Legal Disclaimer: This document is a template prepared with reference to the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), and the Notifiable Data Breaches scheme (Part IIIC). It should be reviewed by a qualified Australian privacy lawyer before publication. It does not constitute legal advice.
Last Updated: 3 March 2026
This Privacy Policy describes how LostMind AI Pty Ltd (ABN [TBD]), a company registered in New South Wales, Australia ("ChatCrawler", "we", "us", or "our"), manages the personal information it collects, holds, uses, and discloses in connection with ChatCrawler Intelligence Edition ("the Service").
We are committed to complying with the Privacy Act 1988 (Cth) and the thirteen Australian Privacy Principles (APPs) contained in Schedule 1 of that Act. This policy is intended to be open and transparent about our information-handling practices so that you can make informed decisions about providing your personal information to us.
Our address: Sydney, New South Wales, Australia
Privacy contact: privacy@chatcrawler.com
This Privacy Policy applies to all personal information collected by ChatCrawler through:
This policy should be read together with our Terms of Service, which governs your use of the Service.
We only collect personal information that is reasonably necessary for, or directly related to, the provision of the Service. The categories of personal information we collect include:
If we receive personal information that we did not solicit, and we determine that we could not have collected it under APP 3, we will destroy or de-identify the information as soon as practicable, provided it is lawful and reasonable to do so.
We collect personal information:
Where it is reasonable and practicable to do so, we collect personal information directly from you rather than from third parties. We do not collect personal information by covert or deceptive means.
At or before the time we collect your personal information, we will take reasonable steps to notify you of the following matters (or ensure you are otherwise aware of them):
We use your personal information for the primary purpose for which it was collected, namely:
We may use or disclose your personal information for a secondary purpose if:
Our secondary purposes include:
We disclose personal information to the following third-party service providers solely for the purpose of providing the Service:
| Provider | Purpose | Data Shared |
|---|---|---|
| Stripe | Payment processing and subscription management | Email, name, payment details |
| Supabase (hosted on AWS) | Database, authentication | Account data, usage records, extraction metadata |
| Qdrant Cloud | Vector database for indexed content | Vector embeddings of extracted content (per-user isolated) |
| Upstash | Redis caching | Temporary session data, rate-limiting counters |
| Google (Gemini API) | AI content processing, summarisation, and chat responses | Extracted text sent for processing (not retained by Google under API terms) |
| Vercel | Frontend hosting and CDN | IP address, browser metadata (server logs) |
| Google Cloud Run | Backend API hosting | All data processed by the API (encrypted in transit) |
We may send you service-related communications, including subscription confirmations, usage alerts, security notices, and product updates. These are transactional in nature and are necessary for the operation of the Service.
If we send you marketing communications (such as newsletters or promotional offers), we will:
You may opt out of marketing communications at any time by using the unsubscribe link in any email or by contacting us at privacy@chatcrawler.com.
Before disclosing personal information to an overseas recipient, we take reasonable steps to ensure that the overseas recipient does not breach the APPs in relation to the information, or that an exception under APP 8.2 applies. You should be aware that, by consenting to the cross-border disclosures described below, we may not be accountable under the Privacy Act if the overseas recipient handles the information in breach of the APPs, and you may not be able to seek redress under the Privacy Act.
The following third-party service providers process or store data outside Australia:
| Provider | Service | Data Storage Location |
|---|---|---|
| Supabase (PostgreSQL) | Primary database and authentication | United States (AWS infrastructure) |
| Qdrant Cloud | Vector database for content embeddings | United States |
| Upstash (Redis) | Caching and rate limiting | United States |
| Stripe | Payment processing | United States |
| Google (Gemini API) | AI content processing | United States |
| Google Cloud Run | Backend API hosting | Australia (australia-southeast1, Sydney) |
All data transmitted to overseas recipients is encrypted in transit using TLS 1.2 or higher. We select service providers that maintain industry-standard security certifications (SOC 2, ISO 27001, or equivalent) and that contractually agree not to use your data for purposes other than providing the contracted service.
ChatCrawler does not collect, use, or disclose government-related identifiers (such as Tax File Numbers, Medicare numbers, or driver's licence numbers). We do not require you to provide any government-related identifier to use the Service.
We take reasonable steps to ensure that the personal information we collect, use, and disclose is accurate, up-to-date, complete, and relevant. You can help us maintain the quality of your personal information by updating your account details promptly when your information changes. See Section 12 for how to access and correct your information.
We take reasonable steps to protect the personal information we hold from misuse, interference, and loss, and from unauthorised access, modification, or disclosure. Our security measures include:
When personal information is no longer needed for any purpose for which it may be used or disclosed under the APPs, we will take reasonable steps to destroy or de-identify the information.
