Privacy notice

Aerta OnTrack · Last updated 12 September 2026

Your weekly plan is stored in your own browser, encrypted with a passphrase only you know. AertaOne cannot read it. We hold no account for you, set no cookies, run no analytics, and the app contacts no other company's servers.

Who is responsible

AertaOne provides Aerta OnTrack and is the data controller for the limited processing described below. For any question about this notice, or to exercise the rights set out at the end, contact ontrack@aertaone.com.

Where your plan actually lives

Everything you enter — your tasks, hours, next steps, requests, decision log and parked notes — is written to a database inside your web browser (IndexedDB) on the device you are using. It is not sent to us, and there is no server-side copy.

Before it is written, it is encrypted with AES-GCM using a key derived from the passphrase you set. The passphrase itself is never stored anywhere, and what sits in the database is ciphertext.

So that refreshing the page does not lock you out, the key that opens your plan is also held in the browser tab's session storage. It is dropped the moment the workspace locks — by hand, or after the idle period you set — and the browser discards it when the tab closes. Be aware that browsers may write session storage to disk in order to restore a session later, so while a tab is open the key is not guaranteed to stay in memory alone. If that matters to you, lock the workspace rather than leaving a tab open.

This has a consequence worth understanding. Because we never receive your plan and cannot derive your key, we cannot recover it for you, produce it on request, or restore it if you forget your passphrase. The privacy guarantee and the absence of a safety net are the same fact.

What we do process

Only what is unavoidable in serving a web page. The app is hosted by Vercel Inc., acting as our processor. When your browser requests the site, Vercel processes standard connection data on our behalf:

DataWhyLawful basis
IP address, date and time, the file requested, browser and operating system identifiersTo deliver the page, keep the service available, and detect abuse or attackLegitimate interests (Article 6(1)(f)) — operating and securing a tool we make available to our people

Vercel retains these request logs for a limited period under its own policies and then deletes them; see the Vercel privacy policy. Vercel is based in the United States, so this involves a transfer outside the European Economic Area, made under the standard contractual clauses in Vercel's data processing agreement.

We do not receive these logs in any form that we use to identify or profile individuals, and we do not combine them with anything else.

What we do not do

Information you put in yourself

The app is deliberately built so that you do not need to record other people's details. There is no field for a requester's name; a request holds a link to the ticket instead, and email addresses and phone numbers are refused wherever you try to type them. The principle is that a link inherits the access control of the system behind it, so the planner never needs its own copy.

Titles, next steps and outcomes remain free text, because a task you cannot read is a task you cannot do. If you choose to write a colleague's name into one of those fields, that is personal data about them, held on your device and under your control. Keep such notes to what you actually need, and remember that anything you export in a backup travels with the file.

Backups you create

You can export your plan as a file and put it wherever you choose — a folder on your device, OneDrive, or another service. Once a backup leaves the app it is governed by whatever you saved it into, and by that provider's terms and privacy policy. We have no visibility of it.

An encrypted backup is protected by a passphrase of its own and is unreadable to the service storing it. A plain backup is readable by anyone who opens the file. Choose the encrypted format for any folder that syncs to a cloud service or is shared with other people.

How long things are kept

Your rights

Under the GDPR you have the right to access your personal data, to have it corrected or erased, to restrict or object to its processing, and to receive it in a portable form.

In practice, most of these you exercise directly and immediately: your plan is on your device, you can export it at any time from Data & backup, you can edit any part of it, and clearing the site's data erases it beyond recovery. We could not comply with a request about your plan even if you made one, because we do not hold it.

For the server request logs described above, write to ontrack@aertaone.com and we will deal with your request. You also have the right to lodge a complaint with the Data Protection Commission, Ireland's supervisory authority.

Security

The site is served only over HTTPS, with a content security policy that permits no external scripts, styles, fonts or connections. Your plan is encrypted at rest with AES-GCM under a key derived from your passphrase using PBKDF2-SHA256 with 310,000 iterations and a random salt generated on your device. The workspace locks itself after a period of inactivity, which discards the key.

No system is perfect, and the honest limits are these: an unlocked session left open on a shared machine is readable by whoever is sitting at it; the key is held in the tab's session storage while unlocked, which a browser may write to disk for session restore; a weak passphrase is a weak lock; and a plain backup protects nothing.

Changes to this notice

If the app starts doing something this notice does not describe, the notice changes first. The date at the top always reflects the current version.