Skip to main content
Amara AI Amara AI

Privacy

Privacy policy

What this company holds today, what would happen to a recording if a product is released, how long anything lives, and how to make us delete it.

Effective 11 August 2026Version 1.0Privacy Act 1988 (Cth)

1Who publishes this, and what it covers

This policy is published by AMARA AI PTY LTD, an Australian proprietary company registered in New South Wales, ACN 696 682 827, ABN 73 696 682 827. Amara AI is a trading name of that company. In this document "we" and "us" mean AMARA AI PTY LTD, and "you" means the person reading it.

What it covers

It covers two different things, and keeping them apart is the only way to read it honestly.

  • What we do today. We operate this website and one mailbox. That is the entire extent of our processing of personal information as at the effective date at the top of this page. Sections that describe current practice say so.
  • What we would do if a product is released. The company is designing a tool that turns speech into a structured note. Nothing has shipped, nobody is using it, and it has never processed anybody else's voice. The sections describing that design are written in advance so that the commitments are on the record before there is any commercial pressure to soften them. Those sections say "would" rather than "does", deliberately.

If you find a sentence in this document that reads as though we already run a service, treat it as a defect and tell us. Nothing on this site is meant to suggest that a product exists.

You may be looking at the wrong company

There is an established and unrelated company trading as AmaraAI at amaraai.com. This policy does not apply to them, does not describe their practices, and gives you no rights against them. We have no shared ownership, no shared directors, no shared personnel and no commercial arrangement with them. If you are trying to exercise a privacy right against that company, sending it to us achieves nothing except putting your email address in our inbox.

2The law this policy answers to

The law that governs this policy is the Privacy Act 1988 (Cth) and, in particular, the thirteen Australian Privacy Principles set out in Schedule 1 to that Act. Throughout this document a reference to "APP 6" or similar means the corresponding Australian Privacy Principle.

Australian Privacy Principle 1, and why this document exists

APP 1 is the reason there is a privacy policy here at all. It requires an entity to manage personal information in an open and transparent way, to take reasonable steps to implement practices, procedures and systems that ensure compliance with the other principles and that allow it to deal with enquiries and complaints, and to keep a clearly expressed and up to date privacy policy. APP 1.4 then sets out what that policy has to cover: the kinds of personal information collected and held, how it is collected and held, the purposes of collection, use and disclosure, how an individual can seek access and correction, how an individual can complain and how the complaint will be handled, and whether the information is likely to be disclosed to overseas recipients and in which countries. Every one of those is answered in a numbered section below rather than left to inference.

The small business threshold, and why it does not get us out of this

Section 6D of the Privacy Act exempts most businesses with an annual turnover of $3 million or less from the Australian Privacy Principles. AMARA AI PTY LTD was registered in 2026 and its turnover is presently below that threshold, so on a narrow reading the Act may not yet bind it.

We are not relying on that. Several of the exceptions in section 6D would in any event pull a business like ours back inside the Act as it grows, including a business that discloses personal information about another individual to anyone else for a benefit, service or advantage. More to the point, the exemption is an accident of turnover, not a statement that the information stops mattering. This policy is written as though the Australian Privacy Principles apply in full, and we will handle requests and complaints on that basis.

If we later become bound by the Act as a matter of law rather than choice, nothing in this policy changes. That is the point of writing it this way now.

Other Australian law that applies

  • Spam Act 2003 (Cth), which governs commercial electronic messages, requires consent, sender identification and a working unsubscribe facility.
  • Do Not Call Register Act 2006 (Cth), which governs unsolicited telemarketing. We do not telemarket.
  • Australian Consumer Law, Schedule 2 to the Competition and Consumer Act 2010 (Cth), which gives you consumer guarantees that cannot be excluded by anything we write.
  • Part IIIC of the Privacy Act, the Notifiable Data Breaches scheme, dealt with at its own section below.
  • Privacy and Other Legislation Amendment Act 2024 (Cth), which introduced a statutory tort for serious invasions of privacy, provided for a Children's Online Privacy Code, and added transparency obligations for certain automated decisions. Those last two are dealt with in their own sections.

3Who is answerable, and for what

Australian privacy law does not use the controller and processor split that European law uses. The Privacy Act 1988 (Cth) applies to an APP entity in respect of personal information that it holds, which means information it has possession or control of. That is a broader and blunter test, and it means we cannot hide behind a label.

Where we would be the entity answerable to you

For everything described in this policy, we are the entity you deal with. If you write to us, if you use a released product, or if your voice reaches us through somebody else's recording, AMARA AI PTY LTD is the organisation responsible for what happens next. We do not intend to offer a version of the product where a business customer is answerable for our handling and we are merely a supplier.

Where a third party is answerable instead

Two places, and both are named rather than implied.

  • Your own systems. Once a note is exported into your notes application, your document store or your email, that copy is yours. We have no access to it, no ability to delete it and no responsibility for it.
  • A transcription service acting on our instructions. If a product is released, converting speech to text would use an external service under a contract that permits processing only for that purpose. We would remain answerable to you for what that service does with the audio, and section 16C of the Privacy Act makes that explicit where the service is overseas.

