Privacy Policy

Last updated: 2 October 2026. This page is in English only.

Customer Experience Insight Pty Ltd trading as WA AI Hub (ABN 61 634 039 759) (we, us) operates AIEdu at aiedu.quest from Western Australia. We are the controller of the personal information described here.

Our commitment. We are a small business operator and, under the Privacy Act 1988 (Cth), are not currently required to comply with the Australian Privacy Principles (APPs). We have chosen to handle personal information as if the APPs applied, including the automated-decision transparency rules in APP 1.7 – 1.9 that start on 10 December 2026, and to give every person, wherever they live, the rights in section 10 (which follow the EU General Data Protection Regulation (GDPR)). If our status changes, or the law changes, we will comply as required. Our commitments here are binding promises to you and are enforceable under the Australian Consumer Law.

1. Contact

Privacy questions, access, correction, deletion and objection requests, and complaints: privacy@wahub.ai. We do not have a Data Protection Officer (not required for our scale and activities) and do not currently target the EU or UK, so we have not appointed an EU or UK representative; you may still use the rights below and contact us directly. You may use the free no-account features without giving us your name (APP 2).

2. What we collect, why, and our legal basis

Where the GDPR applies we rely on the legal bases shown: Contract (Art 6(1)(b)), Legitimate interests (Art 6(1)(f)), Consent (Art 6(1)(a)) or Legal obligation (Art 6(1)(c)).

WhenWhat we collectWhyBasis
You use the free assessment, path or modules without an accountQuiz answers, role, response times, results, browser user-agent string, a random guest ID (cookie) and session ID.Run the assessment, show results and your learning path, understand and improve the product.Contract (providing what you ask for); legitimate interests (product improvement).
You create an account or sign inName, email, hashed password (we never see or store it in plain text), and sign-in session records (including IP address and device details) held by our authentication provider. A record of the Terms version and 18+ confirmation you accepted, with the time.Provide and secure your account.Contract; legitimate interests (security).
You use signed-in featuresSaved paths and progress; Prompt Gym scores, rubric and AI sample output (not the prompt text you typed); Bias Detective answers with the AI’s grade; assessment pillar scores; certificates issued to you; feedback you submit.Save progress, assess certificate eligibility, show the team view if you opt in.Contract; consent for team sharing.
You subscribePlan, subscription status and dates, Stripe customer ID, and payment-event records. Card details go only to Stripe.Take payment, manage subscriptions, prevent fraud, keep tax records.Contract; legal obligation (tax/accounting); legitimate interests (fraud prevention).
You join or are invited to a teamInvited email, role, and whether you share pillar scores (off by default).Operate the Team plan.Contract; consent for score sharing.
You join the waitlistEmail and plan of interest.Tell you when paid plans open; nothing else without your consent.Consent (withdraw any time).
Every requestIP address and request data processed by our host and security layers. For rate limiting we keep only a salted one-way hash of your IP address or guest/user ID, with a counter, in our Sydney database for a few days.Keep the service secure, available and within fair-use limits.Legitimate interests.

We collect directly from you and your device, from Stripe (subscription status) and, for team invitations, from the team owner who invited you. We do not intentionally collect sensitive or special-category information (health, race, religion, biometric and similar) and ask you not to enter it into free-text fields. Providing information is voluntary, but we cannot provide an account, payment or certificate without the information marked as required.

3. Use and disclosure

We use personal information for the purposes above, to respond to you, to meet legal obligations and to protect our rights. We do not sell personal information, we do not “share” it for cross-context advertising, and we do not build advertising profiles. We disclose it only to the processors in section 4 (who act on our instructions), where you ask us to or opt in (team sharing), or where required or authorised by law (for example to a court, regulator or law enforcement).

