Privacy Policy
Last updated: 19 August 2026 · Applies to groundnote.app and groundnote.com.au
Groundnote (ABN 34 557 691 587; "Groundnote", "we", "us", "our"), is committed to protecting your privacy in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). This policy explains what personal information we collect, how we use and store it, and the choices and rights you have.
1. Who we are
Groundnote is an Australian registered entity, ABN 34 557 691 587. For any privacy question or request, contact us at support@groundnote.com.au.
2. Information we collect
- Account information — name, work email, password (stored as a salted hash, never in plain text), and workspace/organisation details.
- Meeting content — audio recordings, transcripts, and the decisions, tasks, risks, and questions Groundnote extracts from them, for meetings you choose to capture.
- Usage data — feature usage, login activity, and diagnostic/telemetry data used to keep the product working and to improve it.
- Payment information — if you subscribe to a paid plan, billing details are collected and processed by our payment provider; we do not store full card numbers ourselves.
- Information from third-party integrations — if you connect Slack, Jira, Asana, Linear, Google/Microsoft Calendar, or similar tools, we access only what's needed to provide the connected feature, per the permissions you grant.
3. How we use your information
- To provide the core service: capturing meetings, extracting decisions/tasks/risks, and delivering them back to you and the participants you choose to share with.
- To operate the commitment-confirmation workflow — sending a task's assignee a secure link so they can accept, edit, or dispute what was detected, without needing an account.
- To bill and administer your subscription, including trial-to-paid conversion reminders and renewal notices.
- To provide customer support and respond to your requests.
- To maintain security, detect misuse, and meet our legal obligations.
- With your consent, to send product updates — you can opt out of marketing email at any time (see section 8, and our compliance with the Spam Act 2003 (Cth)).
4. AI processing of meeting content
Meeting audio and transcripts are processed by AI to generate summaries, decisions, tasks, risks, and confidence/evidence labels. Depending on your workspace's configuration, this processing may run on infrastructure we operate, or — if you've configured a "bring your own AI" provider — on infrastructure you control or a third-party AI provider you've chosen. We do not use your meeting content to train shared/foundation AI models without your explicit consent.
5. Overseas disclosure (APP 8)
Some of our infrastructure and service providers (e.g. cloud hosting, email delivery, optional third-party AI providers you configure) may store or process data outside Australia. Where this occurs, we take reasonable steps to ensure recipients handle your information consistently with the Australian Privacy Principles. Processing locations depend on the services and optional integrations your workspace uses. Contact us for current information about relevant providers and locations.
6. Data retention & deletion
You control the retention period for your workspace's meetings and telemetry via account settings. Deleted meetings are removed through an audited deletion process. You can place a legal hold on specific meetings to exempt them from routine deletion (e.g. for a live dispute), and you can request full account deletion at any time by contacting us.
7. Security
We apply industry-standard safeguards including encrypted transport (TLS), password hashing, optional multi-factor authentication, role-based access control, and an audit log of security-relevant account activity. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security. We have not completed an independent SOC 2, ISO 27001, or equivalent certification as of this writing — if that's a requirement for your organisation, please contact us to discuss.
8. Your rights
Under the Australian Privacy Principles, you can:
- Ask what personal information we hold about you and request a copy (APP 12).
- Ask us to correct inaccurate or out-of-date information (APP 13).
- Withdraw consent to marketing communications at any time.
- Request deletion of your account and associated data, subject to legal retention obligations.
- Lodge a complaint with us, and if unresolved, with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
9. Cookies
Our website and app use cookies and local storage for sign-in, preferences, security, and core functionality. The public website also uses Google Analytics to understand aggregate visits and feature engagement. Google may process device, browser, interaction, and approximate location information for this purpose. We do not use third-party advertising cookies. You can limit analytics through your browser settings or supported privacy controls.
10. Children's privacy
Groundnote is a business tool and is not directed at, or intended for use by, children.
11. Changes to this policy
We may update this policy from time to time. Material changes will be notified via the app or by email before they take effect.
12. Contact us
Questions, requests, or complaints about privacy: support@groundnote.com.au