Privacy Policy
Last updated: 24 August 2026
This Privacy Policy explains how Bot Write Pty Ltd (ABN 40 699 673 151) collects, uses and protects personal information when you use Bot FP. We handle personal information in accordance with the Australian Privacy Principles in the Privacy Act 1988 (Cth).
1. Information we collect
We collect account information, uploaded client and firm documents (including meeting notes, fact finds, statements and other evidence), generated drafts and advice documents, and limited usage and billing metadata. Full card details are handled by Stripe and are never stored on our servers.
2. How we use your information
We use personal information to operate and improve the service, authenticate users, generate advice documents, process payments and invoices, and maintain security and integrity.
3. Third parties and disclosure
We share information with service providers only as needed to run the service: email delivery, payment processing (Stripe), hosting and file storage, and AI model providers. Uploaded client documents, instructions and generated draft text are processed by large-language-model providers — routed through The Bot Club's AI gateway to Anthropic (primary) and, as an automatic backup, OpenAI — to draft and check advice documents; under the API terms we use these providers do not use your content to train their models. We do not sell personal information.
4. Overseas disclosure
Some providers store or process personal information outside Australia, principally in the United States — including the AI model providers (Anthropic and OpenAI), hosting, file storage, email and payment processing. Client documents, including any sensitive information such as health information in insurance fact finds, are sent to those AI model providers whenever a document is drafted or checked. We take reasonable steps under APP 8.1, including contractual terms, to ensure overseas recipients handle personal information consistently with the Australian Privacy Principles.
5. Storage and security
We take reasonable steps to protect personal information from misuse, loss and unauthorised access, including access controls and encrypted connections.
6. Data retention
We retain information only as long as needed to provide the service or meet legal obligations. Eligible account data can be erased through controlled secure deletion; billing and content-free pseudonymised audit records may be retained where required.
7. Access, correction and deletion rights
You may request access to, correction of or erasure of personal information, subject to the retention obligations in this policy.
8. Data breach notification
We will notify affected people and, where required, the Office of the Australian Information Commissioner in accordance with applicable law.
9. Cookies and sessions
We use a secure session cookie to keep you signed in. We do not use third-party advertising cookies.
10. Complaints
Please contact us first with privacy concerns. If you are not satisfied with our response, you can contact the Office of the Australian Information Commissioner.
11. Changes to this policy
We may update this Privacy Policy from time to time. The date above shows when it was last revised.
12. Contact us
For privacy questions or requests, contact us at [email protected].