AUPYNETECHNO LEGAL
HomeProductWho It's ForPricingFAQSign up⬡ Portal
// Legal

Privacy Policy

AUPYNE PTY LTD · ABN 75 696 372 595 · Last updated May 2026

1. About this policy

This Privacy Policy explains how AUPYNE PTY LTD (ABN 75 696 372 595) ("AUPYNE", "we", "us", "our") collects, holds, uses, and discloses personal information in connection with the Hayley service and the aupyne.com.au website. We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

If you have questions about this policy or wish to exercise your privacy rights, contact us at hello@aupyne.com.au.

2. What personal information we collect

We collect the following categories of personal information:

Member account information

When you register for an account wth AUPYNE, we collect your name, email address, and professional role. This information is used to create and manage your account, provide the proofreading service, and communicate with you about your account.

Payment information

Payments are processed by Stripe Australia Pty Ltd. AUPYNE does not store credit card numbers, bank account details, or other payment credentials. We receive confirmation of successful payments and hold subscription status information. Stripe's privacy policy is available at stripe.com/au/privacy.

Uploaded report content

When you upload a forensic engineering or expert liability report for proofreading, the content of that report is transmitted to and processed by our service. Reports typically contain personal information about third parties (parties to proceedings, witnesses, occupants). The handling of this content is described in detail in section 6 (The Redaction Framework) below.

Usage data

We retain records of reports submitted, processing status, and Flesch–Kincaid readability scores. This data is used to provide the service and, in aggregated form, to improve it.

3. How we use your personal information

We use your personal information to:

  • Provide and improve the Hayley proofreading service
  • Manage your membership account and subscription
  • Send transactional communications — report receipts, feedback notifications, payment receipts, and password resets
  • Maintain your Flesch–Kincaid results log and make it accessible through your dashboard
  • Comply with our legal obligations

We do not use your personal information for direct marketing without your consent, and we do not sell your personal information to third parties.

4. Where your data is stored

We have designed our data infrastructure with Australian data residency as a priority.

Data typeServiceLocation
Member account dataSupabaseSydney, Australia (ap-southeast-2)
Uploaded files and feedback reportsSupabase StorageSydney, Australia (ap-southeast-2)
Authentication recordsSupabase AuthSydney, Australia (ap-southeast-2)
Payment recordsStripe Australia Pty LtdAustralia
Transactional email metadataResendUnited States (see section 5)
AI proofreading processingAnthropic APIUnited States (see section 5)

5. Cross-border disclosure

Two of our service providers are based in the United States. Under APP 8, before disclosing personal information to an overseas recipient, we must take reasonable steps to ensure the recipient will handle the information in a way that is consistent with the APPs.

Anthropic API (proofreading processing)

The proofreading analysis is performed by the Anthropic API, which is hosted in the United States. Before any document content is transmitted to the Anthropic API, it is processed through our redaction framework (described in section 6), which identifies and replaces personal information with consistent placeholders. The content transmitted to Anthropic for analysis is therefore substantially de-identified. Anthropic's privacy policy and data processing terms are available at anthropic.com.

We note that transmission to the Anthropic API is the one unavoidable element of our service that requires cross-border processing. The redaction framework is our primary mitigation for the privacy risk this creates.

Original report files are deleted from our servers immediately after your feedback report has been generated and saved. We do not retain your uploaded documents beyond the time required to process them. Only the feedback report and associated metadata (filename, submission date, processing status) are retained on our systems.

Resend (transactional email)

Transactional emails (report receipts, feedback notifications, password resets) are sent via Resend, which is based in the United States. Email metadata (recipient address, send timestamp, delivery status) is held by Resend. The content of our transactional emails does not include uploaded report content or personal information about third parties. Resend's privacy policy is available at resend.com/legal/privacy-policy.

6. The redaction framework

Before any uploaded report is analysed by the Anthropic API, our system applies a redaction step that identifies and replaces personal information with consistent placeholders.

Why redaction is performed

Redaction is performed not because transmission to the Anthropic API is insecure — it is encrypted in transit using HTTPS/TLS — but because reducing the volume and specificity of personal information transmitted to a third-party AI service is sound privacy practice. This approach is consistent with the data minimisation principle that underpins the APPs and modern privacy regulation generally.

