Privacy Policy

Last updated: 19 June 2026

1. About this Policy

Boomerang Study ("we", "us", "our") operates Boomerang.study. We comply with the Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles (APPs). We also comply with the Information Privacy Act 2009 (Qld), the Privacy and Personal Information Protection Act 1998 (NSW), and the Privacy and Data Protection Act 2014 (Vic) where applicable.

2. Data storage and processing locations

Storage: all personal information (profile, attempts, marking, tutor chat, adaptive state, preferences, subscription metadata) is stored exclusively in Australia on AWS infrastructure in the ap-southeast-2 (Sydney) region.

Processing: we are transparent that some real-time processing occurs outside Australia via the subprocessors listed in Section 6. Specifically: AI marking, tutor responses, and handwriting/photo answer extraction (OCR) are processed by Google (Gemini API) and OpenAI (GPT API), routed via US/AP-region inference under paid-tier API terms that prohibit use of your data for model training and limit any retention to short-term abuse monitoring by the provider; the application is served via Cloudflare's global edge network, which means request handling may execute in a Cloudflare PoP geographically nearest your device — no personal data is persisted at the edge. Email delivery is handled by our transactional email provider. We do not transfer data offshore for any other purpose, and we never store personal data outside Australia.

3. What we collect

Account data: name, email, year level, curriculum authority. Practice activity: questions answered, marks, timestamps, session type. AI marking inputs: question text and student answer only — no name, email, or user ID is included. AI chat messages: stored in our Australian database for future personalisation and quality improvement (deletable — see Section 8). Question feedback you submit. Browser type (for app functionality only).

4. How we use your data

Service delivery and adaptive personalisation (contractual necessity). Transactional emails (contractual necessity). Subscription processing via Stripe (contractual necessity). Quality improvement using aggregated anonymised data (consent, opt-out available). Legal compliance (legal obligation). We do not use data for advertising, commercial profiling, or sale.

5. AI marking, tutor, and answer extraction processing

Written answers sent for AI marking and tutor responses include: question text, mark scheme, marks available, and student answer. Photos and handwriting sent for answer extraction (OCR) include the captured image plus the question text for context. We never include name, email, or any user identifier. To keep the service reliable, each AI feature is routed through a fallback chain of providers — if the first model is unavailable or returns an invalid response, we automatically retry with the next.

The current chains are: Marking and tutor: Google Gemini 2.5 Flash → OpenAI GPT-5 mini → Google Gemini 2.5 Pro. Answer extraction (photo / handwriting OCR): OpenAI GPT-5 → Google Gemini 2.5 Pro. The specific model that produced each mark is shown on the result and stored against the attempt for audit. We may add, remove, or re-order providers in these chains, and any change to the set of providers will be reflected in this Policy.

All current providers are used on paid API tiers whose terms state that customer inputs and outputs are not used to train their models, and are retained only for short periods for abuse monitoring and legal compliance by the provider before deletion. Inference may occur in US or AP regions depending on the provider. See Google Gemini API terms and OpenAI API data usage policies.

Uploaded images (photos, PDFs, stylus / handwriting captures): when you upload a photo of your working, a PDF, or a drawing for OCR, the file is stored in our Australian-region file storage bucket (Supabase, ap-southeast-2), scoped to your account and accessible only to you and our OCR pipeline. The image is sent to the OCR provider under the API terms above and is not retained by the provider beyond the short abuse-monitoring window described above. Within our storage, the original image is retained alongside the attempt so you can review what was submitted; it is deleted automatically when you delete the attempt, wipe a subject's data under Settings → Privacy & data, or delete your account (which triggers a full storage purge within 30 days). We do not use uploaded images for training, analytics or any purpose other than extracting your answer text and letting you review your own submission.

6. Subprocessors

We use the following subprocessors. Each is bound by a Data Processing Agreement and the data flow described below.