4. Where your data is held and overseas transfers (APP 8; GDPR Chapter V)

Storage and processing are in Australia by default: our database and sign-in service are hosted by Neon in Sydney (AWS ap-southeast-2) and our application code runs on Vercel’s Sydney (syd1) region, including the rate-limit counters, which are kept in our own database. Personal information goes to the United States only when you use an AI feature (OpenAI, and Google if OpenAI is unavailable), when you pay (Stripe), and in Vercel’s global control plane and operational logs. We take reasonable steps to ensure each recipient protects it consistently with the APPs. For EU/UK individuals we rely on the Standard Contractual Clauses (OpenAI, which is not certified under the EU–US Data Privacy Framework) or the Data Privacy Framework where the recipient is certified (Google, Stripe, Vercel and Neon’s parent, Databricks, state that they are), with supplementary measures. Overseas recipients may be subject to foreign laws, including government access laws.

Provider (role)PurposeInformation involvedLocation
Neon (processor)Database and authenticationAll account and learning records in section 2Sydney, Australia
Vercel (processor)Hosting, request processing, delivery, logsRequest data including IP address; data in transit to the databaseApplication runs in Sydney (syd1); global edge delivery; control plane and some logs may be in the United States
OpenAI (processor)AI scoring, feedback, tutor, path text, translationText you submit to AI features; prompts built from your role and results. We do not intentionally send your name or email.United States
Google — Gemini API (processor)Fallback AI provider for the same functionsAs aboveUnited States
Stripe (independent controller for payments and fraud; processor for subscription data)Payments, billing portal, fraud prevention (Stripe Radar)Name, email, billing details, payment method, device and risk signalsStripe’s global infrastructure, including the United States

5. AI features

Several features use third-party AI models. Text you type into them is sent to the providers above to generate the response; this is disclosed beside every such feature. Under the providers’ published API terms, inputs and outputs are not used to train their models (OpenAI by default; Google for its paid API, which is the only tier we use), and each may retain them for up to 30 days solely for abuse and safety monitoring (longer only if the law requires). We have not opted in to any training or data-sharing programme. Please do not enter personal, client or confidential information. We log technical metadata for each AI call (route, model, token counts, a one-way hash of the prompt, timing, errors) — not the prompt text. AI output can be wrong; see How we use AI.

6. Automated decisions (APP 1.7 – 1.9; GDPR Art 22)

The decisions below are made by, or substantially and directly based on, a computer program using personal information, and could reasonably be expected to significantly affect your rights or interests. The full register and how to ask for a human review is on How we use AI.

Kind of decisionKind of personal information usedSolely by the program?
Whether you are eligible for, and are issued, the “AI Literacy Practitioner” certificateUser ID, whether you completed the diagnostic assessment, AI-generated Prompt Gym rubric scores.Yes — fixed rules applied to AI-generated scores. You can request human review and contest the outcome.
Which features and quotas you can access (free, Pro, Team, Enterprise), including loss of paid access when a subscription ends or payment failsUser ID, tier, subscription status, team membership.Yes — from your subscription status. You can request human review.
AI scoring of Prompt Gym, Bias Detective and Output Critic submissions (substantially and directly related to the certificate decision)The text you submit and the task or case.The score is produced by the program and is a key input to the certificate decision.
Team pillar heat-map shown to managers (opt-in only)Latest pillar scores and email.No — it informs a person; Terms prohibit sole reliance for employment decisions.

Our payment processor separately uses automated fraud scoring (Stripe Radar) that may decline a payment; Stripe is responsible for that decision and you can ask us or Stripe to have it reviewed. We also use automated rules for rate limiting and a rules-based pathway recommendation; we do not consider these significant. You have the right to obtain human intervention, express your view and contest an automated decision (section 10).

7. Cookies and similar technologies

We checked what our live site sets: no cookies are set when you simply visit pages. We use only strictly necessary technologies, which do not require consent under the ePrivacy rules (Art 5(3)):

  • aiedu_anon_id — httpOnly, secure, first-party cookie holding a random guest ID for 30 days, set only when you start the assessment, so your free results can be linked to an account you later create.
  • Sign-in session cookies set by our authentication provider only while you are signed in.
  • Browser storage (sessionStorage / localStorage) for quiz progress, language and theme you choose. It stays on your device.

