Skip to main content

Privacy Policy

Last Updated: January 1, 2025

Introduction

Welcome to Gestalts. We built this app from our lived experience to help families like ours navigate the GLP journey. We understand how precious your child's information is because we're parents first.

This Privacy Policy explains how TLG Digital Solutions Pty Ltd ("TLG Digital," "we," "us," or "our") collects, uses, stores, and protects your personal information when you use the Gestalts mobile application ("App," "Service," or "Gestalts"). We are committed to transparency and protecting your family's privacy.

Our commitment: We collect only what's necessary to provide value. We don't sell data. We don't track you for advertising. We treat your child's information the way we'd want Olivia's information treated.

1. Information We Collect

1.1 Information You Provide Directly

Account Information:

  • Email address (for account creation and authentication)
  • First and Last name (optional)
  • Password (encrypted and never stored in plain text)

Child Profile Information:

  • Child's first name
  • Current GLP stage (optional)
  • Interests (optional, to personalize AI interactions)

Note: We deliberately keep child profiles minimal. We don't ask for surnames, addresses, medical record numbers, or other identifying information beyond what's needed for the App to function.

Memories & Tracking Data:

  • Journal Entries: Text or voice-transcribed notes you create about observations, feelings, and daily experiences
  • Milestones: Developmental markers you record with dates and optional notes
  • Words & Phrases (Gestalts): Language samples you track, including phrases, sources, and contexts
  • Appointment Notes: Questions and notes you prepare for speech pathologists or allied health practitioners, including supported audio attachments where enabled

Support Circle Collaboration Data:

  • Invitations, access grants, roles, permission settings, and recipient selections
  • Strategy/update notes, replies, and linked observations shared with parent-approved practitioners, teachers, educators, carers, family members, or support people
  • Observation metadata such as author, role, child profile, visibility settings, timestamps, and linked strategy focus
  • Notification metadata needed to alert authorised users that an update or reply exists

Support Circle content may be sensitive or health-adjacent when users enter child development, school, or support context. Gestalts is not designed to be a practitioner's formal clinical record, health record, treatment plan, care plan, or clinical handover system.

Health Practitioner Profiles:

  • Practitioner name and type (e.g., "Speech Pathologist")
  • Contact information (optional)
  • Notes about sessions

User-Generated Content:

  • Text input to AI Companion conversations
  • Voice recordings for transcription (transcription-only recordings are deleted after transcription)
  • Audio memory clips you choose to save with journals, milestones, words, or appointment notes (stored encrypted until you delete them)
  • A photo you optionally choose after the photo-to-character notice, solely to create an AI-generated character; the source photo is not saved to your account

1.2 Automatically Collected Information

Usage Data:

  • Coarse app features accessed, screen/page views, counts, durations, and non-identifying mode/type fields (to improve reliability and aggregate product quality)
  • Error logs and crash reports (to fix bugs and improve stability)
  • Device type and operating system version (to ensure compatibility)
  • Operational telemetry for billing, entitlement checks, rate limits, abuse prevention, security, diagnostics, and reliability where needed

We do NOT collect:

  • Precise location data
  • Contacts or other device data unrelated to App functionality
  • Browsing history outside the App
  • Identifiable information for advertising purposes
  • Stable user identifiers, child profile identifiers, child names, report/story/memory IDs, prompts, transcripts, free text, or child observations in product analytics events

1.3 Information from Third-Party Services

AI Services Integration: To provide AI-powered features, we connect to third-party services via API. When you use these features, your data is processed as follows:

Google Gemini (Text-based AI Companion, Storybook Generation):

  • What's sent: The text needed for the selected feature after configured identifiers are replaced with request-specific labels and an additional sensitive-data inspection is applied
  • What's NOT sent: Your email, password, full journal history, or any data unrelated to the specific feature you're using
  • Data usage: Google processes this data to generate AI responses. We do not control Google's data practices beyond our API agreement
  • Minimisation controls: Supported Portal and Mobile generative-AI text routes replace configured identity fields with request-specific labels and use an additional sensitive-data inspection before provider calls. This reduces direct identifiers but does not make free-text context anonymous.
  • Provider terms: Google Cloud/Vertex AI retention, logging, and model-training restrictions are governed by Google Cloud service terms, project configuration, and our data-processing agreement. We do not make a blanket Zero Data Retention claim for every AI route.
  • Google's Privacy Policy: https://policies.google.com/privacy

Google Cloud Text-to-Speech (Story Narration):

