Back to home
Legal

Privacy Policy

Version: 2.1
Effective date: 27 July 2026
Last updated: 27 July 2026

This Privacy Policy explains how Kataro ("Kataro", "we", "us", "our") collects, holds, uses and discloses your personal information when you use the Kataro mobile application, the kataroapp.com website, and related services (together, the "Service"), and how you can access and correct that information or make a complaint.

We are bound by the Privacy Act 1988 (Cth) and handle personal information in accordance with the Australian Privacy Principles (APPs). We are also subject to the Notifiable Data Breaches (NDB) scheme. By ticking the acceptance box at sign-up, creating an account, or using the Service, you consent to the collection, use and disclosure of your personal information as described in this Policy.


1. Who we are and how to contact us

The Service is operated by Kataro, a business based in Australia.

Contact us using these details for any privacy question, request or complaint. We take privacy seriously and will deal with you directly and promptly.


2. What this Policy covers

This Policy covers personal information handled through the Service. It does not cover third-party websites, apps or services that we link to (including retailers and app stores) — their own privacy policies apply to them. "Personal information" has the meaning given in the Privacy Act: information or an opinion about an identified individual, or an individual who is reasonably identifiable.


3. The personal information we collect

We collect only what we reasonably need to operate and improve the Service.

3.1 Information you give us

3.2 Photos

You may take or choose photos to attach to a diagnosis, or photograph an appliance to identify it. Photos are transmitted to our AI provider to generate the result and are not stored by us afterwards — the originals remain on your device. We do not use facial recognition and we ask that you avoid including people (or other people's property or information) in photos.

3.3 Payment information

Subscriptions are processed by Stripe (and, where you buy through an app store, by Apple or Google). We never collect or store your full card number, CVC or banking credentials. We store your subscription status, plan, renewal date, transaction history metadata, and the customer/subscription identifiers our payment providers give us, so we can manage your access and support you.

We never ask for, receive or store your bank account or BSB details, and we will never contact you to request or change payment details, or to ask you to transfer money to an account. If you receive a message that appears to come from Kataro and does any of these things, treat it as fraudulent — do not act on it, and report it to us at support@kataroapp.com.

3.4 Information collected automatically

3.5 Sensitive information

We do not seek to collect sensitive information (such as health information, racial or ethnic origin, religious beliefs, or biometric data) and the Service is not designed for it. Please do not enter sensitive information in free-text fields or include it in photos. If you do submit it, you consent to us handling it as part of the relevant content for the purposes in this Policy, and you can delete it (or your account) at any time.

3.6 If you don't provide information

You can browse our website without identifying yourself. However, the Service itself requires an account, and the core features cannot work without the information described above — for example, we cannot diagnose a problem you haven't described. It is not practicable for us to allow use of the Service anonymously or under a pseudonym, because your content must be linked to your account to be stored securely and shown back to you.


4. How we collect it

We collect personal information: directly from you (when you sign up, fill in your home profile, use features, or contact us); automatically from your device as you use the Service (usage, device and crash data); and from our service providers acting on our behalf (for example, payment status from Stripe, delivery status from our email and push providers). We do not buy personal information from data brokers.


5. Why we collect, hold and use it

We collect, hold and use your personal information to:

We do not sell your personal information, and we do not use your personal information to train our own or third-party AI models.


6. AI processing — exactly what is sent

When you request a diagnosis or use chat, we send to our AI provider (OpenAI): the text of your problem description and follow-up answers, any photos you attach, relevant appliance details you have saved, and non-identifying home context (such as property type, approximate age, and suburb/state). When you scan an appliance, we send the photo. We do not send your name, email address or account identifiers to OpenAI for these purposes. We use OpenAI's API services, which under OpenAI's API terms are not used to train OpenAI's models. AI results are informational only — see our Terms & Conditions.