What we will not do is describe a supplier as a partner in order to make its handling somebody else's problem. If information leaves us, the recipient is named in the recipients section and we remain accountable for the choice.

4What we collect today

Australian Privacy Principle 3 governs collection. It permits collecting personal information only where it is reasonably necessary for one of our functions or activities, requires collection by lawful and fair means, and requires collection from the individual themselves unless that is unreasonable or impracticable. The short answer for today is that we collect almost nothing, and this section says exactly what "almost" covers.

The website

This site is a set of static files. There is no account system, no form, no comment facility, no analytics product, no advertising, no tracking pixel, no session cookie and no server side application that could record anything about you. The only personal information that arises from a visit is what any web server necessarily sees in order to answer a request.

Everything collected when you load a page on amaraai.cc
ItemWhy it existsHeld byHow longIf you withhold it
IP addressA server cannot send a page back without one. Also used by the host to absorb denial of service trafficOur hosting provider, in its edge logsA short operational window set by the provider, then discardedThe page cannot be delivered. A VPN changes which address is seen and we have no objection to that
User agent stringSent by your browser with every request. We do not read itOur hosting providerSame as aboveNothing breaks. Browsers that send a minimal string work normally
Requested URL and response codeOperational logging at the hosting layerOur hosting providerSame as aboveNot applicable
Referring pageSent by your browser if it chooses to. We have no report that reads itOur hosting providerSame as aboveNothing breaks
Font request to GoogleTwo typefaces are loaded from Google Fonts, which discloses your IP address to Google. Explained in the cookie noticeGoogleGoverned by Google's own policy, not oursBlocking it leaves the page fully readable in a fallback typeface

We do not aggregate these logs, we do not build a visitor profile, we do not run a dashboard over them, and we could not tell you how many people read this page.

The mailbox

If you write to [email protected] we hold your email address, your name if your mail client sends one, whatever you chose to put in the message, and the routing headers that carry it. We hold it because you sent it, which is the collection from the individual that APP 3.6 prefers, and we keep it while the matter is open and for a period afterwards described in the retention section.

Sensitive information

Section 6 of the Privacy Act defines sensitive information to include health information, racial or ethnic origin, political opinions, religious beliefs, sexual orientation, criminal record, genetic information, and biometric information that is to be used for automated biometric verification or identification together with biometric templates. Australian Privacy Principle 3.3 prohibits collecting it without consent except in narrow circumstances.

We do not seek sensitive information and no field anywhere asks for it. Two points deserve their own sentences because a speech product invites the assumption otherwise.

  • No biometric template is created from a voice. This is dealt with at length in the voice section below. It is the single most important limit in this policy.
  • Speech can contain anything. A person in a meeting may mention a diagnosis, a religion or a criminal matter without anybody planning it. That would make sensitive information transiently present in a recording. The design answer is that the recording is destroyed once the note exists, so the exposure lasts minutes rather than years, and the answer for the note is that it belongs to you and never comes to us.

5Voice, and what would happen to a recording

This is the section that exists because of what this company is trying to build. It is written now, before any release, so that the commitments cannot be quietly loosened later without the change being visible in the revision history of this page.

A voice recording is personal information whenever the speaker is reasonably identifiable, which in a meeting they almost always are. Everything below therefore describes handling of personal information under the Privacy Act, not handling of an anonymous audio file.

Does the audio leave your device

Yes, for one step, and only that step.

  • Capture happens on your device. While a meeting is being recorded the audio exists in memory on that device and nowhere else.
  • Converting speech to text needs more computing power than a phone or a laptop has, so audio would be sent over an encrypted connection to a transcription service for that single purpose. This is the only point at which a recording leaves your control.
  • Producing the structured note happens from the transcript. By the time the note is being written the audio has already served its purpose.
  • The note is handed back to you. It is not stored by us, indexed by us or searchable by us.

The transcription service and the country its processing happens in are named in the recipients section, and will be named in the released product before you record anything with it. A privacy policy that describes a sub-processor as "a leading provider" is telling you that it does not want you to look it up.

How long the audio is kept

The default retention period for captured audio is zero once the note exists. Concretely, that means the following.

Retention commitments for a released product, by artefact
ArtefactRetentionCan you change it
Live microphone bufferSeconds. Overwritten continuously and never written to a fileNo. It is not a setting
Audio sent for transcriptionDestroyed once the transcript is returned. Contractually the service may not retain it for its own purposesNo. There is no option to keep it
TranscriptHeld on your device only, and destroyed with the recording unless you turn on keeping itYes, and it is off by default
The structured noteKept wherever you export it. We hold no copyIt is yours. We have nothing to delete
Diagnostic or crash informationWould never include audio, a transcript or note contentReportable defects are described without the material that caused them

There is no debug copy, no sample kept for quality review, no human listening programme and no research corpus. Those are the four routine exceptions that hollow out a deletion promise in other products, so all four are refused by name.