  • What's sent: Story text for voice narration (which may include your child's first name where it appears in the story)
  • What's NOT sent: Voice recordings, child photos, journal entries, or other stored data
  • Data usage: Google processes the text to generate narration audio; processing occurs in the australia-southeast1 (Sydney) region
  • Google's Privacy Policy: https://policies.google.com/privacy

Firebase (Google):

  • Authentication: Email and encrypted password for secure login
  • Cloud Storage: Encrypted user data (journals, milestones, gestalts, appointment notes)
  • Cloud Functions: Server-side processing for reports and data operations
  • Storage: Generated avatar images and storybook images (encrypted)
  • Firebase Privacy: Covered under Google's privacy policy

Stripe (Payment Processing):

  • What's sent: Your email address, name, and payment method tokens (not full card numbers)
  • What's NOT sent: Child data, journal entries, language observations, or any developmental information
  • Data usage: Stripe processes payment data to manage subscriptions and billing
  • PCI DSS: Stripe handles PCI compliance; we never store full card numbers
  • Stripe Privacy Policy: https://stripe.com/privacy

Diagnostics, Analytics, and Rate Limiting:

  • Firebase Analytics / Google Analytics via Firebase: Public website analytics where approved, plus coarse app usage events where enabled, such as page or screen views and feature interactions
  • Firebase Crashlytics and Performance: Mobile crash reports, app version, device metadata, and performance telemetry
  • Sentry (Portal Only): Error context and stack traces, with PII scrubbed before sending
  • Upstash Redis (Portal Only): Server-side rate-limit keys and operational metadata for sensitive API paths
  • Product analytics minimisation: Product analytics events do not include stable account IDs, child profile IDs, child names, report/story/memory IDs, free text, prompts, transcripts, or child observations. Where PostHog is enabled after consent, it uses a browser-local random analytics ID instead of Firebase UID.
  • Operational telemetry: Billing, entitlement, rate-limit, security, crash, and reliability systems may use identifiers when required for that operational purpose
  • What's NOT sent: Child observations, journal entries, payment details, free-form prompts, or developmental information are not intentionally sent to analytics, diagnostics, or rate-limiting providers

Important Notes About Third-Party Services: 1. We do not own these AI models - We access them via API under their respective terms of service 2. User photos have one narrow AI exception - The optional photo-to-character flow uses one consented photo under the controls in Section 3.3; all other user-image/refinement inputs remain disabled 3. Voice recordings are transcribed and deleted - Voice input is converted to text, then the audio is deleted 4. AI data-use controls vary by provider and route - We do not train Gestalts-owned models on your content. Third-party model training, logging, and retention are governed by provider terms, configuration, and our data-processing agreements. 5. We cannot control third-party practices - While we choose partners with strong privacy commitments, we recommend reviewing their privacy policies directly 6. Payment data is handled by Stripe - We do not store or process payment card information directly 7. Mobile in-app purchases - RevenueCat, Apple App Store, and Google Play are the mobile subscription processors when native IAP is enabled. Mobile paid IAP must not be switched on until the billing disclosures, app-store answers, and webhook evidence are current.

2. How We Use Your Information

2.1 Primary Uses

We use collected information to:

Provide Core App Features:

  • Authenticate your account and maintain secure access
  • Store and organize your memories, milestones, and tracking data
  • Operate parent-controlled Support Circle sharing, including invitations, permissions, strategy/update notes, replies, observations, and notifications
  • Generate personalized AI Companion responses based on your child's profile and conversation history
  • Create text-described storybook avatars, illustrations, and narratives
  • Generate parent-controlled reports from your saved memories
  • Suggest memory entries based on AI Companion conversations

Improve Service Quality:

  • Fix bugs and technical issues
  • Understand which features are most valuable
  • Optimize app performance and stability
  • Develop new features based on usage patterns

Communicate with You:

  • Send important service updates (e.g., changes to Terms or Privacy Policy)
  • Respond to support requests
  • Notify you about account or security issues

2.2 What We DON'T Do With Your Data

We will NEVER:

  • Sell your personal information to third parties
  • Share your child's data with advertisers
  • Use your data for targeted advertising
  • Share identifiable information with researchers without explicit consent
  • Publicly disclose your journal entries, milestones, or other private content
  • Contact you for marketing purposes unrelated to Gestalts

2.3 Data Retention

Active Account Data:

