Privacy Policy
Last updated: 17 June 2026
1. Who we are and the scope of this policy
This Privacy Policy explains how personal information is handled in connection with AI Super Hub (the "Service"), a web application and installable progressive web app (PWA) available at https://aisuperhub.app.
The Service is operated by Koby Bryant, an individual operating as a sole trader, trading as "AI Super Hub" ("we", "us", "our"). We are based in Queensland, Australia.
We are committed to handling personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). The Office of the Australian Information Commissioner (OAIC) regulates privacy in Australia.
This policy applies to personal information we collect through the Service, including from:
- the account owner (our customer — typically a business operator using AI Super Hub);
- people whose information our customers enter into, upload to, or generate within the Service (for example their own customers, leads, and staff);
- visitors to public pages we serve (such as public booking pages, forms, course pages, storefront tracking snippets, and these policy pages).
Controller and processor — an important distinction for business data
AI Super Hub is a multi-tenant business platform. Where you (our business customer) upload, enter, or otherwise provide the personal information of your own customers, leads, contacts, or staff, you are responsible for that information as its controller, and we act on your behalf as your processor / service provider. In those cases you are responsible for having a lawful basis to collect that information, for providing any required privacy notices to those individuals, and for handling their requests. We handle that information in accordance with your instructions and this policy.
Where we collect personal information for our own purposes — for example to create and manage your account, to bill you, to provide support, and to operate and secure the Service — we act as the responsible entity for that information.
2. The personal information we collect
The Service is modular and you control which modules you use, so not all of the categories below will apply to you. The following is an itemised list, drawn from the actual data the Service handles, of the categories we may collect and why.
2.1 Account and authentication data
- Email address and password (passwords are managed and hashed by our authentication provider, Supabase; we do not store your plaintext password).
- Display name, timezone (defaults to Australia/Brisbane), and multi-factor authentication preferences.
- Passkey / WebAuthn credentials (FIDO2 — e.g. Face ID, Touch ID, Windows Hello, or a security key). We store a credential identifier, public key, device type and a friendly name; the private key never leaves your device.
- Session information, audit logs of actions taken in your account (actor, action, resource, IP address, user-agent, timestamp), login attempts, device fingerprints (stored as hashes), and account-lockout state used for security and fraud prevention.
- Developer API keys (stored as hashes) and webhook subscriptions, if you use the Developer API module.
Why: to create and secure your account, authenticate you, prevent unauthorised access and fraud, and maintain an audit trail.
2.2 Business profile and billing data
- Business name, trading name, ABN, ACN, business address, phone, website, and logo.
- Billing contact details (full name, email, phone, company name, country), your PayPal Payer ID (last-seen, for receipts), marketing opt-in flag, and your transaction and entitlement history.
Why: to identify your business, generate invoices and receipts, process payments, and determine which modules you can access. Note that your business banking details entered for invoice rendering (BSB/account number) are stored to display on invoices; see the security section for how we protect data and the honest limitations disclosed there.
2.3 Financial data
If you use the Finance / AI Accountant module:
- Income and expense records, categories, GST treatment, line items, vendors, and payment methods.
- Receipt images and OCR text (receipt scanning may use OpenAI vision or, optionally, Google Vision API).
- Invoices, customers/debtors, payments, refunds, general-ledger entries, and tax-pack drafts.
- Bank statement imports (via CSV upload or bank-import flows) and personal finance records, if you choose to use those features.
Why: to provide bookkeeping, invoicing, expense tracking and tax-summary features. Financial information is sensitive; we handle it accordingly.
2.4 CRM and customer / lead data
If you use the CRM, Marketing, Lead Generator, Booking, Reputation, or storefront-tracking features, we process information about your contacts, leads and customers, which may include:
- Names, emails, phone numbers, company, job title, address, website, social links, tags, notes, lead scores, and deal/pipeline information.
- Publicly-sourced lead signals harvested for the Lead Generator (for example public posts, author handles, business listings) and enriched contact details.
- Customer profiles and storefront behavioural events (page views, product views, add-to-cart, search, checkout events, referrer, user-agent, device type, approximate country) collected via tracking snippets you embed.
- Booking details, review requests, and NPS survey responses.
Why: to provide the CRM, marketing, lead-generation, booking and reputation features you have chosen to use. For this data you are generally the controller and we act as your processor.
2.5 Staff and team data (Team Portal)
If you use the Team Portal, we process information about your staff, which can include sensitive employment and identity information:
- Names, emails, phone numbers, avatars, roles, job titles, employment type, hourly rate, start/end dates, and status.
- Date of birth, home address, Tax File Number (TFN), bank BSB and account number, superannuation fund and member number, and emergency contact details.
