Privacy Policy
Almost Useful Pty Ltd · Privacy Act 1988 (Cth) & Australian Privacy Principles · Effective 1 October 2026
This Privacy Policy explains how Almost Useful Pty Ltd (671 422 610) ('we', 'us', or 'our') collects, uses, discloses, stores, and protects personal information in accordance with the Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles (APPs) contained in Schedule 1 of that Act.
This Policy applies to all personal information we collect through our website at account.almostuseful.xyz, our products and services, and any other means by which you interact with us. By using our website or services, you acknowledge that you have read and understood this Privacy Policy.
1. About This Policy (APP 1)
1.1 We are committed to managing personal information in an open and transparent manner, as required by Australian Privacy Principle 1 (APP 1). This Privacy Policy is publicly available on our website and sets out how we manage personal information.
1.2 If you have any questions or concerns about how we handle your personal information, or if you wish to make a complaint, you may contact our Privacy Officer using the contact details set out in clause 11 of this Policy.
2. Personal Information We Collect (APP 3)
2.1 We collect only such personal information as is reasonably necessary for our functions and activities, in accordance with Australian Privacy Principle 3 (APP 3). The types of personal information we collect include: email address; display name; account sign-in credentials; information from your sign-in provider when you use social login (such as your name and a provider account identifier); subscription and purchase status; usage and billing information; identifiers and labels for devices you register; communication preferences; and technical information generated when you use the portal (such as IP address, browser type, and log data).
2.2 We collect personal information in the following ways: directly from you when you create an account, sign in, update your profile or communication preferences, contact us, or complete a purchase; automatically when you use the portal, including through session cookies and server logs; from the service providers we use to run the portal — our authentication and database provider (Supabase), payment provider (Stripe), subscription provider (RevenueCat), hosting provider (Vercel), email delivery provider (Resend), error-monitoring provider (Sentry), and AI routing provider (OpenRouter, which sends requests to model providers) — when you sign in, we send account emails, you checkout, subscription events are processed, an error is recorded, or you use an AI feature; and from connected applications when they report usage against your account.
2.3 Where it is reasonable and practicable to do so, we collect personal information directly from the individual concerned. Where we collect personal information about an individual from a third party, we will take reasonable steps to ensure the individual is aware that we have collected that information and the circumstances of collection.
2.4 You are not obliged to provide us with your personal information. However, if you choose not to provide certain information, we may not be able to provide you with some or all of our products and services.
2.5 Content you submit to AI features (such as text to polish or images of handwriting) is sent to our AI routing provider so it can generate a response. We do not store that content in our database, server logs, or error reports. We record only usage details needed to operate billing and the service, such as which app and feature were used, which model ran, the cost, and the time.
3. How We Use Your Personal Information (APP 5 & APP 6)
3.1 We use personal information for the following primary purposes: to create and manage your account; authenticate you; provide access to the digital products and subscriptions you purchase; process payments and manage billing; record and display usage; enforce product and seat limits; send service communications (such as account, security, and billing notices) and usage notifications you have opted into; send marketing communications only where you have opted in; operate, secure, and improve the portal; and comply with legal obligations.
3.2 We may also use your personal information for secondary purposes that are directly related to a primary purpose listed above and where you would reasonably expect us to use it for that secondary purpose, or where we have obtained your consent.
3.3 We will not use or disclose personal information collected for one purpose for another purpose (an unrelated secondary purpose) without your consent, unless otherwise required or authorised by law.
4. Disclosure of Personal Information (APP 6)
4.1 We may disclose your personal information to third parties in the following circumstances:
- to our employees, contractors, and related bodies corporate who require access to perform our functions and activities;
- to service providers engaged to assist us in providing our services, such as our authentication and database, payment, subscription, hosting, email delivery, error-monitoring, and AI routing providers, who are bound by confidentiality and data protection obligations;
- to government agencies, regulators, or law enforcement bodies where required or authorised by law;
- with your consent; or
- where permitted or required under the Privacy Act 1988 (Cth).
4.2 We require all third parties to whom we disclose personal information to protect that information in a manner consistent with this Privacy Policy and the Australian Privacy Principles.
5. Direct Marketing (APP 7)
5.1 We may use your personal information for direct marketing purposes, including sending you promotional materials, newsletters, and information about our products, services, and events, where you have consented to receive such communications or where permitted by applicable law.
5.2 You may opt out of receiving direct marketing communications from us at any time by clicking the unsubscribe link in any marketing email, contacting us using the details in clause 11 of this Policy, or by updating your communication preferences in your account settings.
5.3 We will honour opt-out requests as soon as practicable. We do not sell personal information to third parties for direct marketing purposes.
5.4 We comply with the Spam Act 2003 (Cth), which requires that commercial electronic messages are only sent with consent, include our identity and contact details, and contain a functional unsubscribe mechanism.
6. Cross-Border Disclosure (APP 8)
6.1 We may disclose personal information to recipients located outside Australia, including in the following countries: United States; Germany (error-monitoring events for our Sentry EU organisation).
