Draft. This privacy notice is published for review while Ask The Captain is in its first voyage. It has not yet had legal review and is not approved for reliance; the text is dated 31 August 2026.

Ask The Captain Privacy Notice

DRAFT FOR HUMAN AND LEGAL REVIEW — NOT APPROVED FOR PUBLICATION OR RELIANCE.

This draft is structured with the Australian Privacy Principles (APPs) in mind and is GDPR-aware. It does not conclude that any particular law applies. Every legally significant statement has a reviewer note. Replace all placeholders, complete a data inventory, and obtain privacy counsel review before collecting information from external tenants.

Draft date: 31 August 2026
Proposed entity: Someday Somehow Brewing, an Australian-incorporated business (legal entity name, ACN/ABN and address to be inserted)
Product: Ask The Captain at askthecaptain.app
Privacy contact: [privacy email and postal address to be inserted]

Reviewer note — scope and APP status: Confirm the legal entity and whether it is an APP entity, including turnover and any small-business exceptions or inclusions. Decide whether Captain is controller, processor/service provider, or both in each data flow; identify an EU/UK representative or DPO only if required.

1. What this notice covers

This notice describes how Captain proposes to collect, hold, use, and disclose personal information about tenant owners, authorised users, contacts appearing in tenant data, website visitors, support contacts, and people whose information enters connected workflows.

Reviewer note — data subjects and layered notices: Validate this population against the final product, mobile app, support, marketing, onboarding, employment, and integration flows. Determine which people require direct APP 5 collection notices or GDPR Articles 13/14 notices in addition to this policy.

2. Information we may handle

Proposed categories are:

Captain is not designed to require sensitive information, but tenant content may contain it. Tenants should avoid submitting sensitive information unless the feature expressly supports it and they have authority to do so.

Reviewer note — inventory and sensitive information: Complete a field-level data map before publication. Confirm biometrics/passkeys, camera/voice permissions, precise location, payment handling, analytics/crash tools, cookie identifiers, government identifiers, children’s data, inferred data, and each category of APP “sensitive information” or GDPR special-category/criminal-offence data. Decide whether sensitive content is prohibited, consent-based, or contractually controlled.

3. How information may be collected

Information may be collected directly from a user during signup, onboarding, use, support, or a privacy request; from a tenant administrator; from content uploaded or recorded by a user; automatically from use of the Service; and from third-party services that a tenant deliberately connects.

Reviewer note — collection mechanics: Verify every source, including website analytics, app-store data, referrals, public websites imported during onboarding, vendor webhooks, support tools, cookies/SDKs, and indirectly collected contact data. Prepare just-in-time notices and consent flows where required.

4. Proposed purposes

Captain proposes to use personal information to:

Captain does not propose to use tenant content for targeted advertising or sell personal information.

Reviewer note — purposes and lawful bases: Confirm necessity and proportionality for each purpose. If GDPR applies, map each processing activity to a lawful basis and document any legitimate-interest assessment; identify consent-dependent processing and withdrawal effects. Confirm whether identifiable tenant content, prompts, or outputs may be used for product/model improvement—this draft assumes no such use beyond providing and improving service quality and must be narrowed if needed.

5. AI processing and automated decisions

When a user invokes a connected Anthropic or OpenAI mode, relevant prompts and context may be sent to that user-selected vendor to produce an output. Captain’s product rule is that models interpret and propose while deterministic services and people decide protected operations. Captain does not propose to make solely automated decisions that have legal or similarly significant effects on individuals.

Reviewer note — automated decision transparency: Verify actual workflows and human-review controls. Australian APP 1 automated-decision privacy-policy amendments are scheduled to commence on 10 December 2026; determine whether any decision is within scope and add the required kinds-of-information and decision descriptions. If GDPR applies, assess Article 22 and related transparency obligations. Re-check vendor training, retention, and enterprise settings for each connection mode.

6. Disclosures, service providers, and user-directed vendors

Personal information may be disclosed to infrastructure and service providers needed to operate Captain, and to connected services at the tenant’s direction. The current proposed provider set is documented in the subprocessor register. It includes Fly.io, Neon, AWS KMS, Cloudflare, GitHub, Tigris, and—only when selected or connected—Anthropic or OpenAI.

Captain may also disclose information where required or authorised by law, to professional advisers under confidentiality, during a corporate transaction subject to appropriate protections, or to prevent a serious threat or address misuse.

Reviewer note — recipients and roles: Confirm the complete vendor list, professional advisers, payment/email/push/crash/analytics/app-store providers, corporate-transaction language, compulsory process, and each recipient’s legal role. The label “subprocessor” may not fit user-directed AI vendors or DNS-only Cloudflare; settle this in contracts and the register.