One consequence is worth stating because it is a genuine cost to us. Since the audio is gone, we cannot re-run an improved model over your earlier meetings, we cannot investigate a complaint about a note by listening to the recording, and we cannot recover anything you lose. We accept all three rather than keep the recording.

Training

Your audio, your transcripts and your notes are never used to train, fine tune, evaluate or improve any model without your separate, specific and revocable opt in consent.

  • Consent for training would never be bundled into acceptance of the terms of use, a privacy policy update or the act of installing something.
  • It would be a distinct choice, off by default, with plain wording about what would be retained and for how long, and it would be withdrawable without losing access to anything you had paid for.
  • The contractual terms with any transcription service would prohibit that service from training on our traffic. If a provider will not agree to that in writing, it does not get used.
  • No free tier will be funded by training rights over the speech of people who never agreed to anything.

No voiceprint and no biometric template

A voiceprint is a mathematical representation of how a particular person sounds, which can be stored and later compared against another recording to decide whether the same person is speaking. It is the mechanism that turns a pile of audio into a way of finding a named human being in it.

No voiceprint, speaker embedding, biometric template or voice signature of any kind is created, stored, exported or compared. Not for security, not for convenience, not for analytics, not for fraud prevention.

  • Distinguishing speaker one from speaker two inside a single meeting is a narrower operation that does not require identifying anybody, and anything produced by it is destroyed with the recording. It never becomes a persistent identity.
  • Because no template exists, a person who spoke in one meeting cannot be matched to a different recording later, by us or by anyone who obtains our systems.
  • This is not merely a preference. Biometric templates and biometric information used for automated identification are sensitive information under section 6 of the Privacy Act, and Australian Privacy Principle 3.3 would require consent we have no intention of collecting for a purpose we have no intention of pursuing.
  • Voice authentication is a plausible product idea and we are not going to build it. If that position ever changes it will be a new product with its own policy, not a paragraph edited into this one.

What we would never derive from a voice

  • Age, sex, ethnicity, national origin, accent classification or place of origin.
  • Emotional state, stress level, honesty, confidence or engagement scoring.
  • Health or disability inferences of any kind, including anything derived from speech patterns.
  • Talk time league tables, interruption counts, participation rankings or any other measure of a person's performance in a meeting.

Several of these are technically feasible and some are commercially attractive. They turn a note taking tool into a surveillance instrument pointed at colleagues who never chose to be measured, and refusing them is a large part of the point of the company.

7Telling you at the point of collection

Australian Privacy Principle 5 requires that we tell you certain things at or before the time we collect personal information about you, or as soon as practicable afterwards. Those things include our identity and contact details, the fact and circumstances of collection, the purposes, the consequences of not providing the information, the entities we usually disclose it to, and whether the information is likely to go overseas and to which countries.

How we meet it today

  • This document. It is linked from the footer of every page of this website, it names the company and the mailbox, and the collection tables answer each APP 5 item in the same row as the item it concerns.
  • The cookie notice. The one third party request this website makes is described on its own page rather than buried in a clause here.
  • The contact page. It says what happens to an email you send, before you send it.

How it would be met by a released product

Not by a link to this page in a settings screen. The notice has to arrive at the moment it is relevant.

  • A plain description of what leaves the device, shown before the first recording rather than during onboarding when nobody is reading.
  • The processing country named at that point, not only in this document.
  • Any operating system permission prompt preceded by our own explanation of why the permission is being asked for, so that the operating system prompt is never the first time you learn what it is for.
  • The consequence of declining stated next to the request, which for microphone access is simply that the product cannot work and nothing else is affected.

APP 5 also requires telling you the consequences of not providing information. Those are set out in the last column of the collection table above.

8Dealing with us anonymously

Australian Privacy Principle 2 gives you the option of dealing with us anonymously or under a pseudonym, unless that is impracticable or we are required by law to deal with an identified individual.

Reading this website is anonymous in the ordinary sense. There is no account, no sign in, no cookie that distinguishes you from anybody else, and no analytics that would let us count you. We do not know who visits and we have not built anything that could tell us.

Writing to us from a pseudonymous mail account is fine and we will answer it on the merits. We do not require a real name, an organisation or a job title in order to reply, and we will not go looking for one.

The option narrows in exactly one place. To answer a request for access to or correction of personal information we have to be satisfied that you are the person the information is about, because handing somebody else's correspondence to the wrong person is itself a breach. What that verification looks like, and how light we try to keep it, is set out in the access section.

If a product is released, using it would not require an account for the core function. A tool that records a meeting on your device and hands you back a note does not need to know your name in order to do it, and building a login in front of it would be a choice made for our benefit rather than yours.

9Information we did not ask for

Australian Privacy Principle 4 deals with personal information we receive without having asked for it.

