Privacy policy

How Partner Evidence collects, uses, shares, protects and removes personal information.

Effective and last updated 29 September 2026.

Who we are and how to contact us

Partner Evidence is the service name used in this policy. For access, correction, deletion or privacy complaints, contact us using the details below.

Partner Evidence
Sydney, New South Wales, Australia
support@partnerevidence.com.au

About this policy

This policy applies when you visit our website, create an account, use a case, pay for a case, contact us or take part in the referral program. Relationship evidence can reveal highly personal information about you, your partner and other people. We treat it as private case content and aim to handle personal information consistently with applicable Australian privacy law.

Information we collect and hold

  • Account and contact details, such as your name, email address and authentication records.
  • Case information and content you choose to add, including photos, documents, captions, timeline events, imported conversations and information about people appearing in that material.
  • File-derived information, such as document text, photo metadata, thumbnails, file names and storage references created to provide the features you request.
  • Technical and security information, such as device, browser, IP address at request time, sign-in events, identifiers and limited operational logs.
  • Purchase, entitlement, refund, dispute and referral records. Stripe handles full payment-card details; Partner Evidence receives transaction status and identifiers rather than storing full card numbers as case data.
  • Analytics information collected with permission, including pages viewed, product actions, device or browser information and approximate location derived from network information.
  • Messages you send to support, survey responses and payout details you provide when requesting a referral payout.
  • Consent and preference records, including analytics choices and whether optional AI search is enabled for a case.

How we collect information

Most information comes directly from you when you create an account, upload material, import a chat, invite someone, pay or contact us. We also receive transaction status from Stripe, referral attribution from a link or first-party cookie, and permitted analytics from Google Analytics and PostHog. A collaborator may add information about you to a shared case. If required information is not provided, the related feature may not work.

Why we use it

  • To provide the case workspace, uploads, chat tools, search, collaboration and exports you request.
  • To authenticate users, protect accounts, prevent fraud, enforce limits and maintain reliable service.
  • To process purchases, case entitlements, referrals and manual payout requests.
  • To answer support requests and send account, security, payment and inactivity-removal notices.
  • To understand website and product use, diagnose problems and improve features using consent-based analytics that excludes private evidence contents.
  • To comply with law, enforce our terms, resolve disputes and establish, exercise or defend legal claims.
  • To perform any other purpose disclosed at collection or carried out with your consent.

Google Analytics and PostHog

We use Google Analytics and PostHog Cloud US for analytics only after the applicable consent choice. These services may receive page URLs, product-event names, timestamps, device or browser information, cookie or device identifiers, account identifiers where deliberately configured, and approximate location. Analytics data may be linked across visits so we can understand whether features work.

We do not send chat text, evidence captions, document contents, bank details, file names or generated evidence packs as analytics event properties. We do not use private case content for advertising or enable session replay over private case content. More detail appears in our Cookie Policy.

When we disclose information

We disclose information to service providers acting for us, people you invite to a case, professional advisers under confidentiality, law-enforcement or regulators where legally required, and a buyer or successor in a proposed or completed business transaction subject to confidentiality and applicable law. Providers receive information needed for their function and are not authorised by us to use private case content for their own advertising.

We do not sell or rent personal information, and we do not sell private case content. We may use aggregated or de-identified information that does not reasonably identify a person.

Current service providers and locations

The following providers support the current service. Their own privacy notices explain their handling in more detail. Providers and subprocessors can change; we will update this policy and give notice of material changes where appropriate.

PurposeApplication database, account authentication and access control.
Information involvedAccount details, case records, structured evidence information and security records.
Primary or known locationPrimary project region: Sydney, Australia (ap-southeast-2). Limited support or subprocessors may operate elsewhere.
PurposePrivate object storage and delivery of short-lived file links.
Information involvedUploaded photos, documents, original chat-export files and generated export files.
Primary or known locationOceania location hint. Cloudflare describes R2 location hints as best-effort, not a legal data-residency guarantee.
PurposeCheckout, payment processing, refunds, disputes and fraud prevention.
Information involvedContact, transaction, device and payment information. Partner Evidence does not receive full card numbers.
Primary or known locationAustralia, the United States and other countries in Stripe's global processing network.
PurposeTransactional and service email, including security and inactivity notices.
Information involvedEmail address, delivery data, case display name and scheduled deletion date for retention notices.
Primary or known locationMay be processed outside Australia as described in SMTP2GO's privacy notice and subprocessor arrangements.
PurposeConsent-based website and product analytics.
Information involvedPage and product events, cookie or device identifiers, browser and approximate location information. Google Analytics does not log or store individual IP addresses.
Primary or known locationGoogle operates globally, including in the United States.
PurposeConsent-based product analytics and feature measurement. Session replay is not used for private case content.
Information involvedPage and product events, device or account identifiers and technical context; not evidence contents.
Primary or known locationPostHog Cloud US; information is processed in the United States and by approved subprocessors.
PurposeOptional AI-search answers when a user activates AI search. Matching messages are found by keyword search inside the case; only then is a request made.
Information involvedA search query and the selected relevant message excerpts needed to answer it. No search index is stored with the provider.
Primary or known locationThe United States and other countries used by OpenRouter and the AI models it routes to.

