Attendly Privacy Policy

Last updated: 4 August 2026

Attendly is a workforce management app for employers. It records attendance, leave, expenses and payroll for staff of the organisation that issued your account. This policy explains what the app collects, why, who can see it, and how to get it removed.

The short version. Attendly collects your work identity, your attendance punches and their location, and the expense files you attach. It does not sell your data, show advertising, or contain any tracking or analytics SDKs. Face verification runs entirely on your device and no faceprint is ever created or uploaded. Location is read only while the app is open on screen.

1. Who is responsible for your data

Two parties are involved, and the difference matters for your rights:

2. What the app collects

DataWhyWhere it goes
Name, work email address, optional mobile number, employee ID, job role, team and organisation To create your account and apply the right permissions Google Firebase (Authentication and Cloud Firestore)
Your password To sign you in Handled entirely by Google Firebase Authentication. It is never visible to us or to your employer.
Attendance punches: date and time, check-in method, and the approximate or precise location at the moment you punch To confirm you were at a work site when you clocked in or out Google Cloud Firestore
A photo of your face, if your employer enables face attendance To confirm a real person is present at the moment of the punch The check runs entirely on your device. See section 4.
Files you attach: expense receipts and documents To support expense claims and record-keeping Uploaded to your employer's own web hosting at office.nextolive.com
Leave requests, expense claims, tasks, salary structure and payslips The core record-keeping the app exists to do Google Cloud Firestore
A push notification token for your device To send you approval and reminder notifications Google Firebase Cloud Messaging

What the app does not do: there are no advertising identifiers, no advertising networks, no third-party analytics or tracking SDKs, and no sale or sharing of your data with data brokers.

3. Location

Attendly requests location access so it can attach a position to an attendance punch and show live team locations to your manager.

Location is only read while the app is open on screen. The app does not request background location permission and cannot follow you when it is closed or running in the background. If you decline the location permission you can still use the app, but punches your employer has configured to require a location may be rejected.

4. Face attendance and biometrics

If your employer turns on face attendance, the camera opens when you punch and the app checks that a real, well-lit, centred, blinking person is in frame.

This check runs on your device using Google ML Kit's on-device face detection. Specifically:

5. Camera, photos and storage

The camera permission is used for face attendance and for photographing receipts. Photo access is used only to let you pick an existing receipt or document to attach. Receipt text is read on your device; a receipt image is uploaded only when you attach it to a claim.

6. Who can see your data

We may also disclose data where we are legally required to do so.

7. How long it is kept

Attendance, leave, expense and payroll records are kept for as long as your employer needs them for employment and statutory record-keeping, and are deleted or anonymised on their instruction. Your employer sets that period, because the records belong to them and the retention obligations fall on them.

If your employer closes their Attendly account, their organisation's data is deleted within 90 days.

8. Your rights

Depending on where you live, you may have the right to access, correct, export, restrict or delete your personal data, and to object to certain processing. Because your employer controls these records, please contact your organisation's administrator first.

If you cannot reach them, or you want to raise a concern about how we handle data as a processor, email anwaraftab121@gmail.com from the address registered on your account. We respond within 30 days.

9. Deleting your account

You can ask for your account and its data to be deleted at any time by emailing anwaraftab121@gmail.com with the subject Delete my account, from the address registered on your Attendly account. Include your full name and your organisation's name so we can identify the right record.

Deleting your account removes your sign-in credentials, your profile and your device's push notification token. Attendance, leave, approved expense claims and payroll records belong to your employer and are retained under section 7 above; requests to remove those must go to your employer, who decides them.

10. Security

Traffic between the app and our services is encrypted in transit with HTTPS, and the app refuses unencrypted connections. Access to organisation records is enforced by server-side security rules tied to your signed-in account and role. Your device may additionally require your fingerprint or face to unlock the app. No system is perfectly secure, but we work to protect data against unauthorised access, alteration and loss.

11. Children

Attendly is a workplace tool for employees. It is not directed at children and we do not knowingly collect data from anyone under 16.

12. Changes to this policy

If we change this policy we will update the date at the top of this page and, for significant changes, notify organisation administrators.

13. Contact

Questions about this policy or about your data: anwaraftab121@gmail.com