For a company working on speech, the obvious case is somebody attaching a recording of a meeting to an email in order to show us a problem. Everybody else in that meeting agreed to be recorded by the sender, not by us, and we have no lawful basis for holding their voices. The same applies to a forwarded message thread carrying other people's details. When we receive personal information we did not solicit, we decide within a reasonable period whether we could have collected it under APP 3. If we could not, and the information is not contained in a Commonwealth record, we destroy it or de-identify it as soon as practicable, provided it is lawful and reasonable to do so.

In practice an unsolicited recording is deleted without being played, the sender is told that it was deleted, and the underlying problem is written down in words. Attachments carrying other people's personal information leave the mailbox and fall out of any backup on its ordinary rotation.

10Use and disclosure

Australian Privacy Principle 6 governs what we may do with personal information once we hold it. The rule is that information collected for a particular primary purpose may be used or disclosed for that purpose, and for a secondary purpose only where you would reasonably expect it and the secondary purpose is related to the primary one, or where you have consented, or where a specific exception in the Act applies.

What we use it for today

  • Answering your email. That is the primary purpose of every piece of correspondence we hold, and there is no secondary purpose attached to it.
  • Dealing with a privacy request, a complaint or a security report, and keeping enough of a record to show what we did and when.
  • Keeping this website available, which is why the hosting provider logs requests at all.
  • Meeting a legal obligation where one arises.

What we would use it for if a product is released

  • Producing the transcript and the note you asked for, which is the whole of the primary purpose.
  • Diagnosing a defect you reported, described in words rather than reproduced from your material.
  • Nothing else. There is no analytics purpose, no personalisation purpose, no model improvement purpose and no commercial purpose attached to the content of your meetings.

What we do not do, stated as commitments rather than reassurances

  • We do not sell personal information. Not to data brokers, not to advertisers, not as an audience product, and not as part of a dataset.
  • We do not run advertising anywhere, so no information we hold is used to target anything at you.
  • We do not build a profile of you across other companies' products, and we do not buy data about you from anybody.
  • We do not use your correspondence for marketing, which is dealt with in its own section.
  • We do not use the content of a recording, a transcript or a note for any purpose other than producing the thing you asked for.

Disclosure to law enforcement, courts and regulators

We may disclose personal information where the Act permits it, including where the disclosure is required or authorised by or under an Australian law or a court or tribunal order, where a permitted general situation under section 16A exists such as a serious threat to life, health or safety, or to an enforcement body where reasonably necessary for an enforcement related activity.

Where we make a disclosure to an enforcement body we make a written note of it, as APP 6.5 requires. Where the law allows us to tell you that a request was made, we will tell you. Where it does not, we will not pretend that no request was ever received.

The retention design has a direct bearing here and it is the most useful thing in this section. A request for the audio of a meeting can only be answered with material that still exists. Destroying recordings once the note is produced means there is generally nothing to compel, and that protection is structural rather than a matter of our willingness to resist.

A change of control

If the company were sold, merged or wound up, personal information could pass to the acquirer as part of the business. We commit to two things. The acquirer would be bound by this policy as it stood, and we would publish notice of the change on this website and email anybody whose correspondence we still held before the transfer completed, unless a court ordered otherwise.

11Direct marketing and the Spam Act

Australian Privacy Principle 7 restricts the use of personal information for direct marketing. The Spam Act 2003 (Cth) sits on top of it for anything sent by email, SMS or instant message, and it is a strict regime. A commercial electronic message requires consent, accurate sender identification, and a functional unsubscribe facility that remains live for at least 30 days and is actioned within 5 working days. Consent may be express or, in narrow circumstances, inferred, and an existing business relationship is not a blanket permission.

Our position

We do not operate a marketing list. No marketing message has ever been sent under this company name, and there is nothing on this website that will subscribe you to anything, because there is nothing on this website that submits anywhere.

Writing to our mailbox does not subscribe you to anything. Quietly turning a support thread into a mailing list is the most common way a small company builds one, and we are not doing it.

If that ever changes it will be opt in, the consent will be recorded with a timestamp and the exact wording you agreed to, the first message will say where the address came from, and unsubscribing will take one click and be honoured immediately rather than within the five working days the Act allows.

The Do Not Call Register Act 2006 (Cth) governs unsolicited telemarketing. We do not telemarket, we do not collect telephone numbers, and there is no telephone number on this website.

There is no advertising in anything this company has built or is designing. There is therefore no personalised advertising to opt out of, no advertising identifier in use, and no advertising network receiving anything from us.

12Who receives anything, and where they are

This section is the authoritative list of who receives personal information from us. If a recipient is not in this table, it does not receive anything.

Today

Current recipients, what they receive and where they are
RecipientWhat reaches themWhyLocation
Website hosting and content delivery providerYour IP address, user agent, requested path and response code, in operational logsServing this website and absorbing abusive trafficGlobally distributed edge network, so the answering location depends on where you are
Email providerThe content and headers of any message you send usOperating the mailboxOutside Australia. Named on request before you write, if that matters to you
Google FontsYour IP address and the request for two font filesLoading the typefaces this site uses. Explained in the cookie noticeUnited States and Google's global network
Domain registrar and DNS providerNothing about you. Named for completeness because they sit in the pathResolving the domainOutside Australia

If a product is released

One additional recipient, and it is the significant one.

