Curonian Group Curonian Group Pty Ltd
Retail Products
Pocket Investor Investing companion for retail investors
Enterprise Software
Vards AI Private AI for Australian professional firms Pricing Annual subscription plans
Consulting
Insights
Insights Perspectives on software, AI and operations Substack Writing from Edward Girss
About Contact Enquire
Curonian Group Curonian Group
Home
Retail Products Pocket Investor
Enterprise Software Vards AI Pricing
Consulting
Insights Insights Substack
About Contact Enquire
Legal

Privacy Policy

Last updated: 29 June 2026

Curonian Group Pty Ltd ACN 697 342 966 ABN 73 697 342 966 (Curonian, we, us, our) supplies the Vards AI desktop software (Software). This Privacy Policy explains what personal information we collect when we supply the Software, how we use and disclose it, and the choices you have. It is written to comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

1. Vards AI is self-hosted — what this means for your data

Vards AI is installed and runs on your own hardware. As a deliberate design choice, Curonian does not store, transmit, or have access to:

  • the content of your conversations or prompts;
  • documents, files, or other inputs you upload into the Software;
  • the configurations of any agents, system prompts, or automations you create;
  • outputs generated by the Software or by the AI provider you connect it to;
  • your client data, matter data, or any other business records you handle in the Software.

All of that material stays within your own environment except where you direct Vards AI to send it to a third-party provider that you have configured using your own account and API credentials. Because Curonian does not collect or hold that material, Curonian is not in a position to disclose it, lose it, or use it.

Bring-your-own-key data flow — please read this carefully. Vards AI is designed to be connected to third-party AI, voice, video, and other providers using API keys that you supply. When you use a feature that relies on such a provider, Vards AI sends the relevant content directly from your device to the provider you have chosen and configured, not to Curonian. In particular:

  • When an agent replies, the text of your messages, the full conversation history, and the full extracted text of any knowledge-base documents the agent can access are transmitted to the AI model provider you have configured (see section 2.6 for the list of supported providers).
  • If you enable an optional safety/moderation, voice (telephony, speech-to-text, or text-to-speech), or video feature, the relevant content (for example, message text, call audio, or generation prompts) is transmitted to the corresponding provider you have configured (see section 2.6).
  • What each provider does with that content — including retention and whether it is used for model training — is governed by your agreement with that provider, not by this Privacy Policy. You are responsible for selecting providers and plans whose terms meet your obligations.

Put plainly: Vards AI is private from Curonian; it is not private from the providers you connect it to.

For the purposes of the Privacy Act, Curonian is not a "contracted service provider" or processor in respect of the personal information you handle inside Vards AI or send to a provider you have configured. You remain the APP entity responsible for that information, and you act as the controller in respect of the providers you direct Vards AI to use.

This Privacy Policy otherwise concerns only the limited personal information Curonian does collect when it supplies the Software, which is described below.

2. What we collect

2.1 Information you give us directly

  • Account and billing details: name, business name, business address, email address, phone number (optional), purchase tier, and billing contact information when you purchase a licence or start a trial.
  • Support correspondence: the contents of any email, ticket, or other communication you send to our support or sales team, and our responses.
  • Marketing sign-ups: your name and email address if you subscribe to our newsletter or download marketing materials.

2.2 Information collected automatically — licence activation telemetry

When the Software starts up and at periodic intervals during a Subscription Term, the Software contacts our licence-activation service (a Cloudflare Worker we operate, referred to internally as the "crew-license" service). The activation request transmits:

  • the Licence Key issued to you;
  • a machine identifier — a hashed value derived from non-reversible characteristics of the installed device, used to verify that the Software is running within the Seat Count;
  • a timestamp of the activation request;
  • the IP address from which the request originates (received by Cloudflare as part of standard network operation).

The activation service returns a yes/no decision and licence metadata (tier, Seat Count, expiry). It does not transmit any conversation content, prompts, documents, configurations, outputs, or other Customer Data.

2.3 Information collected by payment processing

When you purchase a licence, payment is processed by Stripe. Stripe collects your payment method details (for example, card details) directly. We receive a confirmation of payment, the last four digits of the card, the card brand, and billing-address fields, but we do not receive or store your full card number. Stripe's handling of your information is governed by Stripe's own privacy policy.

2.4 Transactional email

We use Resend to send licence-delivery emails, payment receipts, renewal reminders, and trial-related notifications. Resend processes the email address, name, and message content on our behalf as a third-party email service.

