Privacy Policy
Effective: 1 March 2026
1. Who We Are
BitBit Pty Ltd (ABN pending) ("BitBit", "we", "us") operates an AI-powered personal and business operations platform. This policy explains how we collect, use, store, and protect your personal information in compliance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
Where we process data of individuals in the European Economic Area, we also comply with the General Data Protection Regulation (GDPR).
2. Information We Collect
Account Information
Name, email address, organisation name, billing address, and payment details (processed by Stripe).
Usage Data
Feature usage, agent invocations, token consumption, API call logs, and session analytics. We use this data to operate, improve, and bill for the Service.
Connected Channel Data
When you connect third-party channels (email, Asana, Calendly, Stripe, WhatsApp), we receive messages, events, and metadata from those services as authorised by you. This data is processed by AI agents to provide automation features.
AI-Processed Content
Content submitted to AI features (drafting, classification, analysis) is sent to Anthropic's Claude API for processing. Anthropic does not use API inputs for model training. See Anthropic's Privacy Policy.
3. AI Processing and Third-Party AI Services
BitBit uses artificial intelligence to power its automation features including task classification, message drafting, lead scoring, and conversational agents.
How Your Data Is Processed by AI
When you use AI-powered features, your input (messages, task descriptions, channel data) is sent to Anthropic's Claude API for processing. This means your data transits through servers located in the United States, even though your primary database is hosted in Australia.
Data Usage by Anthropic
Under Anthropic's commercial API terms, Anthropic does not use your API inputs or outputs to train its models. Your data is processed solely to generate responses and is subject to Anthropic's data retention policies for API customers. See Anthropic's Privacy Policy for details.
AI-Generated Content Disclaimer
Responses generated by AI features may contain inaccuracies. BitBit is a tool to assist your workflow -- it does not replace professional judgment. Always review AI-generated content before acting on it, particularly for financial, legal, or contractual matters.
4. How We Use Your Information
- Provide, maintain, and improve the Service.
- Process payments and manage subscriptions.
- Send transactional emails (invoices, alerts, system notifications).
- Generate analytics and usage reports for your organisation.
- Detect and prevent fraud, abuse, or security incidents.
- Comply with legal obligations.
5. Data Storage and Security
Your primary account data is stored in Supabase-managed PostgreSQL databases in the ap-southeast-2 (Sydney, Australia) region. Data is encrypted at rest (AES-256) and in transit (TLS 1.3). Integration credentials are encrypted with AES-256-GCM before storage.
We implement row-level security (RLS) policies to ensure strict tenant isolation. Each organisation's data is accessible only to authenticated members of that organisation.
6. Third-Party Processors
The following third parties process personal data on our behalf:
| Processor | Purpose | Location |
|---|---|---|
| Supabase | Database, auth, storage | Sydney, AU |
| Anthropic | AI model inference | US |
| Stripe | Payment processing | US / Global |
| Vercel | Application hosting | Global CDN |
| Sentry | Error monitoring | US |
| Processor | Purpose | Location |
|---|---|---|
| Fly.io | Messaging bridge compute (WhatsApp, Android Messages) | US / Multi-region |
| LightNode | iMessage bridge (Mac VPS) | TBC |
| Cloudflare | DNS, DDoS protection, tunnels | Global |
| Resend | Transactional email delivery | US |
| Telnyx | SMS delivery | US |
| OpenAI | Text embeddings (semantic search) | US |
| Voyage AI | Text embeddings (technical content) | US |
| Pinecone | Vector database (embedding storage) | US |
| Brave Search | Web search for AI agents | US |
| Composio | Third-party API integration layer | US |
7. Data Retention
- Active account data: retained while your subscription is active.
- After cancellation: data available for export for 30 days, then deleted.
- Billing records: retained for 7 years per Australian tax law.
- Anonymised analytics: may be retained indefinitely.
8. Your Rights
Under the APPs (and GDPR where applicable), you have the right to:
- Access personal information we hold about you.
- Request correction of inaccurate information.
- Request deletion of your personal information.
- Export your data in a machine-readable format.
- Object to processing (GDPR) or withdraw consent.
- Lodge a complaint with the OAIC or relevant supervisory authority.
To exercise these rights, email privacy@bitbit.au.
8A. International Data Transfers
BitBit transfers personal data to processors located outside Australia, including in the United States. These transfers occur when your data is processed by Anthropic (AI inference), OpenAI and Voyage AI (embeddings), Pinecone (vector storage), Vercel (application hosting), Fly.io (bridge compute), Resend (email), Telnyx (SMS), Brave Search (web search), and Composio (integrations).
For users in the European Economic Area, transfers to the United States are made under Standard Contractual Clauses (SCCs) as approved by the European Commission, or another applicable transfer mechanism. A copy of the applicable transfer mechanism can be requested by emailing privacy@bitbit.au.
For Australian users, BitBit takes reasonable steps to ensure that overseas recipients of personal information handle that information consistently with the Australian Privacy Principles, as required by APP 8.1. Where an overseas recipient cannot provide an equivalent level of protection, we rely on the exception in APP 8.2(b) and will notify you of this in the relevant product interface.
9. Cookies
We use essential cookies for authentication and session management. We do not use advertising or third-party tracking cookies. Analytics are collected server-side.
10. Children
The Service is not directed at individuals under 18. We do not knowingly collect personal information from children.
11. Changes to This Policy
We may update this policy from time to time. We will notify you via email at least 14 days before material changes take effect.
12. Contact
Privacy Officer: privacy@bitbit.au
Office of the Australian Information Commissioner: www.oaic.gov.au