The additional recipient a released product would introduce
RecipientWhat would reach themCommitments before it is used
Speech to text serviceThe audio of a recording, for the single purpose of returning a transcriptNamed publicly, with its processing country, before anybody records anything. Contractually barred from retaining the audio for its own purposes and from training on it. Bound to notify us of a breach. Replaced rather than tolerated if it will not agree in writing
Why it is not named yet

Naming a provider we have not contracted with would be a fabrication, and naming one and then quietly switching is worse than naming none. The commitment we can make now is that the name and the country will be published here and shown in the product before a single recording is processed, and that a change of provider will be published in the same way.

Who does not receive anything

  • No analytics provider, because there is no analytics.
  • No advertising network, ad exchange, attribution service or measurement partner.
  • No data broker, list vendor, enrichment service or lead generation platform.
  • No social network. There is no share button, no embedded post and no pixel on this site.
  • No customer relationship system. Correspondence sits in a mailbox and nowhere else.

13Sending personal information overseas

Australian Privacy Principle 8 governs disclosure of personal information to a recipient outside Australia. Section 16C of the Act makes us accountable for an overseas recipient's act or practice: if an overseas recipient we disclosed information to does something that would have breached the Australian Privacy Principles, that act is taken to have been done by us, and we are liable for it.

We treat that as the operative rule rather than the exceptions, which is why the list of overseas recipients is short and named rather than described as "our trusted partners".

How we meet APP 8

Before disclosing personal information overseas we take reasonable steps to ensure the recipient does not breach the Australian Privacy Principles, principally by contract. The relevant contractual terms are the data processing terms published by each provider, which bind them to process the data only on our instructions, to keep it secure, to assist with individual rights requests, and to notify us of a breach.

We do not rely on the APP 8.2(a) exception for recipients in countries with substantially similar laws, because assessing that for each jurisdiction is a judgement we are not qualified to make and getting it wrong shifts the risk onto you.

Where the data actually goes

The countries in which personal information may be held or accessed are named in the recipients table in this policy. That table is the authoritative list. If a provider changes region we update the table.

14Government related identifiers

Australian Privacy Principle 9 restricts an organisation from adopting, using or disclosing a government related identifier, which includes a tax file number, Medicare number, driver licence number or passport number.

We do not collect any government related identifier. We have no reason to. Nothing we operate today asks you for anything beyond an email address you chose to send us, and nothing in the product being designed has an age check, an identity check or a payment step that would need a government number.

If you send us one anyway, for instance by attaching a photograph of a licence to an email, it is treated as unsolicited personal information under the section above and destroyed.

15Keeping information accurate

Australian Privacy Principle 10 requires that personal information we collect is accurate, up to date and complete, and that information we use or disclose is also relevant.

Almost everything we hold today is something you typed and sent us, which makes it accurate on the day it arrived and progressively less so afterwards. An email address in a thread from last year may no longer reach you. We do not periodically re-verify contact details, because doing so would mean writing to people who had finished dealing with us in order to ask whether they still exist.

The practical remedy is the correction right under APP 13, described below, which you can use at any time and free of charge.

16Security, and what we do not hold

Australian Privacy Principle 11 requires us to take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure, and to destroy or de-identify it when it is no longer needed for any purpose for which it may be used or disclosed.

What "reasonable steps" means for a company at this stage

  • Transport encryption on every connection. This website is served over HTTPS only and sends a strict content security policy, and mail to the published address travels over TLS wherever the sending server offers it.
  • Encryption at rest for stored data, provided by the underlying platform.
  • Multi-factor authentication on every administrative account that exists, which today means the mailbox, the domain registration, the hosting account and the code repositories. There is no other console to protect.
  • Access on a need to know basis. The number of people who can open the mailbox is very small and is reviewed whenever anybody joins or leaves.
  • Nothing in production to breach. There is no hosted service, no account system, no customer database and no archive of recordings behind this site, so the attack surface is a set of static files, one mailbox and a code repository.
  • Collecting less, and destroying sooner. The most reliable security control available to any company is not holding the data, which is why the collection tables in this policy fit on a screen and why the audio retention period is zero.

The control that matters most here

Everything above is ordinary hygiene that any competent small company should manage. The control this company is actually built around is different in kind. Audio is destroyed once the note exists, and no voiceprint is ever created. A control that removes the data cannot be misconfigured, cannot be left unpatched and cannot be exfiltrated, which is more than can be said for any of the others.

What we do not have, stated plainly

AMARA AI PTY LTD does not hold ISO/IEC 27001 certification, a SOC 2 Type I or Type II report, an IRAP assessment, or any other independent security accreditation, and will not represent otherwise until one is genuinely held. We have not engaged a third party to conduct a penetration test. We do not employ a full time security engineer.