- Certifications, availability and rostering preferences, shifts and clock-in/out records (including GPS location at clock-in where location tracking is enabled), and shift-change history.
- Sick calls and absence records, including uploaded medical certificates (stored in a private, application-encrypted storage bucket).
- Onboarding documents and e-signatures (the typed full name and timestamp captured as a record of acceptance).
- Team chat messages, web-push subscription tokens, and kudos / engagement data.
Why: to provide rostering, time-tracking, onboarding, communication and staff-management features to you as the employer. You are the controller of your staff's information and are responsible for notifying your staff and having a lawful basis for collecting it (including TFNs and other government identifiers, which carry specific legal obligations).
2.6 Health and fitness data — sensitive information
If you use the personal Health & Fitness features:
- Health logs (activity, energy, weight, water, habits), nutrition logs (meals, calories, macros, photos), fitness settings (height, weight, goals), and workout routines, sessions and sets.
Health information is sensitive information under the Privacy Act and the APPs and is given additional protection. We only collect it where you actively enter or upload it.
2.7 Location data — sensitive in some contexts
- Friend location sharing (latitude, longitude, accuracy, heading, speed, altitude, precision mode) where you choose to share, controlled by an in-app toggle.
- Staff clock-in GPS coordinates and "at-shop" geofence checks, where a team enables location tracking.
Why: to provide optional location-sharing and geofenced clock-in features. These features are off unless enabled by the relevant user or team.
2.8 Calendar, goals, ideas and reminders
- Calendar events, reminders, goals and milestones, and ideas/roadmap items you create.
Why: to provide scheduling, planning and productivity features.
2.9 Smart home / IoT data (owner-scoped)
- Rooms, devices, device states, scenes, automations, command logs, and connection configuration (provider tokens, host URLs and API keys are encrypted at rest) if you use the Smart Home module.
Why: to let you connect and control smart-home devices through the Service.
2.10 Trading data (read-only)
- Read-only exchange balances and portfolio valuations where you connect a crypto exchange (Bybit, Binance, OKX, Coinbase) using credentials you supply (stored encrypted). Connected wallets via WalletConnect operate client-side.
Why: to provide balance monitoring and the paper-trading / simulation features. The trading module operates in paper/simulation mode; no real trades are executed by the Service.
2.11 Marketing platform and content data
- Brand voice profiles, campaigns, content drafts, scheduled posts, audience segments, A/B tests, and encrypted access/refresh tokens for any marketing platform connections you authorise.
Why: to provide AI-assisted content generation and campaign management.
2.12 AI assistant ("Bo") data
- Your conversations and messages with Bo, including text, tool inputs/outputs, optional voice audio, and token counts.
- "Memories" — facts, preferences and context Bo retains about you, stored with vector embeddings for recall. You can view, correct, verify, and delete these in the Memory module, and disable memory for a given conversation.
- Voice preferences, autonomy settings, and notification preferences.
Why: to provide the conversational assistant and to personalise its responses. You control what Bo remembers.
2.13 Inputs to AI features generally
Many modules send the content you provide — prompts, business text, documents, images, receipts, audio, and contextual data — to third-party AI providers to generate output. See the next section.
2.14 Notifications and communications
- Web-push subscription tokens, email/SMS preferences, quiet hours, and optional Telegram chat IDs.
Why: to deliver the notifications and reminders you have enabled.
2.15 Cookies and similar technologies
We use a small set of essential and preference cookies and first-party storage. We do not use third-party advertising or cross-site behavioural-tracking cookies (no Google Analytics, Facebook Pixel, Segment, Mixpanel, Amplitude, Hotjar, or similar). See our Cookie Policy for the full list.
3. How we collect personal information
We collect personal information:
- Directly from you — when you create an account, configure your business, enter data into modules, upload files, or interact with Bo.
- From your authorised users and staff — for example when staff clock in, complete onboarding, or send messages in the Team Portal.
- From integrations you connect — for example orders and customer details synced from Shopify, transactions from Xero or MYOB, or video metrics from YouTube.
- From public sources — where you use the Lead Generator, which harvests publicly available signals and business listings (for example via Google Places, public posts and review sites).
- Automatically — limited technical data such as IP address, user-agent and device fingerprint for security, and first-party storefront/widget events where you deploy our tracking snippets.
4. AI providers and our position on training
To deliver its features, the Service sends relevant inputs to third-party AI providers. Depending on the feature, this can include your prompts, business text, documents, contracts, receipts and other images, audio recordings, and contextual business or personal data.
The AI providers we use are:
- Anthropic (Claude) — legal drafting, marketing copy, strategy, classification, lead outreach and other reasoning tasks.
