Privacy Policy

Last updated: 26 June 2026

1. Who We Are

Coach Aandi is an AI-personalised learning platform for neurodivergent children. Direct family subscriptions are operated by Meet Aandi. Business-to-business commercial transactions (school pilots, allied health practitioner subscriptions) are operated by Brio Pty Ltd, an Australian company. Both entities apply the same privacy and security controls.

2. Information We Collect

We collect the minimum information necessary to deliver a personalised learning experience:

  • Parent or practitioner email address – for account access, communication, and notifications.
  • Child’s first name – to personalise the learning experience. We do not collect surnames.
  • Year level – to align lessons with the Australian Curriculum.
  • Learning preferences – learning styles, interests, and sensory preferences to tailor lesson delivery.
  • Mood data – daily mood assessments (e.g. calm, energetic, tired) used to adapt lesson tone and pacing.
  • Lesson history – completed lessons, engagement data, and progress tracking.
  • Feedback – child reactions and parent or practitioner notes on lessons.

3. Information We Do NOT Collect

This is a core principle of Coach Aandi. We deliberately do not collect:

  • Diagnosis information – we never ask for or store clinical diagnoses.
  • Clinical or medical data – we are an educational tool, not a health service.
  • Full names or identifying details of children – first name only.
  • Location data – we do not track or store your location.
  • Third-party tracking cookies – we do not use advertising trackers.

4. How We Use Your Data

  • Personalise learning – adapt lesson content, tone, and pacing based on your child’s profile and mood.
  • Improve the platform – analyse anonymised, aggregated data to enhance lesson quality and the learning experience.
  • Communicate with you – send account notifications, safety alerts, and platform updates.
  • Ensure child safety – monitor for concerning content and notify parents when safety flags are raised.

5. Data Storage and Residency

All persistent customer data is stored in Supabase, ap-southeast-2 (Sydney, Australia). Our hosting layer (Vercel) executes functions in the syd1 (Sydney, Australia) region.

Data leaves Australia only for: transient AI inference (lesson prompts to Cerebras in the United States, with no surnames or clinical data sent), AI image generation (prompts to Runware, no personal data sent), and transactional email delivery (recipient email address and message body to SendGrid in the United States). No persistent customer records are stored outside Australia.

We use encrypted connections (TLS 1.2 or higher) for all data in transit, and rely on Supabase’s AES-256 encryption at rest for stored data.

6. Third-Party Services

We use the following third-party services to operate Coach Aandi. For each, we name what data we send, whether they retain it, and the region they process in.

  • Supabase – database, authentication, and file storage. We send all customer-facing data here. Supabase retains this data as our primary store. Region: ap-southeast-2 (Sydney, Australia).
  • Vercel – website hosting and edge function execution. We send request metadata, IP addresses, and basic operational logs. Vercel retains these per their standard policy. Region: syd1 (Sydney, Australia).
  • Cerebras – large language model inference for lesson generation. We send lesson prompts including the child’s first name, year level, learning preferences, and mood. We do not send surnames, diagnoses, or any clinical data. Cerebras does not persist inference traffic by default. Region: United States.
  • Runware – AI image generation for lesson visuals. We send image generation prompts only. No personal information is sent. Region: EU/Global edge.
  • SendGrid – transactional email delivery (account notifications, password resets). We send recipient email addresses and message bodies. SendGrid retains delivery logs. Region: United States.

7. Children’s Privacy

We are committed to protecting children’s privacy and comply with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth).

  • Children do not create their own accounts. All accounts are managed by a parent, guardian, or authorised practitioner.
  • We practise minimal data collection – only what is needed for the learning experience.
  • Children cannot communicate with other users through the platform.
  • All AI interactions are structured lessons, not open-ended conversations.

8. Data Retention and Deletion

We retain your data for as long as your account is active. Student records use soft deletes to maintain data integrity and support anonymised aggregate analysis to improve the platform.

Parents or practitioners can request full deletion of their data at any time by emailing us at gerard.blokdyk@theartofservice.com. We will process deletion requests within 30 days.

9. Security Measures

We take the security of your data seriously and have implemented the following measures:

  • Row Level Security (RLS) – database policies ensure parents and practitioners can only access their own family’s or practice’s data.
  • Encrypted connections – all data is transmitted over HTTPS/TLS.
  • Multi-factor authentication on admin accounts – staff who access the administrative back-end must complete TOTP-based MFA on every session.
  • No sensitive data in local storage – we do not store personal or learning data in the browser’s localStorage.
  • Secure authentication – powered by Supabase Auth with industry-standard password hashing.

Our full security policy is available at /security.

10. Notifiable Data Breaches

We comply with the Australian Notifiable Data Breaches (NDB) scheme under the Privacy Act 1988 (Cth), Part IIIC. If we become aware of an eligible data breach (unauthorised access or disclosure of personal information likely to result in serious harm), we will:

  • Conduct a reasonable and expeditious assessment within 30 days.
  • Notify the Office of the Australian Information Commissioner (OAIC) as soon as practicable after determining the breach is eligible.
  • Notify each affected individual whose personal information was involved, with a description of the breach and the steps they can take in response.

11. Your Rights

Under the Australian Privacy Principles, you have the right to:

  • Access the personal information we hold about you and your child.
  • Request correction of any inaccurate information.
  • Request deletion of your data (see section 8).
  • Lodge a complaint with the Office of the Australian Information Commissioner (OAIC) if you believe your privacy has been breached.

12. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you via the email address associated with your account. The “Last updated” date at the top of this page indicates when the policy was last revised.

13. Contact Us

If you have any questions or concerns about this Privacy Policy or how we handle your data, please contact us at: gerard.blokdyk@theartofservice.com