01Scope
Subtext is operated by Josephmark Pty Ltd (“Josephmark”, “we”, “us”), an Australian company. Josephmark is the entity accountable for the personal information described in this policy.
1.1This policy describes how we collect, use, disclose and retain personal information in connection with the Subtext application and the connectors we publish to third-party AI assistant directories (together, the “Service”).
1.2This policy does not apply to third-party services you connect to the Service, or to third-party AI assistants that retrieve information from it. Those services are governed by their own privacy policies.
1.3By using the Service you agree to the handling of personal information described in this policy.
02Information we collect
2.1Account information. Your email address and display name, obtained from the identity provider you use to sign in. Where you purchase a subscription or credits, a customer reference and payment status supplied by our payment processor. We do not receive or store payment card numbers.
2.2Content you provide. Documents you upload, audio you record, text you enter, and the content retrieved from any third-party service you connect. This content, and the structured representation we derive from it, constitutes the substance of the Service.
2.3Derived content. Structured pages, entity records, relationships between them, and numerical representations (“embeddings”) generated from the content described in 2.2 for the purpose of search and retrieval.
2.4Usage records. Records of retrievals performed by connected AI assistants, including the identity of the connection, the operation performed, the query or resource requested, and the time. Records of processing volume for the purpose of billing.
2.5Technical records. Diagnostic records of calls made to third-party services on your behalf, including timing, outcome, and where a call fails, the error returned by that service. Error text returned by a third party may incidentally contain fragments of the content that was being processed.
2.6We do not collect biometric information, precise geolocation, or special categories of personal data as a matter of design. Content you choose to provide under 2.2 may contain such information; we process it as content and apply no special handling beyond that described in this policy.
03Sources you connect
3.1Each third-party source is authorised separately. Authorising one source does not grant access to any other, and withdrawing authorisation for one does not affect the others.
3.2Electronic mail. Where you connect a mail account, we access only those conversations you have explicitly labelled for that purpose using a label we create on connection. We do not access, scan or index the remainder of your mailbox. Where a labelled conversation continues, subsequent messages in that conversation are accessed.
3.3Calendar. Where you connect a calendar, we access event records and attendee details on a read-only basis.
3.4Documents. Where you import documents, we access only the individual files you select through the provider’s own file selection interface. We do not hold general access to your document storage.
3.5Direct provision. Files and audio you upload to the Service directly.
3.6You may withdraw authorisation for any source at any time. Deletion of your account withdraws our authorisation at the provider in addition to deleting our copy of the credential.
04Connections to AI assistants
4.1The Service is designed to be connected to third-party AI assistants. Each connection is authorised by you through an authorisation flow operated by our identity provider. Your credentials for the Service are not disclosed to the assistant; a separate credential is issued to each connection.
4.2Each connection is subject to an access scope selected by you, limiting the portion of your information the connection may retrieve.
4.3Connections are read-only unless you expressly grant write access.
4.4You may suspend or revoke any connection at any time, with immediate effect. Revoking your session credentials revokes all connections simultaneously.
4.5Each retrieval performed by a connection is recorded and made visible to you in the Service.
4.6Information retrieved by a third-party AI assistant is thereafter subject to that assistant’s own privacy policy and retention practices, over which we have no control and for which we accept no responsibility.
05Purposes of processing
5.1We process personal information for the following purposes:
- (a) to create, maintain and present your structured knowledge graph;
- (b) to respond to queries you submit within the Service;
- (c) to synchronise content from sources you have authorised;
- (d) to make information available to AI assistants you have connected;
- (e) to administer subscriptions, credits and billing;
- (f) to maintain the security, integrity and availability of the Service;
- (g) to comply with legal obligations.
5.2Where our processing relies on consent — specifically, access to each third-party source under Section 3 — that consent is given per source and may be withdrawn per source, without affecting the lawfulness of processing carried out before withdrawal.
5.3Where our processing relies on the performance of a contract, it is limited to what is necessary to provide the Service you have requested.
06Automated processing
6.1The Service uses automated processing, including large language models, to derive structure from the content described in Section 2.2 and to respond to your queries.