  • All memories, milestones, gestalts, and appointment notes are retained indefinitely while your account is active
  • Support Circle notes, replies, observations, access grants, and notification metadata are retained while your account and relevant child profile are active unless deleted through available controls or an approved deletion request
  • You can delete supported individual entries from the App
  • Saved audio memory clips are encrypted and stored until you delete them

After Account Deletion:

  • Approved deletion requests are processed against active account-linked records within 30 days where technically supported
  • Some records may be retained where required for legal, security, billing, dispute, audit, child-safety, or fraud-prevention purposes
  • Anonymised, aggregated usage statistics (no personal identifiers) may be retained to improve the App
  • Deleted active records cannot be recovered after deletion

Temporary Processing Data:

  • Voice recordings: Deleted immediately after transcription
  • Photo-to-character source: Re-encoded in the App, held in Gestalts server memory only for the request, then discarded; the App deletes its prepared cache copy after the request or when you discard it. The original photo remains in your device library if it came from there.
  • AI provider processing: Temporary files we control are deleted after processing. Provider retention, logging, and caching controls are governed by provider terms and feature configuration.
  • Cached data: Cleared according to standard mobile app practices (refers to local device caching only)

3. Data Processing and Storage

3.1 Where Your Data is Stored

Primary Storage:

  • User data (journals, milestones, gestalts, appointment notes) is stored on Google Firebase servers
  • Primary Firestore records and the production app file-storage bucket are configured in australia-southeast1 (Sydney)
  • Cloud Functions currently process production and staging workloads in us-central1
  • Firebase Authentication, Hosting, logging, support, diagnostics, analytics, and AI providers may process data in provider-managed, US, or global regions
  • All data is encrypted at rest using industry-standard encryption (AES-256)
  • Data is encrypted in transit using TLS/SSL protocols

Local Device Storage:

  • The App caches some data locally on your device for offline access (journals, milestones, basic profile info)
  • Local data is protected by your device's security measures (passcode, biometric authentication)

3.2 Data Residency and Cross-Border Transfers (APP 8 Disclosure)

Our Australian hosting commitment:

We are an Australian company and our intent is to keep your family's information in Australia. Your stored records and media already live in Sydney, and we are progressively moving the remaining processing (server-side functions, AI processing, and speech-to-text) to Australian regions as our providers make the required services available there. Until that migration is complete, some processing occurs overseas, and we tell you exactly what and where below rather than making a blanket residency claim.

Where each type of data is stored and processed today:

Data typeExamplesWhere it is stored / processedHow it is protected
Stored recordsAccount details, child profiles, journals, milestones, gestalts, appointment notes, reports, stories, Support Circle contentAustralia (Sydney) - Firestore, australia-southeast1Encrypted at rest (AES-256) and in transit (TLS); owner-scoped security rules
Stored mediaSaved audio memory clips, generated illustrations, profile imagesAustralia (Sydney) - Firebase Storage production bucketEncrypted; owner-scoped storage rules
Sensitive-data inspectionDe-identification of text before any AI callAustralia (Sydney) - Google Sensitive Data Protection regional endpointFails closed if unavailable
Story narrationStory text sent for voice synthesisAustralia (Sydney) - Google Cloud Text-to-SpeechText only; no voice recordings sent
Server-side processingCloud Functions that operate the AppUnited States (us-central1) today; Australian migration plannedTransient processing; stored results written back to Sydney
AI text processingAI Companion, storybook, and report textUnited States / global endpoints (Google Vertex AI - Gemini, Claude) today; Australian endpoints planned as model availability allowsText minimised before sending where supported (see Section 3.3); provider DPA controls
Photo-to-character image processingOne parent-selected, locally re-encoded source photoGlobal endpoint (Google Vertex AI image model); processing may occur outside AustraliaJust-in-time consent, authority confirmation, App Check/auth, transient Gestalts server memory, provider DPA/terms controls; pixels are not text-tokenised or DLP-redacted
Speech-to-textAudio you record for transcriptionUnited States (Google Speech-to-Text) today; Australian migration plannedSent solely for transcription; transcription-only audio deleted after transcription; transcripts stored in Sydney
Analytics and diagnosticsCrash reports, PII-scrubbed usage eventsUnited States / global (Firebase Crashlytics, Analytics); EU (PostHog, portal, consent-gated); United States (Sentry, portal, PII-scrubbed)No child content, prompts, transcripts, or stable child identifiers in product analytics
PaymentsEmail, name, payment tokensUnited States (Stripe; RevenueCat if native in-app purchases are enabled)PCI DSS; no child data shared
Rate limitingOperational keys onlyProvider-controlled regions (Upstash Redis, portal)No personal content