- OpenAI — live chat, vision (e.g. receipt and image analysis), structured outputs, image generation, and Whisper speech-to-text.
- ElevenLabs — text-to-speech (voice replies and voiceovers).
- Stability AI — optional photorealistic image generation.
- Replicate (MusicGen) — optional background-music generation.
Our honest position on AI training: We do not sell your personal information, and our intention is that the data you submit through the Service is used to provide the feature you requested and is not used to train third-party AI models. We rely on the AI providers' commercial / business terms, which for the providers named above generally state that data submitted via their APIs is not used to train their models by default. However, we do not control those third parties, their terms can change, and you should review their own privacy terms. We do not use your content to train our own general-purpose AI models. AI-generated output can be inaccurate or incomplete, and you are responsible for reviewing it before relying on it; certain modules (legal, finance/tax, health/fitness, trading, marketing) carry specific disclaimers in our Terms of Service.
5. Sub-processors and disclosure of your information
We disclose personal information to service providers ("sub-processors") who help us operate the Service. We do not sell personal information. Many of these services are env-gated, meaning they are only active if you or we have configured the relevant integration.
| Service | Purpose | Data involved |
|---|---|---|
| Supabase | Database, authentication, file storage, real-time | Account, app data, uploaded files |
| Vercel | Hosting and serverless execution | Technical request data (e.g. IP, user-agent) |
| Anthropic (Claude) | AI reasoning, drafting, classification | Prompts and contextual content you submit |
| OpenAI | AI chat, vision, image generation, transcription | Prompts, images, audio, business data |
| ElevenLabs | Text-to-speech | Text to be voiced |
| Stability AI | Image generation (optional) | Image prompts and reference images |
| Replicate (MusicGen) | Music generation (optional) | Prompts and optional input audio |
| PayPal | Payments, subscriptions, payouts | Order details, amounts, payer info, email |
| Resend / SendGrid / Postmark / AWS SES | Transactional & marketing email | Recipient email, subject, content |
| Twilio / ClickSend | SMS and WhatsApp messaging | Recipient phone numbers, message content |
| Telegram | Optional notifications | Notification content, chat ID |
| Web Push (VAPID) | In-app/browser push notifications | Push subscription tokens, notification content |
| Shopify | Store, order, product and customer sync | Orders, products, inventory, customer details |
| Amazon SP-API / eBay Sell API | Marketplace product listing | Product/listing data |
| Xero / MYOB | Accounting sync | Transactions, invoices, contacts |
| Google Places API | B2B lead search, address lookup | Search queries, location |
| Google Vision API | Receipt OCR (optional) | Receipt/image data |
| Google (OAuth / YouTube) | Sign-in and video upload | Email, profile, video files and metadata |
| Shotstack | Video rendering (optional) | Video timeline (images, audio, captions) |
| Crypto exchanges (Bybit, Binance, OKX, Coinbase) & CoinGecko | Read-only balance monitoring and pricing | Encrypted exchange credentials, balances |
| WalletConnect | Client-side wallet connection | Wallet address, signing requests |
| Cloudflare Turnstile | Anti-bot CAPTCHA | CAPTCHA token, IP (privacy-preserving) |
| TinEye | Reverse image search (optional) | Image hash/URL |
| IPapi.co | IP geolocation (optional) | IP address |
| Error webhook (optional) | Error reporting | Error details, limited context |
| FTP/SFTP servers (user-configured) | Data feed export | Product/inventory feed data |
We may also disclose personal information where required or authorised by law, to protect our rights or the safety of others, or in connection with a sale or restructure of our business.
6. Overseas disclosure and international data transfers (APP 8)
Several of our sub-processors operate, store data, or process data outside Australia. In particular:
- Supabase and Vercel may store or process data in overseas regions (for example the United States or Europe).
- The AI providers (Anthropic, OpenAI, ElevenLabs, Stability AI, Replicate), PayPal, email and SMS providers, Shopify, Amazon, eBay, Google, and other services listed above are likely to process data overseas, commonly in the United States.
This means that by using the Service, your personal information (and, for business customers, the personal information you upload) may be disclosed to and processed by recipients located overseas. We take reasonable steps to use reputable providers, but we cannot guarantee that overseas recipients will be subject to laws substantially similar to the APPs. Where you upload other individuals' personal information, you are responsible for ensuring your own compliance with APP 8 in respect of that disclosure.
7. How we protect your information
We use a range of security measures, and we describe them honestly below. We do not hold, and do not claim, any formal security certifications (such as ISO 27001, SOC 2, or PCI DSS). Payment card processing is handled by PayPal; we do not store card numbers.
