AUPYNE PTY LTD · ABN 75 696 372 595 · Last updated May 2026
This Privacy Policy explains how AUPYNE PTY LTD (ABN 75 696 372 595) ("AUPYNE", "we", "us", "our") collects, holds, uses, and discloses personal information in connection with the Hayley service and the aupyne.com.au website. We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
If you have questions about this policy or wish to exercise your privacy rights, contact us at hello@aupyne.com.au.
We collect the following categories of personal information:
When you register for an account wth AUPYNE, we collect your name, email address, and professional role. This information is used to create and manage your account, provide the proofreading service, and communicate with you about your account.
Payments are processed by Stripe Australia Pty Ltd. AUPYNE does not store credit card numbers, bank account details, or other payment credentials. We receive confirmation of successful payments and hold subscription status information. Stripe's privacy policy is available at stripe.com/au/privacy.
When you upload a forensic engineering or expert liability report for proofreading, the content of that report is transmitted to and processed by our service. Reports typically contain personal information about third parties (parties to proceedings, witnesses, occupants). The handling of this content is described in detail in section 6 (The Redaction Framework) below.
We retain records of reports submitted, processing status, and Flesch–Kincaid readability scores. This data is used to provide the service and, in aggregated form, to improve it.
We use your personal information to:
We do not use your personal information for direct marketing without your consent, and we do not sell your personal information to third parties.
We have designed our data infrastructure with Australian data residency as a priority.
| Data type | Service | Location |
|---|---|---|
| Member account data | Supabase | Sydney, Australia (ap-southeast-2) |
| Uploaded files and feedback reports | Supabase Storage | Sydney, Australia (ap-southeast-2) |
| Authentication records | Supabase Auth | Sydney, Australia (ap-southeast-2) |
| Payment records | Stripe Australia Pty Ltd | Australia |
| Transactional email metadata | Resend | United States (see section 5) |
| AI proofreading processing | Anthropic API | United States (see section 5) |
Two of our service providers are based in the United States. Under APP 8, before disclosing personal information to an overseas recipient, we must take reasonable steps to ensure the recipient will handle the information in a way that is consistent with the APPs.
The proofreading analysis is performed by the Anthropic API, which is hosted in the United States. Before any document content is transmitted to the Anthropic API, it is processed through our redaction framework (described in section 6), which identifies and replaces personal information with consistent placeholders. The content transmitted to Anthropic for analysis is therefore substantially de-identified. Anthropic's privacy policy and data processing terms are available at anthropic.com.
We note that transmission to the Anthropic API is the one unavoidable element of our service that requires cross-border processing. The redaction framework is our primary mitigation for the privacy risk this creates.
Original report files are deleted from our servers immediately after your feedback report has been generated and saved. We do not retain your uploaded documents beyond the time required to process them. Only the feedback report and associated metadata (filename, submission date, processing status) are retained on our systems.
Transactional emails (report receipts, feedback notifications, password resets) are sent via Resend, which is based in the United States. Email metadata (recipient address, send timestamp, delivery status) is held by Resend. The content of our transactional emails does not include uploaded report content or personal information about third parties. Resend's privacy policy is available at resend.com/legal/privacy-policy.
Before any uploaded report is analysed by the Anthropic API, our system applies a redaction step that identifies and replaces personal information with consistent placeholders.
Redaction is performed not because transmission to the Anthropic API is insecure — it is encrypted in transit using HTTPS/TLS — but because reducing the volume and specificity of personal information transmitted to a third-party AI service is sound privacy practice. This approach is consistent with the data minimisation principle that underpins the APPs and modern privacy regulation generally.
| Item | Placeholder |
|---|---|
| Personal names (parties, witnesses, occupants) | [PERSON_1], [PERSON_2], … |
| Dates of birth | [DOB] |
| Incident / accident / loss dates | [DATE_OF_INCIDENT] |
| All other specific dates | [DATE_1], [DATE_2], … |
| Street and site addresses | [ADDRESS_1], [ADDRESS_2], … |
| Phone numbers | [PHONE] |
| Email addresses | [EMAIL] |
| Policy, claim, Medicare, or TFN numbers | [ID_NUMBER] |
The following are intentionally not redacted: the expert's own name (retained for the FK results log and professional identification); the "X v Y" case title (public record); matter and report reference numbers; company and organisation names; published case names; Australian Standards citations; and inspection, report, and letter dates (material to admissibility analysis).
Redaction is best-effort, not a forensic guarantee. Users should be aware of the following limitations:
We retain your personal information for as long as your membership account is active and for a reasonable period afterwards to comply with our legal obligations, resolve disputes, and enforce our agreements.
Under the Privacy Act 1988 (Cth), you have the right to:
To exercise any of these rights, contact us at hello@aupyne.com.au. We will respond within 30 days.
We take the following steps to protect your personal information:
No security system is impenetrable. If you believe your personal information has been compromised, contact us immediately at hello@aupyne.com.au.
If you have a complaint about how we have handled your personal information, please contact us first at hello@aupyne.com.au. We will acknowledge your complaint within 5 business days and aim to resolve it within 30 days.
If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or by calling 1300 363 992.
We may update this policy from time to time. Material changes will be notified to members by email. The date at the top of this page reflects when the policy was last updated. Continued use of the service after a change constitutes acceptance of the updated policy.
This privacy policy has been prepared by AUPYNE PTY LTD and reflects our genuine approach to data handling. It has not been reviewed by a lawyer. Members who are legal professionals and wish to review the underlying technical architecture before using the service are welcome to contact us at hello@aupyne.com.au.