How we protect information that leaves Australia:

1. De-identification first: Before any text reaches an AI provider, known identifiers (like names) are replaced with random request-specific labels and the text passes an additional sensitive-data inspection at the Sydney endpoint. This is pseudonymisation and minimisation, not anonymisation - free text can still be identifying - but it substantially reduces what overseas systems see. 2. Data minimisation: We only send the minimum data necessary for each feature to function. Photo pixels in the optional photo-to-character route cannot be text-tokenised or meaningfully redacted while preserving a likeness, so that route instead uses a separate notice, explicit confirmations, metadata stripping, strict authorization, and transient processing. 3. Contractual protections: We maintain data processing agreements with our service providers that include privacy, security, retention, and model-training obligations (see Section 3.4 and our sub-processor register). 4. Provider selection: We select providers with demonstrated privacy commitments and security certifications (SOC 2, ISO 27001) and GDPR compliance. 5. Encryption: All data is encrypted in transit (TLS) and at rest.

Your Consent:

In accordance with Australian Privacy Principle 8 (APP 8), by creating an account and using Gestalts you consent to the transfer of your personal information to the countries described above for the purposes described above. If you do not consent to these transfers, please do not use the App. We will update this section as processing moves to Australian regions.

For Global Users:

  • Data may be processed in Australia, the United States, the European Union, or other regions where our service providers operate
  • We ensure appropriate safeguards are in place for international transfers per applicable law

3.3 AI Privacy Boundary and User Images

Gestalts offers one narrow user-image feature: after a just-in-time notice, a parent may optionally choose or take one photo to create an AI-generated character. Before the App opens the picker or asks for camera/photo-library permission, you must confirm that you are the person shown, are their parent or legal guardian, or have permission from every identifiable person shown, and separately confirm that Google Vertex AI will process the photo. The App re-encodes the selected image to remove embedded metadata and reduce its size. It sends the image in one authenticated request to a Gestalts Cloud Function, which holds the bytes in memory only and does not write the source photo to Gestalts Storage or create a token-bearing source URL. The image is processed through Google Vertex AI's global image endpoint and may therefore be processed outside Australia. Photo pixels are not passed through the text identifier-replacement or DLP controls because those controls cannot preserve the requested likeness. Google-side retention, logging, and caching are governed by the current service terms and Gestalts configuration; Gestalts does not promise zero provider retention. The generated character is shown for review and is stored with your account only if you choose Save; it may still resemble the person shown.

All arbitrary image URLs, base64 image payloads, client image references, and general user-image refinement inputs remain disabled. You can always create a character from a text description without providing a photo.

For supported generative-AI text routes, known identifiers such as a child's or parent's name are replaced with random, request-specific labels before the provider call. Google Cloud Sensitive Data Protection is then used at a Sydney regional endpoint to detect and replace additional common identifiers. Only identifier types allowed for the feature may be restored in a model response. If the production inspection service is unavailable or not configured, the protected request fails closed instead of being sent without inspection.

These controls are pseudonymisation and data minimisation, not anonymisation. The details a user writes may still identify a person, Gestalts retains account and operational records needed to provide and secure the service, and provider processing is governed by current terms, configuration, and data-processing agreements. Audio must first be sent to the approved speech-to-text processor; the resulting transcript is protected before later generative-AI use.

3.4 AI Service Providers and Model Training

We use a small number of AI service providers, and we take specific steps to prevent your family's information being used to train their models:

ProviderWhat it does for GestaltsWhat it receivesModel training position
Google Vertex AI (Gemini models)AI Companion, storybook text and illustrations, report drafting, optional photo-to-character generationMinimized/pseudonymised feature text where the text boundary applies; one consented source photo for photo-to-characterUnder Google Cloud's generative AI service terms, customer prompts and outputs are not used to train Google's foundation models; provider-side abuse-monitoring and retention terms may still apply
Anthropic Claude (via Google Vertex AI)Report drafting; internal content review; summarising and drafting replies to emails you send usDe-identified feature text only. For Email CRM AI, message bodies are de-identified before egress and sender, recipient, subject and contact identifiers remain inside the Gestalts CRM boundaryContent submitted through this commercial route is not used to train Anthropic's models by default
Google Cloud Sensitive Data Protection (DLP)Detecting and removing personal details from text before it reaches any AI modelThe text being de-identified, processed in Sydney (australia-southeast1)Not a generative model; not used for model training
Google Speech-to-TextTranscribing audio you recordThe audio recording, solely for transcription. Processed in the United States - see Section 4Not used for model training under our configuration; transcription-only audio is deleted after transcription
Google Cloud Text-to-SpeechStorybook narrationStory text onlyNot used for model training under our configuration

Anthropic is reached through Google Vertex AI under Google Cloud's commercial terms, not through Anthropic's own API. One internal engineering tool, used by our team and never on family data, is the exception; it does not receive your content.