Measures we actually use include:
- Application-level encryption (AES-256-GCM) of sensitive items such as third-party API keys and OAuth tokens, and of certain private documents (for example uploaded medical certificates), before storage.
- Encrypted OAuth tokens and credentials for connected integrations (e.g. Shopify, Xero/MYOB, YouTube, marketing connections, exchange credentials).
- Row-Level Security (RLS) in our database to isolate data per user and per team.
- Access controls and authentication, including passkeys/WebAuthn, optional multi-factor authentication, optional IP-based session binding, idle logout, brute-force lockout, and anti-bot CAPTCHA.
- Private storage buckets with time-limited signed URLs for sensitive files (receipts, onboarding documents, medical certificates).
- Audit logging of sensitive actions.
- Encryption in transit via HTTPS.
Despite these measures, no method of transmission or storage is completely secure. An honest limitation we disclose: certain banking details entered for invoice rendering and certain staff bank details may be stored without additional application-level encryption beyond our database and access controls; please take this into account when deciding what to enter. If our encryption keys were compromised, application-encrypted data could be at risk. We encourage you to use strong, unique credentials and to enable multi-factor authentication.
8. How long we keep your information
We keep personal information for as long as it is needed to provide the Service, to maintain your account, to comply with legal obligations (for example, tax and business records), to resolve disputes, and to enforce our agreements.
- Account and business data is retained while your account is active.
- Transaction and billing records are retained for the period required by Australian law (tax records are generally retained for several years).
- Bo "memories" may have an expiry you can configure, and you can delete them at any time.
- Login attempts are retained for around 90 days; some security records are kept only while active.
- Some tracking and event data does not have a fixed automatic purge and is retained subject to storage limits; you may request deletion.
When personal information is no longer needed, we will take reasonable steps to delete or de-identify it. If you close your account, we will delete or de-identify your data within a reasonable period, except where we are required or permitted by law to retain it.
9. Cookies and tracking
We use only essential and preference cookies and first-party storage, and a small set of first-party analytics tools (for example storefront and chatbot widget visitor IDs that you deploy). We do not use third-party advertising or cross-site behavioural tracking. For the full, itemised list of cookies and storage we use — and how to control them — please see our Cookie Policy.
10. Your privacy rights (the APPs)
Under the Australian Privacy Principles, you have rights to:
- Access the personal information we hold about you;
- Correct information that is inaccurate, out of date, incomplete or misleading;
- Ask questions about how we handle your information; and
- Complain if you believe we have breached the APPs.
To exercise any of these rights, contact us at admin@aisuperhub.app. We will respond within a reasonable time. We may need to verify your identity before acting on a request. There is generally no charge for making a request, though we may charge a reasonable cost for access in some circumstances. If we refuse access or correction, we will tell you why and how you can complain.
For information held on behalf of a business customer: if you are an individual whose information was uploaded by a business that uses AI Super Hub (for example as their customer, lead, or staff member), that business is generally responsible for your information as the controller. Please direct access, correction and deletion requests to that business in the first instance; we will assist them as their processor.
11. Making a complaint
If you have a privacy concern or complaint, please contact us first at admin@aisuperhub.app so we can try to resolve it. We will acknowledge your complaint and aim to respond within a reasonable time.
If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC):
- Website: https://www.oaic.gov.au
- Phone: 1300 363 992
12. Data breaches (Notifiable Data Breaches scheme)
We have procedures to identify and respond to data breaches. If a data breach occurs that is likely to result in serious harm to affected individuals, we will comply with the Notifiable Data Breaches (NDB) scheme under the Privacy Act. This means we will assess the breach and, where required, notify affected individuals and the OAIC as soon as practicable. Where we act as a processor for a business customer, we will notify that customer promptly so they can meet their own obligations.
13. Children and eligibility
The Service is intended for business and professional use by adults aged 18 or over. It is not directed at children, and we do not knowingly collect personal information from children. If you believe a child has provided personal information to us, please contact us so we can take appropriate steps. Where business customers upload information about individuals (including, for example, staff who may be under 18), that customer is responsible for ensuring they have any necessary consents.
14. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes to the Service, our practices, or the law. When we make material changes, we will update the "Last updated" date above and, where appropriate, take additional steps to notify you. Your continued use of the Service after an update constitutes acceptance of the revised policy.
15. How to contact us
For any privacy enquiry, request, or complaint, contact:
AI Super Hub (Koby Bryant, sole trader) Email: admin@aisuperhub.app Location: Queensland, Australia
We will handle your enquiry in accordance with this policy and the Australian Privacy Principles.
Other policies
Questions about this Privacy Policy? Contact us at admin@aisuperhub.app.