We say this because the alternative is a paragraph of confident language that means nothing. No system is perfectly secure, and a company that tells you otherwise is either mistaken or selling something.

17Retention, and the obligation to delete

Australian Privacy Principle 11.2 requires that we destroy or de-identify personal information once it is no longer needed for any purpose for which it may be used or disclosed, unless we are required by law to keep it. Retention is therefore an obligation to delete rather than a licence to hold.

Retention periods, with the reason for each one
WhatHow longWhy that period
Hosting provider request logsThe short operational window the provider applies, then discardedThey exist to keep the site running and to absorb abuse. Neither purpose survives the week
Ordinary correspondenceWhile the matter is open, then up to 24 monthsPeople come back to a thread months later, and losing the history makes the second conversation worse. Ask us and we will delete it sooner
Privacy requests and our responses3 yearsEvidence that a statutory request was answered, and within what time
Privacy complaints and their outcomes3 yearsThe complaint may go to the Commissioner after we have answered it, and we should still be able to show what we did
Security reports and incident records5 yearsPart IIIC assessments and the reasoning behind them should be reviewable well after the event
Records with a statutory retention periodAs the relevant law requires, including 5 years for records the Corporations Act 2001 (Cth) and the tax law require a company to keepNot our choice
Captured audio, if a product is releasedZero once the note existsThe purpose is exhausted the moment the note is produced, and APP 11.2 then requires destruction rather than permitting storage
Transcripts, if a product is releasedDestroyed with the audio unless you turn on keeping them, in which case they stay on your deviceSame reasoning. A default that keeps things is a default that accumulates risk on your behalf

What deletion means

Removed from live systems immediately, and gone from any backup on that backup's ordinary rotation rather than surviving in a long lived archive. We do not run indefinite backups, so there is no copy quietly outliving the deletion. Where a mail provider operates its own deletion delay, that delay applies and we will tell you what it is rather than claim an instantaneous erasure we do not control.

18Access and correction

Australian Privacy Principle 12 gives you the right to ask for access to the personal information we hold about you. Australian Privacy Principle 13 gives you the right to ask us to correct it.

How to ask

Email [email protected] with "Privacy request" in the subject line. Tell us what you want and give us enough to find it. In practice that means the email address you wrote to us from, because correspondence is the only thing we hold. There is no account number, no customer identifier and no device identifier in use anywhere in this company.

Verifying who you are

We have to be satisfied you are the person the information is about, or an authorised representative. Since what we hold is correspondence, we verify by replying to the address the correspondence came from. That is a modest level of assurance and we would rather describe it accurately than dress it up. We will not ask you to send identity documents. Demanding a licence or a passport in order to answer a privacy request collects far more sensitive information than the request was ever about, and if a photograph of an identity document arrives anyway it is treated as unsolicited information and destroyed.

Timing and cost

We respond within 30 days. Access is free. We do not charge for making a request, and we do not charge for correction. If giving access in a particular form imposes a genuine cost, for example producing a bulk export in an unusual format, we will tell you the charge before doing the work and it will not be excessive.

When we can refuse

The Act lists the grounds, and they are narrower than people expect. They include where giving access would have an unreasonable impact on the privacy of others, where the request is frivolous or vexatious, where the information relates to existing or anticipated legal proceedings and would not be discoverable, and where giving access would be unlawful.

If we refuse, in whole or in part, we will give you written reasons, tell you which ground we rely on, and tell you how to complain. Where we can give you part of the information, or give it in another way that meets your need, we will offer that instead of a flat refusal.

If you were recorded by somebody using a released product

The same rights apply and you do not need the permission of whoever made the recording. Write to us and say what meeting you are asking about. By design the answer will usually be that nothing about you exists, because the recording was destroyed when the note was produced and no voiceprint was created, and we will say that plainly rather than treat it as a reason not to reply.

Correction

If information is inaccurate, out of date, incomplete, irrelevant or misleading, we will correct it. If we have disclosed the information to someone else and you ask us to notify them of the correction, we will take reasonable steps to do so unless it is impracticable or unlawful.

If we refuse to correct, you may ask us to attach a statement to the record saying that you consider it inaccurate, and we will take reasonable steps to make that statement apparent to anyone who later looks at the record. That right is often overlooked and it is worth knowing about.

19Deleting what we hold

Deletion is dealt with separately from access and correction because it is the request people actually want to make, and burying it inside another section makes it harder to find.

How to ask

Email [email protected] with Delete my data in the subject line. You do not have to give a reason and we will not ask for one.

What we will do

  • Confirm receipt, and identify what we hold that relates to you. In most cases that is one email thread.
  • Delete it, including the thread carrying the request itself once the request has been completed and confirmed.
  • Confirm in writing what was deleted and when, within 30 days, at no charge.

