⚠️ DRAFT — Pending legal review. This is an interim Privacy Policy based on the Australian Privacy Principles (APPs) and the OAIC Children's Online Privacy Code exposure draft. The final version will be independently reviewed before public launch.

Privacy Policy

Last updated: 2026-09-21 · Effective: at first launch

1. Who we are

BambooPrep is operated by Henry Huang (ABN active from 21 May 2026), trading as "BambooPrep" (ASIC business name registration in progress). Contact: hello@bambooprep.com.au.

This Privacy Policy explains how we collect, use, hold, and disclose your personal information in accordance with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth), and the OAIC Children's Online Privacy Code (effective 10 December 2026).

2. Personal information we collect

From parents (account holders):

  • Email address (required for sign-up + transactional emails)
  • Name (legal name, as it appears on payment card)
  • Phone number (optional, used only for account recovery)
  • Payment card details (processed by Stripe — we never store full card numbers)
  • Preferred language (English)
  • Exam registration, membership status and Selective discount eligibility requests, including review decisions.

Free diagnostic: anonymous answers are used to score the sample, not stored in a student profile. If a parent chooses to save, pending answers stay in this browser tab during registration, with a one-hour save window. They are cleared on successful save, discard, expiry detection or closing the tab. After account setup and confirmation, the saved report becomes student practice data covered by account export and deletion. Diagnostic answers are never sent to an AI model.

From children (under parent account):

  • Display name (can be a nickname — does not need to be legal name)
  • Target exam (OC / Selective)
  • Exam month (optional)
  • Practice attempt data (questions answered, time taken, correct/incorrect)

We do not collect: health information, biometrics, government IDs (other than what Stripe receives for payment), photos/videos, or location data.

3. Why we collect it (purposes)

  • To deliver personalised practice sessions to your child
  • To generate fresh AI questions calibrated to your child's level and weak areas
  • To send your account confirmations, receipts, and weekly progress reports
  • To verify parental consent under the Children's Online Privacy Code
  • To bill subscriptions and process refunds
  • To improve our AI question quality (aggregated and de-identified metrics only)

We will not: sell your data, train external AI models on your child's answers, share data with marketers, or use data for advertising profiles.

4. How we hold it (security + data residency)

All consumer personal information is stored in Australian data centres:

  • Database: Neon Postgres, Sydney region (aws-ap-southeast-2)
  • Serverless functions: Vercel, pinned to syd1 (Sydney) region
  • Static assets: Vercel global CDN (cached HTML only, no PII)

Data is encrypted in transit (TLS 1.3) and at rest (AES-256). We follow industry standard practices for password hashing (Clerk-managed), credential rotation, and least-privilege access controls.

5. Who we share with (sub-processors)

We use the following trusted sub-processors. Each is bound by a Data Processing Agreement:

  • Vercel Inc. (US) — hosting + serverless. Functions pinned to Sydney region for compliance.
  • Neon Inc. (US-controller, Sydney data) — Postgres database hosted in Sydney region.
  • Clerk Inc. (US) — authentication. Stores account sign-in details and the OC or Selective registration preference used to prepare account setup.
  • Anthropic PBC (US) — AI question generation. We send only curriculum and question requirements, without student-identifying information, and receive generated content. Workspace configured with "Zero data retention".
  • Stripe Inc. (US/IE) — payment processing. We share only what's required for billing.
  • Resend Inc. (US) — transactional email delivery (welcome, receipt, weekly digest).

6. Overseas disclosure (APP 8)

Some of our sub-processors (Anthropic, Clerk, Stripe, Resend) operate from the United States. Under Australian Privacy Principle 8, we take reasonable steps to ensure these providers handle your data consistently with the APPs through written contracts (DPAs).

The learning-profile setup records the parent or legal guardian's agreement to this Privacy Policy and the collection of practice data. Backend AI processing is disclosed here and does not provide a chat or direct AI interaction to students.

7. Children's data (special handling)

For children under 15, we follow the OAIC Children's Online Privacy Code:

  • Children cannot create accounts directly — only a parent or legal guardian can create an account on behalf of a child
  • We require a parent or legal guardian aged 18 or older to acknowledge this Privacy Policy and consent to collection of the student's practice data
  • The most-restrictive privacy settings are enabled by default for child accounts
  • There is no chat between children, no public profiles, and no direct messaging features that could expose children to strangers
  • The account remains parent-owned and can be exported or deleted by the account holder
  • We do not allow targeted advertising of any kind to children

8. Your rights (APP 12 + APP 13)

You can, at any time:

  • Access your data — request a complete export of all data we hold about your account and your children (delivered within 30 days). Available at Account → Data export.
  • Correct inaccurate data — update your account information through Account settings or by emailing us
  • Delete your data — close your account and request full erasure within 30 days (including from backups). Available at Account → Delete account.
  • Withdraw consent — withdraw data-collection consent by closing the account and requesting deletion
  • Complain — to us first at privacy@bambooprep.com.au. If unresolved, you may complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au

9. Data breach notification (NDB Scheme)

If we become aware of a data breach likely to result in serious harm to you or your child, we will notify both you and the Office of the Australian Information Commissioner without undue delay (typically within 30 days), per the Notifiable Data Breaches scheme.

10. Changes to this policy

We will notify you of material changes by email and via an in-app notice. The effective date at the top of this page indicates when the current version took effect. After the OAIC Children's Online Privacy Code is formally registered (10 December 2026), we will issue a refreshed version aligned with the final registered Code.

11. Contact us

Privacy enquiries: privacy@bambooprep.com.au
General enquiries: hello@bambooprep.com.au