Additional commitments:

  • We do not train Gestalts-owned models on your content. The only exception is the optional, off-by-default conversation-evaluation consent, which you can enable or disable at any time and which is used solely to review AI quality.
  • Retention at providers: Providers may hold transient copies of requests for a limited period (for example, for abuse monitoring) under their terms. We are pursuing zero-retention / abuse-monitoring opt-out configurations where the provider offers them, and we record the current status for each provider in our sub-processor register.
  • Deletion boundary: When you delete data or your account, we erase the records covered by our deletion process from our active systems, and we are extending that process to cover every category of data we hold. Some records are deliberately retained for a defined period where we are required or permitted to keep them - these are listed in Section 5. Content stored on your own device is removed when you delete the app. We cannot reach into provider systems, but provider-side transient copies expire under the retention terms above.
  • Data processing agreements: We maintain a register of our sub-processors and the data processing agreements that bind them, available on request via info@gestalts.com.au.

3.5 Your Consent Records

We record each consent you give with a timestamp, the method used, and the document version you accepted, so you can always see what you agreed to and when.

Consents we record:

  • Acceptance of the Terms & Conditions and this Privacy Policy (including age verification)
  • Audio recording consent (before you first record audio in the App)
  • Profile photo consent (before you first add an optional profile or avatar image)
  • Photo-to-character AI consent (before the photo picker opens; separate authority and overseas AI-processing confirmations)
  • Optional AI conversation-evaluation consent (off by default)
  • Marketing communications consent
  • Analytics consent (portal and website, where applicable)

Where to view them:

  • Mobile App: Settings → Privacy & Consents
  • Portal: Profile → Privacy & Data

You can withdraw an ongoing consent at any time in the same place you gave it (or by contacting info@gestalts.com.au); withdrawing consent stops later related processing but does not affect processing that already happened. The photo-to-character flow asks for the current notice again at the start of each new creation flow.

4. Data Sharing and Disclosure

4.1 With Your Explicit Consent

User-Controlled Sharing:

  • Reports for Practitioners: You choose when to generate and share reports. Reports are not automatically sent to anyone
  • Export Data: You can export supported records in available formats and share them as you wish
  • Multi-User Profiles (Future Feature): If we add family sharing, you will control who has access to what data

4.2 With Third-Party Service Providers

We share limited data with service providers who help us operate the App:

Service Provider | Data Shared | Purpose | Safeguards ---|---|---|--- Google Firebase | All user-generated content (encrypted), diagnostics metadata and coarse scrubbed analytics events where enabled | Database, authentication, storage, analytics, diagnostics | Google Cloud security, encryption, configured data residency where available Google Gemini (Vertex AI) | Text prompts and feature context after the applicable identifier-minimisation controls; one consented, locally re-encoded source photo only when you invoke photo-to-character | AI text generation, text-to-image generation, and optional photo-to-character generation | Gestalts-managed API access; just-in-time photo notice and authority confirmation; provider retention, logging, training restrictions, and processing regions are governed by current terms, configuration, and DPA evidence Google Cloud Text-to-Speech | Story text (may include your child’s first name) | Voice synthesis for storybook narration | API-only access, processed in Australia (australia-southeast1), no training on your data Stripe | Customer email, name, payment tokens | Payment processing, subscriptions | PCI DSS compliant, no full card numbers stored by us Sentry | Error logs, crash data | Bug tracking and app stability (portal only) | PII scrubbed via beforeSend hook, no child data transmitted Upstash Redis | Rate-limit keys and operational metadata | Portal rate limiting | No child content, prompts, or payment details intentionally stored RevenueCat | Mobile entitlement and app-store purchase metadata | Native mobile in-app purchase path | Required for iOS/Android subscriptions; must be reviewed before mobile paid IAP launches

All service providers:

  • Are contractually obligated to protect your data
  • Cannot use your data for their own purposes (beyond providing the service to us)
  • Must comply with applicable privacy laws

4.3 Legal Requirements

We may disclose information if required by law:

Legal Obligations:

  • To comply with court orders, subpoenas, or legal processes
  • To respond to lawful requests from government authorities (with appropriate legal basis)
  • To protect our rights, safety, or property
  • To investigate potential violations of our Terms of Service
  • In connection with child safety concerns (mandatory reporting laws)

Transparency Commitment:

  • We will notify you if legally permitted before disclosing your data
  • We will challenge overly broad or unjustified requests
  • We will disclose only the minimum necessary information

4.4 Business Transfers

If Gestalts is acquired, merged, or undergoes a business transition:

  • User data may be transferred as part of the business assets
  • You will be notified via email and in-app notice
  • The new entity must honor this Privacy Policy
  • You will have the option to delete your account before transfer

5. Your Rights and Choices

5.1 Access and Portability

Australian Privacy Principles (APPs) & GDPR Rights:

You have the right to:

  • Access: Request a copy of all personal data we hold about you
  • Portability: Export supported records in available machine-readable or app-supported formats
  • Correction: Update or correct inaccurate information

How to Exercise:

  • Access most data directly in the App (Memories, Profile settings)
  • Email us at info@gestalts.com.au for data-export requests

5.2 Deletion and Erasure

"Right to be Forgotten" (GDPR) / Erasure (APPs):

You can delete:

  • Individual journal entries, milestones, gestalts, or appointment notes (within the App)
  • Generated storybook images or avatars
  • Your entire account (Settings → Delete Account)

Account Deletion:

  • Deletes active account-linked personal data within 30 days where technically supported
  • Some operational, billing, consent, security, audit, safety, or legally required records may be retained
  • Cannot be undone
  • Anonymised usage statistics may be retained

How to Delete:

  • In-app deletion for individual items
  • Account deletion via App settings or email info@gestalts.com.au

5.3 Marketing and Communications

Email Communications:

  • You can opt out of non-essential emails (feature updates, tips)
  • You cannot opt out of critical service emails (security alerts, Terms changes)
  • Manage preferences in Settings or click "Unsubscribe" in emails

5.4 Data Correction

Update Your Information:

  • Child profiles, practitioner info, and account details can be edited directly in the App
  • Email info@gestalts.com.au if you cannot update something

5.5 Complaints and Concerns

Australian Users:

  • You have the right to lodge a complaint with the Office of the Australian Information Commissioner (OAIC)
  • OAIC: https://www.oaic.gov.au | Phone: 1300 363 992

European Users:

  • Contact your local Data Protection Authority
  • EU DPA list: https://edpb.europa.eu/about-edpb/board/members_en

Contact Us First:

  • We encourage you to contact us first so we can resolve your concern
  • Email: info@gestalts.com.au

6. Security Measures

6.1 Technical Safeguards

Encryption:

  • Data at Rest: AES-256 encryption for all stored data, applied by Google Cloud Platform to Firestore and Cloud Storage by default
  • Data in Transit: TLS 1.2+ encryption for all data transmission
  • Passwords: We never see or store your password. Authentication is handled by Firebase Authentication, which stores credentials using a hardened, salted hashing scheme (a modified scrypt) rather than storing recoverable passwords.

Access Controls:

  • Your account is protected by your password (or your Google or Apple sign-in, if you use one)
  • Role-based access: your records are reachable only by you, by anyone you have explicitly granted access to through Support Circle, and by our administrators where operationally necessary (see Section 6.2)
  • Third-party services are authenticated with short-lived platform credentials rather than long-lived shared keys where the provider supports it

Infrastructure Security:

  • Firebase Security Rules restrict direct database and file access to the account that owns the record
  • Access you grant to a practitioner or support person is enforced server-side against the specific permissions you set, and can be revoked by you at any time
  • Automated dependency vulnerability scanning and secret scanning run on every change
  • Automated test suites verify our database and file access rules before any release
  • Automatic security updates for dependencies

6.2 Organizational Safeguards

Internal Policies:

  • Administrator access to user data is limited to what is necessary to operate the service, provide support, investigate a safety concern, or meet a legal obligation
  • Administrator actions that change or delete your data are recorded in an audit log
  • Confidentiality obligations apply to anyone with data access

Incident Response & Notifiable Data Breaches (NDB) Scheme:

Under the Australian Notifiable Data Breaches (NDB) scheme (Part IIIC of the Privacy Act 1988), we are required to notify the Office of the Australian Information Commissioner (OAIC) and affected individuals if an eligible data breach occurs — that is, a breach likely to result in serious harm.

  • Assessment of suspected breaches within 72 hours of discovery
  • Notification to the OAIC and affected individuals within 30 days if an eligible breach is confirmed
  • Immediate user notification if your data is compromised
  • Post-incident review and remediation
  • Formal breach response plan maintained at all times

6.3 Your Responsibilities

Protect Your Account:

  • Use a strong, unique password
  • Don't share your account credentials
  • Log out on shared devices
  • Report suspicious activity immediately

7. Children's Privacy

Gestalts is designed for parents and caregivers of children who are gestalt language processors. Because our app processes children's personal information, we apply enhanced privacy protections in accordance with the Australian Privacy Act 1988 and best practices under the anticipated Children's Online Privacy Code.

7.1 Age Requirements & Parental Consent

User Accounts:

  • The App is intended for parents/guardians (18+ years old)
  • Children do not create their own accounts
  • Parents manage child profiles within their parent account

Parental Consent Mechanism:

  • Before any child data can be entered, the parent or caregiver must confirm they are 18 years or older via an age verification gate
  • Parents must accept both the Terms & Conditions and this Privacy Policy before proceeding
  • Consent is recorded in our systems with timestamp, method, and version accepted
  • Parents can withdraw consent at any time by deleting their child's profile or their account

7.2 What Child Data We Collect

Child Profile Data (provided by parents):

  • Child's name and birthdate
  • GLP stage and developmental characteristics
  • Language observations and milestones

Child Activity Data (generated through app use):

  • Journal entries documenting language development
  • Audio transcripts you choose to save
  • AI Companion conversation context
  • Report data generated from observations

Audio Data:

  • Voice recordings may be captured during AI Companion sessions or transcription features
  • Audio is stored in Firebase Storage (australia-southeast1, Sydney)
  • Story text (which may include your child’s first name) may be sent to Google Cloud Text-to-Speech for voice synthesis (australia-southeast1, Sydney); audio may be processed by Vertex AI for transcription
  • Audio recordings are retained only as long as needed for the feature and can be deleted by the parent at any time

Photo Data:

  • A parent may optionally choose one photo for the dedicated photo-to-character route after the versioned notice and confirmations described in Section 3.3; the source is transient and the resulting character is saved only after review
  • Other camera, gallery, arbitrary image URL/base64, and client image-reference inputs are not accepted for AI generation or refinement
  • If the App allows you to add a profile picture or child avatar image, that image is stored encrypted with your account until you delete it and is never sent to an AI model
  • Adding any photo is optional, requires your explicit in-app consent (recorded with date and version), and can be reversed by deleting the image

7.3 Data Minimization & Protection

We commit to the following principles for children's data:

  • Collection minimization: We collect only the child data necessary to provide the app's features
  • No behavioral advertising: We do not use children's data for advertising or profiling purposes
  • No third-party marketing: We do not share children's data with third parties for marketing
  • No direct collection from children: All child data is provided and managed by the parent/caregiver
  • Enhanced security: Children's data is encrypted at rest (AES-256) and in transit (TLS). Firebase Security Rules restrict direct access to the parent who owns the profile. Any access you grant to a practitioner or support person is enforced server-side against the specific permissions you set, and can be revoked by you at any time. Our administrators can also access children's data where operationally necessary, as described in Section 6.2.
  • Deletion on request: Parents can delete all child-related data at any time through the app or by contacting info@gestalts.com.au

7.4 Parental Control

You Control Your Child's Data:

  • You decide what information to include in your child's profile
  • You can delete any child-related data at any time
  • You control when and how to share reports with practitioners
  • You can export all child data via the data export feature
  • You can request complete account deletion, which removes all child data within 30 days

9. International Users

9.1 Australian Privacy Principles (APPs)

For Australian Users:

  • We comply with the Privacy Act 1988 (Cth) and Australian Privacy Principles
  • Data is stored in Australia where possible via Firebase regional options
  • You have rights under APPs (access, correction, erasure, complaints)

9.2 GDPR (European Users)

For EU/EEA/UK Users:

  • We comply with the General Data Protection Regulation (GDPR)
  • Legal Basis for Processing:
  • Contract: To provide the App services you've signed up for
  • Consent: For optional features like the AI Companion and audio recording
  • Legitimate Interest: To improve the App and ensure security
  • You have GDPR rights (access, portability, erasure, restriction, objection)

9.3 Other Jurisdictions

For Users in Other Countries:

  • We strive to meet the highest privacy standards globally
  • Specific compliance varies by jurisdiction
  • Contact info@gestalts.com.au with jurisdiction-specific questions

10. Changes to This Privacy Policy

10.1 Notification of Changes

How We Update:

  • Material changes will be notified via email (to your registered email address)
  • In-app notification upon next login
  • Updated "Last Updated" date at the top of this policy

Your Choices After Changes:

  • Continued use of the App constitutes acceptance of changes
  • If you disagree with changes, you may delete your account before they take effect

10.2 Review Frequency

  • We review this policy annually at minimum
  • Updates may occur more frequently as features or laws change

11. Contact Us

11.1 Privacy Questions or Concerns

Email: info@gestalts.com.au Subject Line: Privacy Inquiry - [Your Name]

We will respond within:

  • 5 business days for general inquiries
  • 30 days for formal data access/deletion requests (as required by law)

11.2 Data Protection Officer (DPO)

For GDPR-related inquiries: Email: info@gestalts.com.au

11.3 Mailing Address

TLG Digital Solutions Pty Ltd Suite 4, Riverwalk One Building 140 Robina Town Centre Drive Robina QLD 4226 Australia

ABN: 19 684 760 503

12. Definitions

"Personal Information": Information that identifies or can reasonably identify an individual (e.g., name, email, child's name)

"Processing": Any operation performed on data (collection, storage, use, deletion, etc.)

"Third Party": An entity that is not TLG Digital Solutions Pty Ltd, you, or our service providers

"User," "You," "Your": The parent/guardian who creates and manages the Gestalts account

"Child": The child whose profile is created and managed within your Gestalts account

"Gestalts" or "App": The Gestalts mobile application

"TLG Digital," "We," "Us," "Our": TLG Digital Solutions Pty Ltd and the team behind Gestalts

Conclusion

We built Gestalts because we needed it for Olivia. We understand the trust you place in us when you share your child's journey. We treat your data with the same care we'd want for our own daughter.

If you have questions, concerns, or suggestions about privacy, please reach out. We're parents first, and we're here to listen.

Email: info@gestalts.com.au

Document Change Log

VersionDateSummary
1.9-draft25 July 2026Reality-reconciliation pass: every claim in this document was checked against the code that implements it, and claims that were not code-backed were corrected rather than retained. Removed the multi-factor authentication claim (no MFA implementation exists anywhere in the estate). Removed "regular security audits and penetration testing" (never performed; replaced with the automated scanning and rules-testing that IS in place). Corrected the password-hashing description (Firebase Authentication uses a hardened scrypt variant, not bcrypt). Corrected Section 6.1 and Section 7.3, which stated that Firebase Security Rules restrict child data to the parent alone - practitioner, Support Circle and administrator access is enforced server-side and bypasses those rules. Disclosed administrator access and audit logging in Section 6.2. Narrowed the deletion-boundary statement in Section 3.4 to what the erasure engine actually covers. Added Google Cloud Sensitive Data Protection (DLP) to the AI provider table and recorded that Speech-to-Text processes audio in the United States. Recorded that Anthropic is reached via Google Vertex AI under Google Cloud terms, and that email bodies are de-identified before AI processing while envelope metadata is not. Counsel review required before publication.
1.8-draft21 July 2026Added the optional consent-gated photo-to-character flow; disclosed authority confirmation, on-device metadata stripping, transient in-memory Gestalts processing, global Vertex AI processing, provider-side retention boundary, generated-character save behavior, consent registry entry, and the continuing prohibition on general client-image/refinement inputs. Counsel review required before publication or activation.
1.7-draft19 July 2026Removed Play Analyzer references (feature withdrawn from production pending regulatory review). Rewrote Section 3.2 as a per-data-type residency table with an explicit Australian hosting commitment and honest disclosure of current US/global processing. Added Section 3.4 (AI service providers and model training, including no-training positions, provider retention, and the deletion boundary). Added Section 3.5 (consent records and where to view them). Added Section 8.3 (website cookies and analytics consent). Clarified audio handling (transcription-only vs saved memory clips) and optional profile photo consent. Removed the retired photo-upload workflow block (history preserved in version control). Corrected the stale version footer.
1.6-draft18 July 2026AI-privacy and user-image amendments (implementation-aligned drafting).
1.1-draft9 November 2025Baseline draft published to the mobile fallback.

Last Updated: July 25, 2026 Version: 1.9-draft