What we would keep, and why

Only a minimal record that a deletion request was received and completed, which is the evidence that we did what we said. That record does not contain the content of your correspondence. Where a law requires a specific record to be retained, we will tell you which law and what is being kept.

If a product is released

The deletion story becomes shorter rather than longer, which is the point of the design. There would be no account to close, no archive of recordings to purge and no library of notes to clear out, because none of those would exist on our side. Removing the software from your device and deleting the notes you exported would be the whole of it. If we ever hold something you would have to ask us to delete, that fact will be stated here first.

20Children and young people

Nothing this company makes is directed at children, designed to appeal to children, or usable by a child in any way that would make sense. A tool for people who sit in a lot of meetings has an adult professional audience by its nature.

The Australian position

The Privacy Act does not fix an age at which a person can consent for themselves. The OAIC's guidance is that an organisation should assess capacity individually where practicable, and that as a general rule a person aged 15 or over may be presumed to have capacity unless there is something to suggest otherwise. We apply that presumption.

The Privacy and Other Legislation Amendment Act 2024 (Cth) provides for a Children's Online Privacy Code to be developed by the Information Commissioner, applying to services likely to be accessed by children. We will comply with that Code to the extent it applies to us once it is registered and in force, and we will update this policy at that point rather than guessing at its terms in advance.

Practical position

  • We do not knowingly collect personal information from a child under 15 without the consent of a parent or guardian.
  • This website has no account, no profile, no social feature, no messaging, no user generated content and no advertising, so there is no mechanism by which a child could disclose anything to us other than by sending an email.
  • A recording of a meeting could contain a child's voice, for example if somebody's family is audible in the background of a call from home. The retention design means that audio is destroyed once the note exists, which is the same answer as for every other voice in the room and is why the answer does not need a special case.

If a child's information has reached us

Write to [email protected]. We will delete it without requiring you to prove a legal relationship beyond what we need to be satisfied the request is genuine, and we will confirm when it is done.

21Automated decisions

The Privacy and Other Legislation Amendment Act 2024 (Cth) inserts a requirement that a privacy policy disclose the kinds of personal information used in substantially automated decisions that significantly affect an individual's rights or interests, together with the kinds of such decisions made. That requirement commences on 10 December 2026. This section is published in advance of that date.

Our position

We make no automated decision that significantly affects your rights or interests. Nothing we operate decides whether you get credit, a job, a service, a benefit, an insurance product or a legal entitlement, and nothing we operate makes a decision about you at all.

Automated processing that would happen, and why none of it is a decision about you

  • Speech to text. A model converts audio into words. It is a transformation of material you supplied, not a judgement about you, and its output is handed straight back to you.
  • Note generation. A language model summarises a transcript into sections. It produces a draft for the person who was in the room. It does not rate anybody, rank anybody, score anybody or reach a conclusion about anybody, and its output is not used for any purpose beyond being read by you.

Both are worth being suspicious of for a different reason. A summary can be confidently wrong, can invent emphasis that nobody intended, and can omit the one line that mattered. That is a quality problem rather than an automated decision, and it is addressed by presenting the note as a draft and marking quoted material as quoted.

If we ever build something that does make a decision about a person, it will be described here before it starts running rather than after, and the description will say what information it uses and what the decision affects.

22Data breaches and the notification scheme

Part IIIC of the Privacy Act establishes the Notifiable Data Breaches scheme. It applies to an eligible data breach, meaning unauthorised access to, unauthorised disclosure of, or loss of personal information where a reasonable person would conclude the access or disclosure would be likely to result in serious harm to any of the individuals to whom the information relates, and the risk has not been prevented by remedial action.

The process we follow

  1. Contain. Stop the access, revoke the credential, take the affected component offline if that is what it takes.
  2. Assess. Where we suspect an eligible data breach may have occurred, we carry out a reasonable and expeditious assessment and complete it within 30 days of becoming aware of the grounds for suspicion, which is the period section 26WH allows.
  3. Remediate. If remedial action means serious harm is no longer likely, the breach is not notifiable and we record why.
  4. Notify. If it is an eligible data breach, we prepare a statement for the Commissioner and notify the Office of the Australian Information Commissioner (OAIC), GPO Box 5218, Sydney NSW 2001, telephone 1300 363 992, oaic.gov.au as soon as practicable. We then notify affected individuals, or if that is not practicable, publish the statement on this website and take reasonable steps to publicise it.

What a notification will contain

Our identity and contact details, a description of the breach, the kinds of information concerned, and the steps we recommend you take. We will not pad it with reassurance that has not been earned, and we will say what we do not yet know.

If you think a breach has happened

Write to [email protected] with "Security" in the subject line. We would rather chase a false alarm than miss a real one, and we will not treat a good faith report as hostile.

23The statutory tort of serious invasion of privacy

A statutory tort of serious invasion of privacy commenced on 10 June 2025 under Schedule 2 to the Privacy and Other Legislation Amendment Act 2024. It allows an individual to sue for intrusion upon seclusion or misuse of information, where the invasion was intentional or reckless, where a person in the plaintiff's position would have had a reasonable expectation of privacy, and where the invasion is serious.

