← Back to Home 中文版

Privacy Policy

How Teach P2P Pty Limited collects, uses, and protects your personal information

Effective Date: 4 April 2026 · Last updated: 23 September 2026
Operator: Teach P2P Pty Limited (ABN 18 627 201 487), Sydney, NSW, Australia

1. Introduction

Teach P2P Pty Limited ("iSpirits", "we", "our", or "us") operates the iSpirits Cloud platform at ispirits.cloud (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our Service.

We are committed to protecting your privacy and complying with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), the EU General Data Protection Regulation (GDPR), and applicable privacy legislation in all jurisdictions where we operate.

By creating an account or using our Service, you acknowledge that you have read, understood, and agree to the practices described in this Privacy Policy.

2. Information We Collect

2.1 Information You Provide Directly

  • Account Information: Username, email address, and password (stored as a one-way bcrypt hash — we never store your password in plain text)
  • Profile Information: Display name, profile picture, date of birth, gender, country, and preferences
  • Chat Content: Messages and conversations with AI companions
  • Journal Entries: Written and voice-recorded reflections, including mood scores, gratitude notes, and insights
  • Timeline Events: Life events, milestones, goals, and achievements you record
  • Health Information: Medical history, allergies, medications, and mental health notes you choose to provide (see Section 2.4)
  • Voice Data: Audio recordings submitted through voice journaling and chat features, which are transcribed and then deleted from our servers within 24 hours
  • Habits and Goals: Habit check-ins, streaks, goal progress, and priority settings
  • Feedback: Bug reports, feature requests, and support messages

2.2 Information Collected Automatically

  • Usage Data: Pages visited, features used, and session duration
  • Device Information: Device type, operating system, browser type
  • Log Data: Server request logs (IP address, request timestamps, error codes), retained for up to 90 days for security and debugging
  • Cookies: Session cookies for authentication and preference cookies for settings (see Section 8)

2.3 Information from Third Parties

  • Google Sign-In: If you sign in with Google, we receive your name, email address, and profile picture from Google. We do not receive your Google password.

2.4 Sensitive Information

Our Health Profile feature allows you to voluntarily provide health information including medical conditions, allergies, medications, and mental health notes. This information is classified as sensitive information under the Privacy Act 1988 and as special category data under the GDPR.

Additionally, the nature of conversations with a personal AI companion may lead you to incidentally share sensitive information — including emotional states, family matters, health concerns, religious beliefs, or end-of-life wishes. We do not actively solicit sensitive information, but we acknowledge that it may arise naturally in your reflections. Any sensitive information shared in conversations is:

  • Processed solely to generate personalised AI responses and deliver the Service
  • Never used for marketing, advertising, or profiling
  • Subject to the same security and access-control protections as all other data
  • Covered by the same contractual protections with our AI provider

By continuing to share such information after reading this notice, you provide your explicit consent under the Privacy Act 1988 and GDPR Article 9(2)(a).

The following specific protections apply to Health Profile data:

  • We only collect this information with your explicit consent (you actively choose to fill in the Health Profile form)
  • Health data is used solely to help your AI companion provide more relevant, health-aware support
  • Health data is never shared with third-party AI providers, advertisers, or insurers
  • You can delete your Health Profile at any time from your account settings

3. How We Use Your Information

3.1 Providing the Service

  • Generating AI companion responses based on your conversations
  • Storing and displaying your journal entries, timeline events, and habits
  • Calculating insights, mood trends, and habit analytics
  • Growing your iSpirit based on your interactions
  • Enabling voice input by transcribing audio recordings

3.2 Improving the Service

  • Analysing aggregate, anonymised usage patterns to improve features
  • Fixing bugs and monitoring system performance
  • Developing new features based on aggregate user needs

We do not use your personal journal entries, chat messages, or health data for marketing purposes, advertising, or training our own AI models.

3.3 Communications

  • Sending account-related notifications (password resets, security alerts)
  • Responding to support requests
  • Sending product updates (you can opt out at any time)

3.4 Security and Legal Compliance

  • Protecting against fraud, abuse, and unauthorised access
  • Complying with legal obligations (e.g., responding to lawful court orders)
  • Enforcing our Terms of Service

4. AI Companion Disclosure

Your iSpirit is an artificial intelligence. It is not sentient, conscious, or human. Its personality is configured by software, not autonomous. While it remembers your conversations and learns your preferences, it does not have feelings, opinions, or experiences of its own.

