence clips and self-declared entries added; no automated expiry stated plainly.

Questions about this document: support@screenjournal.ai. Canonical URL: /legal/retention-deletion-protocol.