6.2This processing does not produce legal effects concerning you or similarly significantly affect you. It is applied to your own content, at your direction, for your own use.
6.3Outputs of automated processing are presented to you in the Service and may be corrected or deleted by you.
07Disclosure to model providers
7.1To perform the processing described in Section 6, content you provide is transmitted to large language models operated by Amazon Web Services, and to that provider’s embedding and transcription services, identified in Section 8.
7.2Access to those models is mediated by an inference gateway that we operate ourselves. The gateway is not a third party: it is our own software, run by us, and content passing through it does not leave our control or the provider infrastructure identified in Section 8. It performs routing and accounting only, and does not retain the content of requests or responses.
7.3Content transmitted for processing is not used to train machine learning models, and is not retained beyond what is necessary to return the result of the request. This applies both to our inference gateway and to the underlying model provider.
7.4Content is transmitted for the purpose of processing and the result is returned to us. It is not disclosed for any other purpose.
08Third-party processors
8.1We engage the following categories of processor:
| Processor | Function | Processing location |
|---|---|---|
| Amazon Web Services | Application hosting, data storage, message queueing, compute | Australia |
| Amazon Web Services (Bedrock) | Large language model inference, and generation of embeddings for search | Australia |
| Amazon Web Services (Transcribe) | Conversion of recorded audio to text | Australia |
| Auth0 (Okta, Inc.) | Authorisation of third-party AI assistant connections | United States |
| Google LLC | Sign-in, and access to sources you authorise | Global |
| Stripe, Inc. | Payment processing | Global |
8.2The inference gateway described in Section 7.2 is our own software and is not a third party. It is not listed above for that reason.
8.3We do not sell personal information. We do not disclose personal information for advertising, cross-context behavioural advertising, or any similar purpose.
8.4We may disclose personal information where required by law, by binding order of a court or regulator, or where necessary to establish, exercise or defend legal claims. Where we are permitted to notify you of such a disclosure, we will.
8.5In the event of a merger, acquisition or sale of assets, personal information may be transferred, subject to the acquirer being bound by commitments no less protective than those in this policy.
09International transfers
9.1The Service is hosted in Australia and your content is stored there.
9.2Certain processors identified in Section 8 operate globally, and personal information disclosed to them may be processed outside Australia. Where such transfers occur from a jurisdiction that restricts them, they are made pursuant to the transfer mechanisms available under that jurisdiction’s law.
10Security
10.1Encryption in transit. All connections to the Service are encrypted using Transport Layer Security version 1.2 or higher, negotiated under a current cipher policy. Requests to the web interface over unencrypted connections are redirected to an encrypted connection. Certificates are issued by a public certificate authority and renewed automatically.
10.2Encryption at rest. Personal information stored by the Service is encrypted at rest using AES-256. This applies to the primary database, to the storage holding the structured knowledge graph, and to object storage holding uploaded files and derived material. Encryption uses a customer-managed key under our sole control rather than a provider default key, and the same key governs each of those stores. Backups inherit the encryption of the storage they are taken from.
10.3Protection of third-party credentials. Credentials issued to us by services you authorise are subject to authenticated symmetric encryption at the application layer before they are written to storage, in addition to any storage-layer encryption. We retain only the ciphertext and a short non-sensitive prefix for display. Plaintext is recovered only at the point of making an authorised request on your behalf and is not persisted. The key protecting these credentials is maintained separately from the key used to sign session credentials, so that compromise of one does not yield the other. Key rotation is supported without loss of access to previously encrypted material.
10.4Credential storage. Credentials issued by us to connected AI assistants are stored as irreversible hashes. The credential itself is recoverable only by the holder.
10.5Authentication and revocation. Connections by third-party AI assistants are authorised using OAuth 2.0. Tokens are verified against the issuing authority using asymmetric cryptography and are bound to a specific audience, so that a token issued for another service cannot be presented to ours. Session credentials carry a generation identifier which permits immediate and complete revocation of every outstanding credential for an account.
10.6Authorisation. Authorisation is re-evaluated against live account state on every request, rather than relying on assertions contained in the credential. Suspension or revocation of an account takes effect on the next request without delay.
