To give you complete peace of mind, here is exactly how our application handles data privacy, security, and governance when you interact with our AI features. Where the answer differs depending on which feature you're using, we've said so, rather than giving you one answer that's may not be relevant to your usage. Below are direct answers to the questions we're asked most.
Data lifecycle and retention
We keep your information for as long as it is actively serving you, and no longer than we need to.
Is my uploaded file kept in the system, or processed and discarded?
Where you upload something for a single, one-off request such as a photo used to inspire a lesson plan, the file is held in memory only for as long as the request takes, read once, and then discarded. It is never written to disk, never saved to your service's files, and cannot be retrieved afterwards by you, by us, or by anyone else.
Where you upload something as part of an ongoing piece of work, such as a document you attach to a conversation with the AI Mentor it is kept deliberately, so the conversation still makes sense when you come back to it, in the same way an attachment stays in an email thread. Anything stored this way sits in your own account. It is not visible to other members or to other services.
Can I delete my data, and does “delete” mean delete?
Yes, and we've built it so that deleting reaches everywhere the information went.
Deleting an AI Mentor conversation permanently removes the conversation, every message in it, and any file you attached to it. Those records are gone from our systems, not hidden or archived, and they are removed from every location they were held in.
Deleting a saved lesson plan removes it from your library and from every view in the app. The underlying record is marked as deleted rather than erased from the database, a standard approach that protects against accidental loss.
We keep two kinds of operational record that aren't part of your content. The first is a count of how much of the AI service has been used, for billing and fair-use purposes; it holds no part of what you wrote. The second is a record that a generation took place, including the details you submitted and the time, which we use to run the service and investigate misuse.
Third-party processing
We send our AI providers only what a request actually needs. They delete it within 30 days, and neither uses it to train their models.
What is sent to the AI provider, and what do they retain?
We use established AI providers under commercial agreements, and only send them what a request actually needs.
For the AI Mentor, that is the text of your conversation, any file you've attached to it, and the relevant passages from the National Quality Framework and ACECQA reference material we hold. Where your question requires it, the Mentor may look up your own service's documents and policies from your Desktop account and include the relevant extract in what it sends - that's how it can answer questions about your service specifically rather than in general terms.
For the lesson plan generator, that is the learning theme, the children's voices you entered, the age group, the framework you selected, any additional details you typed, and the photo where you used one. Your name, your service's name and your account details are not sent. Because the additional details box is free text, please don't type a child's full name or family details into it, the generator doesn't need them, and anything you type there forms part of what's sent.
Our AI providers are Anthropic and OpenAI, depending on the feature. Both delete the inputs and outputs of a request within 30 days. Neither uses content sent through their interfaces to train their models.
We won't tell you our providers retain nothing, because that isn't how these arrangements work. A short, defined retention window for abuse monitoring is the standard commercial position across the industry, and it's what applies to us.
What do you keep about my AI requests?
Usage counts and timing, which we need to meter and bill the service. We don't store the text of your questions or the answers you receive beyond your own conversation history, which you control and can delete.
Is my data used to train or improve AI models?
No. Your conversations, your uploaded files, your prompts and the results you receive are not used to train, fine-tune or improve any AI model; not ours, and not our providers'.
Data sovereignty
Your documents and your service's records stay in Australia. Only the text needed to answer an individual AI question travels overseas.
Where does my data sit geographically?
Your documents and your service's data are stored in Australia. The Desktop runs on Amazon Web Services in the Sydney region. Your policies, your uploaded documents, your service's records and your account data are all held there, on Australian soil, under Australian privacy law and the Australian Privacy Principles.
The AI Mentor's conversations and attachments are stored on Cloudflare's network in the Asia-Pacific region.
The AI models themselves run on our providers' infrastructure outside Australia. So when you ask an AI question, the text needed to answer that one question travels overseas, is answered, and comes back, subject to the 30-day retention described above. Your documents and your service's records are not copied or moved offshore, only the content of the individual request is sent.
A note on accountability
The National Quality Framework has no position on AI yet. We hold ourselves to the standard that applies to any external consultant: you remain the one who signs off.
There is currently no position on the use of AI within the National Quality Framework. NSW's regulatory authority has stated that where a service uses AI, the expectation is the same as when a service uses an external consultant: whatever you provide to the regulator must be accurate, current, understood, and reflected in actual practice at your service.
We think that's the right standard, and it's how we've built these features. Our AI does the reading, surfaces what's changed and drafts a starting point. You know your service, and you remain the one who signs off on what goes out.
If you have a question this page doesn't answer, please let us know.
Something here not clear?
If any part of this document is confusing, that is our problem to fix. Tell us which clause and we will rewrite it.