Optional AI processing

AI search is off until an authorised user activates it. When enabled, OpenAI creates embeddings for the text needed to build the case search index, and Anthropic may receive a question plus relevant excerpts to produce an answer. The activation screen identifies the processing and available controls. Basic WhatsApp parsing and activity analysis run in the browser where the feature says they do.

AI output may be inaccurate. Private evidence is not used to train a Partner Evidence model. We use provider API or business services under their applicable data terms, but provider retention and approved subprocessors are controlled by those providers and requests may be processed outside Australia. Turning off AI search deletes the case's AI index according to the product control; it does not itself delete the underlying source material.

Overseas disclosure and processing

Supabase primary project data is configured for Sydney, Australia. Cloudflare R2 uses an Oceania location hint, which is best-effort rather than a jurisdiction guarantee. Stripe, Google, PostHog US, OpenAI, Anthropic, SMTP2GO and their subprocessors may process or access information in the United States and other countries where they operate. Privacy protections in those countries may differ from Australia. We take reasonable steps through provider selection, contracts, access controls and data minimisation, while recognising that not every overseas disclosure can be made subject to identical local law.

Security

We use private object storage, role-based access controls, short-lived signed file links, encrypted connections, input validation, audit records, backups and restricted administrative access. A person removed from a case loses case access immediately, although a signed file link already issued may continue to work until its short expiry.

No online service can guarantee absolute security. You must protect account credentials, use a secure device and tell us promptly about suspected unauthorised access. Do not send evidence files through ordinary support email or the public contact form.

Data incidents

We investigate suspected loss, misuse or unauthorised access. If an incident is likely to result in serious harm and Australian notification law applies, we will notify affected people and the Office of the Australian Information Commissioner as required. We may also give voluntary notice where it is useful for protection even when the statutory threshold is not met.

Inactivity removal and advance notices

If a case has no authenticated opening or use for 24 consecutive months, its stored case files are scheduled for permanent removal. This is a file-retention process, not automatic deletion of the account or the entire case record.

When we notify you

We schedule six advance notices to the case owner's account email and show notices inside the shared case. A final notice is scheduled on the deletion date. Only the owner receives the email; every authorised case member can see the in-app warning.

  • 365 days before
  • 180 days before
  • 90 days before
  • 30 days before
  • 7 days before
  • 1 days before

The inactivity process removes

  • Uploaded photo and document files, their file records, and related extracted text or photo metadata.
  • The original uploaded chat-export file. Parsed chat messages and other structured case records are not removed by this file-retention process.
  • Generated PDF or archive export files held by the service.

It does not delete the whole case

The account and case remain. Case names, members, milestones, checklist state, evidence-item titles, dates and categories, parsed chat records and other structured records may remain until you delete the case or account, or we action a valid deletion request, subject to records we must or may retain by law.

Opening the case while signed in before the deadline marks it active and restarts the inactivity period. If deletion has already begun, we stop when the system detects new activity, but anything already permanently removed cannot be restored.

Keep the account email current and check in-app notices. Email delivery can fail or be filtered, and deletion is based on the displayed scheduled date rather than whether an email was opened. If a notice cannot be delivered, we may retry it, but the inactivity period does not automatically pause.

Removal is permanent. Download anything you need before the scheduled date. You may also delete individual material, AI indexes, a case or your account earlier through available controls or by contacting us. Read the plain-language retention explanation.

Other retention and backups

Account, consent, billing, tax, refund, fraud, referral, security, support and audit records are retained only for as long as reasonably needed for the purpose collected, dispute handling, enforcement or legal obligations. Different periods apply to different records. We may preserve information subject to a legal hold or active dispute even after a deletion request.

Deleted information may remain for a limited period in encrypted backups or provider recovery systems before being overwritten. It is not returned to normal use and may be restored only for disaster recovery, legal or security purposes, after which the deletion process continues.

Information about partners and other people

Do not upload another person's information unless you have a lawful basis and authority to do so. Tell invited collaborators how the shared case works and consider whether consent is appropriate before uploading sensitive material about a partner, child or other person. We may remove material or restrict access where necessary to respond to a valid privacy, safety or legal request.

Children

The service is for adults. A case may contain information about a child where an adult user has lawful authority to add it for the case purpose. We do not knowingly permit children to create accounts. Contact us if you believe a child has created an account or their information has been added without proper authority.

Access, correction and control

You can view and update much of your information in the product. You may ask for access to or correction of personal information we hold, withdraw optional analytics or AI consent, or ask how information is being handled. We may verify identity and authority, refuse or limit a request where permitted by law, and explain any refusal.

You can delete individual evidence, chat imports, AI indexes, exports or a whole case using available controls. You may also request account deletion. Deletion requests do not override records we must or may retain for law, safety, fraud prevention, payment disputes, accounting or legal claims. Deleting a shared case affects every member, so owner permissions and confirmation may apply.

Privacy questions and complaints

Send a privacy question or complaint to support@partnerevidence.com.au.

Include enough detail for us to identify the issue, but do not attach private evidence unless we ask for it through a secure channel. We aim to acknowledge complaints promptly and respond within a reasonable period, normally within 30 days.

If you are not satisfied with our response, you may be able to contact the Office of the Australian Information Commissioner.

Changes to this policy

We may update this policy when law, providers, product features or handling practices change. We will change the effective date and, where a change materially affects existing users, provide reasonable notice in the product, by email or both before it takes effect where practical.

Partner Evidence is not a registered migration agent or law firm and does not provide immigration assistance or legal advice.