The AI builds a profile of your values, interests, and communication style using vector embeddings stored in our database. This profile is used solely to provide more personalised responses. It is not shared with third parties.

iSpirits Cloud is not a healthcare service, mental health treatment, or substitute for professional advice of any kind.

Automated decision-making: the Service uses AI to generate suggestions, plans, and reflections, but no decision producing legal or similarly significant effects about you is made solely by automated means. You can always ignore, edit, or delete AI output, and account-level actions (like suspension) involve human review.

5. AI Processing and Third-Party Providers

To power AI features, certain data is sent to third-party AI providers for processing. We believe in complete transparency about this.

5.1 What Data Is Sent

  • Chat messages: The content of your conversation is sent to generate AI responses
  • Journal prompts: When you use AI-assisted reflection, your journal content may be sent for analysis
  • Context data: Relevant memories and context may be included to provide personalised responses

5.2 What Data Is NOT Sent

  • Your password or authentication credentials
  • Your health profile data
  • Your email address or account details
  • Data from features you are not actively using

5.3 Our AI Providers

We currently use OpenAI as the primary model for conversation. Amazon Web Services (Amazon Bedrock) runs Anthropic Claude models for background and execution tasks and takes over conversation if OpenAI is unavailable, with the Sydney (Australia) region as the primary endpoint, and runs Cohere models for search embeddings and ranking; some of this processing occurs in other AWS regions, including the United States. An OpenAI-compatible routing service (apitokens.org) serves OpenAI models for parts of the guided-wizard flow and for image generation, and is a last-resort fallback for conversation. When you switch on the natural voice, replies are read aloud by Google Cloud Text-to-Speech (processed on Google's global infrastructure), with Amazon Polly (Sydney region) as the fallback. On a paid plan, what you dictate with the microphone is transcribed by AssemblyAI (EU region); we delete the recording and transcript from AssemblyAI as soon as the text comes back. Profile images are edited on our own hardware. Under our agreements with OpenAI, Amazon Web Services and Google:

  • Your data is processed solely to generate AI responses for you
  • These providers do not use your data to train or improve their AI models
  • Data is transmitted over encrypted connections (TLS 1.2+)
  • Data is not retained by these providers beyond short abuse-monitoring windows (up to 30 days for some providers), and is never used to train their models

apitokens.org forwards requests to OpenAI models. We have not verified its own data-retention terms, so we use it only for guided-wizard steps, image generation and as a last-resort conversation fallback.

If we change AI providers, we will update this policy and notify you.

5.4 We Never Sell Your Data

We do not sell, rent, or trade your personal information to any third party, for any purpose, ever. This applies to all data categories, including data processed by AI providers.

6. Other Information Sharing

6.1 Service Providers

We use the following service providers, each bound by data processing agreements:

  • Cloud infrastructure: servers hosted in Australia (our own hardware)
  • AI processing: OpenAI (primary conversation model); Amazon Web Services / Amazon Bedrock (Anthropic Claude and Cohere models; Sydney region primary, with some processing in other regions including the United States); apitokens.org, an OpenAI-compatible routing service (guided wizards, image generation, conversation fallback); Google Cloud Text-to-Speech (natural voice; global infrastructure) and Amazon Polly (voice fallback; Sydney region); AssemblyAI (voice input; EU region) — see Section 11 on international transfers
  • Payments: Stripe — your card details are collected and stored by Stripe, never by us; we receive only the payment status and a customer reference
  • Transactional email: Resend (password resets, invitations, receipts, alerts you opt into)
  • Messaging (only if you connect it): Telegram — your morning message (task titles, questions, decision options) and your replies pass through and are stored by Telegram; not end-to-end encrypted
  • CDN and security: Cloudflare (DDoS protection and content delivery)

Error tracking stays in-house: when something breaks, the crash report is sent to error-tracking software we run on our own hardware — not to a third-party service — and it is scrubbed of request content before storage.

