Tallywren legal information
Privacy Policy
This page explains, in plain English, how Tallywren handles information in the product for an Australian audience.
Important information
This page is general information about the current product and is not legal advice. You should obtain independent advice about your privacy, health-information, NDIS, and record-keeping obligations.
What Tallywren collects and why
Tallywren may collect the information you enter or create while using the product, including:
- account details such as your name and email address, to create and manage your account;
- participant information and participant goals, to provide the workspace you use;
- shift notes and other session details, to create and edit note drafts;
- generated reports and report sections, to support review and approval; and
- related audit and export data, to show report activity and support requested exports.
The product uses this information to provide the note and report workflow, keep your records associated with your account, and support the review, approval, and export features you use.
Participant and sensitive information
Participant information and shift notes may include health information and other sensitive information. You are responsible for deciding what information is appropriate to enter, having authority to enter it, and obtaining any consent or other permission required for your work.
Do not enter information that you are not authorised to handle. Check that your use of Tallywren fits your obligations to participants, your organisation, and applicable Australian privacy and NDIS requirements.
Storage and hosting
[TO CONFIRM: the country or countries and regions where Tallywren data is stored and hosted.]
Until this is confirmed from authoritative deployment information, do not assume that Tallywren data is stored in Australia or in any particular region.
AI-assisted drafting
Tallywren can send note-drafting requests through a Polsia-managed AI proxy. The application source confirms the proxy route, but it does not identify the underlying AI provider or its data practices.
- [TO CONFIRM: the name of the AI provider used behind the Polsia-managed AI proxy.]
- [TO CONFIRM: whether information sent through the AI proxy is processed outside Australia.]
- [TO CONFIRM: whether the AI provider uses submitted information to train or improve its models.]
Generated content is a draft. You must review it and decide what, if anything, to keep in a final record.
Access, permissions, and security
In the current application, product records are scoped to the authenticated account owner. The application also has reviewer and administrator approval roles for the report workflow. You should keep your login details secure and only give access through the permissions available to the people who need it.
- [TO CONFIRM: the people, platform operators, support personnel, and providers who may access data outside the application permissions described above.]
- [TO CONFIRM: the authoritative encryption-in-transit controls used for Tallywren data.]
- [TO CONFIRM: the authoritative encryption-at-rest controls used for stored Tallywren data.]
- [TO CONFIRM: the complete platform and operational access-control scope, including support and infrastructure access.]
Retention and deletion
The app currently provides a draft-retention preference. Its available choices are to keep drafts indefinitely or review them manually; automatic expiry is not enabled. This setting is not a complete retention schedule for every type of data.
An authenticated account owner can delete a participant after confirming the participant reference. The current deletion operation removes that participant, linked goals, linked notes, and their report-audit events. This describes the application behavior; it is not a promise about copies outside that operation.
- [TO CONFIRM: retention periods for account, authentication, report, audit, export, and operational data not covered by the participant deletion flow.]
- [TO CONFIRM: how an account owner requests account closure and what happens to account data after closure.]
- [TO CONFIRM: backup retention and the timing or process for deleting data from backups.]
Access, correction, and complaints
You can contact us to ask about access to or correction of information associated with your account. The operational process, identity checks, response times, and any limits for these requests are [TO CONFIRM: the access and correction request process for Tallywren information.]
For a privacy question or complaint, contact tallywren-t0ouq2@polsia.app. If you are not satisfied with the response, you can contact the Office of the Australian Information Commissioner (OAIC) through its privacy complaint information at oaic.gov.au/privacy/privacy-complaints.
Related information
Read the Terms before creating an account.