6.2 Where we disclose personal information to overseas recipients, we take reasonable steps to ensure that those overseas recipients do not breach the Australian Privacy Principles in relation to that information, in accordance with APP 8.1. This may include entering into data processing agreements that require overseas recipients to comply with privacy standards equivalent to the APPs.
6.3 By providing us with your personal information, you consent to the disclosure of that information to overseas recipients in the countries identified above, subject to the protections described in this clause.
7. Cookies and Tracking Technologies
7.1 We use essential session cookies to keep you signed in. We do not use analytics, advertising, or behavioural tracking technologies on the portal. Our payment provider may use cookies when you complete checkout on their site.
7.2 Cookies are small text files placed on your device by your browser. You can control or delete cookies through your browser settings, but disabling essential cookies may prevent you from signing in to or using the portal.
8. Security of Personal Information (APP 11)
8.1 We take reasonable steps to protect the personal information we hold from misuse, interference, loss, and unauthorised access, modification, or disclosure, in accordance with Australian Privacy Principle 11 (APP 11). We use HTTPS for data in transit and restrict access to personal information. No security measure is perfect.
8.2 Despite our reasonable security measures, no data transmission over the internet or electronic storage system is entirely secure. We cannot guarantee the absolute security of personal information transmitted to or from us.
8.3 We retain personal information only for as long as necessary for the purposes for which it was collected, or as required by applicable law. We retain account and profile information while your account is active and for a reasonable period after closure. Subscription, entitlement, and usage records are retained while needed to provide the service, resolve disputes, and meet legal obligations. Financial and tax-related records are retained for at least 7 years where required by law. Server logs are retained for a limited period for security and troubleshooting, then deleted or de-identified. When personal information is no longer required, we will take reasonable steps to destroy or de-identify it.
8.4 In the event of a data breach that is likely to result in serious harm to any individual, we will comply with our obligations under the Notifiable Data Breaches (NDB) scheme in Part IIIC of the Privacy Act 1988 (Cth), including notifying affected individuals and the Office of the Australian Information Commissioner (OAIC) as required.
9. Access to Your Personal Information (APP 12)
9.1 Under Australian Privacy Principle 12 (APP 12), you have the right to access personal information we hold about you. To make an access request, please contact us using the details in clause 11 of this Policy.
9.2 We will respond to your access request within 30 days. In some circumstances, we may refuse access or limit the information we provide, for example where access would be unlawful, would prejudice an investigation or enforcement activity, or would unreasonably affect the privacy of other individuals. If we refuse or limit access, we will give you written notice explaining our reasons.
9.3 We do not generally charge a fee for making an access request. However, if responding to your request involves significant time and resources, we may charge a reasonable fee. We will inform you of any applicable fee before proceeding with your request.
10. Correction of Personal Information (APP 13)
10.1 Under Australian Privacy Principle 13 (APP 13), you have the right to request that we correct personal information we hold about you that you believe is inaccurate, out of date, incomplete, irrelevant, or misleading. To request a correction, please contact us using the details in clause 11.
10.2 We will consider your correction request and take reasonable steps to correct the information within 30 days. If we refuse to correct the information, we will give you written notice explaining our reasons and informing you that you may associate a statement with the information noting that you requested the correction.
11. Contact Us and Complaints Process
11.1 For any privacy enquiries, access or correction requests, or complaints about how we handle your personal information, please contact our Privacy Officer: Almost Useful Pty Ltd, 3 Valewood Dr, email: support@almostuseful.xyz.
11.2 We will acknowledge your complaint within 5 business days and aim to resolve it within 30 days. If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC): GPO Box 5218, Sydney NSW 2001; phone 1300 363 992; website www.oaic.gov.au.
11.3 The OAIC can investigate complaints and require us to take action to remedy any breach of the Australian Privacy Principles. Complaints to the OAIC are free of charge.
12. Applicability of the Privacy Act 1988 (Cth)
12.1 The Privacy Act 1988 (Cth) and the Australian Privacy Principles generally apply to organisations with an annual turnover of more than AUD $3 million, and to all Commonwealth agencies. Certain small businesses with an annual turnover of AUD $3 million or less are exempt from the Act unless they engage in specified activities (such as trading in personal information, operating a health service, or being a contracted service provider for a Commonwealth contract).
12.2 Even if an organisation is not legally required to comply with the Privacy Act 1988 (Cth), we voluntarily commit to complying with the Australian Privacy Principles as a matter of best practice and to build trust with our customers and users.
13. Changes to This Privacy Policy
13.1 We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or business operations. When we make material changes, we will notify you by posting the updated Privacy Policy on our website at account.almostuseful.xyz and updating the effective date at the top of this Policy.
13.2 We encourage you to review this Privacy Policy periodically. Your continued use of our website or services after the publication of any updated Privacy Policy constitutes your acceptance of the updated terms.