6.2 Legal Requirements

We may disclose information when required to:

  • Comply with a lawful court order, subpoena, or government request
  • Protect the rights, property, or safety of iSpirits, our users, or the public
  • Prevent fraud or enforce our Terms of Service

We will notify you of any government request for your data unless legally prohibited from doing so.

6.3 Business Transfers

If Teach P2P Pty Limited is involved in a merger, acquisition, or asset sale, your personal information may be transferred. We will provide notice before your data is transferred and becomes subject to a different privacy policy.

6.4 Connected Apps

You can let an AI tool you already use — such as Claude Desktop or Codex — read and act on your own goals, tasks and journal, using a personal access token you create and can revoke at any time under Profile → Connected apps. You choose which of those it can see and change. A connected app can never read your Life Spec, your iSpirit's memory of you, your chat history, or your wizard intake answers — there is no code path that returns them. What it can read is bounded to the goals, tasks and journal entries you've granted it: if something your iSpirit already wrote to your journal was shaped by your Life Spec or memory, a connected app with journal access sees that entry the same way you do on your own journal page — not the source it was built from, but not nothing either. Once something leaves iSpirits Cloud through a connected app, it is handled by that app's own provider under their own terms, not ours.

7. Data Security

  • At rest: Your data is stored on our own access-controlled infrastructure (not third-party cloud storage); credentials and secret keys are encrypted
  • Encryption in transit: All connections use TLS 1.2 or higher
  • Password security: Passwords are hashed using bcrypt with salt rounds
  • Access controls: Employee access to personal data is restricted on a need-to-know basis
  • Regular audits: We conduct regular security reviews of our infrastructure
  • Incident response: We have procedures in place to detect, report, and respond to data breaches within 72 hours as required by the GDPR and Australian privacy law

We comply with the Notifiable Data Breaches (NDB) scheme under the Privacy Act 1988. In the event of a data breach that is likely to result in serious harm, we will notify affected individuals and the OAIC within 72 hours of becoming aware of the breach.

8. Data Retention

Data Type Retention Period
Account information Until you delete your account
Chat messages and journal entries Until you delete them or your account
Health profile data Until you delete it or your account
Voice recordings Deleted within 24 hours of transcription
Server logs 90 days
After account deletion All personal data deleted within 30 days; backups purged within 90 days

9. Cookies

We use a minimal set of cookies:

Cookie Purpose Duration Type
Session token (JWT) Keeps you logged in 30 minutes (access) / 7 days (refresh) Essential
UX mode preference Remembers your Comfort Mode setting Persistent Functional
Cloudflare (__cf_bm) Bot protection and security 30 minutes Essential (third-party)

We do not use analytics cookies, advertising cookies, or tracking pixels. We do not use Google Analytics or any similar tracking service.

Our landing page sends us anonymous counts — page loaded, scrolled halfway or to the end, a button pressed — so we can tell whether visitors read it. No cookie, identifier or IP address is stored with these counts, and they cannot be linked to you.

When you ask your iSpirit to look something up, only the short search query leaves our systems — sent to Brave Search — never your goals, journal or chat.

10. Your Rights

10.1 All Users

Regardless of where you live, you have the right to:

  • Access your personal data (export via account settings or by request)
  • Correct inaccurate personal information
  • Delete your data (individual items or your entire account)
  • Object to processing of your personal information
  • Withdraw consent at any time for optional data collection (e.g., Health Profile)

10.2 Australian Privacy Act Rights

Teach P2P Pty Limited complies with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). As an Australian resident, you additionally have the right to:

  • Lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au if you believe we have breached the APPs
  • Request access to your personal information held by us free of charge
  • Not be disadvantaged for exercising your privacy rights

10.3 European Union / EEA (GDPR)

If you are in the EU or EEA, you have additional rights under the General Data Protection Regulation:

  • Right to data portability — receive your data in a structured, machine-readable format
  • Right to restrict processing — limit how we use your data
  • Right to erasure ("right to be forgotten")
  • Right to object to automated decision-making — our AI features do not make legally binding decisions about you
  • Right to lodge a complaint with your local data protection authority

Legal basis for processing: We process your data under Article 6(1)(b) (contract performance) for core service features, and Article 6(1)(a) (consent) for optional features like the Health Profile. For sensitive health data, we rely on Article 9(2)(a) (explicit consent).

