Privacy Policy

Effective: 7 July 2026

1. Who we are

Guidelya ("Guidelya", "we", "us", "our") provides AI-guided onboarding for major life transitions. This Privacy Policy explains how we handle personal information in accordance with the Privacy Act 1988 (Cth), the 13 Australian Privacy Principles (APPs), the Notifiable Data Breaches (NDB) scheme, and the Privacy and Other Legislation Amendment Act 2024. Where they apply to you, we also comply with the EU / UK GDPR, the California CCPA/CPRA, Brazil's LGPD (Lei Geral de Proteção de Dados), China's PIPL (Personal Information Protection Law), India's DPDP Act 2023, and the transparency duties of the EU AI Act.

Legal review notice. This document is a plain-English template. It is not legal advice. If any of it conflicts with a binding contract you have signed with us, that contract prevails.

2. Information we collect

  • Account data: name, email address, password hash, display name, preferences (locale, timezone, notifications).
  • Journey data: the tasks you tick, custom notes, journey selections (e.g. Student, Parent), progress state.
  • Assistant data: the messages you send to our AI chat, including any context you choose to share (e.g. suburb, visa status, due date).
  • Technical data: IP address, device/browser type, cookies, referral/click data used to attribute partner referrals.
  • Sensitive information (as defined by APP 3): collected only with your express consent when relevant to your journey (e.g. health or pregnancy details you volunteer to the assistant). You can decline and still use the service.

3. How we use your information

  • To provide personalised guidance, checklists and progress tracking.
  • To operate the AI assistant and improve prompt quality.
  • To match you with verified partners you choose to engage.
  • To send you account, security and service-related notices.
  • To meet legal, tax, and safety obligations.

We do not sell your personal information. We do not use your data or chats to train third-party foundation models.

4. AI transparency (EU AI Act & global norms)

Guidelya uses large language models via the Lovable AI Gateway to generate suggestions and chat replies. You are always interacting with an AI — not a licensed professional. AI output can be wrong, incomplete or out-of-date. Guidelya does not provide legal, migration, medical or financial advice; we surface thought-provoking guidance and links to verified official sources.

We do not use your inputs to train the underlying models. Prompts are transmitted to the model provider strictly to generate your reply and are retained only as needed to run the service.

5. Legal bases (GDPR / UK GDPR)

Where GDPR applies, we rely on:

  • Contract: to deliver the service you request.
  • Consent: for optional analytics, marketing cookies, and any sensitive information.
  • Legitimate interests: to secure the service, prevent fraud, and improve product quality.
  • Legal obligation: to meet tax, safety and regulatory duties.

6. Sharing & disclosure

We do not sell your personal information and we do not share it for cross-context behavioural advertising. We disclose personal information only to:

  • Subprocessors that run the service under written data-processing agreements (see Section 7).
  • Verified partners you engage with. When you tap a referral or booking link we share only the minimum needed for the introduction (typically the referral ID and the fact that you came from Guidelya). If a form asks for your name, contact details or a description of your need, we tell you clearly before you submit and only pass what you provided.
  • Onboarded service providers that we recommend to you. Providers are onboarded by our admin team, sign a Partnership Agreement with confidentiality and data-protection obligations, and only receive user information when you have chosen to contact them.
  • Law enforcement, regulators and courts where we are legally required, or where we believe in good faith it is necessary to protect rights, safety or the integrity of the service.
  • Successors in a merger, acquisition or restructuring, subject to equivalent privacy protections and notice to you.

7. Subprocessors

We rely on the following categories of subprocessors. A current list is available on request from privacy@goeasy.app.

  • Supabase — managed Postgres database, auth and file storage (data hosted in the region configured for the project).
  • Cloudflare — content delivery, DDoS protection, and Worker runtime for server functions.
  • Lovable AI Gateway — routes assistant prompts to the underlying model provider; prompts are not used to train third-party foundation models.
  • Resend — transactional email delivery for security notices, agreement notifications and account updates.

8. Cross-border data transfers

Personal information may be processed outside Australia (typically in the US, EU, or Singapore) by the subprocessors listed above. For each region we rely on the appropriate lawful transfer mechanism:

  • Australia (APP 8): we take reasonable steps to ensure overseas recipients handle your data consistently with the APPs.
  • EU / UK GDPR: Standard Contractual Clauses (SCCs) and, where applicable, the UK IDTA plus supplementary measures.
  • Brazil (LGPD): ANPD-recognised safeguards including SCCs and specific consent where required by Art. 33.
  • China (PIPL): separate consent for outbound transfers of PIPL-covered data and standard contract filings where applicable under Art. 38.
  • India (DPDP): transfers to jurisdictions not restricted by the Central Government under s.16.

