Curonian Group Pty Ltd ACN 697 342 966 ABN 73 697 342 966 (Curonian, we, us, our) supplies the Vards AI desktop software (Software). This Privacy Policy explains what personal information we collect when we supply the Software, how we use and disclose it, and the choices you have. It is written to comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
Vards AI is installed and runs on your own hardware. As a deliberate design choice, Curonian does not store, transmit, or have access to:
All of that material stays within your own environment except where you direct Vards AI to send it to a third-party provider that you have configured using your own account and API credentials. Because Curonian does not collect or hold that material, Curonian is not in a position to disclose it, lose it, or use it.
Bring-your-own-key data flow — please read this carefully. Vards AI is designed to be connected to third-party AI, voice, video, and other providers using API keys that you supply. When you use a feature that relies on such a provider, Vards AI sends the relevant content directly from your device to the provider you have chosen and configured, not to Curonian. In particular:
Put plainly: Vards AI is private from Curonian; it is not private from the providers you connect it to.
For the purposes of the Privacy Act, Curonian is not a "contracted service provider" or processor in respect of the personal information you handle inside Vards AI or send to a provider you have configured. You remain the APP entity responsible for that information, and you act as the controller in respect of the providers you direct Vards AI to use.
This Privacy Policy otherwise concerns only the limited personal information Curonian does collect when it supplies the Software, which is described below.
When the Software starts up and at periodic intervals during a Subscription Term, the Software contacts our licence-activation service (a Cloudflare Worker we operate, referred to internally as the "crew-license" service). The activation request transmits:
The activation service returns a yes/no decision and licence metadata (tier, Seat Count, expiry). It does not transmit any conversation content, prompts, documents, configurations, outputs, or other Customer Data.
When you purchase a licence, payment is processed by Stripe. Stripe collects your payment method details (for example, card details) directly. We receive a confirmation of payment, the last four digits of the card, the card brand, and billing-address fields, but we do not receive or store your full card number. Stripe's handling of your information is governed by Stripe's own privacy policy.
We use Resend to send licence-delivery emails, payment receipts, renewal reminders, and trial-related notifications. Resend processes the email address, name, and message content on our behalf as a third-party email service.
The Software includes two strictly opt-in diagnostic channels. Both are off by default and send no data unless you turn them on:
You can turn both channels on or off at any time in Settings. Disabling a channel stops outbound traffic to it.
As described in section 1, when you configure and use a third-party provider with your own API credentials, the Software sends the relevant content directly from your device to that provider at your direction. Curonian does not receive that content. The categories of provider the Software supports are:
These providers are not Curonian's sub-processors. You choose them, you contract with them, and your use of them is governed by their terms and privacy policies. We list them so you can assess where your data may flow before you enable a feature. The current list is maintained against the Software's published capabilities; the providers actually contacted depend on what you configure.
This section concerns the Curonian website experience, separate from the Software.
The Software itself sets no advertising or tracking cookies. It runs locally and uses an essential, locally-stored session cookie (HttpOnly) solely to keep you signed in to your own workspace; this cookie is not transmitted to Curonian.
This website uses no third-party analytics or tracking tools and sets only strictly necessary cookies. We do not use advertising cookies, cross-site tracking, or behavioural profiling, and we do not load third-party analytics scripts. Because we use only strictly necessary cookies and no tracking technologies, no cookie-consent banner is required for this website.
We collect this information to:
Under the APPs, the primary purposes of collection are licence administration, payment, support, and compliance. We will only use or disclose the information for a secondary purpose where you would reasonably expect it, where you consent, or where the law permits or requires it.
We disclose the limited personal information we collect (described in sections 2.1–2.5) to the following service providers we engage, only as needed for them to perform services for us:
Customer-directed providers are different. The AI model, safety, voice, video, and tool providers listed in section 2.6 are not providers we engage on your behalf and are not our sub-processors. Where content flows to them, it does so because you configured and used them with your own credentials, at your direction (see sections 1 and 2.6). Curonian does not select those providers for you, does not contract with them on your behalf, and does not receive the content sent to them.
We do not sell personal information. We do not share personal information with advertisers.
Some of the service providers we engage (section 4) store or process information outside Australia. In particular:
Before disclosing personal information to an overseas recipient, we take reasonable steps to ensure that the recipient handles the information consistently with the APPs. By using the Software, you acknowledge these overseas disclosures.
Customer-directed providers (section 2.6) are not Curonian's overseas disclosures. Where you configure and use an AI model, safety, voice, video, or tool provider, you may be sending content overseas depending on the provider and plan you select. That cross-border flow is your disclosure as the controlling entity, not Curonian's, and you are responsible for assessing it against your own obligations (including APP 8 where it applies to you) before enabling the relevant feature.
We hold information in cloud-based systems operated by reputable providers (Stripe, Resend, Cloudflare, Sentry, GitHub, and our internal records systems). We apply reasonable technical and organisational measures — including encryption in transit, access controls, multi-factor authentication, and the principle of least privilege — to protect personal information from misuse, interference, loss, unauthorised access, modification, or disclosure.
No system is perfectly secure. If a notifiable data breach occurs as defined under Part IIIC of the Privacy Act, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) in accordance with the law.
When an account is erased (whether at your request or by your workspace administrator), the Software hard-deletes all personal data linked to that user across every table that holds it — including the account record, conversations and message content, notifications, usage telemetry, memberships, terms-acceptance records (including any stored IP address), call and video records, and any device push subscriptions. The workspace audit log is retained for its legally-required record-keeping and tamper-evidence function, but the erased user's identity is irreversibly removed from it (the user identifier and display name are cleared and free-text detail is dropped).
Residual backups. The Software keeps short-lived local backups of the workspace database (for example, automatic pre-update snapshots and rolling backups). These offline copies cannot be edited in place and are therefore not purged at the moment of erasure. Personal data already deleted from the live database may persist in those backups until they age out under our backup-retention schedule, after which they are overwritten or deleted. We do not restore erased personal data from a backup except where required to meet a legal obligation.
Under the Privacy Act and the APPs, you may:
We will respond to access and correction requests within a reasonable period (generally 30 days) and free of charge, except where a charge is reasonably permitted.
The Software is supplied to professional services firms for business use. It is not directed at children, and we do not knowingly collect personal information from individuals under 18.
If you have a privacy question, want to exercise your rights, or want to make a complaint, contact:
We will acknowledge your complaint within 7 business days and respond substantively within 30 days. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner at https://www.oaic.gov.au, by phone on 1300 363 992, or by post at GPO Box 5288, Sydney NSW 2001.
We may update this Privacy Policy from time to time. Material changes will be notified to active customers by email and posted on our website. The "Last updated" date at the top of this policy shows when it was most recently revised.