Privacy Policy
Last updated July 7, 2026 · Version 2.0
This policy explains how Cyberinfra Limited (Isle of Man) ("ScreenJournal", "we") handles personal data in connection with the ScreenJournal workforce-activity services (the "Services").
1. Who we are, and whose data this covers
ScreenJournal is a business-to-business employee-monitoring service. Employers (our "Customers") deploy it on work devices to understand work activity.
- If you are a monitored employee or contractor: your employer is the data controller of your monitoring data and decides what is monitored and why. ScreenJournal processes that data on your employer's behalf and instructions. Your employer is your first point of contact for questions and requests about your data.
- If you are a Customer administrator or website visitor: we act as the controller of your account, billing, and site data, as described below.
2. Information we collect
Monitoring data (processed for your employer):
- Screen activity in work applications. The desktop app captures screen content from work applications and derives an activity timeline (which applications were used, window titles, and a description of the work activity). Applications and sites designated sensitive or personal — banking, payroll, HR, health, and personal accounts — are blocked from capture and are not recorded or analysed.
- Call audio and transcripts — only where your employer has enabled call transcription. Where enabled, audio from business calls is transcribed. There is no ambient or always-on microphone capture, and no voiceprints, speaker identification, or biometric processing of any kind.
- Device and log data. App version, device identifiers, timestamps, and technical logs needed to operate the Services.
Account data (we are the controller): name, email address, job title, authentication credentials, and organisation details of Customer administrators; billing data (processed by Paddle as merchant of record); support correspondence.
3. How we use information
- To provide the Services to your employer: producing activity timelines, reports, and analytics about work activity.
- To operate, secure, and support the Services (authentication, tenant isolation, abuse prevention, troubleshooting).
- To bill Customers and administer accounts.
- To comply with law.
We do not sell personal data, and we do not use monitoring data for advertising.
4. AI and automated processing
Screen content is analysed by Google's AI services, and call audio (where transcription is enabled) is transcribed by DeepInfra, under contracts with those providers, to produce activity timelines and transcripts. The output is decision support for your employer. The Services make no automated employment decisions: any decision affecting you is made by people at your employer, not by the Services.
5. Who we share data with
We share personal data only with the service providers we use to run the Services — currently Google (screen-content analysis), DeepInfra (audio transcription, where enabled), Amazon Web Services (storage), Paddle (billing), and MongoDB Atlas (report cache) — and with professional advisers or authorities where required by law.
6. International transfers
The Services process data in the United States (Google, DeepInfra, AWS). Transfers are made under our data-processing terms with Customers and our contracts with these providers.
7. Retention
- Source screen recordings are analysed to derive the activity timeline and then deleted — the underlying video is not stored.
- Activity timelines and call transcripts are retained while your employer's subscription is active, and are deleted following account closure or a verified deletion request from your employer. We are introducing fixed retention windows with automatic deletion; this policy will be updated when they take effect.
- Account and billing data is kept for the life of the account plus statutory retention periods.
8. Security
Monitoring data is encrypted in transit and at rest. Access is scoped by authenticated, tenant-isolated credentials, sensitive applications are excluded from capture before anything is recorded, and analysis output passes automated redaction of secrets, card numbers, and identifiers.
9. Your rights
You may request access to, correction of, or deletion of your personal data.
- Monitored employees: because your employer is the controller, requests about monitoring data are handled with your employer — contact your employer's privacy contact first. We assist the employer in fulfilling requests, and we pass on any request we receive directly.
- India: you may exercise the rights in the Digital Personal Data Protection Act, 2023, and escalate unresolved grievances to the Data Protection Board of India.
- Philippines: you may exercise the rights in the Data Privacy Act of 2012 (RA 10173) and may lodge a complaint with the National Privacy Commission (privacy.gov.ph).
10. Biometrics
None. The Services perform no voiceprint, faceprint, or other biometric identification, and no emotion recognition.
11. Data breaches
If a breach affects your personal data, we notify the affected Customers (controllers) without undue delay, and regulators and affected individuals where required by applicable law.
12. Children
The Services are workplace tools and are not directed at children. We do not knowingly process children's data.
13. Changes to this policy
This policy is versioned; the current version and effective date are shown at the top. We will notify Customers of material changes and keep prior versions available on request.
14. Contact
Privacy questions and requests: support@screenjournal.ai
Cyberinfra Limited, Isle of Man