We do not use advertising, analytics or cross-site tracking cookies. Stripe, when you check out, sets its own cookies on its hosted pages under its policy.

8. Security (APP 11; GDPR Art 32) and breaches

  • Encryption in transit (HTTPS with HSTS); data in our database is encrypted at rest by our provider; passwords are hashed; hosted payment pages mean card data never reaches us.
  • Role-restricted infrastructure access; same-origin and rate-limit protections on account actions; a record of the Terms and age confirmation you gave; secrets held in the hosting platform’s encrypted environment; admin reporting behind a secret token; rate limiting against abuse; security headers (CSP, frame and content-type protections).
  • Multi-factor authentication is not currently offered for learner accounts. To compensate, we offer passwordless email sign-in links and ask you to use a unique password. We are assessing adding MFA.
  • No internet service is perfectly secure. If an eligible data breach occurs we will assess and notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as required by Part IIIC of the Privacy Act and, where the GDPR applies, the supervisory authority within 72 hours (Art 33).

9. How long we keep information (APP 11.2; GDPR Art 5(1)(e))

Retention is enforced by an automated daily job and by deletion on request; the periods below are the ones the job applies.

InformationHow long
Guest cookie30 days.
Anonymous quiz records (never linked to an account)Deleted automatically after 12 months.
Account, saved paths, scores, attempts, certificatesWhile your account is open. Deleted immediately when you delete your account yourself (section 10), or within 30 days of a verified request.
Sign-in sessions held by our authentication provider (include IP address and device details)Until they expire; expired sessions and email-verification tokens are deleted automatically within 30 days. Deleted with your account.
AI call metadata (route, model, token counts, prompt hash)Deleted automatically after 12 months, or with your account.
Payment-event records we keep to run subscriptionsPersonal details in them are erased automatically after 90 days (a non-identifying ledger entry remains), or on account deletion.
Payment and tax records held by Stripe5 years after the transaction, as Australian tax law requires. Stripe retains these even if you delete your account.
Terms-acceptance recordsWhile your account is open (evidence of the version you accepted); then deleted. We keep only an anonymous, one-way-hashed entry proving a deletion request was honoured.
Waitlist emailUntil you ask us to remove it, or 24 months.
Unaccepted team invitationsDeleted automatically after 90 days.
Rate-limit counters (hashed keys)Deleted automatically within about 3 days; the monthly generation counter within about 5 weeks.
Hosting and security logsShort-lived, on our host’s standard schedule.

We also review stored data at least annually. Backups kept by our database provider are overwritten in its ordinary cycle.

10. Your rights

Whoever and wherever you are, you may ask us to: give you access to the personal information we hold (APP 12; GDPR Art 15) and a portable copy (Art 20); correct it (APP 13; Art 16); delete it (Art 17); restrict or object to processing based on legitimate interests (Arts 18, 21); withdraw consent at any time; and obtain human review of, and contest, an automated decision (Art 22). Signed-in users can download their data and permanently delete their account themselves under Account → Your data. For anything else, email privacy@wahub.ai from the address on your account. We will verify your identity, and respond within 30 days (extendable by up to two further months for complex requests, with notice). There is no charge unless a request is manifestly unfounded or excessive. If we refuse, we will say why and how to complain. Withdrawing consent does not affect earlier lawful processing.

11. Children

AIEdu is for adults aged 18 or over and is not directed at children. See our Children’s Privacy Policy.

12. Complaints and regulators

Contact us first at privacy@wahub.ai; we will acknowledge within 7 days and aim to resolve within 30 days. You may complain to the OAIC at oaic.gov.au (1300 363 992). If you are in the EU/EEA you may complain to your local data protection authority, and if in the UK to the Information Commissioner’s Office.

13. Changes

We will update this policy and its date when our practices change, and take reasonable steps to tell account holders of material changes before they take effect. Related: Terms of Use, Refund Policy, How we use AI.