Privacy Policy
Version: 2.1
Effective date: 27 July 2026
Last updated: 27 July 2026
This Privacy Policy explains how Kataro ("Kataro", "we", "us", "our") collects, holds, uses and discloses your personal information when you use the Kataro mobile application, the kataroapp.com website, and related services (together, the "Service"), and how you can access and correct that information or make a complaint.
We are bound by the Privacy Act 1988 (Cth) and handle personal information in accordance with the Australian Privacy Principles (APPs). We are also subject to the Notifiable Data Breaches (NDB) scheme. By ticking the acceptance box at sign-up, creating an account, or using the Service, you consent to the collection, use and disclosure of your personal information as described in this Policy.
1. Who we are and how to contact us
The Service is operated by Kataro, a business based in Australia.
- Privacy contact: support@kataroapp.com
Contact us using these details for any privacy question, request or complaint. We take privacy seriously and will deal with you directly and promptly.
2. What this Policy covers
This Policy covers personal information handled through the Service. It does not cover third-party websites, apps or services that we link to (including retailers and app stores) — their own privacy policies apply to them. "Personal information" has the meaning given in the Privacy Act: information or an opinion about an identified individual, or an individual who is reasonably identifiable.
3. The personal information we collect
We collect only what we reasonably need to operate and improve the Service.
3.1 Information you give us
- Account details: your name and email address. Your password is created by you and stored only in securely hashed form by our authentication provider — we never see or store your plain-text password.
- Home profile: details about your property — type (house/apartment/townhouse), approximate location (suburb and state only — we do not collect GPS coordinates or your street address), approximate age, number of bedrooms and bathrooms, and selected features.
- Problem descriptions and app content: the text you type for a diagnosis, follow-up answers, chat messages, repair and maintenance logs, appliances you add, saved guides, checklist progress, and shopping-list ticks.
- Support and other communications: anything you send us when you contact support, respond to a survey, or otherwise correspond with us.
3.2 Photos
You may take or choose photos to attach to a diagnosis, or photograph an appliance to identify it. Photos are transmitted to our AI provider to generate the result and are not stored by us afterwards — the originals remain on your device. We do not use facial recognition and we ask that you avoid including people (or other people's property or information) in photos.
3.3 Payment information
Subscriptions are processed by Stripe (and, where you buy through an app store, by Apple or Google). We never collect or store your full card number, CVC or banking credentials. We store your subscription status, plan, renewal date, transaction history metadata, and the customer/subscription identifiers our payment providers give us, so we can manage your access and support you.
We never ask for, receive or store your bank account or BSB details, and we will never contact you to request or change payment details, or to ask you to transfer money to an account. If you receive a message that appears to come from Kataro and does any of these things, treat it as fraudulent — do not act on it, and report it to us at support@kataroapp.com.
3.4 Information collected automatically
- Usage and analytics data: screens viewed and key in-app actions (for example, starting a diagnosis or opening a guide), associated with a pseudonymous identifier — you can opt out at any time (see section 10).
- Device and technical data: device model, operating system and version, app version, language and region settings, IP address, timestamps, and diagnostic, performance and crash logs.
- Push token: if you enable notifications, the device push token needed to deliver them.
3.5 Sensitive information
We do not seek to collect sensitive information (such as health information, racial or ethnic origin, religious beliefs, or biometric data) and the Service is not designed for it. Please do not enter sensitive information in free-text fields or include it in photos. If you do submit it, you consent to us handling it as part of the relevant content for the purposes in this Policy, and you can delete it (or your account) at any time.
3.6 If you don't provide information
You can browse our website without identifying yourself. However, the Service itself requires an account, and the core features cannot work without the information described above — for example, we cannot diagnose a problem you haven't described. It is not practicable for us to allow use of the Service anonymously or under a pseudonym, because your content must be linked to your account to be stored securely and shown back to you.
4. How we collect it
We collect personal information: directly from you (when you sign up, fill in your home profile, use features, or contact us); automatically from your device as you use the Service (usage, device and crash data); and from our service providers acting on our behalf (for example, payment status from Stripe, delivery status from our email and push providers). We do not buy personal information from data brokers.
5. Why we collect, hold and use it
We collect, hold and use your personal information to:
- create, secure and manage your account, and authenticate you (including sending one-time verification codes by email);
- provide the core features — generate diagnoses and follow-ups, identify appliances, match and generate guides, keep your history, appliances, saved guides, logs and checklist, calculate your Home Health score, and show product suggestions;
- process subscriptions, manage free-tier limits, prevent abuse of limits, and administer billing via our payment providers;
- send service communications (verification codes, receipts, important account or legal notices) and, where you have opted in, reminders and marketing (see section 9);
- monitor, analyse and improve the Service, fix bugs and crashes, develop new features, and keep the Service secure — using aggregated or de-identified data wherever practicable;
- comply with our legal obligations, enforce our Terms & Conditions, and establish or defend legal claims; and
- any other purpose you would reasonably expect, that you consent to, or that is required or authorised by law.
We do not sell your personal information, and we do not use your personal information to train our own or third-party AI models.
6. AI processing — exactly what is sent
When you request a diagnosis or use chat, we send to our AI provider (OpenAI): the text of your problem description and follow-up answers, any photos you attach, relevant appliance details you have saved, and non-identifying home context (such as property type, approximate age, and suburb/state). When you scan an appliance, we send the photo. We do not send your name, email address or account identifiers to OpenAI for these purposes. We use OpenAI's API services, which under OpenAI's API terms are not used to train OpenAI's models. AI results are informational only — see our Terms & Conditions.
