Privacy
What this service stores about you and the people who use it, why, and for how long. Written to be read rather than agreed to.
First drafted 2026-08-18.
What we collect
Three things, and no more. Account details you type in: a name, an email address, a hashed password, and which organization and branches you belong to. Content you upload: images, video and the campaigns and schedules built from them. Operational readings from your screens: when each one last checked in, what it is playing, the resolution it reports, whether it is online, and how much local storage it has left.
What we use it for
Running the service you are paying for, and nothing else. Your email address signs you in, receives invitations and password resets, and is where we reply when you ask us something. Screen readings drive the monitoring pages and the alerts that tell you a display went dark. We do not build advertising profiles, we do not sell anything to anybody, and there is no third-party analytics or tracking script on the pages you sign into.
Who else sees it
The companies that run the infrastructure underneath: the host the application runs on, the object storage that holds your media, and the mail relay that delivers invitations and password resets. Each one only handles what it needs to do that job. We do not pass your data to anyone else, and nobody buys access to it.
How long it is kept
Your account, media and campaigns stay for as long as the account exists. Screen telemetry — the heartbeat readings behind the monitoring pages — is trimmed automatically after a retention window your operator sets, thirty days by default, because a menu board's playback log from last spring is of no use to anyone. Database backups are taken nightly and rotate out on their own schedule. Close the account and we delete the content; ask first if you want an export.
What you can ask for
A copy of what we hold about you, a correction to anything wrong, or deletion. Write to us and we will do it. There is no form and no ticket number: this is a small service and these requests are handled by a person.
How it is protected
Passwords are hashed, never stored in a form anyone can read. Traffic is encrypted in transit. Access inside your organization is by permission rather than by seniority, and every change of consequence is written to an audit log you can read yourself. If we ever have a breach that affects you, we will tell you what happened rather than wait to be asked.
The screens themselves
A paired display holds a device token in its browser storage so it can identify itself, and it reports the readings listed above. It does not have a camera or a microphone, it collects nothing about the people walking past it, and it counts nobody. It is a screen that shows what you published to it.
Questions about this
Ask, and a person will answer. If something here does not match what you were told, tell us — this page is meant to describe what actually happens.
This is a plain-language draft written by the people who built the service, describing how it works today. It has not yet been reviewed by a lawyer. Where it is ever in conflict with a signed agreement between us, the signed agreement is the one that counts.