← Back to Home 中文版

Privacy Policy

How Teach P2P Pty Limited collects, uses, and protects your personal information

Effective Date: 4 April 2026 · Last updated: 2 August 2026
Operator: Teach P2P Pty Limited (ABN 18 627 201 487), Sydney, NSW, Australia

1. Introduction

Teach P2P Pty Limited ("iSpirits", "we", "our", or "us") operates the iSpirits Cloud platform at ispirits.cloud (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our Service.

We are committed to protecting your privacy and complying with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), the EU General Data Protection Regulation (GDPR), and applicable privacy legislation in all jurisdictions where we operate.

By creating an account or using our Service, you acknowledge that you have read, understood, and agree to the practices described in this Privacy Policy.

2. Information We Collect

2.1 Information You Provide Directly

  • Account Information: Username, email address, and password (stored as a one-way bcrypt hash — we never store your password in plain text)
  • Profile Information: Display name, profile picture, date of birth, gender, country, and preferences
  • Chat Content: Messages and conversations with AI companions
  • Journal Entries: Written and voice-recorded reflections, including mood scores, gratitude notes, and insights
  • Timeline Events: Life events, milestones, goals, and achievements you record
  • Health Information: Medical history, allergies, medications, and mental health notes you choose to provide (see Section 2.4)
  • Voice Data: Audio recordings submitted through voice journaling and chat features, which are transcribed and then deleted from our servers within 24 hours
  • Habits and Goals: Habit check-ins, streaks, goal progress, and priority settings
  • Feedback: Bug reports, feature requests, and support messages

2.2 Information Collected Automatically

  • Usage Data: Pages visited, features used, and session duration
  • Device Information: Device type, operating system, browser type
  • Log Data: Server request logs (IP address, request timestamps, error codes), retained for up to 90 days for security and debugging
  • Cookies: Session cookies for authentication and preference cookies for settings (see Section 8)

2.3 Information from Third Parties

  • Google Sign-In: If you sign in with Google, we receive your name, email address, and profile picture from Google. We do not receive your Google password.

2.4 Sensitive Information

Our Health Profile feature allows you to voluntarily provide health information including medical conditions, allergies, medications, and mental health notes. This information is classified as sensitive information under the Privacy Act 1988 and as special category data under the GDPR.

Additionally, the nature of conversations with a personal AI companion may lead you to incidentally share sensitive information — including emotional states, family matters, health concerns, religious beliefs, or end-of-life wishes. We do not actively solicit sensitive information, but we acknowledge that it may arise naturally in your reflections. Any sensitive information shared in conversations is:

  • Processed solely to generate personalised AI responses and deliver the Service
  • Never used for marketing, advertising, or profiling
  • Subject to the same security and access-control protections as all other data
  • Covered by the same contractual protections with our AI provider

By continuing to share such information after reading this notice, you provide your explicit consent under the Privacy Act 1988 and GDPR Article 9(2)(a).

The following specific protections apply to Health Profile data:

  • We only collect this information with your explicit consent (you actively choose to fill in the Health Profile form)
  • Health data is used solely to help your AI companion provide more relevant, health-aware support
  • Health data is never shared with third-party AI providers, advertisers, or insurers
  • You can delete your Health Profile at any time from your account settings

3. How We Use Your Information

3.1 Providing the Service

  • Generating AI companion responses based on your conversations
  • Storing and displaying your journal entries, timeline events, and habits
  • Calculating insights, mood trends, and habit analytics
  • Growing your iSpirit based on your interactions
  • Enabling voice input by transcribing audio recordings

3.2 Improving the Service

  • Analysing aggregate, anonymised usage patterns to improve features
  • Fixing bugs and monitoring system performance
  • Developing new features based on aggregate user needs

We do not use your personal journal entries, chat messages, or health data for marketing purposes, advertising, or training our own AI models.

3.3 Communications

  • Sending account-related notifications (password resets, security alerts)
  • Responding to support requests
  • Sending product updates (you can opt out at any time)

3.4 Security and Legal Compliance

  • Protecting against fraud, abuse, and unauthorised access
  • Complying with legal obligations (e.g., responding to lawful court orders)
  • Enforcing our Terms of Service

4. AI Companion Disclosure

Your iSpirit is an artificial intelligence. It is not sentient, conscious, or human. Its personality is configured by software, not autonomous. While it remembers your conversations and learns your preferences, it does not have feelings, opinions, or experiences of its own.

The AI builds a profile of your values, interests, and communication style using vector embeddings stored in our database. This profile is used solely to provide more personalised responses. It is not shared with third parties.

iSpirits Cloud is not a healthcare service, mental health treatment, or substitute for professional advice of any kind.