2.5 Error monitoring and product telemetry (in the Software)

The Software includes two strictly opt-in diagnostic channels. Both are off by default and send no data unless you turn them on:

  • Crash reporting (Sentry). If you enable crash reporting, technical error reports are sent to Sentry (Functional Software, Inc., trading as Sentry) to help us diagnose faults. Before each report leaves your device, the Software applies a scrubber that removes message text beyond a short length, stack-frame local variables, breadcrumbs, request bodies and cookies, query strings, user identity, and similar context, and redacts strings that look like API keys. A crash report may still reveal the type and code location of an error. Crash reporting requires both a production build configured with a Sentry endpoint and your explicit preference; if either is absent, nothing is sent.
  • Anonymised usage ping. If you enable usage analytics, the Software sends a periodic ping containing counts of a fixed list of feature events (for example, that the knowledge base was opened or an export was used). It contains no message content, no document content, and no user identifiers. It is disabled by default.

You can turn both channels on or off at any time in Settings. Disabling a channel stops outbound traffic to it.

2.6 Customer-directed third-party providers (bring-your-own-key)

As described in section 1, when you configure and use a third-party provider with your own API credentials, the Software sends the relevant content directly from your device to that provider at your direction. Curonian does not receive that content. The categories of provider the Software supports are:

  • AI model providers: Anthropic, OpenAI, Google, Mistral, Groq, DeepSeek, Perplexity, and xAI.
  • Optional safety / content-moderation providers: OpenAI Moderation, Azure AI Content Safety (Prompt Shields), Lakera Guard, and AWS Bedrock Guardrails.
  • Optional speech-to-text / transcription providers: Deepgram, AssemblyAI, OpenAI (Whisper), Google Speech-to-Text, and Azure Speech.
  • Optional text-to-speech providers: ElevenLabs and Cartesia.
  • Optional telephony / voice-call providers: Twilio and Telnyx.
  • Optional video-generation providers: Runway, Kling, and Luma.
  • Optional agent tools: web search (Brave Search where you provide a key, otherwise DuckDuckGo) and web fetch; and email send/receive via an SMTP/IMAP server you configure (the Software does not impose a particular email provider).

These providers are not Curonian's sub-processors. You choose them, you contract with them, and your use of them is governed by their terms and privacy policies. We list them so you can assess where your data may flow before you enable a feature. The current list is maintained against the Software's published capabilities; the providers actually contacted depend on what you configure.

2.7 Website analytics and cookies

This section concerns the Curonian website experience, separate from the Software.

The Software itself sets no advertising or tracking cookies. It runs locally and uses an essential, locally-stored session cookie (HttpOnly) solely to keep you signed in to your own workspace; this cookie is not transmitted to Curonian.

This website uses no third-party analytics or tracking tools and sets only strictly necessary cookies. We do not use advertising cookies, cross-site tracking, or behavioural profiling, and we do not load third-party analytics scripts. Because we use only strictly necessary cookies and no tracking technologies, no cookie-consent banner is required for this website.

3. Why we collect it and the legal basis

We collect this information to:

  • supply the Software, issue and validate Licence Keys, and enforce Seat Counts;
  • process payments, issue invoices, and manage renewals;
  • respond to your support and sales enquiries;
  • send transactional notifications about your licence (renewals, expiries, security advisories);
  • send marketing communications, but only where you have opted in, and you can opt out at any time;
  • comply with our legal, tax, and accounting obligations.

Under the APPs, the primary purposes of collection are licence administration, payment, support, and compliance. We will only use or disclose the information for a secondary purpose where you would reasonably expect it, where you consent, or where the law permits or requires it.

4. Who we share it with

We disclose the limited personal information we collect (described in sections 2.1–2.5) to the following service providers we engage, only as needed for them to perform services for us:

  • Stripe (Stripe Payments Australia Pty Ltd) — payment processing.
  • Resend (Resend, Inc.) — transactional and marketing email delivery.
  • Cloudflare, Inc. — licence-activation worker, DNS, and edge networking.
  • Sentry (Functional Software, Inc.) — error and crash diagnostics, only where you have opted in to crash reporting (see section 2.5).
  • GitHub, Inc. — distribution of application updates via GitHub Releases (the auto-updater retrieves update files; this is a standard download request and does not transmit your workspace data).
  • Our other operational providers — for example hosting, accounting software, and CRM — for the operational purposes set out above.
  • Professional advisers (lawyers, accountants, auditors) — under confidentiality, when reasonably required.
  • Regulators, courts, or law enforcement — where required or permitted by law.

