Oppermind Pty Ltd (ABN 89 689 605 918) ("Oppermind", "we", "us", or "our") is committed to protecting your privacy and handling your personal information responsibly. This Privacy Policy explains how we collect, use, disclose, store, and protect your personal information when you use the Oppermind platform and services (the "Service"). We aim to handle personal information in accordance with applicable law.
Our identity: Oppermind Pty Ltd (ABN 89 689 605 918), operating from Perth, Western Australia, Australia. For inquiries, contact us at enquiry@oppermind.com.
This Privacy Policy applies to all users of the Oppermind platform worldwide, including visitors to our website, registered users, and subscribers. It covers information collected through our web application, mobile interfaces, APIs, email integration features, autonomous agent features, and any other services provided by Oppermind.
This policy should be read in conjunction with our Terms and Conditions. Terms not defined in this policy have the meanings given to them in the Terms and Conditions.
The categories of personal information we collect are enumerated in Sections 2.1–2.8 below. We do not collect categories beyond those enumerated without first updating this Privacy Policy and notifying you in accordance with Section 16 (Changes to This Privacy Policy). The specific items collected within each enumerated category, and whether they are collected at all in a given session, depend on which of the features listed in those sections you actually use.
When you create an account, we collect registration information such as your name, email address, and password. Passwords are stored using industry-standard one-way cryptographic methods and are never stored in plaintext. You may optionally provide additional profile details.
We collect and store content you create, submit, upload, or generate through the Service. This includes, without limitation, conversations, prompts, documents, files, media, projects, and any other data you provide or that is generated in connection with your use of any feature of the platform. We may collect metadata associated with your content, including timestamps, usage statistics, and performance data.
When you use features of the Service (including but not limited to AI chat, productivity tools, email integration, device pairing, and agent features), we may collect data necessary to provide those features. This includes credentials you provide for third-party integrations (stored in encrypted form), connection and configuration data, and operational data generated during feature use.
Payment processing is handled by our third-party payment processor, Stripe, Inc. We store subscription identifiers and billing status information. We do not directly store your full credit card numbers, bank account details, or other sensitive payment instrument data. See Stripe's Privacy Policy for details on how payment data is handled.
We automatically collect technical information when you access the Service, including IP address, browser and device information, operating system, session data, and similar technical identifiers. If you use device pairing or agent features, we may collect additional device-specific data necessary to provide those features.
To protect the safety and integrity of the Service and our users, we collect security-related data including authentication logs, threat detection data, content moderation records, and audit logs. This data is collected and retained as necessary for security, legal compliance, and enforcement of our Terms and Conditions.
We collect information from communications you send to us, feedback you provide through the Service, and any other information you voluntarily submit.
We use third-party bot detection and abuse prevention services to protect the integrity of the Service. These services may collect device and application data for analysis in accordance with their own privacy policies.
Sections 2.1–2.8 constitute the complete current list of categories of personal information we collect. We will not begin collecting an additional category outside this list without first updating this Privacy Policy and notifying you via in-Service notice or email, in accordance with Section 16. Adding new optional features that collect data only within the existing categories does not require notification.
We may use automated systems to analyse content processed through the Service for various purposes, including safety, content moderation, service improvement, and analytics. This processing is performed in accordance with our Terms and Conditions.
We do not send marketing emails without your explicit opt-in consent, in compliance with the Spam Act 2003 (Cth) and applicable anti-spam legislation.
If you are located in the European Union, EEA, or United Kingdom, we process your personal data on the following legal bases:
| Purpose | Legal Basis |
|---|---|
| Providing the Service, managing your account, processing payments | Performance of contract (Art. 6(1)(b) GDPR) |
| Safety, security, content moderation, fraud prevention | Legitimate interest (Art. 6(1)(f) GDPR) |
| Service improvement and analytics (aggregated data) | Legitimate interest (Art. 6(1)(f) GDPR) |
| Compliance with legal obligations | Legal obligation (Art. 6(1)(c) GDPR) |
| Automated analysis and service improvement | Legitimate interest (Art. 6(1)(f) GDPR); you may object under Art. 21 |
| Marketing communications (if applicable) | Consent (Art. 6(1)(a) GDPR) |
| Bot detection and abuse prevention | Legitimate interest (Art. 6(1)(f) GDPR) |
For Australian users, the relevant legal framework is the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). We collect and handle personal information in accordance with APP 3 (collection), APP 5 (notification), APP 6 (use and disclosure), and the other APPs as applicable.
We do not sell or share your personal information as those terms are defined under applicable privacy law, including the CCPA/CPRA.
When you use AI features, your input data (prompts, queries, conversation context, and uploaded content) may be processed by third-party service providers acting as data processors on Oppermind's behalf. These providers are contractually bound to process data only in accordance with our instructions and to maintain appropriate security measures. We transmit only the data necessary for processing your AI request (your current prompt and relevant conversation context). The identity of our AI service providers is proprietary and confidential, and may change from time to time as we optimise the Service.