Automated decision-making: the Service uses AI to generate suggestions, plans, and reflections, but no decision producing legal or similarly significant effects about you is made solely by automated means. You can always ignore, edit, or delete AI output, and account-level actions (like suspension) involve human review.

5. AI Processing and Third-Party Providers

To power AI features, certain data is sent to third-party AI providers for processing. We believe in complete transparency about this.

5.1 What Data Is Sent

  • Chat messages: The content of your conversation is sent to generate AI responses
  • Journal prompts: When you use AI-assisted reflection, your journal content may be sent for analysis
  • Context data: Relevant memories and context may be included to provide personalised responses

5.2 What Data Is NOT Sent

  • Your password or authentication credentials
  • Your health profile data
  • Your email address or account details
  • Data from features you are not actively using

5.3 Our AI Providers

We currently use Amazon Web Services (Amazon Bedrock) as our primary AI platform — running Anthropic Claude models for conversation and execution tasks and Cohere models for search embeddings, with the Sydney (Australia) region as the primary endpoint, though some processing may occur in other AWS regions. OpenAI serves as a fallback provider so conversations keep working during an outage, and Microsoft Azure OpenAI (operated by Microsoft Corporation) handles image generation and voice features. Under our agreements with these providers:

  • Your data is processed solely to generate AI responses for you
  • These providers do not use your data to train or improve their AI models
  • Data is transmitted over encrypted connections (TLS 1.2+)
  • Data is not retained by these providers beyond short abuse-monitoring windows (up to 30 days for some providers), and is never used to train their models

If we change AI providers, we will update this policy and notify you.

5.4 We Never Sell Your Data

We do not sell, rent, or trade your personal information to any third party, for any purpose, ever. This applies to all data categories, including data processed by AI providers.

6. Other Information Sharing

6.1 Service Providers

We use the following service providers, each bound by data processing agreements:

  • Cloud infrastructure: servers hosted in Australia (our own hardware)
  • AI processing: Amazon Web Services / Amazon Bedrock (Anthropic Claude and Cohere models; Sydney region primary), OpenAI (fallback), and Microsoft Azure OpenAI (image generation and voice; Australia East and US East 2 regions) — see Section 11 on international transfers
  • Payments: Stripe — your card details are collected and stored by Stripe, never by us; we receive only the payment status and a customer reference
  • Transactional email: Resend (password resets, invitations, receipts, alerts you opt into)
  • CDN and security: Cloudflare (DDoS protection and content delivery)

Error tracking stays in-house: when something breaks, the crash report is sent to error-tracking software we run on our own hardware — not to a third-party service — and it is scrubbed of request content before storage.

6.2 Legal Requirements

We may disclose information when required to:

  • Comply with a lawful court order, subpoena, or government request
  • Protect the rights, property, or safety of iSpirits, our users, or the public
  • Prevent fraud or enforce our Terms of Service

We will notify you of any government request for your data unless legally prohibited from doing so.

6.3 Business Transfers

If Teach P2P Pty Limited is involved in a merger, acquisition, or asset sale, your personal information may be transferred. We will provide notice before your data is transferred and becomes subject to a different privacy policy.

7. Data Security

  • At rest: Your data is stored on our own access-controlled infrastructure (not third-party cloud storage); credentials and secret keys are encrypted
  • Encryption in transit: All connections use TLS 1.2 or higher
  • Password security: Passwords are hashed using bcrypt with salt rounds
  • Access controls: Employee access to personal data is restricted on a need-to-know basis
  • Regular audits: We conduct regular security reviews of our infrastructure
  • Incident response: We have procedures in place to detect, report, and respond to data breaches within 72 hours as required by the GDPR and Australian privacy law

We comply with the Notifiable Data Breaches (NDB) scheme under the Privacy Act 1988. In the event of a data breach that is likely to result in serious harm, we will notify affected individuals and the OAIC within 72 hours of becoming aware of the breach.

8. Data Retention

Data Type Retention Period
Account information Until you delete your account
Chat messages and journal entries Until you delete them or your account
Health profile data Until you delete it or your account
Voice recordings Deleted within 24 hours of transcription
Server logs 90 days
After account deletion All personal data deleted within 30 days; backups purged within 90 days

9. Cookies

We use a minimal set of cookies:

Cookie Purpose Duration Type
Session token (JWT) Keeps you logged in 30 minutes (access) / 7 days (refresh) Essential
UX mode preference Remembers your Comfort Mode setting Persistent Functional
Cloudflare (__cf_bm) Bot protection and security 30 minutes Essential (third-party)

We do not use analytics cookies, advertising cookies, or tracking pixels. We do not use Google Analytics or any similar tracking service.

