Oppermind Back

Privacy Policy

Last updated: 25 May 2026  |  Effective: 25 May 2026

Oppermind Pty Ltd (ABN 89 689 605 918) ("Oppermind", "we", "us", or "our") is committed to protecting your privacy and handling your personal information responsibly. This Privacy Policy explains how we collect, use, disclose, store, and protect your personal information when you use the Oppermind platform and services (the "Service"). We aim to handle personal information in accordance with applicable law.

Our identity: Oppermind Pty Ltd (ABN 89 689 605 918), operating from Perth, Western Australia, Australia. For inquiries, contact us at enquiry@oppermind.com.

1. Scope of This Policy

This Privacy Policy applies to all users of the Oppermind platform worldwide, including visitors to our website, registered users, and subscribers. It covers information collected through our web application, mobile interfaces, APIs, email integration features, autonomous agent features, and any other services provided by Oppermind.

This policy should be read in conjunction with our Terms and Conditions. Terms not defined in this policy have the meanings given to them in the Terms and Conditions.

2. Information We Collect

The categories of personal information we collect are enumerated in Sections 2.1–2.8 below. We do not collect categories beyond those enumerated without first updating this Privacy Policy and notifying you in accordance with Section 16 (Changes to This Privacy Policy). The specific items collected within each enumerated category, and whether they are collected at all in a given session, depend on which of the features listed in those sections you actually use.

2.1 Account Information

When you create an account, we collect registration information such as your name, email address, and password. Passwords are stored using industry-standard one-way cryptographic methods and are never stored in plaintext. You may optionally provide additional profile details.

2.2 User Content & Interactions

We collect and store content you create, submit, upload, or generate through the Service. This includes, without limitation, conversations, prompts, documents, files, media, projects, and any other data you provide or that is generated in connection with your use of any feature of the platform. We may collect metadata associated with your content, including timestamps, usage statistics, and performance data.

2.3 Service & Feature Data

When you use features of the Service (including but not limited to AI chat, productivity tools, email integration, device pairing, and agent features), we may collect data necessary to provide those features. This includes credentials you provide for third-party integrations (stored in encrypted form), connection and configuration data, and operational data generated during feature use.

2.4 Payment & Billing Data

Payment processing is handled by our third-party payment processor, Stripe, Inc. We store subscription identifiers and billing status information. We do not directly store your full credit card numbers, bank account details, or other sensitive payment instrument data. See Stripe's Privacy Policy for details on how payment data is handled.

2.5 Technical & Device Data

We automatically collect technical information when you access the Service, including IP address, browser and device information, operating system, session data, and similar technical identifiers. If you use device pairing or agent features, we may collect additional device-specific data necessary to provide those features.

2.6 Security & Compliance Data

To protect the safety and integrity of the Service and our users, we collect security-related data including authentication logs, threat detection data, content moderation records, and audit logs. This data is collected and retained as necessary for security, legal compliance, and enforcement of our Terms and Conditions.

2.7 Communications & Feedback

We collect information from communications you send to us, feedback you provide through the Service, and any other information you voluntarily submit.

2.8 Bot Prevention

We use third-party bot detection and abuse prevention services to protect the integrity of the Service. These services may collect device and application data for analysis in accordance with their own privacy policies.

2.9 Adding New Categories

Sections 2.1–2.8 constitute the complete current list of categories of personal information we collect. We will not begin collecting an additional category outside this list without first updating this Privacy Policy and notifying you via in-Service notice or email, in accordance with Section 16. Adding new optional features that collect data only within the existing categories does not require notification.

3. How We Use Your Information

3.1 Providing the Service

  • Process your AI requests through Oppermind's AI infrastructure and delivering responses
  • Store and retrieve your conversations, documents, and other content
  • Manage your account, authentication, and session security
  • Process payments and manage your subscription through Stripe
  • Provide email integration, agent, and productivity features
  • Provide relevant functionality based on your account settings and feature configurations

3.2 Safety & Security

  • Detect, prevent, and respond to fraud, abuse, and security threats
  • Moderate content to enforce our Acceptable Use Policy and prevent harmful outputs
  • Monitor for unauthorised access, data breaches, and suspicious activity
  • Enforce rate limits and prevent automated abuse
  • Maintain audit logs for security investigations

3.3 Service Improvement

  • Analyse aggregated usage patterns to improve features and user experience
  • Identify and fix technical issues and bugs
  • Perform analytics and generate internal reports on service performance
  • Develop new features and capabilities based on usage trends

3.4 Automated Analysis

We may use automated systems to analyse content processed through the Service for various purposes, including safety, content moderation, service improvement, and analytics. This processing is performed in accordance with our Terms and Conditions.