You have the right to request access to the personal information we hold about you. You can access most of your information directly through the Service:
For information not accessible through the Service, you may submit a written access request to privacy@chatcrawler.com. We will respond to your request within 30 days. We will not charge a fee for making or responding to an access request unless the request is manifestly excessive.
We may refuse access in the limited circumstances permitted by APP 12.3, including where providing access would pose a serious threat to the life or health of any individual, or where the request is frivolous or vexatious. If we refuse access, we will provide you with written reasons for the refusal.
You have the right to request correction of personal information we hold about you that is inaccurate, out-of-date, incomplete, irrelevant, or misleading. You can correct most information directly through your account settings.
For corrections you cannot make yourself, contact us at privacy@chatcrawler.com. We will respond to correction requests within 30 days. If we refuse to correct the information, we will provide written reasons and, at your request, attach a statement to the information noting that you consider it inaccurate.
Extracted content, indexed vector data, and chat histories are retained for the following periods, depending on your subscription tier:
| Subscription Tier | Retention Period |
|---|---|
| Freemium | 7 days |
| Basic | 30 days |
| Pro | 90 days |
| Max | 365 days |
After the applicable retention period, your extracted content, vector embeddings, and chat histories are automatically and permanently deleted from our systems.
Account information (email, name, subscription status) is retained for the duration of your account plus 30 days after account deletion, to allow for account recovery in case of accidental deletion.
You may delete your data at any time through the Service:
Deletion requests initiated through the Service are processed within 30 days. This is equivalent to the right of erasure under the EU General Data Protection Regulation (GDPR), Article 17.
ChatCrawler uses artificial intelligence (AI) and machine learning technologies. We believe in transparency about how AI is used within the Service.
We use AI (specifically, Google's Gemini large language model) for the following purposes:
Important: AI-generated content (including summaries, chat responses, and extraction results) may contain inaccuracies, omissions, or misinterpretations. AI responses do not constitute legal, financial, medical, or other professional advice. You should independently verify any critical information before relying on it.
When you use ChatCrawler to extract content from websites, the extracted content may contain personal information about third parties (for example, names, email addresses, or phone numbers published on the target website).
We use only essential cookies that are strictly necessary for the operation of the Service:
| Cookie | Purpose | Duration |
|---|---|---|
| Session cookie | Maintains your authenticated session | Until browser close or session expiry |
| Authentication token | Verifies your identity on subsequent requests | 7 days (refreshed on use) |
| CSRF token | Prevents cross-site request forgery attacks | Session |
We may use privacy-focused analytics tools to understand aggregated usage patterns (such as page views and feature adoption). If we implement analytics, we will update this section to identify the provider and the data collected. Any analytics tool we adopt will be configured to anonymise IP addresses and will not use third-party cookies.
We comply with the Notifiable Data Breaches (NDB) scheme established under Part IIIC of the Privacy Act 1988 (Cth).
In the event of an eligible data breach — that is, a breach that is likely to result in serious harm to any individual whose personal information is involved — we will:
The Service is not intended for, and is not directed at, individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a child under 18 without verified parental consent, we will take reasonable steps to delete that information as soon as practicable.
If you believe that we have inadvertently collected personal information from a child, please contact us immediately at privacy@chatcrawler.com.
If you believe that we have breached the APPs or otherwise handled your personal information inappropriately, you may lodge a complaint with us. Complaints should be directed to:
We will acknowledge receipt of your complaint within 5 business days and will investigate and respond to your complaint within 30 days. If we need additional time to investigate, we will notify you of the expected timeframe.
If you are not satisfied with our response to your complaint, or if you wish to make a complaint directly, you may contact the OAIC:
Office of the Australian Information Commissioner (OAIC)
We may update this Privacy Policy from time to time to reflect changes in our practices, the Services we offer, legal requirements, or other factors.
For material changes, we will provide you with at least 30 days' notice via email to the address associated with your account and/or by displaying a prominent notice on the Service. We encourage you to review this policy periodically.
The "Last Updated" date at the top of this page indicates when the most recent revision was published.
If you have any questions, concerns, or requests regarding this Privacy Policy or our handling of your personal information, please contact us:
| Right | How to Exercise |
|---|---|
| Access your data | Account Settings → Data Export |
| Correct your data | Account Settings → Edit Profile |
| Delete your data | Account Settings → Delete Account |
| Export your data | Account Settings → Data Export (JSON format) |
| Opt out of marketing | Unsubscribe link in emails, or contact privacy@chatcrawler.com |
| Lodge a complaint | Email privacy@chatcrawler.com or contact the OAIC (see Section 19) |
This Privacy Policy is effective as of 3 March 2026 and applies to all users of ChatCrawler Intelligence Edition.
© 2026 LostMind AI Pty Ltd. All rights reserved.