10. Your Rights

10.1 All Users

Regardless of where you live, you have the right to:

  • Access your personal data (export via account settings or by request)
  • Correct inaccurate personal information
  • Delete your data (individual items or your entire account)
  • Object to processing of your personal information
  • Withdraw consent at any time for optional data collection (e.g., Health Profile)

10.2 Australian Privacy Act Rights

Teach P2P Pty Limited complies with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). As an Australian resident, you additionally have the right to:

  • Lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au if you believe we have breached the APPs
  • Request access to your personal information held by us free of charge
  • Not be disadvantaged for exercising your privacy rights

10.3 European Union / EEA (GDPR)

If you are in the EU or EEA, you have additional rights under the General Data Protection Regulation:

  • Right to data portability — receive your data in a structured, machine-readable format
  • Right to restrict processing — limit how we use your data
  • Right to erasure ("right to be forgotten")
  • Right to object to automated decision-making — our AI features do not make legally binding decisions about you
  • Right to lodge a complaint with your local data protection authority

Legal basis for processing: We process your data under Article 6(1)(b) (contract performance) for core service features, and Article 6(1)(a) (consent) for optional features like the Health Profile. For sensitive health data, we rely on Article 9(2)(a) (explicit consent).

10.4 California (CCPA/CPRA)

If you are a California resident:

  • You have the right to know what personal information we collect and how it is used
  • You have the right to delete your personal information
  • You have the right to opt out of the sale of personal information — we do not sell personal information
  • We will not discriminate against you for exercising your privacy rights

10.5 Exercising Your Rights

To exercise any of these rights, contact us at [email protected]. We will respond within 30 days (or sooner where required by law). We may ask you to verify your identity before processing your request.

11. International Data Transfers

Your data is primarily stored on servers located in Australia. When data is sent to AI providers (Amazon Web Services / Amazon Bedrock, OpenAI, and Microsoft Azure OpenAI) for processing, it may be temporarily processed on servers outside Australia — including where a nominally Australian endpoint routes through a provider's global infrastructure. Payment processing (Stripe), transactional email (Resend), and CDN/security (Cloudflare) also involve processing outside Australia, primarily in the United States.

For transfers outside Australia, we rely on:

  • Standard contractual clauses approved by the European Commission (for EU data)
  • The fact that the recipient is subject to comparable privacy protections
  • Your informed consent (provided when you agreed to this policy)

12. Children's Privacy

iSpirits Cloud is for adults. You must be at least 18 years of age to use the Service — registration includes an age confirmation. We do not knowingly collect personal information from anyone under 18. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately at [email protected] and we will delete the information.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we make material changes, we will:

  • Post the updated policy on this page with a new "Last Updated" date
  • Notify you via email (if you have provided an email address)
  • Display a notice within the Service

Your continued use of the Service after a change becomes effective constitutes acceptance of the updated Privacy Policy. If you disagree with a change, you may delete your account.

14. Contact Us

If you have questions about this Privacy Policy, wish to exercise your rights, or want to make a complaint, please contact us:

Privacy Officer
Teach P2P Pty Limited
Sydney, NSW, Australia
Email: [email protected]
Response time: Within 30 days (within 72 hours for data breach notifications)

If you are not satisfied with our response, you may lodge a complaint with:

  • Australia: Office of the Australian Information Commissioner (OAIC) — oaic.gov.au
  • EU: Your local Data Protection Authority
  • UK: Information Commissioner's Office (ICO) — ico.org.uk

15. Version History

2 August 2026 — Updated the AI-provider disclosure to match what actually runs the Service: Amazon Bedrock (Anthropic Claude + Cohere, Sydney region primary) as the primary platform, OpenAI as fallback, Microsoft Azure OpenAI for image generation and voice. Corrected the retention claim to acknowledge providers' short abuse-monitoring windows, and noted that Australian endpoints may route through global provider infrastructure.

5 July 2026 (second update) — Benchmark pass: international-transfers section now covers payments/email/CDN processors, and added an automated decision-making statement.

5 July 2026 — Named our actual service providers (Stripe for payments, Resend for email) and documented that error tracking is self-hosted on our own hardware. Minimum age raised from 16 to 18 to match registration.

Version Date Summary of Changes
1.1 6 April 2026 Fixed section numbering inconsistencies (Sections 5, 6, 10). Added Cookie Policy link. Added version history section.
1.0 4 April 2026 Initial publication.

This Privacy Policy is effective as of 4 April 2026 and was last updated on 2 August 2026.

See also: Legal entity information · Terms of Service · Cookie Policy