  • Supabase — database, authentication, file storage. Region: Australia (ap-southeast-2). Data: all account data and practice content.
  • Cloudflare — application hosting, TLS termination, edge serving. Region: global (request executes at the PoP nearest you; no personal data persisted at the edge).
  • Google (Gemini API) — AI marking and tutor responses (primary). Region: US/AP. Data: question text + your answer only (no identifiers). Paid API tier: not used for training; retained only for short-term abuse monitoring.
  • OpenAI (GPT API) — AI marking fallback when Gemini is unavailable. Region: US. Data: question text + your answer only (no identifiers). Paid API tier: not used for training; retained only for short-term abuse monitoring.
  • Stripe — subscription billing and payment processing. Region: global; payment card data resides in Stripe's PCI DSS Level 1 environment. Data: email, name, payment instrument.
  • Resend — transactional email delivery (receipts, password resets, weekly digest). Region: US. Data: email address and message content.

We do not sell, rent, or trade personal information. We may disclose data if required by law or court order. The current subprocessor list is reviewed quarterly; material changes will be reflected in this Policy.

7. Student privacy — users under 18

We primarily serve students aged 16–18. We do not serve advertising. We do not share student data with schools, government, or third parties without consent. Users under 13 require parental consent.

8. Parent Access (optional)

Students can choose to link a parent or guardian to their account. When linked, the parent sees: study activity (time spent, sessions, questions attempted), assessment scores and accuracy by subject and topic, AI feedback summaries (high-level marker comments on written answers, not the full student text), and the weekly digest email. Parents do not see: full student answer text, tutor chat conversations, or login credentials.

Revoking access: the student can disconnect a linked parent at any time from Settings › Parent Access. Revoking is immediate — the parent loses all visibility on the next page load and stops receiving the weekly digest. Historical digest emails already delivered to the parent's inbox cannot be recalled by us.

9. Your rights

Access & portability: download a complete JSON export of your account, attempts, tutor chat, adaptive state, preferences and subscriptions from Settings › Privacy & data ("Download my data").

Correction: edit profile in Settings or contact us.

Granular deletion: Settings › Privacy & data lets you, per subject, clear tutor chat, reset adaptive learning state, or delete every attempt; or do the same globally across all subjects. The History page lets you clear chat or delete any individual attempt.

Full account deletion: Settings › Account › "Delete account" schedules permanent deletion. A 30-day grace period applies — sign in any time within those 30 days and click "Cancel deletion" to keep your account. After 30 days, your profile, attempts, tutor chat, adaptive state, preferences and question reports are irreversibly purged from our Australian database. Account deletion is blocked while an active paid subscription exists — cancel in Settings › Billing first. Billing records are retained for ~7 years as required by Australian tax law (see Section 10).

Withdrawal of consent: toggle optional data uses in Settings › Privacy.

Complaint: contact us first, then the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or 1300 363 992.

10. State considerations

QLD: Information Privacy Act 2009. NSW: Privacy and Personal Information Protection Act 1998. VIC: Privacy and Data Protection Act 2014. All states: Privacy Act 1988 (Cth) as the national minimum standard.

11. Data retention

Personal data deleted within 30 days of confirmed account deletion request (after the 30-day grace period). Anonymised aggregate statistics may be retained indefinitely. Stripe and our internal billing records are retained for ~7 years per Australian financial regulations even after account deletion. Inactive accounts (24 months no login) receive a deletion notice before removal.

12. Security

TLS 1.2+ on all connections. bcrypt password hashing. Row Level Security on every database table. API keys stored in encrypted server secrets (never in client code). Notifiable Data Breach (NDB) scheme compliance — affected users and OAIC notified within 30 days of a confirmed breach.

13. Cookies and local storage

Session cookies: authentication only — essential for login. LocalStorage: curriculum cache and session draft state — no personal data. No advertising, tracking, or fingerprinting cookies.

14. Contact

For privacy enquiries use our privacy contact form. Response within 10 business days.