Privacy Policy

Last updated: 19 May 2026 · Effective: 19 May 2026

Important disclaimer: Carearoo generates AI-assisted draft reports only. All AI-generated content must be reviewed, verified, and approved by the qualified occupational therapist or allied health professional responsible for the client. Carearoo does not provide clinical advice, medical advice, or professional recommendations. The registered clinician bears full responsibility for the accuracy, appropriateness, and submission of any report.

1. Who We Are

Carearoo ("we", "us", "our") is an Australian software service that provides AI-assisted report drafting tools for NDIS-registered allied health professionals. Our registered business operates from Melbourne, Victoria, Australia.

Contact: info@carearoo.com

2. What Information We Collect

Account information: Name, email address, and professional details you provide when you sign up.

Report content: Client information and uploaded documents you provide when generating reports. This content is stored temporarily and deleted automatically after report download.

Usage data: How you interact with our service, including pages visited and features used, to improve the product.

Payment information: Processed by Stripe. We do not store card numbers or full payment details.

Communications: Messages you send us via the contact form or email.

3. How We Use Your Information

  • To provide, maintain, and improve the Carearoo service
  • To process your payments and send transaction confirmations
  • To send service-related communications (e.g. verification emails, receipts)
  • To respond to support requests and enquiries
  • To detect and prevent fraud or misuse
  • To comply with applicable Australian law

We do not use your data or your clients\' data to train AI models. Client information you enter is used solely to generate the requested report draft.

4. Data Storage and Security

All data is stored on servers located in Sydney, Australia (AWS ap-southeast-2) via Supabase. Data does not leave Australia.

We implement industry-standard security measures including:

  • AES-256 encryption for data at rest
  • TLS 1.3 encryption for data in transit
  • Row-level security policies on all database tables
  • Strict access controls and authentication requirements

You can permanently delete report attachments and uploaded documents from our servers at any time with one click from within the report editor. We recommend deleting your uploads once you have downloaded your completed report.

5. Sharing of Information

We do not sell, rent, or trade your personal information. We share data only with:

  • Supabase (database and authentication infrastructure, on Australian servers)
  • Stripe (payment processing, PCI-DSS compliant)
  • Resend (transactional email delivery)
  • AI report generation service (processes report content to generate drafts; inputs are never used for model training)
  • Law enforcement or government agencies when required by law

All third-party providers are contractually bound to handle data in accordance with applicable privacy laws.

6. Australian Privacy Act 1988 (APP) Compliance

We comply with the Australian Privacy Act 1988 and the Australian Privacy Principles (APPs). Specifically:

  • APP 1: This policy openly describes our information handling practices
  • APP 3: We collect only information reasonably necessary for our functions
  • APP 5: We notify you about collection of personal information
  • APP 6: We only use information for the primary purpose it was collected
  • APP 11: We take reasonable steps to protect information from misuse and unauthorised access
  • APP 12: You may request access to personal information we hold about you
  • APP 13: You may request correction of inaccurate or incomplete information

7. NDIS Practice Standards

As a tool used by NDIS providers, we support compliance with the NDIS Quality and Safeguards Commission standards. We do not act as an NDIS provider and do not store participant information beyond the period necessary to generate the requested draft.

Registered NDIS providers using Carearoo retain full responsibility for compliance with their own obligations under the NDIS Act 2013 and the NDIS Practice Standards.

8. Your Rights

You have the right to:

  • Access the personal information we hold about you
  • Request correction of inaccurate information
  • Request deletion of your account and associated data
  • Withdraw consent for optional processing
  • Lodge a complaint with the Office of the Australian Information Commissioner (OAIC)

To exercise these rights, contact us at info@carearoo.com. We will respond within 30 days.

9. Cookies and Tracking

We use only essential session cookies required for authentication and service functionality. We do not use advertising cookies, tracking pixels, or third-party analytics that identify you personally.

10. Children's Privacy

Carearoo is intended for use by qualified healthcare professionals. We do not knowingly collect personal information from anyone under 18 years of age.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by email. Continued use of the service after changes constitutes acceptance of the updated policy.

12. Contact and Complaints

For privacy enquiries: info@carearoo.com

If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or on 1300 363 992.