Our Service is hosted on cloud infrastructure providers. Your data is stored and processed on servers operated by these providers, who act as data processors under contractual obligations to protect your data.
We use third-party bot detection services to protect the Service from automated abuse. This may involve transmitting certain technical data to the service provider for analysis, in accordance with their privacy policies.
When you use email integration features, your email data is transmitted to and from your chosen email provider using standard email protocols. This connection is made on your behalf and subject to the terms and policies of your email provider.
We may disclose your personal information if we believe in good faith that such disclosure is necessary to:
In the event of a merger, acquisition, reorganisation, bankruptcy, or sale of all or a portion of our assets, your personal information may be transferred as part of that transaction. We will provide notice of any such transfer and any choices you may have regarding your information.
We may share aggregated or de-identified data that cannot reasonably be used to identify you. Such data is not subject to the restrictions of this Privacy Policy.
Oppermind operates from Australia, and our cloud infrastructure and third-party service providers may process your data in various countries, including Australia, the United States, and other jurisdictions where our providers operate. By using the Service, you acknowledge that your data may be transferred to and processed in countries outside your country of residence.
In accordance with Australian Privacy Principle 8, before disclosing personal information to an overseas recipient, we take reasonable steps to ensure that the overseas recipient does not breach the APPs in relation to that information. These steps include contractual obligations, data processing agreements, and due diligence on the privacy and security practices of our service providers.
For transfers of personal data from the EU, EEA, or UK to countries that have not received an adequacy decision from the European Commission, we rely on appropriate safeguards, including Standard Contractual Clauses (SCCs) approved by the European Commission, supplemented by additional technical and organisational measures where necessary.
Regardless of where your data is processed, we apply consistent security protections, including encryption in transit and at rest, access controls, and contractual data protection obligations on all service providers.
If you are located in the European Union, European Economic Area, or the United Kingdom, the Oppermind Data Processing Addendum ("DPA") automatically applies to all processing of your personal data and is incorporated by reference into these Terms and this Privacy Policy. The DPA includes the Standard Contractual Clauses (SCCs) approved by the European Commission as an annex. By creating an account or using the Service, you accept and agree to the DPA as a condition of use. If you do not accept the DPA, you may not use the Service. A copy of the DPA is available at oppermind.com/dpa or by contacting enquiry@oppermind.com.
For users in other jurisdictions subject to data protection laws that require formal data processing arrangements, the DPA also applies and is incorporated by reference on the same terms.
We retain personal information for as long as reasonably necessary to fulfil the purposes for which it was collected, including to satisfy legal, regulatory, accounting, or reporting requirements. The retention period for any particular category of data depends on the nature and sensitivity of the data, the purposes for which it is processed, and applicable legal requirements.
| Category | Retention period |
|---|---|
| Account data (name, email, profile, preferences) | For the life of your account, deleted within 30 days of account closure (subject to legal holds in Section 7.3) |
| Conversations and prompts | For the life of your account, deleted within 30 days of account closure or sooner if you delete the conversation yourself |
| Uploaded attachments and generated artifacts (documents, images, video) | For the life of your account, deleted within 30 days of account closure or sooner if you delete the file yourself |
| Security and threat-detection records (auto-blocked IPs, attempted exploits, canary alerts, content moderation records) | 12 months, after which they are de-identified or deleted in accordance with Australian Privacy Principle 11.2 |
| Error reports and application logs | 90 days (rolling window), then deleted |
| Authentication and session logs (login, logout, session_id) | 12 months, then deleted |
| Billing and financial records (invoices, subscription history) | 7 years (Australian tax / record-keeping minimum under the Income Tax Assessment Act 1997 and Corporations Act 2001) |
| Marketing and analytics events (only if you opted in to analytics cookies) | 26 months (Google Analytics default), then aggregated or deleted |
| Aggregated / de-identified data that cannot reasonably re-identify you | May be retained indefinitely for service improvement and reporting |
In general:
Upon account deletion, we will take commercially reasonable steps to delete or de-identify your personal data from production systems within a reasonable period. Anonymised or aggregated data that cannot reasonably be used to identify you may be retained indefinitely for analytics and service improvement purposes.
We may retain personal data beyond any stated or typical retention periods where required or permitted by applicable law, regulation, or legal proceedings, or for the establishment, exercise, or defence of legal claims.
We implement and maintain appropriate technical and organisational security measures designed to protect personal information against unauthorised access, alteration, disclosure, or destruction. These measures are commensurate with the nature and sensitivity of the data we process and are regularly reviewed and updated. The specific nature and details of our security implementations are proprietary and confidential.
No method of transmission over the Internet or method of electronic storage is completely secure. While we strive to use commercially acceptable means to protect your personal information, we cannot guarantee its absolute security. You acknowledge and accept the inherent risks of transmitting data over the Internet. In the event of a data breach, we will comply with our notification obligations under applicable law (see Section 12).
