How Teach P2P Pty Limited collects, uses, and protects your personal information
Teach P2P Pty Limited ("iSpirits", "we", "our", or "us") operates the iSpirits Cloud platform at ispirits.cloud (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our Service.
We are committed to protecting your privacy and complying with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), the EU General Data Protection Regulation (GDPR), and applicable privacy legislation in all jurisdictions where we operate.
By creating an account or using our Service, you acknowledge that you have read, understood, and agree to the practices described in this Privacy Policy.
Our Health Profile feature allows you to voluntarily provide health information including medical conditions, allergies, medications, and mental health notes. This information is classified as sensitive information under the Privacy Act 1988 and as special category data under the GDPR.
Additionally, the nature of conversations with a personal AI companion may lead you to incidentally share sensitive information — including emotional states, family matters, health concerns, religious beliefs, or end-of-life wishes. We do not actively solicit sensitive information, but we acknowledge that it may arise naturally in your reflections. Any sensitive information shared in conversations is:
By continuing to share such information after reading this notice, you provide your explicit consent under the Privacy Act 1988 and GDPR Article 9(2)(a).
The following specific protections apply to Health Profile data:
We do not use your personal journal entries, chat messages, or health data for marketing purposes, advertising, or training our own AI models.
Your iSpirit is an artificial intelligence. It is not sentient, conscious, or human. Its personality is configured by software, not autonomous. While it remembers your conversations and learns your preferences, it does not have feelings, opinions, or experiences of its own.
The AI builds a profile of your values, interests, and communication style using vector embeddings stored in our database. This profile is used solely to provide more personalised responses. It is not shared with third parties.
iSpirits Cloud is not a healthcare service, mental health treatment, or substitute for professional advice of any kind.
Automated decision-making: the Service uses AI to generate suggestions, plans, and reflections, but no decision producing legal or similarly significant effects about you is made solely by automated means. You can always ignore, edit, or delete AI output, and account-level actions (like suspension) involve human review.
To power AI features, certain data is sent to third-party AI providers for processing. We believe in complete transparency about this.
We currently use Amazon Web Services (Amazon Bedrock) as our primary AI platform — running Anthropic Claude models for conversation and execution tasks and Cohere models for search embeddings, with the Sydney (Australia) region as the primary endpoint, though some processing may occur in other AWS regions. OpenAI serves as a fallback provider so conversations keep working during an outage, and Microsoft Azure OpenAI (operated by Microsoft Corporation) handles image generation and voice features. Under our agreements with these providers:
If we change AI providers, we will update this policy and notify you.
We do not sell, rent, or trade your personal information to any third party, for any purpose, ever. This applies to all data categories, including data processed by AI providers.
We use the following service providers, each bound by data processing agreements:
Error tracking stays in-house: when something breaks, the crash report is sent to error-tracking software we run on our own hardware — not to a third-party service — and it is scrubbed of request content before storage.
We may disclose information when required to:
We will notify you of any government request for your data unless legally prohibited from doing so.
If Teach P2P Pty Limited is involved in a merger, acquisition, or asset sale, your personal information may be transferred. We will provide notice before your data is transferred and becomes subject to a different privacy policy.
We comply with the Notifiable Data Breaches (NDB) scheme under the Privacy Act 1988. In the event of a data breach that is likely to result in serious harm, we will notify affected individuals and the OAIC within 72 hours of becoming aware of the breach.
| Data Type | Retention Period |
|---|---|
| Account information | Until you delete your account |
| Chat messages and journal entries | Until you delete them or your account |
| Health profile data | Until you delete it or your account |
| Voice recordings | Deleted within 24 hours of transcription |
| Server logs | 90 days |
| After account deletion | All personal data deleted within 30 days; backups purged within 90 days |
We use a minimal set of cookies:
| Cookie | Purpose | Duration | Type |
|---|---|---|---|
| Session token (JWT) | Keeps you logged in | 30 minutes (access) / 7 days (refresh) | Essential |
| UX mode preference | Remembers your Comfort Mode setting | Persistent | Functional |
| Cloudflare (__cf_bm) | Bot protection and security | 30 minutes | Essential (third-party) |
We do not use analytics cookies, advertising cookies, or tracking pixels. We do not use Google Analytics or any similar tracking service.
Regardless of where you live, you have the right to:
Teach P2P Pty Limited complies with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). As an Australian resident, you additionally have the right to:
If you are in the EU or EEA, you have additional rights under the General Data Protection Regulation:
Legal basis for processing: We process your data under Article 6(1)(b) (contract performance) for core service features, and Article 6(1)(a) (consent) for optional features like the Health Profile. For sensitive health data, we rely on Article 9(2)(a) (explicit consent).
If you are a California resident:
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days (or sooner where required by law). We may ask you to verify your identity before processing your request.
Your data is primarily stored on servers located in Australia. When data is sent to AI providers (Amazon Web Services / Amazon Bedrock, OpenAI, and Microsoft Azure OpenAI) for processing, it may be temporarily processed on servers outside Australia — including where a nominally Australian endpoint routes through a provider's global infrastructure. Payment processing (Stripe), transactional email (Resend), and CDN/security (Cloudflare) also involve processing outside Australia, primarily in the United States.
For transfers outside Australia, we rely on:
iSpirits Cloud is for adults. You must be at least 18 years of age to use the Service — registration includes an age confirmation. We do not knowingly collect personal information from anyone under 18. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately at [email protected] and we will delete the information.
We may update this Privacy Policy from time to time. When we make material changes, we will:
Your continued use of the Service after a change becomes effective constitutes acceptance of the updated Privacy Policy. If you disagree with a change, you may delete your account.
If you have questions about this Privacy Policy, wish to exercise your rights, or want to make a complaint, please contact us:
Privacy Officer
Teach P2P Pty Limited
Sydney, NSW, Australia
Email: [email protected]
Response time: Within 30 days (within 72 hours for data breach notifications)
If you are not satisfied with our response, you may lodge a complaint with:
2 August 2026 — Updated the AI-provider disclosure to match what actually runs the Service: Amazon Bedrock (Anthropic Claude + Cohere, Sydney region primary) as the primary platform, OpenAI as fallback, Microsoft Azure OpenAI for image generation and voice. Corrected the retention claim to acknowledge providers' short abuse-monitoring windows, and noted that Australian endpoints may route through global provider infrastructure.
5 July 2026 (second update) — Benchmark pass: international-transfers section now covers payments/email/CDN processors, and added an automated decision-making statement.
5 July 2026 — Named our actual service providers (Stripe for payments, Resend for email) and documented that error tracking is self-hosted on our own hardware. Minimum age raised from 16 to 18 to match registration.
| Version | Date | Summary of Changes |
|---|---|---|
| 1.1 | 6 April 2026 | Fixed section numbering inconsistencies (Sections 5, 6, 10). Added Cookie Policy link. Added version history section. |
| 1.0 | 4 April 2026 | Initial publication. |
This Privacy Policy is effective as of 4 April 2026 and was last updated on 2 August 2026.