7. Who we disclose it to
We disclose personal information only to the following categories of recipients, and only to the extent needed:
- Supabase — database, authentication, storage and edge-function hosting (holds your account and app data).
- OpenAI — AI processing of the data described in section 6.
- Stripe — subscription payment processing (card details go directly to Stripe; we never hold them).
- PostHog — product analytics (usage events with a pseudonymous identifier; not used if you opt out).
- Expo, Apple and Google — app distribution, over-the-air updates and push-notification delivery.
- Resend / our email provider — delivery of verification codes and service emails.
- Sentry (if enabled) — crash and error reporting (technical diagnostic data).
- Professional advisers — lawyers, accountants, auditors and insurers, under duties of confidence.
- Government, regulators and law enforcement — where required or authorised by law, or where reasonably necessary to protect the rights, property or safety of Kataro, our users or the public.
- A purchaser or successor — if we sell, merge or restructure our business, personal information may be transferred as part of that transaction, subject to this Policy or an equivalent standard of protection.
Each service provider is permitted to use your information only to provide its service to us, and we take reasonable steps to ensure providers are bound by contractual privacy and security obligations.
8. Overseas disclosure (APP 8)
Some of our providers store or process data outside Australia — principally in the United States (OpenAI, Stripe, PostHog, Sentry, Expo) and in the regions where our hosting provider operates. By using the Service you consent to your personal information being disclosed to these overseas recipients. We take reasonable steps — including contractual safeguards and choosing reputable providers — to ensure overseas recipients handle your personal information in a way consistent with the APPs; however, overseas recipients are subject to the laws of their own jurisdictions.
9. Direct marketing (APP 7)
We only send marketing communications if you have opted in, and every marketing message includes a working unsubscribe mechanism. We comply with the Spam Act 2003 (Cth). Service messages (verification codes, receipts, security and legal notices) are not marketing and are sent as needed. Push-notification reminders are sent only if you enable notifications, and can be turned off in the App or your device settings at any time. We never provide your details to third parties for their own marketing.
10. Analytics, tracking and your controls
The App includes product analytics (PostHog) that records screens viewed and key actions against a pseudonymous identifier, so we can see which features are used and improve them. It does not record the content of your diagnoses. You can opt out at any time in the App (Account → Privacy & data → "Share anonymous usage data") and analytics collection stops. Our website uses only the minimal cookies/technologies needed to operate; we do not run third-party advertising trackers, and we do not engage in cross-site tracking or sell data to advertisers.
11. Storage, security and retention
11.1 Security measures. We take reasonable technical and organisational steps to protect personal information from misuse, interference, loss, and unauthorised access, modification or disclosure, including: encryption of data in transit (TLS); passwords stored only as salted hashes by our authentication provider; row-level security so each account can only read its own data; scoped API keys and least-privilege access controls; and secrets kept out of the client app. No system is perfectly secure, and we cannot guarantee absolute security — please use a strong, unique password.
11.2 Retention. We keep personal information only for as long as needed for the purposes in this Policy: account and content data are kept while your account is active; if you delete your account, your personal data is deleted from our production systems promptly, and from backups in the ordinary backup-rotation cycle; payment records may be retained as required for tax, accounting and legal purposes (generally up to 7 years) in de-identified or minimal form where practicable; and we may keep de-identified, aggregated data (which is no longer personal information) indefinitely.
11.3 Data breaches. We are subject to the Notifiable Data Breaches scheme. If a data breach occurs that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as required by law, and take prompt steps to contain and remediate the breach.
12. Access, correction and deletion (APPs 12 and 13)
- Access: you can view most of your information directly in the App. You may also request a copy of all personal information we hold about you by emailing support@kataroapp.com. We will respond within a reasonable period (usually within 30 days) and provide the information in a usable form, free of charge for reasonable requests.
- Correction: you can edit your account and home profile in the App at any time, or ask us to correct anything that is inaccurate, out of date, incomplete or misleading. If we decline a correction request, we will tell you why, and you may ask us to attach a statement noting your view.
- Deletion: you can permanently delete your account and data in the App (Account → Delete account), or ask us to do it by email. Deletion is subject only to records we are legally required to keep (see section 11.2).
- Identity verification: for your protection, we may take reasonable steps to verify your identity before actioning access, correction or deletion requests.
13. Children
The Service is intended for adults (18+) and is not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided personal information to us, contact support@kataroapp.com and we will delete it promptly.
14. Government identifiers
We do not collect, use or disclose government-related identifiers such as tax file numbers, Medicare numbers, driver-licence numbers or passport numbers. Please never enter them into the Service.
15. Users outside Australia
The Service is designed for Australian users and this Policy is written to Australian law. If you use the Service from another jurisdiction, you may have additional rights under local law (for example, rights of access, correction, deletion, portability or objection). We will honour any such rights that apply to us — contact support@kataroapp.com.
16. Complaints
If you believe we have breached the APPs or mishandled your personal information, please contact us first at support@kataroapp.com with the details. We will acknowledge your complaint promptly (usually within 7 days), investigate it, and aim to give you a substantive response within 30 days. If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC): online at www.oaic.gov.au, by phone on 1300 363 992, or by post to GPO Box 5288, Sydney NSW 2001.
17. Changes to this Policy
We may update this Policy from time to time, including to reflect changes to the Service, our providers or the law. If we make material changes, we will notify you in the App or by email before they take effect. The version number and "Last updated" date above identify the current version. Your continued use of the Service after an update takes effect constitutes acceptance of the updated Policy.
© 2026 Kataro. All rights reserved.