7. Who we disclose it to

We disclose personal information only to the following categories of recipients, and only to the extent needed:

Each service provider is permitted to use your information only to provide its service to us, and we take reasonable steps to ensure providers are bound by contractual privacy and security obligations.


8. Overseas disclosure (APP 8)

Some of our providers store or process data outside Australia — principally in the United States (OpenAI, Stripe, PostHog, Sentry, Expo) and in the regions where our hosting provider operates. By using the Service you consent to your personal information being disclosed to these overseas recipients. We take reasonable steps — including contractual safeguards and choosing reputable providers — to ensure overseas recipients handle your personal information in a way consistent with the APPs; however, overseas recipients are subject to the laws of their own jurisdictions.


9. Direct marketing (APP 7)

We only send marketing communications if you have opted in, and every marketing message includes a working unsubscribe mechanism. We comply with the Spam Act 2003 (Cth). Service messages (verification codes, receipts, security and legal notices) are not marketing and are sent as needed. Push-notification reminders are sent only if you enable notifications, and can be turned off in the App or your device settings at any time. We never provide your details to third parties for their own marketing.


10. Analytics, tracking and your controls

The App includes product analytics (PostHog) that records screens viewed and key actions against a pseudonymous identifier, so we can see which features are used and improve them. It does not record the content of your diagnoses. You can opt out at any time in the App (Account → Privacy & data → "Share anonymous usage data") and analytics collection stops. Our website uses only the minimal cookies/technologies needed to operate; we do not run third-party advertising trackers, and we do not engage in cross-site tracking or sell data to advertisers.


11. Storage, security and retention

11.1 Security measures. We take reasonable technical and organisational steps to protect personal information from misuse, interference, loss, and unauthorised access, modification or disclosure, including: encryption of data in transit (TLS); passwords stored only as salted hashes by our authentication provider; row-level security so each account can only read its own data; scoped API keys and least-privilege access controls; and secrets kept out of the client app. No system is perfectly secure, and we cannot guarantee absolute security — please use a strong, unique password.

11.2 Retention. We keep personal information only for as long as needed for the purposes in this Policy: account and content data are kept while your account is active; if you delete your account, your personal data is deleted from our production systems promptly, and from backups in the ordinary backup-rotation cycle; payment records may be retained as required for tax, accounting and legal purposes (generally up to 7 years) in de-identified or minimal form where practicable; and we may keep de-identified, aggregated data (which is no longer personal information) indefinitely.

11.3 Data breaches. We are subject to the Notifiable Data Breaches scheme. If a data breach occurs that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as required by law, and take prompt steps to contain and remediate the breach.


12. Access, correction and deletion (APPs 12 and 13)


13. Children

The Service is intended for adults (18+) and is not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided personal information to us, contact support@kataroapp.com and we will delete it promptly.


14. Government identifiers

We do not collect, use or disclose government-related identifiers such as tax file numbers, Medicare numbers, driver-licence numbers or passport numbers. Please never enter them into the Service.


15. Users outside Australia

The Service is designed for Australian users and this Policy is written to Australian law. If you use the Service from another jurisdiction, you may have additional rights under local law (for example, rights of access, correction, deletion, portability or objection). We will honour any such rights that apply to us — contact support@kataroapp.com.


16. Complaints

If you believe we have breached the APPs or mishandled your personal information, please contact us first at support@kataroapp.com with the details. We will acknowledge your complaint promptly (usually within 7 days), investigate it, and aim to give you a substantive response within 30 days. If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC): online at www.oaic.gov.au, by phone on 1300 363 992, or by post to GPO Box 5288, Sydney NSW 2001.


17. Changes to this Policy

We may update this Policy from time to time, including to reflect changes to the Service, our providers or the law. If we make material changes, we will notify you in the App or by email before they take effect. The version number and "Last updated" date above identify the current version. Your continued use of the Service after an update takes effect constitutes acceptance of the updated Policy.


© 2026 Kataro. All rights reserved.