What is replaced

ItemPlaceholder
Personal names (parties, witnesses, occupants)[PERSON_1], [PERSON_2], …
Dates of birth[DOB]
Incident / accident / loss dates[DATE_OF_INCIDENT]
All other specific dates[DATE_1], [DATE_2], …
Street and site addresses[ADDRESS_1], [ADDRESS_2], …
Phone numbers[PHONE]
Email addresses[EMAIL]
Policy, claim, Medicare, or TFN numbers[ID_NUMBER]

What is retained

The following are intentionally not redacted: the expert's own name (retained for the FK results log and professional identification); the "X v Y" case title (public record); matter and report reference numbers; company and organisation names; published case names; Australian Standards citations; and inspection, report, and letter dates (material to admissibility analysis).

Limitations of redaction

Redaction is best-effort, not a forensic guarantee. Users should be aware of the following limitations:

  • Name spelling variants are silently absorbed into placeholders. If a name is spelled inconsistently across the document, the inconsistency may not be detected. Users should verify name spelling manually before filing.
  • Incident date and address consistency can only be checked at the placeholder level. Discrepancies in how dates or addresses are stated across sections may not be detected.
  • Date-sequencing admissibility checks may be impaired where specific dates have been replaced with placeholders.
  • Redaction relies on contextual language analysis and is not guaranteed to be complete. Unusual names appearing only once, or names embedded in technical strings, may be missed.
  • The source document is never modified. Redaction applies only to the copy of the content processed for analysis.

7. Data retention

We retain your personal information for as long as your membership account is active and for a reasonable period afterwards to comply with our legal obligations, resolve disputes, and enforce our agreements.

  • Member account and profile information: retained while your account is active and for 7 years after closure.
  • Uploaded report files: deleted from Supabase Storage immediately after your feedback report has been generated and saved. We do not retain the original uploaded file beyond the time required to process it.
  • Feedback reports: retained in our database while your account is active. You may request deletion at any time.
  • FK results log: retained while your account is active and accessible through your dashboard.
  • Payment records: retained for 7 years for tax and accounting purposes.

8. Your rights

Under the Privacy Act 1988 (Cth), you have the right to:

  • Access the personal information we hold about you
  • Request correction of inaccurate, incomplete, or out-of-date personal information
  • Request deletion of your personal information (subject to our legal retention obligations)
  • Complain about a breach of the APPs

To exercise any of these rights, contact us at hello@aupyne.com.au. We will respond within 30 days.

9. Security

We take the following steps to protect your personal information:

  • Encryption in transit: all data transmitted between your browser and our servers uses HTTPS/TLS encryption.
  • Row-level security: our database is configured so that each member can only access their own data. Practice managers can access data for their practice. No member can access another practice's data.
  • No storage of payment credentials: we do not store credit card numbers or bank account details.
  • Access controls: access to production systems is restricted to authorised personnel.

No security system is impenetrable. If you believe your personal information has been compromised, contact us immediately at hello@aupyne.com.au.

10. Complaints

If you have a complaint about how we have handled your personal information, please contact us first at hello@aupyne.com.au. We will acknowledge your complaint within 5 business days and aim to resolve it within 30 days.

If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or by calling 1300 363 992.

11. Changes to this policy

We may update this policy from time to time. Material changes will be notified to members by email. The date at the top of this page reflects when the policy was last updated. Continued use of the service after a change constitutes acceptance of the updated policy.

// NOTE

This privacy policy has been prepared by AUPYNE PTY LTD and reflects our genuine approach to data handling. It has not been reviewed by a lawyer. Members who are legal professionals and wish to review the underlying technical architecture before using the service are welcome to contact us at hello@aupyne.com.au.

We are based in Naarm — Melbourne — on the Country of the Wurundjeri Woi Wurrung and Bunurong peoples of the Kulin Nation, whose deep stewardship of this land we gratefully acknowledge. We pay our respects to their Elders past, present, and emerging, and to all First Nations people across the Countries on which our users live and work.

AUPYNE Techno Legal Services
// www.aupyne.com.au
Privacy PolicyTerms of UseDisclaimerContact