Legal
Privacy policy
What we collect, why we collect it, who sees it, and how to get it corrected or deleted.
1. What we collect
Account information: your name, email address and password (stored only as a secure hash).
Membership information: your plan, billing period and payment status. Card details are handled by our payment processor and never stored on our servers.
Learning data: lesson progress, quiz and assessment results, saved chart layouts, journal entries and notes you create.
Technical data: IP address, browser and device type, and pages visited, used to keep the service secure and working.
2. Why we collect it
To provide the service — tracking progress, unlocking stages, delivering alerts you have asked for, and processing your membership.
To support you when you contact us, and to investigate security or billing problems.
To improve the material, using aggregated patterns such as which lessons are commonly re-read. We do not sell personal information, ever.
3. AI features and your data
When you use an AI feature, the specific content needed for that request is sent to our AI provider to generate a response. Journal entries are sent only when you explicitly ask the journal coach to review them.
We do not send your payment details, password or account identifiers to AI providers.
4. Who we share it with
Service providers who help us operate: hosting, database, email delivery, payment processing and AI providers. Each is bound to use the information only to provide their service to us.
Law enforcement or regulators where we are legally required to do so.
Some providers store data outside Australia. We take reasonable steps to ensure overseas recipients handle your information consistently with the Australian Privacy Principles.
5. How long we keep it
Account and learning data is kept while your account is open and for a reasonable period afterwards so you can reactivate. Billing records are kept for the period required by Australian tax and financial services law.
You can request deletion of your account at any time; we will delete what we are not legally required to retain.
6. Security
Data is encrypted in transit and at rest, passwords are hashed, and access controls restrict who can see member data. No system is perfectly secure, and we will notify you and the OAIC of any eligible data breach as required by the Notifiable Data Breaches scheme.
7. Access, correction and complaints
You can access and correct most of your information from your account settings. For anything else, contact [Compliance contact email — to be supplied].
If you are not satisfied with how we have handled a privacy matter, you can complain to the Office of the Australian Information Commissioner.
8. Cookies
We use cookies necessary to keep you signed in and to remember preferences such as light or dark mode. We do not use advertising cookies or sell data to advertising networks.
This policy is a working draft prepared for a platform in development. Have it reviewed by an Australian legal practitioner before launch.