Privacy Policy

Effective 24 August 2026

1. Overview

This policy describes how TW AI Pty Ltd (ACN 697 524 771), trading as Cintelis, handles personal information in GuardStein. The short version: we collect the minimum an account and billing require, your notes belong to you, vault workspaces are encrypted so that we cannot read them even if compelled, and we sell nothing to anyone.

2. What we collect

Account data: your email address, a salted password hash (never the password), optional two-factor enrolment (a TOTP secret, or passkey public keys and credential identifiers, which are not usable to impersonate you), sign-in timestamps, and a consent record of when and from which IP address you accepted the terms.

Content: the notes, diagrams, boards and files you create. In standard workspaces this is stored as you wrote it. In vault workspaces it is encrypted in your browser before upload; we store ciphertext and hold no keys.

People you invite: when you share a note by link or invite someone into a deal room, we store the email address you addressed it to, so that a code or an invitation can be delivered and, where you asked for it, so that access can be limited to the holder of that mailbox. Those people may have no account with us. You are responsible for having a basis to share their address with us, and we use it only to operate the share or the room you created.

Access records: shared links and deal rooms keep a log of every open and every refusal, recording the time, the document or note, the person as far as we can identify them, the IP address and the country it resolves to. This is a feature rather than a by-product: the trail is what makes a disclosure defensible, and it is visible to the workspace that created the share.

Billing data: your subscription state, seat counts and credit ledger. Card details go directly to Stripe and never touch our servers.

Operational data: logs needed to run and secure the service (request metadata, rate-limit counters, error traces). We run no advertising trackers and no third-party analytics on your content.

3. What we deliberately cannot see

Vault workspace content, including note titles and attachments, is sealed with keys that exist only in your browser, wrapped by your password, passkeys and recovery codes. We cannot read, recover, or hand over vault plaintext, because we never possess it. The trade is described in the Terms: losing every unlock method loses the data.

Deal room documents are sealed the same way, under keys held by the participants rather than by us. What encryption does not hide is structure, and we would rather state it than let you discover it: we can see how many documents a room contains, approximately how large they are, when each was uploaded and opened, and the email address of everyone invited to it. Filenames, document contents, participant names and the room's real name are sealed. A room shows a code name for exactly this reason.

4. When content leaves our infrastructure

Only when you explicitly invoke a feature that requires it: asking the diagram assistant sends your prompt and diagram context to our AI provider (DeepSeek); sharing a note into Teams or email sends that file through Microsoft's Graph API under your own Microsoft sign-in; embedding a Miro board uses Miro under your own Miro account; syncing to your own S3 bucket sends content to infrastructure you control. None of these run in the background or on vault content.

5. Processors we rely on

Vercel (application hosting), Neon (database), Cloudflare (authentication service and board collaboration), Stripe (payments), and Microsoft (transactional email). Each processes only what its role requires.

6. Cookies

We set session cookies (HttpOnly, first-party) to keep you signed in and to remember your active workspace. There are no advertising or cross-site tracking cookies.

7. Retention and deletion

Access logs for shared links and deal rooms are retained for as long as the workspace that created them exists, because their purpose is to answer a question raised long after the event. Content is retained while your account or workspace exists. Deleting a workspace permanently removes its notes, files and memberships; deleting a vault removes ciphertext that was unreadable to us anyway. Billing records are retained as required by tax law. Backups age out on a rolling schedule.

8. Your rights

We handle personal information in accordance with the Australian Privacy Principles. You can access and export your content at any time from within the service, correct your account details, and request deletion of your account and data. If you believe we have mishandled your information you may complain to us and, if unresolved, to the Office of the Australian Information Commissioner.

9. Changes and contact

Material changes to this policy will be announced in the service or by email, with the effective date above updated. Questions or requests: nick@cintelis.ai.