WaysteadScheduler
Back home
Legal

Privacy

Last updated 1 July 2026
⚠ Draft — not legal advice. This is a starting draft prepared to reflect what the app does. It has not been reviewed by a solicitor. Waystead Scheduler is currently a private, self-hosted household planner; public or invited sign-up by other families is not enabled. Several sections below describe an intended future model and are written cautiously — before any public/invited use goes live, these terms must be reviewed by a qualified data-protection solicitor, particularly the sections concerning children’s data (UK GDPR and the ICO Age Appropriate Design Code / “Children’s Code”).

The short version

Waystead Scheduler holds your household’s plan so you can find your way through the week. We keep only what the app needs to work, we do not sell your data, we do not send it to third parties for advertising, and we give you a clear way to export or delete it. Your data lives on the server the household operator runs.

Who is responsible for your data

Waystead Scheduler is self-hosted: the household that runs the instance (the “household operator” — the primary parent who set it up) controls the server and the data on it. For your own household’s instance, the household operator is the data controller for the information in it. Waystead provides the software; it does not, by default, receive or store your household’s planning data centrally.

(Intended future model — not currently enabled: if Waystead ever offers a hosted service where multiple, unrelated families sign up, Waystead would act as data controller and/or processor for that service, and this policy would be revised and legally reviewed before launch.)

What we store

To plan your week, the app stores the information you put into it:

  • Household & accounts — the household, its members (e.g. primary parent, partner), and sign-in details (email and a securely hashed password).
  • Planning data — your rituals, tasks, projects/OKRs, away periods, and the generated weekly schedule.
  • Children & learning data — where you use the tutoring features: a child’s name, year group, school (if entered), the subjects/curriculum you teach, lesson outlines, and mastery/progress records.
  • Household content — shared shopping lists, notes, and calendar entries.
  • Operational data — minimal technical logs needed to run and secure the service (e.g. sign-in events, errors).

We store this because it is what lets the scheduler plan your week and remember where each child is up to. We do not collect data we don’t need for these purposes.

Children’s data

Some features are designed for parents tracking their own children’s learning. We treat children’s information with particular care:

  • A child’s data is entered and managed by a responsible adult in the household (the primary parent or partner), under that adult’s direction.
  • We store only what the tutoring feature needs (name, year group, optional school, curriculum, progress). We do not ask children to create accounts or interact with the service directly.
  • Children’s data is subject to the same export/deletion rights below, exercised by the responsible adult.

(Intended future safeguards — not currently enabled: any future public/invited model that would involve processing children’s data across unrelated households would be designed to the ICO Children’s Code and reviewed by a solicitor before launch, including age-appropriate defaults, data minimisation, and a clear lawful basis.)

What we do NOT do

  • We do not sell your data.
  • We do not use your data for advertising, or share it with advertisers.
  • We do not send your household’s planning or children’s data to third-party AI services on our own initiative. Where an optional feature uses an external service, it is described at the point of use and is under your control.

Third-party services we rely on

To operate, the service may use a small number of providers strictly for infrastructure:

  • Email delivery (e.g. for sign-in or notifications) via a transactional email provider.
  • Hosting/storage on the server infrastructure the household operator chooses, including off-site encrypted backups.

These providers process data only to deliver their function and are not permitted to use it for their own purposes.

Your rights

Under UK data protection law you have rights over your personal data, including to access, correct, export, and delete it, and to object to certain processing. In a self-hosted household instance, the household operator can action these directly (export or delete data in the app or database). For any request, contact the household operator of your instance.

Data retention

We keep your data for as long as your household uses the service. When you delete records (or a household is closed), the data is removed from the live system; encrypted backups age out on a rolling schedule.

Security

We protect data with access controls that isolate each household’s information, encrypted off-site backups, and standard security practices. No system is perfectly secure, but we design to keep your household’s data private to your household.

Changes to this policy

We may update this policy as the app changes. Material changes — particularly any move toward public or invited use, or any change in how children’s data is handled — will be made clear, and (per the note at the top) reviewed by a solicitor before such changes take effect.

Contact

For any privacy question about your instance, contact your household operator. (A contact address will be added here.)