Privacy
What happens to what you upload.
GetScheduleFA prepares your Schedule FA from what you upload: your broker statements and tax documents. This page is the exact boundary — what that upload is used for, and what it is never used for.
Your documents
What happens to what you upload
Used solely to prepare your Schedule FA
The broker statements and tax documents you upload are used for exactly one purpose: preparing your Schedule FA CSV. Nothing you upload is used for any other purpose.
Retained until you delete
We keep your uploaded statements and your finished Schedule FA securely on our server in India so that next year's filing can start from what you've already given us.You stay in control: every delivered filing has a Delete button that permanently removes your documents and deliverables from our server immediately — or email us and we'll do it.Deleted files also age out of our encrypted backups within 7 days.If you upload documents but never complete a filing, we delete those uploads automatically after 180 days of inactivity.We never sell, share, or train AI models on your data.
Never sold, never shared, never used to train anything
Your statements, holdings, quantities, amounts and account numbers are never sold, shared with a third party, or used for any purpose beyond preparing the one filing you asked for.
Full disclosure
What we count
Beyond the documents you choose to upload, two things go out: anonymous usage counts to a first-party endpoint we run ourselves, and Google Analytics, which measures how people find the site.
Anonymous usage counts we collect ourselves
We count how the site is used, so we can fix what’s broken. The complete list: which page was viewed (from a fixed set of pages), and any campaign tags (utm_source, utm_medium, utm_campaign, utm_term, utm_content, gclid) that were in the link you clicked. The endpoint reads no IP address and no browser user-agent, and carries no visitor or session identifier — nothing links one visit to the next.
Google Analytics — which pages were visited, and its cookies
We use Google Analytics to learn how people find this site. It loads Google's measurement script and reports the page you are on, roughly where in the world you are, and what kind of device you are using — and it sets its own cookies (_ga and _ga_… ) to recognise a repeat visit. It never receives a document you upload, an account number, or anything from your Schedule FA: nothing in this app hands it any of those, and the browser's content-security policy allows Google exactly two things — to load that script and to receive its measurement pings. Advertising signals and ad personalisation are switched off, IP addresses are anonymised, and for visitors in the EEA, the UK and Switzerland analytics storage is denied by default, so no Google cookie is set there at all.
Identity
Signed in with Google, plus the cookies Google Analytics sets
- Signing in uses Google OAuth: we receive your Google account id, name and email address, and issue our own signed session cookie so you stay signed in for 7 days. We do not receive or store your Google password.
- Google Analytics sets its own measurement cookies (_ga and _ga_… ) so a repeat visit is not double-counted — except in the EEA, the UK and Switzerland, where it is configured to store nothing and set no cookie.
- If a campaign tag or referring site's domain (e.g. utm_source, gclid) was present when you first landed on the site and you go on to sign in during that same visit, we attach it to your new account — along with which page of our site you first landed on — so we know which channel brought you. This is stored once, on your account, and never re-derived or changed by a later sign-in. It never leaves your device unless you sign in, and only the referring domain is kept, never the page you came from.
- Our web server keeps standard access logs (IP address, timestamp, requested page) for security and reliability, as any web server does.
Contact
Questions or a data request
Read our security and data handling page for where data is stored, who can access it, and its lifecycle. Write to getschedulefa@gmail.com. GetScheduleFA is in founding beta; this policy will be expanded as the product grows — and if what the product does ever changes, this page changes first.
Last updated: 28 July 2026.