Privacy Policy
Last updated: 2 September 20261. Who we are
Aimavera is a project scheduling application published by Vantis Project Intelligence Ltd, a company registered in England and Wales under company number 17285923, with its registered office at 128 City Road, London, United Kingdom, EC1V 2NX. In this policy, “we”, “us” and “our” mean Vantis Project Intelligence Ltd. We are the data controller for the limited personal data described below.
You can reach us at support@aimavera.com.
2. What we collect
Very little. Aimavera does not require an account, and we do not ask you to register, sign in, or provide a name, email address or payment details in order to use it.
We collect:
- Standard server logs. Our hosting provider records the requests made to aimavera.com, including IP address, timestamp, requested URL, referring page and browser user-agent string. These are used to keep the service running and to detect abuse.
We do not collect:
- Your schedule files or any data inside them
- Account details, because there are no accounts
- Payment information, because Aimavera is free to use
- Behavioural or advertising profiles
3. How your schedule data is processed
Your schedule file is never uploaded to our servers.
When you open an XER, MSPDI or PMXML file in Aimavera, that file is read and parsed entirely by JavaScript running in your own browser, on your own device. Critical path calculation, resource levelling, Monte Carlo simulation and DCMA 14-point checks all run locally. Files you export are generated in the browser and saved directly to your device.
At no point is the file, or any activity, resource, cost or logic data inside it, transmitted to Vantis Project Intelligence Ltd. We cannot see your schedules, recover them, or produce them in response to a third-party request, because we never hold them.
4. The AI assistant and your API key
Aimavera includes an optional AI assistant. It is off unless you choose to use it, and it is not required for any scheduling function.
To use it you supply your own API key for a model provider of your choosing — for example Anthropic, OpenAI or Google — or point Aimavera at a model running locally on your own machine.
- Your API key is stored in your browser's local storage on your own device. It is never transmitted to us and we never see it.
- Requests to the model provider are made directly from your browser to that provider. They do not pass through our servers.
- Whatever you send to the assistant is governed by the privacy policy and terms of the provider whose key you supplied. We are not a party to that exchange and have no visibility of it.
- You can remove your key at any time by clearing it in the application or clearing your browser's site data for aimavera.com.
We do not host, operate or provide any AI model.
5. Sub-processors
We use one sub-processor:
| Provider | Purpose | Location |
|---|---|---|
| Vercel Inc. | Hosting and delivery of the aimavera.com website and application | United States, with global edge delivery |
Where personal data in server logs is transferred outside the UK, that transfer is covered by appropriate safeguards, including the UK International Data Transfer Addendum to the EU Standard Contractual Clauses.
Model providers you connect to using your own API key are not our sub-processors. You contract with them directly.
6. Cookies and local storage
Aimavera sets no advertising or tracking cookies and uses no third-party analytics.
The application uses your browser's local storage to remember your own settings — for example your interface preferences and, if you have configured one, your model API key. This data stays on your device, is not readable by us, and is cleared when you clear site data for aimavera.com.
7. Legal bases for processing
For the limited personal data in server logs, our legal basis is our legitimate interest in operating, securing and maintaining the service (UK GDPR Article 6(1)(f)). We do not process special category data.
8. Retention and deletion
Server logs are retained by our hosting provider for a short operational period and then deleted. Because we hold no accounts and no schedule data, there is nothing further to retain, and nothing for us to delete on request.
Data held in your browser's local storage is under your control and is removed when you clear site data for aimavera.com.
9. Your rights
Under UK data protection law you have the right to access, correct, erase, or restrict processing of your personal data, to object to processing, and to data portability. Given how little we hold, most requests will be answered by confirming that we hold no personal data relating to you beyond transient server logs.
Write to support@aimavera.com. If you are not satisfied with our response, you may complain to the Information Commissioner's Office at ico.org.uk.
10. Security
Aimavera is served over HTTPS. Because schedule data never leaves your device, the largest category of risk in comparable tools — a breach of stored customer project data — does not apply here. Report a security concern to support@aimavera.com, or see our published policy at https://aimavera.com/.well-known/security.txt.
11. Changes
We will update this page if our practices change, and will revise the date at the top. Material changes will be noted on the site.