Depending on your location, you have certain rights regarding your personal information. We are committed to honouring these rights in accordance with applicable law.
To exercise any of these rights, contact us at enquiry@oppermind.com. We will respond to verified requests within the timeframes required by applicable law. We may need to verify your identity before fulfilling your request.
Oppermind primarily uses browser local storage and session storage rather than traditional cookies. We use these technologies for:
In production environments, we may set HTTP-only cookies containing your authentication token for enhanced security. These are strictly necessary cookies required for the Service to function.
Third-party services used by the platform (such as bot detection services) may set cookies or use similar technologies as part of their functionality. These are governed by the respective service provider's privacy and cookie policies.
We do not use third-party advertising cookies, tracking pixels, or analytics cookies that track you across other websites. We do not participate in cross-site advertising networks.
You can clear browser local storage and cookies through your browser settings. Note that clearing authentication data will log you out of the Service.
The Service is for adults aged 18 years and over. The Service is not directed at, designed for, or made available to anyone under 18. We do not knowingly collect, use, or store personal information from any person under 18. If you are under 18, please do not create an account, sign in, upload anything, or otherwise use the Service.
There is no parental-consent pathway into the Service. The 18+ rule is platform-wide: we do not operate any tiered access, age-graded experience, or graduated feature set for users under 18. This position is recorded in Section 1.3 of our Terms & Conditions and is explained in greater detail in our Children's Privacy Policy.
If we learn that we have collected personal information from a person under 18, we will suspend the relevant account and delete the information from our production systems within a reasonable period, subject only to legal retention requirements (for example, where we are required to preserve and report material relating to suspected child sexual abuse, exploitation, or other serious criminal conduct). The full discovery and deletion process is set out in Section 7 of the Children's Privacy Policy.
If you are a parent or legal guardian and you believe a person under 18 has provided us with personal information, please contact us as soon as practicable at enquiry@oppermind.com with the subject line "Under-18 Use Report" so we can apply the discovery process. We comply with applicable child privacy protection laws in the jurisdictions where we operate, including (without limitation) the Children's Online Privacy Protection Act (COPPA) in the United States, Article 8 of the EU/UK GDPR, the UK Age Appropriate Design Code, Quebec Law 25, the relevant US state child-privacy laws, the Australian Privacy Principles under the Privacy Act 1988 (Cth), and the Online Safety Act 2021 (Cth).
In the event of a data breach involving personal information, we will comply with all applicable breach notification laws and regulations, including the Notifiable Data Breaches scheme under Part IIIC of the Privacy Act 1988 (Cth) and, where applicable, the GDPR's breach notification requirements. Notifications will be provided to the relevant authorities and affected individuals within the timeframes required by applicable law.
When you use AI features on Oppermind, your data is processed by Oppermind's AI infrastructure, which may include third-party service providers acting as data processors on our behalf. These providers are bound by contractual obligations to process data solely in accordance with our instructions and to maintain appropriate technical and organisational security measures.
When you use AI features, the data you submit or make available through the Service (including prompts, queries, conversation context, uploaded content, and any other data you direct the Service to process) may be transmitted to AI processing infrastructure. The scope of data processed depends on the features you use and the instructions you provide to the Service.
The specific AI models, providers, and technologies used by Oppermind are proprietary and confidential. We may change, update, or replace AI service providers and models at any time to improve the quality, safety, and performance of the Service. All AI service providers engaged by Oppermind are subject to data processing agreements that require compliance with applicable privacy and data protection laws.
We may also transmit limited data to the following types of services to provide platform features:
In order to operate, secure, and improve the Service, Oppermind may process user data internally as necessary for the purposes described in this Privacy Policy and our Terms and Conditions. Such processing is conducted in accordance with applicable data protection laws and is limited to what is reasonably necessary for the stated purposes, including service delivery, safety, legal compliance, and enforcement of our Terms. Access to user data within Oppermind is subject to appropriate internal controls and safeguards.
We do not track users across third-party websites and therefore do not respond to "Do Not Track" (DNT) browser signals. As we do not sell or share personal information for cross-context behavioural advertising, Global Privacy Control (GPC) signals do not apply; however, we respect such signals as a general expression of privacy preference.
We may update this Privacy Policy from time to time to reflect changes in our data practices, technology, legal requirements, or business operations. We will make reasonable efforts to notify you of material changes via email or a prominent notice within the Service. The "Last updated" date at the top of this policy indicates the date of the most recent revision. Your continued use of the Service after any changes to this Privacy Policy constitutes your acceptance of the updated Privacy Policy. We encourage you to review this policy periodically.
For any questions or concerns about this Privacy Policy or our data practices, please contact us:
If you have a complaint about how we handle your personal information, please contact us first at the address above. We will investigate your complaint and endeavour to respond within a reasonable timeframe.
If you are not satisfied with our response, you may lodge a complaint with the relevant regulatory authority: