Privacy Policy

Effective 4 March 2026

How we handle personal information, under the Australian Privacy Principles. For the detail on where your data is physically stored and which providers can see it, see Security and data residency.

1. Who we are

StreamsApp (ABN 87 140 781 510), based in Australia, operates the workflow software at streamsapp.app. StreamsApp is a registered business name, and the entity responsible for the information covered by this policy is identified in section 17. In this policy, "we", "us" and "StreamsApp" mean that entity, and "you" means anyone whose personal information we handle.

We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). This policy explains what we collect, why, where it is kept, who else can see it, and what you can ask us to do about it.

2. Two different roles, and why the difference matters

This policy covers two situations that are easy to confuse.

Information about our customers. When you sign up, pay us, or contact support, we decide what to collect and why. We are responsible for that information, and this policy governs it.

Information our customers put into StreamsApp. Our customers use StreamsApp to run their own workflows, and the records they create often contain personal information about their clients, staff and suppliers. We hold that information on our customer's behalf and act on their instructions. We do not decide what goes in, we do not use it for our own purposes, and we do not sell it or share it with anyone except the providers listed in section 7.

If a business uses StreamsApp to manage your matter and you want to know what they hold about you, ask them directly. They control that record. We will help them respond, but we cannot hand over their data to a third party without their authority.

3. What we collect

When you create an account: your name, email address, and a hashed password. If you enable two-factor authentication or a passkey, we store the credential needed to verify you, never anything that lets us act as you. We also record that you accepted the terms of service, which version you accepted, and the date and IP address it happened from, because that record is the only proof either of us has of the agreement.

When you use StreamsApp: the records, fields, notes, documents and files you create or upload. Your organisation name, address and country. An audit trail of actions taken in your account, including who made each change, when, and the values before and after.

When you pay us: billing contact details and a customer reference from our payment processor. We never see or store your full card number. Stripe handles the card directly.

Automatically: your IP address, browser type, and pages visited on our public website. Sign-in events, including failed attempts, are recorded so account takeovers can be detected.

If you contact us: whatever you put in the message.

We do not seek out sensitive information (health, race, religion, criminal record and similar) about our own customers. If our customers choose to store sensitive information in their records, they are responsible for having a lawful basis to do so.

4. Why we collect it

To provide the service and keep your account working; to authenticate you and protect the account; to bill you; to send service messages such as receipts, security notices and workflow notifications you have configured; to answer support requests; to detect misuse and meet our legal obligations; and to understand which parts of our public website are useful.

We do not sell personal information. We do not use your records to train AI models, and we never combine one organisation's data with another's.

5. Cookies and analytics

We use a cookie to keep you signed in. It is essential; the app will not work without it.

On our public website we use Vercel Analytics and Speed Insights to count page views and measure loading speed. We do not use advertising cookies, and we do not track you across other websites.

6. Where your information is stored

Everything you store in StreamsApp is held in Australia. Records, files, uploaded documents, the audit log and backups are all in Sydney. The servers that run StreamsApp are in Sydney. Document scanning runs on our own service in Sydney.

7. Who else can access it, and where they are

We use a small number of providers to run parts of the service. Each one only receives what it needs, and only when the relevant feature is used.

ProviderWhat it handlesLocation
Neon (on AWS)The database holding your recordsAustralia (Sydney)
VercelRunning the application, and file storageAustralia (Sydney)
Google CloudOur document scanning serviceAustralia (Sydney)
ResendSending emailUnited States
TwilioSending SMS and WhatsApp messagesUnited States
Google (Gemini API)The optional AI featuresUnited States
StripePayments and billingUnited States
Vercel AnalyticsPublic website page viewsUnited States

If you connect an accounting system (Xero, MYOB or QuickBooks), invoices you choose to sync are sent to that provider, in whichever location it operates.

We may also disclose information where the law requires it, or to protect our rights or someone's safety.

8. Disclosure of information overseas (APP 8)

Four of the providers above are in the United States: Resend, Twilio, Google (for the AI features) and Stripe. Using those features means the relevant information is disclosed overseas. Each one is bound by contract to protect it and to use it only to provide the service to us.

We use the paid tier of Google's Gemini API, under which Google states it does not use prompts or responses to improve its products and retains them only briefly to detect abuse. The free tier does not carry those terms, which is why we do not use it.

If you do not use the AI features, and do not send email, SMS or WhatsApp from StreamsApp, nothing you store with us is disclosed outside Australia.

9. How we protect it

Information is encrypted in transit (TLS) and at rest (AES-256). Every record carries the organisation that owns it, and every request is scoped to the organisation of the person signed in. Passwords are hashed and never stored in readable form. Two-factor authentication and passkeys are available, and an administrator can require two-factor for everyone in their organisation. Every change is recorded in an audit trail.

No system is perfectly secure, and we do not claim otherwise. Section 12 sets out what we do if something goes wrong.

10. How long we keep it

We keep your information for as long as your account is open, so that returning does not mean starting again. Archived records are kept rather than destroyed, so a mistake stays recoverable.

If you close your account and ask us to delete it, we delete your organisation and its contents. We may keep a limited record of transactions where tax or other law requires it, and backups may retain data for a short period before being cycled out.

11. Accessing, correcting and exporting your information

You can export your organisation's data at any time, yourself, in standard file formats, at no charge.

You can also ask us for a copy of the personal information we hold about you, or ask us to correct it. Email us at hello@streamsapp.app. We will respond within 30 days. There is no fee. If we cannot give you access, we will tell you why in writing.

12. Data breaches

If a breach occurs that is likely to cause you serious harm, we will notify you and the Office of the Australian Information Commissioner, as the Notifiable Data Breaches scheme requires. If the breach affects records our customers hold, we will notify the customer so they can meet their own obligations.

13. Marketing

We only send marketing email to people who have opted in. Every one includes an unsubscribe link that works immediately, and we honour it permanently. Service messages about your account, billing and security are not marketing and continue regardless.

14. Complaints

If you think we have mishandled your information, email hello@streamsapp.app with "Privacy complaint" in the subject. We will acknowledge within 5 business days and respond within 30 days.

If you are not satisfied, you can take it to the Office of the Australian Information Commissioner: oaic.gov.au, or 1300 363 992.

15. Children

StreamsApp is business software and is not intended for anyone under 16. We do not knowingly collect their information.

16. Changes

If we change this policy we will update the date at the top. For changes that materially affect you, we will tell account holders by email before they take effect.

17. Contact

StreamsApp is a registered business name of Luke Thomas Harpin (ABN 87 140 781 510). Australia. Email hello@streamsapp.app.

Questions about anything on this page?

hello@streamsapp.app