3.5 Communications

  • Send essential service notifications (account verification, password resets, payment confirmations and failures, security alerts)
  • Notify you of material changes to our Terms, Privacy Policy, or Service

We do not send marketing emails without your explicit opt-in consent, in compliance with the Spam Act 2003 (Cth) and applicable anti-spam legislation.

3.6 Legal Compliance

  • Comply with applicable laws, regulations, and legal processes
  • Respond to lawful requests from law enforcement and government authorities
  • Protect our legal rights and enforce our Terms and Conditions

4. Legal Bases for Processing (GDPR)

If you are located in the European Union, EEA, or United Kingdom, we process your personal data on the following legal bases:

Purpose Legal Basis
Providing the Service, managing your account, processing payments Performance of contract (Art. 6(1)(b) GDPR)
Safety, security, content moderation, fraud prevention Legitimate interest (Art. 6(1)(f) GDPR)
Service improvement and analytics (aggregated data) Legitimate interest (Art. 6(1)(f) GDPR)
Compliance with legal obligations Legal obligation (Art. 6(1)(c) GDPR)
Automated analysis and service improvement Legitimate interest (Art. 6(1)(f) GDPR); you may object under Art. 21
Marketing communications (if applicable) Consent (Art. 6(1)(a) GDPR)
Bot detection and abuse prevention Legitimate interest (Art. 6(1)(f) GDPR)

For Australian users, the relevant legal framework is the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). We collect and handle personal information in accordance with APP 3 (collection), APP 5 (notification), APP 6 (use and disclosure), and the other APPs as applicable.

5. Who We Share Your Data With

We do not sell or share your personal information as those terms are defined under applicable privacy law, including the CCPA/CPRA.

5.1 AI Service Providers

When you use AI features, your input data (prompts, queries, conversation context, and uploaded content) may be processed by third-party service providers acting as data processors on Oppermind's behalf. These providers are contractually bound to process data only in accordance with our instructions and to maintain appropriate security measures. We transmit only the data necessary for processing your AI request (your current prompt and relevant conversation context). The identity of our AI service providers is proprietary and confidential, and may change from time to time as we optimise the Service.

5.2 Payment Processor

  • Stripe, Inc.: Processes subscription payments. Stripe receives your payment method details, billing information, and transaction data. See Stripe's Privacy Policy.

5.3 Cloud Infrastructure

Our Service is hosted on cloud infrastructure providers. Your data is stored and processed on servers operated by these providers, who act as data processors under contractual obligations to protect your data.

5.4 Bot Detection Services

We use third-party bot detection services to protect the Service from automated abuse. This may involve transmitting certain technical data to the service provider for analysis, in accordance with their privacy policies.

5.5 Email Service Providers

When you use email integration features, your email data is transmitted to and from your chosen email provider using standard email protocols. This connection is made on your behalf and subject to the terms and policies of your email provider.

5.6 Legal & Safety Disclosures

We may disclose your personal information if we believe in good faith that such disclosure is necessary to:

  • Comply with applicable law, regulation, legal process, or enforceable governmental request;
  • Enforce our Terms and Conditions;
  • Detect, prevent, or address fraud, security issues, or technical problems;
  • Protect the rights, property, or safety of Oppermind, our users, or the public, as required or permitted by law.

5.7 Business Transfers

In the event of a merger, acquisition, reorganisation, bankruptcy, or sale of all or a portion of our assets, your personal information may be transferred as part of that transaction. We will provide notice of any such transfer and any choices you may have regarding your information.

5.8 Aggregated & De-identified Data

We may share aggregated or de-identified data that cannot reasonably be used to identify you. Such data is not subject to the restrictions of this Privacy Policy.

6. International Data Transfers

6.1 Cross-Border Processing

Oppermind operates from Australia, and our cloud infrastructure and third-party service providers may process your data in various countries, including Australia, the United States, and other jurisdictions where our providers operate. By using the Service, you acknowledge that your data may be transferred to and processed in countries outside your country of residence.

