Request a security review

Privacy Policy

What we collect, why, and how long we keep it.

Last updated 1 October 2026

Overview Terms Privacy DPA Refunds Security Subprocessors SLA Questionnaire

This policy explains what FULLPASS does with personal data. It applies to the website at https://fullpass.ai and the application at https://app.fullpass.ai. The controller is FULLPASS (ABN 79 297 751 595), Queensland, Australia.

We are an Australian company, so the Privacy Act 1988 and the Australian Privacy Principles apply to us. Where we handle the personal data of people in the UK or the European Economic Area, we also meet the UK and EU GDPR, and this policy is written to satisfy both.

1. What we collect

WhatWhyBasis
Name, work email, organisation nameTo create and run your accountPerformance of a contract
Password, stored only as a bcrypt hashTo let you sign inPerformance of a contract
Trusted browsers: a one-way hash of a random identifier stored in your browser, with the browser's name, for each browser you have signed in onTo ask for an emailed sign-in code only on browsers you have not used beforePerformance of a contract (keeping your account secure)
Free-trial record: keyed one-way hashes of your email address, of the network (IP address) and of the browser identifier a free trial was started fromSo that each person gets one free trial, not one per sign-upLegitimate interests (preventing abuse of the free trial)
Profile picture, if you upload oneTo show who did what on a shared accountConsent — it is optional
Reports produced from your coursesThe service itselfPerformance of a contract
Billing records and invoicesTo take payment and meet tax obligationsContract and legal obligation
Support messages you send usTo answer themLegitimate interests
Server logs: request times, errors, IP addressTo keep the service working and secureLegitimate interests
Product usage events: that a scan ran, an export was taken, a plan changed — with no IP address, no device identifier and nothing from your courseTo see whether the product actually works for the people using itLegitimate interests

2. What we do not collect

We do not store your course files. An uploaded package — and any storyboard or brand palette uploaded with it — is held in memory only for as long as the scan takes, then discarded. It is never written to our disks and never sent to any third party.

We do not see your card details. Payment is handled entirely by Stripe.

We do not use advertising trackers, and we do not sell personal data to anyone, ever.

3. What the reports contain

A report quotes the parts of your course that a finding refers to — the misspelled sentence, the caption line, the text read from a video. If your course contains personal data in its content, that text may appear in the report. Bear that in mind when deciding who to share a report with.

4. How long we keep it

Reports: Trial 30 days · Solo 180 days · Studio 365 days · Team 365 days. Reports past that age are deleted automatically by a job that runs every day. You can delete any report yourself at any time.

Account data: for as long as the account is open. When you close an account, the organisation, its people and its reports are deleted immediately.

Trusted browsers: 30 days from the last sign-in code, and all of them are forgotten when you change your password.

Free-trial records: 12 months, then deleted automatically. These are kept when an account is closed — that is their purpose, since otherwise closing an account and signing up again would give a second trial — but they are hashes that cannot be turned back into an address.

Billing records: retained as long as tax law requires, typically several years, regardless of whether the account is still open.

Logs: a rolling short window, as kept by our hosting provider.

5. Who we share it with

Only the processors we need to run the service. The current list, and what each one receives, is on our Subprocessors page. We do not share personal data with anyone else unless the law requires it.

6. Your rights

You can ask us to give you a copy of your data, correct it, delete it, or restrict what we do with it. Two of these are built into the product and do not need to be requested:

For anything else, write to info@fullpass.ai and we will respond within 30 days. If you are not satisfied with our answer, you may complain to the Office of the Australian Information Commissioner, or — if you are in the UK or the EEA — to your own data protection authority.

7. Where your data is held, and overseas disclosure

Although we are an Australian company, the application and its database are hosted in the European Union (Amsterdam, Netherlands), not in Australia. Our other processors operate in the European Union and the United States. This is an overseas disclosure for the purposes of Australian Privacy Principle 8, and we make it plainly here rather than burying it.

Where data leaves the UK or the EEA, transfers rely on the processor's Standard Contractual Clauses or on an adequacy decision. The full list of processors and the country each operates in is on our Subprocessors page.

8. Cookies

FULLPASS sets two cookies, both httpOnly, sameSite and — in production — secure:

Both are strictly necessary for signing in securely, so no consent banner is shown. We set no analytics or advertising cookies.

We do measure how the product is used, but on our own servers and against your account rather than against your browser: no cookie, no device identifier, no IP address, and no third-party analytics service involved. That is why there is nothing here to consent to.

9. Changes

We will post any change here and, if it is material, tell you by email.

10. Contact

info@fullpass.ai