This policy explains what FULLPASS does with personal data. It applies to the website at https://fullpass.ai and the application at https://app.fullpass.ai. The controller is FULLPASS (ABN 79 297 751 595), Queensland, Australia.
We are an Australian company, so the Privacy Act 1988 and the Australian Privacy Principles apply to us. Where we handle the personal data of people in the UK or the European Economic Area, we also meet the UK and EU GDPR, and this policy is written to satisfy both.
1. What we collect
| What | Why | Basis |
|---|---|---|
| Name, work email, organisation name | To create and run your account | Performance of a contract |
| Password, stored only as a bcrypt hash | To let you sign in | Performance of a contract |
| Trusted browsers: a one-way hash of a random identifier stored in your browser, with the browser's name, for each browser you have signed in on | To ask for an emailed sign-in code only on browsers you have not used before | Performance of a contract (keeping your account secure) |
| Free-trial record: keyed one-way hashes of your email address, of the network (IP address) and of the browser identifier a free trial was started from | So that each person gets one free trial, not one per sign-up | Legitimate interests (preventing abuse of the free trial) |
| Profile picture, if you upload one | To show who did what on a shared account | Consent — it is optional |
| Reports produced from your courses | The service itself | Performance of a contract |
| Billing records and invoices | To take payment and meet tax obligations | Contract and legal obligation |
| Support messages you send us | To answer them | Legitimate interests |
| Server logs: request times, errors, IP address | To keep the service working and secure | Legitimate interests |
| Product usage events: that a scan ran, an export was taken, a plan changed — with no IP address, no device identifier and nothing from your course | To see whether the product actually works for the people using it | Legitimate interests |
2. What we do not collect
We do not store your course files. An uploaded package — and any storyboard or brand palette uploaded with it — is held in memory only for as long as the scan takes, then discarded. It is never written to our disks and never sent to any third party.
We do not see your card details. Payment is handled entirely by Stripe.
We do not use advertising trackers, and we do not sell personal data to anyone, ever.
3. What the reports contain
A report quotes the parts of your course that a finding refers to — the misspelled sentence, the caption line, the text read from a video. If your course contains personal data in its content, that text may appear in the report. Bear that in mind when deciding who to share a report with.
4. How long we keep it
Reports: Trial 30 days · Solo 180 days · Studio 365 days · Team 365 days. Reports past that age are deleted automatically by a job that runs every day. You can delete any report yourself at any time.
Account data: for as long as the account is open. When you close an account, the organisation, its people and its reports are deleted immediately.
Trusted browsers: 30 days from the last sign-in code, and all of them are forgotten when you change your password.
Free-trial records: 12 months, then deleted automatically. These are kept when an account is closed — that is their purpose, since otherwise closing an account and signing up again would give a second trial — but they are hashes that cannot be turned back into an address.
Billing records: retained as long as tax law requires, typically several years, regardless of whether the account is still open.
Logs: a rolling short window, as kept by our hosting provider.
5. Who we share it with
Only the processors we need to run the service. The current list, and what each one receives, is on our Subprocessors page. We do not share personal data with anyone else unless the law requires it.
6. Your rights
You can ask us to give you a copy of your data, correct it, delete it, or restrict what we do with it. Two of these are built into the product and do not need to be requested:
- A copy of everything — Account → "Download everything we hold"
- Deletion — Account → "Delete account and all data"
For anything else, write to info@fullpass.ai and we will respond within 30 days. If you are not satisfied with our answer, you may complain to the Office of the Australian Information Commissioner, or — if you are in the UK or the EEA — to your own data protection authority.
7. Where your data is held, and overseas disclosure
Although we are an Australian company, the application and its database are hosted in the European Union (Amsterdam, Netherlands), not in Australia. Our other processors operate in the European Union and the United States. This is an overseas disclosure for the purposes of Australian Privacy Principle 8, and we make it plainly here rather than burying it.
Where data leaves the UK or the EEA, transfers rely on the processor's Standard Contractual Clauses or on an adequacy decision. The full list of processors and the country each operates in is on our Subprocessors page.
8. Cookies
FULLPASS sets two cookies, both httpOnly, sameSite and — in production — secure:
- A session cookie that keeps you signed in.
- A browser identifier — a random value, lasting 30 days — so that we can tell a browser you have already signed in on from a new one, and ask for an emailed code only on the new one. It is also how a second free trial from the same browser is recognised.
Both are strictly necessary for signing in securely, so no consent banner is shown. We set no analytics or advertising cookies.
We do measure how the product is used, but on our own servers and against your account rather than against your browser: no cookie, no device identifier, no IP address, and no third-party analytics service involved. That is why there is nothing here to consent to.
9. Changes
We will post any change here and, if it is material, tell you by email.
10. Contact
info@fullpass.ai