7. Overseas processing

Core application and database infrastructure is planned for Sydney, Australia. Some providers operate globally or may process support, account, security, or user-directed AI data outside Australia. Known or planned locations are listed in the subprocessor register; locations that are not contractually pinned are identified as such.

Reviewer note — cross-border disclosure: Conduct the APP 8 analysis and specify likely destination countries where practicable. If GDPR applies, document adequacy decisions, standard contractual clauses, transfer-impact assessments, and supplementary measures. Confirm whether access from another country is a “use” or “disclosure” under the applicable framework and do not claim Australian-only residency unless contracts and telemetry support it.

8. Storage, security, and credentials

Proposed safeguards include tenant isolation, role-based access, authenticated encryption for stored credentials, per-tenant envelope keys backed by AWS KMS, short-lived capability tokens, audit records, encrypted transport, backups, access review, and an incident process. User subscription credentials for hosted Claude Code or Codex clients are intended to remain between the user, the unmodified client, and the selected vendor; Captain should record connection status rather than the vendor session credential.

Reviewer note — security accuracy: Validate every statement against production before publication and avoid disclosing exploitable detail. Confirm encryption scope, backup encryption, access locations, support controls, Sprite credential isolation, certifications, security retention, and contractual security standard. No security measure should be described as absolute.

9. Retention and deletion

Captain proposes to retain personal information only while needed for the purposes above, the Customer relationship, security, backup, dispute, tax, and legal requirements. Tenant offboarding is intended to revoke access and connections, offer an export, apply any authorised retention hold, and then delete data through a controlled process. Specific retention periods have not yet been approved.

Reviewer note — mandatory retention schedule: Insert category-specific periods and triggers for accounts, tenant content, credentials, logs, audit events, backups, support, billing, rejected invitations, deleted accounts, hosted user environments, and legal holds. Confirm APP 11.2 destruction/de-identification duties, GDPR storage limitation where applicable, backup deletion practicality, export windows, and deletion receipts.

10. Access, correction, and other choices

Individuals may ask Captain to access or correct personal information Captain controls by contacting [privacy contact]. Captain will verify identity, coordinate with the relevant tenant where the tenant controls the information, and respond as required by applicable law. Users may manage connections, permissions, notifications, and certain account information through product settings when those controls are available.

If GDPR applies to a request, additional rights may include erasure, restriction, portability, objection, withdrawal of consent, and complaint to a supervisory authority. Those rights are subject to legal conditions and exceptions.

Reviewer note — rights procedure: Define request intake, identity verification, authorised agents, tenant/controller routing, response periods, refusal grounds and notices, fees, correction statements, export format, consent withdrawal, and regulator contacts. Do not present GDPR rights as universally applicable; determine territorial scope and the correct controller for each request.

11. Complaints

Privacy complaints may be sent to [privacy contact] with enough detail to investigate. Captain proposes to acknowledge a complaint promptly, investigate fairly, communicate an outcome, and explain available escalation. People may be entitled to complain to the Office of the Australian Information Commissioner (OAIC) or another competent regulator.

Reviewer note — complaint procedure: Insert acknowledgement and substantive-response targets, escalation owner, record retention, OAIC prerequisites/contact wording, relevant state or overseas regulators, and non-retaliation commitments. Confirm Captain’s APP status before implying a statutory OAIC pathway.

12. Data breaches

Captain will handle suspected personal-information breaches under its incident process. Where the Australian Notifiable Data Breaches scheme applies, an eligible data breach requires notification to affected individuals at risk of serious harm and the OAIC. Other laws may impose different or shorter deadlines.

Reviewer note — notification duties: Confirm whether the NDB scheme applies to the entity and each incident. The OAIC states that suspected eligible breaches must be assessed expeditiously, with all reasonable steps taken to complete assessment within 30 calendar days, and eligible breaches notified as soon as practicable. If GDPR applies, supervisory-authority notification may be due within 72 hours. Counsel must direct each notification decision.

13. Children

The Service is intended for adult business users and is not directed to children. Tenant content could nevertheless contain information about a child.

Reviewer note — children: Decide whether under-18 account use is prohibited, how age is handled, whether child-related tenant content is prohibited or restricted, parental-consent requirements, and whether the Children’s Online Privacy Code or overseas children’s laws may apply at launch.

14. Changes and contact

Captain proposes to publish changes to this notice and give additional notice for material changes before they take effect where required. Questions and requests should be directed to [privacy email and postal address].

Reviewer note — publication and notice: Insert version/effective dates, change-notice method and period, archived versions, accessibility formats, translations, and final contact details. APP 1 generally expects a clearly expressed, current policy made freely available; this draft must not be published as the final policy.

Reference points for reviewers

Reviewer note — sources: These links are orientation material, not a legal opinion or exhaustive statement of applicable law. Counsel must verify currency and applicability at review and launch.