6.2 Australian Privacy Act (APP 8)

In accordance with Australian Privacy Principle 8, before disclosing personal information to an overseas recipient, we take reasonable steps to ensure that the overseas recipient does not breach the APPs in relation to that information. These steps include contractual obligations, data processing agreements, and due diligence on the privacy and security practices of our service providers.

6.3 GDPR Transfers (EU/EEA/UK Users)

For transfers of personal data from the EU, EEA, or UK to countries that have not received an adequacy decision from the European Commission, we rely on appropriate safeguards, including Standard Contractual Clauses (SCCs) approved by the European Commission, supplemented by additional technical and organisational measures where necessary.

6.4 Safeguards

Regardless of where your data is processed, we apply consistent security protections, including encryption in transit and at rest, access controls, and contractual data protection obligations on all service providers.

6.5 Data Processing Addendum

If you are located in the European Union, European Economic Area, or the United Kingdom, the Oppermind Data Processing Addendum ("DPA") automatically applies to all processing of your personal data and is incorporated by reference into these Terms and this Privacy Policy. The DPA includes the Standard Contractual Clauses (SCCs) approved by the European Commission as an annex. By creating an account or using the Service, you accept and agree to the DPA as a condition of use. If you do not accept the DPA, you may not use the Service. A copy of the DPA is available at oppermind.com/dpa or by contacting enquiry@oppermind.com.

For users in other jurisdictions subject to data protection laws that require formal data processing arrangements, the DPA also applies and is incorporated by reference on the same terms.

7. Data Retention

7.1 Retention Principles

We retain personal information for as long as reasonably necessary to fulfil the purposes for which it was collected, including to satisfy legal, regulatory, accounting, or reporting requirements. The retention period for any particular category of data depends on the nature and sensitivity of the data, the purposes for which it is processed, and applicable legal requirements.

Category Retention period
Account data (name, email, profile, preferences) For the life of your account, deleted within 30 days of account closure (subject to legal holds in Section 7.3)
Conversations and prompts For the life of your account, deleted within 30 days of account closure or sooner if you delete the conversation yourself
Uploaded attachments and generated artifacts (documents, images, video) For the life of your account, deleted within 30 days of account closure or sooner if you delete the file yourself
Security and threat-detection records (auto-blocked IPs, attempted exploits, canary alerts, content moderation records) 12 months, after which they are de-identified or deleted in accordance with Australian Privacy Principle 11.2
Error reports and application logs 90 days (rolling window), then deleted
Authentication and session logs (login, logout, session_id) 12 months, then deleted
Billing and financial records (invoices, subscription history) 7 years (Australian tax / record-keeping minimum under the Income Tax Assessment Act 1997 and Corporations Act 2001)
Marketing and analytics events (only if you opted in to analytics cookies) 26 months (Google Analytics default), then aggregated or deleted
Aggregated / de-identified data that cannot reasonably re-identify you May be retained indefinitely for service improvement and reporting

In general:

  • Account-related data is retained while your account is active and for a reasonable period thereafter;
  • Financial and billing records are retained as required by applicable tax and financial reporting laws;
  • Security and operational logs are retained for the period necessary to fulfil their security and compliance purposes;
  • Data associated with terminated features or disconnected integrations is removed within a reasonable period.

7.2 Post-Deletion

Upon account deletion, we will take commercially reasonable steps to delete or de-identify your personal data from production systems within a reasonable period. Anonymised or aggregated data that cannot reasonably be used to identify you may be retained indefinitely for analytics and service improvement purposes.

7.3 Legal Holds

We may retain personal data beyond any stated or typical retention periods where required or permitted by applicable law, regulation, or legal proceedings, or for the establishment, exercise, or defence of legal claims.

8. Data Security

8.1 Security Measures

We implement and maintain appropriate technical and organisational security measures designed to protect personal information against unauthorised access, alteration, disclosure, or destruction. These measures are commensurate with the nature and sensitivity of the data we process and are regularly reviewed and updated. The specific nature and details of our security implementations are proprietary and confidential.

8.2 Security Limitations

No method of transmission over the Internet or method of electronic storage is completely secure. While we strive to use commercially acceptable means to protect your personal information, we cannot guarantee its absolute security. You acknowledge and accept the inherent risks of transmitting data over the Internet. In the event of a data breach, we will comply with our notification obligations under applicable law (see Section 12).

9. Your Privacy Rights

Depending on your location, you have certain rights regarding your personal information. We are committed to honouring these rights in accordance with applicable law.