Customer-directed providers are different. The AI model, safety, voice, video, and tool providers listed in section 2.6 are not providers we engage on your behalf and are not our sub-processors. Where content flows to them, it does so because you configured and used them with your own credentials, at your direction (see sections 1 and 2.6). Curonian does not select those providers for you, does not contract with them on your behalf, and does not receive the content sent to them.

We do not sell personal information. We do not share personal information with advertisers.

5. Overseas disclosure

Some of the service providers we engage (section 4) store or process information outside Australia. In particular:

  • Stripe may process information in the United States and other jurisdictions where Stripe operates.
  • Resend processes information in the United States.
  • Cloudflare operates a global edge network; activation requests may be processed at the Cloudflare data centre nearest to you.
  • Sentry (opt-in crash reporting only) processes information in the United States.
  • GitHub (update distribution) processes information in the United States.

Before disclosing personal information to an overseas recipient, we take reasonable steps to ensure that the recipient handles the information consistently with the APPs. By using the Software, you acknowledge these overseas disclosures.

Customer-directed providers (section 2.6) are not Curonian's overseas disclosures. Where you configure and use an AI model, safety, voice, video, or tool provider, you may be sending content overseas depending on the provider and plan you select. That cross-border flow is your disclosure as the controlling entity, not Curonian's, and you are responsible for assessing it against your own obligations (including APP 8 where it applies to you) before enabling the relevant feature.

6. How we hold and protect information

We hold information in cloud-based systems operated by reputable providers (Stripe, Resend, Cloudflare, Sentry, GitHub, and our internal records systems). We apply reasonable technical and organisational measures — including encryption in transit, access controls, multi-factor authentication, and the principle of least privilege — to protect personal information from misuse, interference, loss, unauthorised access, modification, or disclosure.

No system is perfectly secure. If a notifiable data breach occurs as defined under Part IIIC of the Privacy Act, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) in accordance with the law.

7. Retention

  • Licence and billing records: retained for at least 7 years after the end of the Subscription Term to meet our tax and record-keeping obligations under the Income Tax Assessment Act 1997 (Cth) and related laws.
  • Support correspondence: retained for up to 3 years after closure of the matter.
  • Activation logs: retained in operational form for up to 90 days, then aggregated or deleted.
  • Marketing contacts: retained until you unsubscribe, then suppressed (we keep the minimum information necessary to honour your unsubscribe request).

7.1 Erasure and residual backups

When an account is erased (whether at your request or by your workspace administrator), the Software hard-deletes all personal data linked to that user across every table that holds it — including the account record, conversations and message content, notifications, usage telemetry, memberships, terms-acceptance records (including any stored IP address), call and video records, and any device push subscriptions. The workspace audit log is retained for its legally-required record-keeping and tamper-evidence function, but the erased user's identity is irreversibly removed from it (the user identifier and display name are cleared and free-text detail is dropped).

Residual backups. The Software keeps short-lived local backups of the workspace database (for example, automatic pre-update snapshots and rolling backups). These offline copies cannot be edited in place and are therefore not purged at the moment of erasure. Personal data already deleted from the live database may persist in those backups until they age out under our backup-retention schedule, after which they are overwritten or deleted. We do not restore erased personal data from a backup except where required to meet a legal obligation.

8. Your rights

Under the Privacy Act and the APPs, you may:

  • Access the personal information we hold about you.
  • Correct personal information that is inaccurate, out of date, incomplete, irrelevant, or misleading.
  • Withdraw consent to marketing communications by clicking unsubscribe or contacting us.
  • Complain if you believe we have breached the APPs (see clause 10 below).

We will respond to access and correction requests within a reasonable period (generally 30 days) and free of charge, except where a charge is reasonably permitted.

9. Children

The Software is supplied to professional services firms for business use. It is not directed at children, and we do not knowingly collect personal information from individuals under 18.

10. Contact and complaints

If you have a privacy question, want to exercise your rights, or want to make a complaint, contact:

Privacy Officer, Curonian Group Pty Ltd Email: privacy@curoniangroup.com
Postal: 2/39 Dover Road, Rose Bay NSW 2029, Australia

We will acknowledge your complaint within 7 business days and respond substantively within 30 days. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner at https://www.oaic.gov.au, by phone on 1300 363 992, or by post at GPO Box 5288, Sydney NSW 2001.

11. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be notified to active customers by email and posted on our website. The "Last updated" date at the top of this policy shows when it was most recently revised.

← Back to Legal

© 2026 Curonian Group Pty Ltd  ·  Australia
Retail Products Enterprise Software Consulting Insights Substack About Contact Privacy Terms