9. Data security & account protection

We use encryption in transit (TLS), encryption at rest, row-level security in our database, hashed passwords, least-privilege access, and audit logging. In addition, Guidelya gives every account the following protections you can manage under Settings → Security:

  • Two-factor authentication (2FA): optional TOTP-based 2FA using any authenticator app (Google Authenticator, 1Password, Authy, etc.), with 10 single-use recovery codes stored only as one-way hashes.
  • Strong-password enforcement: minimum 10 characters with a real-time strength check (zxcvbn); weak or commonly-breached passwords are rejected at sign-up and reset.
  • Rate limiting: sign-in, sign-up and password-reset attempts are throttled per email and IP to slow credential-stuffing and brute-force attacks.
  • Security activity log: review recent sign-ins, password changes, 2FA changes and session revocations, with a "This wasn't me" panic action that signs out every device and forces a password reset.
  • Active session management: see every device and browser currently signed in and revoke any of them individually.
  • Idle auto sign-out: configurable inactivity timeout (15 / 30 / 60 minutes, or never) so an unattended device doesn't stay logged in.
  • Email privacy: your email address is masked in the UI (e.g. h•••o@gmail.com) and is never exposed through the public API — other users only see your display name and avatar via a restricted public profile view.

No system is 100% secure — please use a strong, unique password and enable 2FA. If you suspect your account has been compromised, use the "This wasn't me" action in your security activity log immediately and contact privacy@goeasy.app.

10. Data retention

We keep personal information only as long as needed for the purpose it was collected, or as required by law (for example, signed partnership agreements are retained for the life of the commercial relationship plus seven years for tax and audit purposes). You can request deletion at any time (see Section 12); we will honour it except where a specific legal obligation requires us to retain the record.

11. Data breach notification

If a data breach is likely to result in serious harm, we will notify affected individuals and the relevant regulator within the statutory window — the Office of the Australian Information Commissioner (OAIC) under the NDB scheme, EU / UK supervisory authorities within 72 hours under GDPR Art. 33, Brazil's ANPD under the LGPD, and other regulators as required by PIPL, DPDP and state-level US breach-notice laws.

12. Your rights (by region)

Every user, regardless of location, can:

  • Access the personal information we hold about you.
  • Correct information that is inaccurate or out-of-date.
  • Request deletion of your account and associated data.
  • Withdraw consent, including for cookies and marketing.
  • Port your data in a machine-readable format.
  • Object to fully automated decisions that produce legal or similarly significant effects, and request human review.

Region-specific rights:

  • Australia (Privacy Act 1988): lodge a complaint with the OAIC at oaic.gov.au.
  • EU / UK (GDPR): right to restriction of processing (Art. 18), right to lodge a complaint with your local Data Protection Authority.
  • California (CCPA/CPRA): right to know, delete, correct, and limit use of sensitive personal information; right to opt out of sale/sharing (we do not sell or share for cross-context behavioural advertising).
  • Brazil (LGPD): right to information about public and private entities with which we have shared your data (Art. 18 IV) and right to review of automated decisions.
  • China (PIPL): right to withdraw separate consent for sensitive information or cross-border transfers; right to nominate a person to exercise rights on your behalf after death.
  • India (DPDP Act): right to nominate another individual to exercise rights on your behalf, and right of grievance redressal via our Grievance Officer.

To exercise any right, email privacy@goeasy.app. We respond within 30 days (or the shorter statutory window that applies to you) and never charge a fee for a first request.

13. Cookies

We use strictly-necessary cookies to run the service and, only with your consent, optional analytics and preference cookies. Consent is captured through the cookie banner and can be changed at any time. See Cookie Settings.

14. Children

Guidelya is not directed to children under 15 (or under 18 in jurisdictions that treat all minors as children for privacy purposes, including India's DPDP Act). We do not knowingly collect their personal information. Contact us if you believe a child has provided data and we will delete it.

15. Changes to this policy

When we make material changes, we will update the "Effective" date above, publish a version note through the in-app policy banner, and notify registered users by email at least 14 days before the changes take effect. Continued use after that date means you accept the updated policy.

16. Contact & Grievance Officer

Privacy Officer, Guidelya — privacy@goeasy.app

This inbox also serves as our Grievance Officer for the purposes of India's DPDP Act and as our EU / UK Article 27 representative point of contact pending appointment of a local representative.