10.4 California (CCPA/CPRA)

If you are a California resident:

  • You have the right to know what personal information we collect and how it is used
  • You have the right to delete your personal information
  • You have the right to opt out of the sale of personal information — we do not sell personal information
  • We will not discriminate against you for exercising your privacy rights

10.5 Exercising Your Rights

To exercise any of these rights, contact us at [email protected]. We will respond within 30 days (or sooner where required by law). We may ask you to verify your identity before processing your request.

11. International Data Transfers

Your data is primarily stored on servers located in Australia. When data is sent to AI providers (OpenAI, Amazon Web Services / Amazon Bedrock and Amazon Polly, apitokens.org, Google Cloud, and AssemblyAI) for processing, it may be temporarily processed on servers outside Australia — including where a nominally Australian endpoint routes through a provider's global infrastructure. Payment processing (Stripe), transactional email (Resend), and CDN/security (Cloudflare) also involve processing outside Australia, primarily in the United States. If you connect Telegram, your morning message and your replies are also processed and stored by Telegram outside Australia.

For transfers outside Australia, we rely on:

  • Standard contractual clauses approved by the European Commission (for EU data)
  • The fact that the recipient is subject to comparable privacy protections
  • Your informed consent (provided when you agreed to this policy)

12. Children's Privacy

iSpirits Cloud is for adults. You must be at least 18 years of age to use the Service — registration includes an age confirmation. We do not knowingly collect personal information from anyone under 18. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately at [email protected] and we will delete the information.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we make material changes, we will:

  • Post the updated policy on this page with a new "Last Updated" date
  • Notify you via email (if you have provided an email address)
  • Display a notice within the Service

Your continued use of the Service after a change becomes effective constitutes acceptance of the updated Privacy Policy. If you disagree with a change, you may delete your account.

14. Contact Us

If you have questions about this Privacy Policy, wish to exercise your rights, or want to make a complaint, please contact us:

Privacy Officer
Teach P2P Pty Limited
Sydney, NSW, Australia
Email: [email protected]
Response time: Within 30 days (within 72 hours for data breach notifications)

If you are not satisfied with our response, you may lodge a complaint with:

  • Australia: Office of the Australian Information Commissioner (OAIC) — oaic.gov.au
  • EU: Your local Data Protection Authority
  • UK: Information Commissioner's Office (ICO) — ico.org.uk

15. Version History

23 September 2026 — Added Telegram as an optional messaging channel you can connect for a morning message, and listed it among our service providers.

17 September 2026 — Voice input on paid plans is now transcribed by AssemblyAI in the EU, and deleted there once the text is returned.

16 September 2026 — Updated the AI-provider disclosure to match what runs the Service today: OpenAI as the primary conversation model, with Amazon Bedrock (Anthropic Claude, Sydney region primary) for background tasks and as the conversation fallback; Cohere on Amazon Bedrock for search; an OpenAI-compatible routing service (apitokens.org) for guided wizards, image generation and as a last-resort conversation fallback; Google Cloud Text-to-Speech for the natural voice, with Amazon Polly as its fallback. Microsoft Azure is no longer used.

2 August 2026 — Updated the AI-provider disclosure to match what actually runs the Service: Amazon Bedrock (Anthropic Claude + Cohere, Sydney region primary) as the primary platform, OpenAI as fallback, Microsoft Azure OpenAI for image generation and voice. Corrected the retention claim to acknowledge providers' short abuse-monitoring windows, and noted that Australian endpoints may route through global provider infrastructure.

5 July 2026 (second update) — Benchmark pass: international-transfers section now covers payments/email/CDN processors, and added an automated decision-making statement.

5 July 2026 — Named our actual service providers (Stripe for payments, Resend for email) and documented that error tracking is self-hosted on our own hardware. Minimum age raised from 16 to 18 to match registration.

Version Date Summary of Changes
1.1 6 April 2026 Fixed section numbering inconsistencies (Sections 5, 6, 10). Added Cookie Policy link. Added version history section.
1.0 4 April 2026 Initial publication.

This Privacy Policy is effective as of 4 April 2026 and was last updated on 23 September 2026.

See also: Legal entity information · Terms of Service · Cookie Policy