This is a right you have against anyone, including us, and it exists independently of the complaints process described below. We mention it because most privacy policies do not, and a right you do not know about is not much of a right.

24Cookies on this website

This website sets no cookies of its own. There is no analytics cookie, no advertising cookie, no session cookie, no preference cookie and no consent cookie, because there is nothing to consent to.

It also stores nothing in local storage or session storage, and it registers no service worker. Your browser will cache the pages, the stylesheet, the images and the one script, which is ordinary caching and is under your control.

Two typefaces are loaded from Google Fonts, which means your browser makes a request to a Google domain and Google therefore receives your IP address. Blocking that request leaves every page fully readable in a fallback typeface, and nothing on this site depends on it.

The cookie notice sets all of this out in full, including why Australian law does not require a consent banner for a site that behaves this way, and how to block the font request if you would rather.

25Complaints

Step one: tell us

Email [email protected] with "Privacy complaint" in the subject line. Set out what happened and what you want done. We acknowledge within 5 business days and respond substantively within 30 days. If it will take longer, we will tell you why and give you a date.

Step two: the Commissioner

If you are not satisfied with our response, or we do not respond within 30 days, you can complain to the Office of the Australian Information Commissioner (OAIC), GPO Box 5218, Sydney NSW 2001, telephone 1300 363 992, oaic.gov.au.

The OAIC will normally expect you to have complained to us first and given us 30 days, but it can accept a complaint without that in appropriate cases. There is no fee. You do not need a lawyer and you do not need our agreement.

What we will not do

We will not require you to sign a non-disclosure agreement as a condition of us dealing with a privacy complaint, and we will not treat making a complaint as a breach of our terms of use.

26If you are outside Australia

This policy is written to Australian law because that is the law that binds us. If you are outside Australia, some additional rights may apply to you, and we do not want the absence of a mention to be read as a refusal.

European Economic Area and United Kingdom

Where the General Data Protection Regulation or the UK GDPR applies to our processing, you have rights of access, rectification, erasure, restriction, portability and objection, and a right to complain to your national supervisory authority. Where we rely on legitimate interests, you may object and we will stop unless we can demonstrate compelling legitimate grounds that override your interests. Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.

Send any such request to [email protected] and say which law you are relying on, so we apply the right timetable. We answer GDPR requests within one month.

California

Under the California Consumer Privacy Act as amended, you have rights to know, delete, correct and opt out of the sale or sharing of personal information. We do not sell personal information and we do not share it for cross context behavioural advertising as those terms are defined in that Act. There is no advertising anywhere in this company and no advertising identifier in use, so there is no sharing to opt out of in the first place. Global Privacy Control signals sent by your browser to this website are honoured, although since nothing is sold or shared, honouring one changes nothing about how the site behaves.

Everywhere else

If a right exists where you live and you tell us about it, we will deal with the request on its merits rather than on whether we are technically obliged to.

27Changes to this policy

We may change this policy. When we do, the effective date and the version number in the header of this page change with it.

Where a change materially reduces your rights, materially expands what we collect, or weakens any of the voice commitments in this document, we will give notice before it takes effect. That means a dated note at the top of this page for at least 30 days, and, once there is a product, a notice in the product on next launch. We will not make a material change effective retrospectively.

The voice commitments deserve a specific promise, because they are the reason to trust the design rather than the description. If we ever intend to retain audio beyond the production of the note, to create a voiceprint, or to train on user speech, that change will be announced as its own change with its own notice period, and consent will be sought afresh rather than inferred from continued use.

Previous versions are not published as separate pages, but we keep them. If you want to know what this document said on a particular date, ask and we will send you that version.

This policy is a professionally structured document. It is not legal advice, and it is not a substitute for advice from an Australian legal practitioner on your own circumstances.

28How to contact us

All privacy matters reach one address.

Contact points for privacy matters
MatterSubject lineResponse
Access to your personal information (APP 12)Privacy request30 days
Correction of your personal information (APP 13)Privacy request30 days
Deletion of everything we hold about youDelete my data30 days
Complaint about our handling of personal informationPrivacy complaintAcknowledged in 5 business days, answered in 30 days
Suspected security incident or data breachSecuritySame or next business day
You meant the unrelated AmaraAI at amaraai.comName confusion5 business days
Anything elseAnything sensible5 business days

Email: [email protected]

Entity: AMARA AI PTY LTD, ACN 696 682 827, ABN 73 696 682 827, an Australian proprietary company, New South Wales.

We do not publish a postal address on this website. If you need to serve a document, the company's registered office is recorded against ACN 696 682 827 on the register maintained by the Australian Securities and Investments Commission, which is the address that has legal effect for service.

If you would rather not deal with us at all, you can go straight to the Office of the Australian Information Commissioner (OAIC), GPO Box 5218, Sydney NSW 2001, telephone 1300 363 992, oaic.gov.au.