Skip to content

Privacy Policy

Version 0.12-draft · Last updated 3 September 2026

Draft — PENDING COUNSEL REVIEW

This document has been updated with the owner’s commercial decisions and current provider terms, but has not yet been reviewed or approved by Australian legal counsel. It is published for launch review and is not yet the final approved statement of your rights or ours.

Who we are

Home Logbook is a digital property logbook operated by Christopher Michael, trading as Home Logbook (ABN 50 806 369 057), a sole trader based in Australia. We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles.

What we collect

Account details. Your email address and name, a password hash if you set a password, and identifiers from Google if you sign in with Google. If you subscribe or buy a report, we also hold the customer and subscription identifiers our payment processor gives us.

Property records. The addresses you add and everything you record against them — materials, maintenance, renovations, systems, timeline entries, development applications, jobs and garden records — together with property attributes we retrieve from data providers.

Documents and photos you upload. The files themselves, and the text and fields extracted from them.

Assistant conversations. Your questions, the answers, the records used to answer them, and summaries generated from those conversations. The summaries are used as memory so the assistant can refer back to earlier conversations.

Email you forward to your logbook. The sender address, subject, body and attachments of messages sent to your logbook’s email address.

Payment records. The amount, currency, the address a report was purchased for, and the payment processor’s session identifier. We do not receive or store your card number.

Usage information. If — and only if — you turn analytics on, which pages you visit (as route templates, never including any link token or payment identifier) and a small allowlisted set of event properties. We do not send your email address or your property address to analytics.

Error reports. Technical information when something goes wrong, including your account identifier so we can trace an incident. Session recording is off unless you turn analytics on, and when it is on, on-screen text, form inputs and images are masked.

Why we use it

To run the service you asked for: storing your records, generating reports, answering your questions, sending the reminders you have chosen, taking payment, and keeping the service working and secure. If you turn analytics on, we also use it to understand how the product is used so we can improve it.

We do not sell your personal information.

The service is for adults and is not directed to children. We do not knowingly create accounts for, or send customer content to an AI provider on behalf of, anyone under 18. Contact us if you believe a child has provided personal information so we can investigate and remove it where appropriate.

Artificial intelligence

Reading your documents, describing your photos, generating the property narrative and answering assistant questions are all done using AI services provided by third parties outside Home Logbook. To do that, the content concerned — including the text of documents you upload, copies of your photos, and your assistant questions together with the records used to answer them — is sent to those providers.

We use more than one provider: a failover chain of Google Gemini, OpenAI and Anthropic. A request may be handled by any of them depending on the feature and availability, and may be processed outside Australia. We do not opt customer content in to general model improvement or training. Production is prevented from using Gemini unless its API key has been confirmed as a paid Google Cloud service; Google’s unpaid service terms permit broader improvement use and are not suitable for customer property content.

Provider safety systems can temporarily retain prompts and output. Google states that Gemini abuse-monitoring content is retained for 55 days. OpenAI API abuse-monitoring logs are normally retained for up to 30 days. Anthropic normally deletes API inputs and outputs within 30 days. Each provider may retain flagged content longer to enforce its safety rules, comply with law or protect its service; Anthropic says flagged content may be held for up to two years and related safety scores for up to seven years.

AI-generated content is labelled where it appears. It can be wrong, and it is not legal, planning, valuation, financial, building or trade advice.

Who else receives it

We use service providers only for the functions described here. The likely storage or processing locations for this deployment are:

  • Australia: the Neon database is in Sydney; HtAG Analytics and Geoscape process Australian property lookups in Australia. The Upstash rate-limit database currently routes through Sydney and can use provider-configured global read replicas.
  • United States and other global locations: Vercel (hosting, compute and file storage), Google (Gemini, Maps, sign-in and Analytics), OpenAI, Anthropic, Stripe (payments), Resend (email), PostHog (analytics) and Sentry (error monitoring). Their affiliates and subprocessors may process data in the United States, Europe, Asia, Australia and other countries where they operate. Anthropic says API data is stored in the United States. This deployment’s PostHog and Sentry endpoints are in the United States.

Google Maps requests can include search terms, an IP address and coordinates, and Google may retain and use them under the Google Privacy Policy. Provider locations and subprocessor lists can change; we review this disclosure when they do.

We also share information when you choose to: a share link you create, or a logbook transfer you initiate, discloses the records you have chosen to the person you send it to.

How long we keep it

Your account records — properties, documents, photos, maintenance, assistant conversations, shares and notification settings — are kept for as long as your account exists. When you delete your account we delete them, including the files in storage.

Email forwarded to your logbook is kept while the account is open. It is removed from the active account during account deletion; temporary service copies and backups are allowed up to 90 days to be erased or age out.

Two record types are deliberately kept after account deletion. Purchase records are unlinked from your account and normally kept for six years from the transaction for tax, accounting and consumer-claim purposes. Payment-event ledgers are keyed by the processor event identifier and kept for the same period to prevent an old event being processed twice. Records may be kept longer where law requires it or while an actual dispute, chargeback, investigation or fraud issue remains unresolved; after that they are deleted or de-identified.

With your consent, Google Analytics user and event data is retained for no more than 14 months. PostHog analytics is stored in its United States cloud under the project’s retention setting and can be deleted using its person and event deletion tools. Sentry error and consented replay data is held in its United States region for the account’s configured period, no more than 90 days. The AI-provider periods are stated in the Artificial intelligence section above.

Your choices and rights

Access. You can download everything in your logbook as a file at any time from your account settings. You may also ask us for access to other personal information associated with you.

Correction. You can edit or remove any record in the product. Correcting or deleting your own records is never restricted by your plan.

Deletion. You can delete an individual assistant conversation — which removes its messages and the summary the assistant keeps of it — from the assistant’s settings, and you can delete your entire account from your account settings. Account deletion shows you exactly what was removed and what was retained.

Analytics. Analytics is off until you turn it on, and you can change your mind at any time using the “Privacy choices” link in the footer. A change takes effect immediately.

Email. You control which reminders you receive in notification settings, and every non-transactional email carries a one-click unsubscribe link.

Security

Access to your records requires you to be signed in, and every record is checked against your account before it is returned. Uploaded files are stored under opaque identifiers and are served only through an authenticated request; a file link cannot be guessed or shared by URL alone.

We use access controls, data minimisation, secret scanning, request limits and monitoring to reduce the risk of unauthorised access or misuse. No online service can guarantee absolute security. If you believe your account or a share link has been compromised, contact us promptly and revoke the affected link or session where possible.

Complaints and contact

To ask for access or correction, raise a privacy concern or make a complaint, email privacy@homelogbook.com.au or use the contact form. Describe what happened and the outcome you want. We may ask for enough information to verify your identity and investigate without exposing another person’s information.

We will assess the issue fairly, tell you the outcome and aim to provide a substantive response within 30 days. If you are not satisfied, or we do not respond within 30 days, you may complain to the Office of the Australian Information Commissioner.

Changes

This notice is versioned. When it changes materially we will update the version and the date at the top, and where the change affects analytics we will ask for your preference again.