Privacy Policy
Last updated: 22 July 2026
This policy explains what personal information [your business/trading name — ABN if registered] ("we", "us", "our") collects through Narrator (the "Service"), why, and how it's handled. We're based in Australia and handle personal information in line with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth).
1. What we collect
- Account information: your email address, from Microsoft sign-in or a one-time email link.
- Report content: the prompts you write, their generation settings, and the narrations generated from them.
- Report data at narration time: the column names, row count, and row values your Power BI report sends when a narration is generated. This is sent to a third-party AI model to generate the narration (see "Who we share it with" below) and may be temporarily cached to avoid re-billing identical requests.
- Usage and billing data: how many narrations each report has generated, timestamps, and — if you have a paid subscription — billing status and subscription details managed by Stripe. We don't receive or store your card details.
- Technical logs: request metadata (timing, status, which endpoint was called) for operating and debugging the Service.
2. How we use it
- To operate the Service: authenticate you, generate narrations, enforce usage limits, and bill paid subscriptions.
- To maintain and improve reliability, including diagnosing failed or slow narrations from technical logs.
- To communicate with you about your account, e.g. sign-in links or billing notices.
We do not sell personal information, and we do not use the data your reports send us to train AI models.
3. Who we share it with
We share data with the following service providers, only as needed to run the Service:
- Groq — receives your prompt and report data at narration time to generate the narration text.
- Stripe — processes payments and manages subscriptions for paid report slots; receives your email and billing details, not your report content.
- Microsoft (Entra ID) — if you sign in with a Microsoft account, authenticates you and provides your email address to us.
- Resend — delivers one-time email sign-in links if you use email sign-in instead of Microsoft.
- Railway — hosts the Service's infrastructure and stored data.
We don't share your data with anyone else except where required by law.
4. Storage and security
Prompts, cached narrations, billing records, and request logs are
encrypted at rest (AES-256-GCM). Endpoint secrets are stored as
one-way hashes, not in plain text — we can't recover a lost secret,
only issue a new one. Sign-in sessions are stored as a hashed token in
an HttpOnly cookie, valid for 30 days. Email sign-in links
expire after 15 minutes and are held only in memory, never written to
disk.
5. Retention
Technical logs are retained for a limited period (14 days by default) before automatic deletion. Report content, prompts, and account data are retained for as long as your account or report exists, or as needed to comply with our legal obligations, after which they're deleted or de-identified.
6. Cookies
We use a single session cookie to keep you signed in. We don't use third-party advertising or tracking cookies.
7. Your rights
You can ask us to access, correct, or delete the personal information we hold about you by contacting us below. If you're unsatisfied with how we've handled a privacy concern, you can complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
8. Children
The Service is not directed at children and we don't knowingly collect personal information from them.
9. Changes to this policy
We may update this policy from time to time; material changes will be reflected in the "Last updated" date above.
10. Contact
Privacy questions, or to request access to or deletion of your data: [privacy/contact email].