Bot FP Back to home

Privacy Policy

Last updated: 24 August 2026

This Privacy Policy explains how Bot Write Pty Ltd (ABN 40 699 673 151) collects, uses and protects personal information when you use Bot FP. We handle personal information in accordance with the Australian Privacy Principles in the Privacy Act 1988 (Cth).

1. Information we collect

We collect account information, uploaded client and firm documents (including meeting notes, fact finds, statements and other evidence), generated drafts and advice documents, and limited usage and billing metadata. Full card details are handled by Stripe and are never stored on our servers.

2. How we use your information

We use personal information to operate and improve the service, authenticate users, generate advice documents, process payments and invoices, and maintain security and integrity.

3. Third parties and disclosure

We share information with service providers only as needed to run the service: email delivery, payment processing (Stripe), hosting and file storage, and AI model providers. Uploaded client documents, instructions and generated draft text are processed by large-language-model providers — routed through The Bot Club's AI gateway to Anthropic (primary) and, as an automatic backup, OpenAI — to draft and check advice documents; under the API terms we use these providers do not use your content to train their models. We do not sell personal information.

4. Overseas disclosure

Some providers store or process personal information outside Australia, principally in the United States — including the AI model providers (Anthropic and OpenAI), hosting, file storage, email and payment processing. Client documents, including any sensitive information such as health information in insurance fact finds, are sent to those AI model providers whenever a document is drafted or checked. We take reasonable steps under APP 8.1, including contractual terms, to ensure overseas recipients handle personal information consistently with the Australian Privacy Principles.

5. Storage and security

We take reasonable steps to protect personal information from misuse, loss and unauthorised access, including access controls and encrypted connections.

6. Data retention

We retain information only as long as needed to provide the service or meet legal obligations. Eligible account data can be erased through controlled secure deletion; billing and content-free pseudonymised audit records may be retained where required.

7. Access, correction and deletion rights

You may request access to, correction of or erasure of personal information, subject to the retention obligations in this policy.

8. Data breach notification

We will notify affected people and, where required, the Office of the Australian Information Commissioner in accordance with applicable law.

9. Cookies and sessions

We use a secure session cookie to keep you signed in. We do not use third-party advertising cookies.

10. Complaints

Please contact us first with privacy concerns. If you are not satisfied with our response, you can contact the Office of the Australian Information Commissioner.

11. Changes to this policy

We may update this Privacy Policy from time to time. The date above shows when it was last revised.

12. Contact us

For privacy questions or requests, contact us at [email protected].