9.1 Rights for All Users

  • Access: You may request a copy of the personal information we hold about you.
  • Correction: You may update or correct your personal information through your account settings or by contacting us.
  • Deletion: You may request deletion of your account and associated personal data. We will comply within a reasonable period, subject to legal retention requirements and applicable law.
  • Data Export: You may request a portable copy of your data.
  • Withdraw Consent: Where processing is based on consent, you may withdraw consent at any time without affecting the lawfulness of processing carried out prior to withdrawal.
  • Opt-Out of Non-Essential Processing: You may request to opt out of non-essential automated analysis features where applicable.

9.2 Additional Rights for Australian Users (Privacy Act 1988)

  • Access (APP 12): You have the right to request access to your personal information held by us.
  • Correction (APP 13): You have the right to request correction of inaccurate, out-of-date, incomplete, irrelevant, or misleading personal information.
  • Complaint: You have the right to lodge a complaint with us about our handling of your personal information. If unsatisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.

9.3 Additional Rights for EU/EEA/UK Users (GDPR)

  • Right of access (Art. 15): Obtain confirmation and a copy of your personal data.
  • Right to rectification (Art. 16): Correct inaccurate personal data.
  • Right to erasure (Art. 17): Request deletion of your personal data ("right to be forgotten").
  • Right to restriction (Art. 18): Restrict processing in certain circumstances.
  • Right to data portability (Art. 20): Receive your data in a structured, commonly used, machine-readable format.
  • Right to object (Art. 21): Object to processing based on legitimate interests, including automated analysis and profiling.
  • Automated decision-making (Art. 22): Our content moderation system uses automated processing. You have the right to request human review of automated decisions that significantly affect you.
  • Complaint: You have the right to lodge a complaint with your local data protection supervisory authority.

9.4 Additional Rights for California Residents (CCPA/CPRA)

  • Right to know: You have the right to request information about the categories and specific pieces of personal information we collect, use, and disclose.
  • Right to delete: You may request that we delete your personal information, subject to certain exceptions.
  • Right to correct: You may request correction of inaccurate personal information.
  • Right to opt-out of sale/sharing: We do not sell or share your personal information. No opt-out is necessary.
  • Right to non-discrimination: We will not discriminate against you for exercising your CCPA rights.
  • Authorised agent: You may designate an authorised agent to submit requests on your behalf.

9.5 Exercising Your Rights

To exercise any of these rights, contact us at enquiry@oppermind.com. We will respond to verified requests within the timeframes required by applicable law. We may need to verify your identity before fulfilling your request.

10. Cookies & Browser Storage

10.1 What We Use

Oppermind primarily uses browser local storage and session storage rather than traditional cookies. We use these technologies for:

  • Authentication: Storing your session token to maintain your login session
  • Preferences: Storing your theme, display settings, and workspace configuration
  • User data: Caching your basic profile information (name, email, user ID) for the user interface

10.2 Authentication Cookies

In production environments, we may set HTTP-only cookies containing your authentication token for enhanced security. These are strictly necessary cookies required for the Service to function.

10.3 Third-Party Technologies

Third-party services used by the platform (such as bot detection services) may set cookies or use similar technologies as part of their functionality. These are governed by the respective service provider's privacy and cookie policies.

10.4 No Third-Party Tracking

We do not use third-party advertising cookies, tracking pixels, or analytics cookies that track you across other websites. We do not participate in cross-site advertising networks.

10.5 Managing Browser Storage

You can clear browser local storage and cookies through your browser settings. Note that clearing authentication data will log you out of the Service.

11. Children's Privacy

The Service is for adults aged 18 years and over. The Service is not directed at, designed for, or made available to anyone under 18. We do not knowingly collect, use, or store personal information from any person under 18. If you are under 18, please do not create an account, sign in, upload anything, or otherwise use the Service.

There is no parental-consent pathway into the Service. The 18+ rule is platform-wide: we do not operate any tiered access, age-graded experience, or graduated feature set for users under 18. This position is recorded in Section 1.3 of our Terms & Conditions and is explained in greater detail in our Children's Privacy Policy.

If we learn that we have collected personal information from a person under 18, we will suspend the relevant account and delete the information from our production systems within a reasonable period, subject only to legal retention requirements (for example, where we are required to preserve and report material relating to suspected child sexual abuse, exploitation, or other serious criminal conduct). The full discovery and deletion process is set out in Section 7 of the Children's Privacy Policy.