10.7Least privilege. Permissions requested from third-party services are limited to the narrowest scope sufficient for the stated function, as described in Section 3.
10.8Network isolation. Databases are not accessible from the public internet. Access is restricted to the application components that require it. Object storage is configured to deny all public access.
10.9Secret management. Infrastructure credentials are held in a managed, encrypted secret store. They are not stored in source code or in configuration committed to source control.
10.10Backups. Automated backups of the primary database are taken daily and retained for seven days, after which they are overwritten. The storage holding the structured knowledge graph is snapshotted daily on the same seven-day retention. Backups and snapshots inherit the encryption described in 10.2.
10.11No method of transmission or storage is completely secure. We do not represent that the Service is immune from compromise. This Section describes the measures we apply; it is not a warranty of outcome.
10.12Where we become aware of a breach of security affecting your personal information, we will notify you and any applicable regulator to the extent and within the timeframes required by applicable law.
11Retention
11.1We retain personal information for the periods set out below.
| Category | Retention period |
|---|---|
| Structured knowledge graph, pages and relationships | Duration of the account |
| Query history | Duration of the account |
| Uploaded files and recorded audio | 30 days from upload |
| Transcripts of recorded audio | Until the account is deleted |
| Diagnostic records containing third-party error text | 30 days |
| Records of retrievals by connected assistants | Duration of the account |
| Backups and snapshots | 7 days |
| Session credentials | 30 days, or until revoked |
11.2The knowledge graph is retained for the duration of the account because its accumulated content is the function of the Service. Material that is incidental to producing it is deleted on the schedule above regardless of account status.
11.3Transcripts of recorded audio are retained for the duration of the account rather than on a fixed schedule. They are deleted when the account is deleted, as described in Section 12.1. The uploaded audio from which they are derived is deleted 30 days after upload regardless of account status.
11.4Following deletion of an account we retain operational records that contain no personal information and are not linked to an identifiable individual, for the purpose of maintaining the Service.
12Deletion and your rights
12.1Deletion. You may delete your account at any time from within the Service. On deletion we permanently delete your knowledge graph, pages and relationships, query history, uploaded files, recorded audio and transcripts, and credentials for authorised sources; and we withdraw our authorisation at each third-party service you had connected. Deletion is immediate and irreversible. Copies contained in backups and snapshots are overwritten within seven days.
12.2Access and correction. Your information is visible and editable within the Service. Where you require information we hold that is not accessible through the Service, you may request it using the contact details in Section 16.
12.3Export. A copy of the information we hold about you is provided on request, in a structured, commonly used and machine-readable format, within the period stated in 12.6.
12.4Depending on your jurisdiction you may additionally have the right to object to processing, to request restriction of processing, to withdraw consent, and to lodge a complaint with your supervisory authority. Australian residents may complain to the Office of the Australian Information Commissioner.
12.5We do not discriminate against you for exercising any right under this Section.
12.6We will respond to requests under this Section within 30 days, or such shorter period as applicable law requires.
13Tracking
13.1We do not use third-party analytics, advertising or behavioural tracking services in the Service, in our marketing site, or in our backend systems.
13.2We do not set advertising cookies and we do not participate in cross-context behavioural advertising.
13.3Cookies and equivalent local storage are used only as necessary to maintain your authenticated session and your interface preferences.
14Children
14.1The Service is not directed to, and may not be used by, individuals under 16 years of age. We do not knowingly collect personal information from such individuals.
14.2Where we become aware that we have collected personal information from an individual under 16, we will delete it. If you believe this has occurred, please contact us using the details in Section 16.
15Changes to this policy
15.1We may amend this policy. Where an amendment materially affects your rights or our handling of your personal information, we will provide notice within the Service before the amendment takes effect.
15.2The date at the head of this policy indicates when it was last amended.
16Contact and complaints
16.1Enquiries and requests under Section 12 should be directed to hello@josephmark.com.au.
16.2If you are dissatisfied with our response, you may refer the matter to the Office of the Australian Information Commissioner.