If you are a parent or legal guardian and you believe a person under 18 has provided us with personal information, please contact us as soon as practicable at enquiry@oppermind.com with the subject line "Under-18 Use Report" so we can apply the discovery process. We comply with applicable child privacy protection laws in the jurisdictions where we operate, including (without limitation) the Children's Online Privacy Protection Act (COPPA) in the United States, Article 8 of the EU/UK GDPR, the UK Age Appropriate Design Code, Quebec Law 25, the relevant US state child-privacy laws, the Australian Privacy Principles under the Privacy Act 1988 (Cth), and the Online Safety Act 2021 (Cth).

12. Data Breach Notification

In the event of a data breach involving personal information, we will comply with all applicable breach notification laws and regulations, including the Notifiable Data Breaches scheme under Part IIIC of the Privacy Act 1988 (Cth) and, where applicable, the GDPR's breach notification requirements. Notifications will be provided to the relevant authorities and affected individuals within the timeframes required by applicable law.

13. AI Data Processing

13.1 How AI Features Process Your Data

When you use AI features on Oppermind, your data is processed by Oppermind's AI infrastructure, which may include third-party service providers acting as data processors on our behalf. These providers are bound by contractual obligations to process data solely in accordance with our instructions and to maintain appropriate technical and organisational security measures.

13.2 Data Used for AI Processing

When you use AI features, the data you submit or make available through the Service (including prompts, queries, conversation context, uploaded content, and any other data you direct the Service to process) may be transmitted to AI processing infrastructure. The scope of data processed depends on the features you use and the instructions you provide to the Service.

13.3 Proprietary Technology

The specific AI models, providers, and technologies used by Oppermind are proprietary and confidential. We may change, update, or replace AI service providers and models at any time to improve the quality, safety, and performance of the Service. All AI service providers engaged by Oppermind are subject to data processing agreements that require compliance with applicable privacy and data protection laws.

13.4 Other Third-Party Services

We may also transmit limited data to the following types of services to provide platform features:

  • Weather services: City name queries for weather information (no personal data transmitted)
  • Search services: Search queries for web search features (no personal data transmitted)

14. Internal Data Use

In order to operate, secure, and improve the Service, Oppermind may process user data internally as necessary for the purposes described in this Privacy Policy and our Terms and Conditions. Such processing is conducted in accordance with applicable data protection laws and is limited to what is reasonably necessary for the stated purposes, including service delivery, safety, legal compliance, and enforcement of our Terms. Access to user data within Oppermind is subject to appropriate internal controls and safeguards.

15. "Do Not Track" & Global Privacy Controls

We do not track users across third-party websites and therefore do not respond to "Do Not Track" (DNT) browser signals. As we do not sell or share personal information for cross-context behavioural advertising, Global Privacy Control (GPC) signals do not apply; however, we respect such signals as a general expression of privacy preference.

16. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our data practices, technology, legal requirements, or business operations. We will make reasonable efforts to notify you of material changes via email or a prominent notice within the Service. The "Last updated" date at the top of this policy indicates the date of the most recent revision. Your continued use of the Service after any changes to this Privacy Policy constitutes your acceptance of the updated Privacy Policy. We encourage you to review this policy periodically.

17. Contact Us & Complaints

17.1 General Inquiries

For any questions or concerns about this Privacy Policy or our data practices, please contact us:

  • Email: enquiry@oppermind.com
  • Location: Perth, Western Australia, Australia

17.2 Privacy Complaints

If you have a complaint about how we handle your personal information, please contact us first at the address above. We will investigate your complaint and endeavour to respond within a reasonable timeframe.

17.3 External Complaint Bodies

If you are not satisfied with our response, you may lodge a complaint with the relevant regulatory authority:

  • Australia: Office of the Australian Information Commissioner (OAIC) — www.oaic.gov.au
  • Western Australia: WA Department of Mines, Industry Regulation and Safety (Consumer Protection) — www.commerce.wa.gov.au
  • European Union: Your local data protection supervisory authority (a list is available at edpb.europa.eu)
  • United Kingdom: Information Commissioner's Office (ICO) — ico.org.uk
  • California, USA: California Privacy Protection Agency (CPPA) — cppa.ca.gov

© 2026 Oppermind Pty Ltd. All rights reserved.
Terms Privacy AUP DPA Cookies Refunds Accessibility Children's Privacy Withdraw consent