Privacy Policy
Your family's data is protected by Australian law, Australian infrastructure, and our unwavering commitment to children's privacy.
Effective date: 20 July 2026
Introduction
SeeMe Learn (“we”, “us”, “our”) is an Australian company that builds AI-powered educational books for neurodiverse children and children with special needs. This Privacy Policy explains how we collect, use, store, and protect personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
We understand that your family's data, particularly information about children, is deeply sensitive. We are committed to collecting the minimum data necessary, storing it on Australian soil, and giving you full control over what we hold. Data leaves Australia only transiently, and only in three situations: when an uploaded photo is safety-screened before we store it, when a story's text is generated, and when an illustration is generated. We use these providers on their paid API tiers, whose published terms state that data sent through the API is not used to train their models (see “AI & Image Processing”).
We never sell personal information. We never use children's data for advertising. Full stop.
Information We Collect
We collect the minimum data necessary to deliver personalised educational books. Here is what we collect and why:
Account Information
Your name, email address, and password (hashed) to create and manage your account.
Child Profiles
First name, learning level, age range, and pronouns. We deliberately do not collect surnames, addresses, or school details for children.
Photographs (with Consent)
Reference photos of a child, uploaded only after explicit parental consent. These are used solely to generate personalised book illustrations. EXIF metadata (GPS coordinates, device information, timestamps) is automatically stripped on upload.
Usage Data
Basic analytics such as pages visited and features used, to improve the service. We do not use third-party tracking scripts.
We collect the minimum data necessary. Child profiles never include surnames, addresses, or school details.
How We Use Your Information
We use the information we collect to:
- Generate personalised books: phonics readers, social stories, and emotion stories tailored to each child's learning level and interests.
- Manage your account: authentication, session management, and role-based access.
- Improve the service: aggregate usage patterns to refine our user experience. For quality assurance and safety review, we may retain the AI generation prompts and responses produced for sample (non-child) demonstration profiles. Prompts generated for a real child’s profile are never retained for this purpose.
- Communicate with you: service notifications, policy updates, and support responses.
We never sell your data. We never share personal information with advertisers. We never use children's data for marketing.
Children’s Information
Children's data receives the highest level of protection in our system. SeeMe Learn is designed for use by parents, guardians, educators, and therapists on behalf of children and children do not create accounts themselves.
Parental Consent
Before any child photograph can be uploaded, the parent or guardian must provide explicit, informed consent through our consent wizard. Consent records are immutable and cannot be edited or deleted, creating a full audit trail.
Minimal Data Collection
Child profiles contain only a first name, learning level, age range, and pronouns. No surnames, no school details, no location data.
Photo Usage
Reference photos are used exclusively to generate consistent character illustrations in educational books. Photos are encrypted at rest and served via time-limited pre-signed URLs (15-minute expiry) in production.
Consent is required before any photo upload. Consent records are immutable and create a permanent audit trail.
AI & Image Processing
We use artificial intelligence to generate book text and illustrations. Here is exactly how your data interacts with AI systems:
Upload Safety Screening
Every uploaded photo is safety-screened by OpenAI (United States) before it is stored— an automated moderation check that protects children. The photo is used only for that check. OpenAI's published API terms state that data submitted through their API is not used to train their models.
Text Generation
Story text is generated using Anthropic's Claude API (United States). The child's name is replaced with a placeholder before sending and re-inserted on our servers; their age, pronouns, learning level, and selected topic are included to personalise the story. No photos accompany these story-text requests.
Image Generation
Creating an illustration involves two separate overseas transfers: the child's reference photo is sent to Anthropic (United States) for appearance analysis, and then to the image provider — OpenAI (United States) as our primary provider, or Google Gemini (United States) as a fallback — to generate the illustration. Reference photos are provided at inference time only, included in the API request to guide the illustration. We use these providers on their paid API tiers, whose published terms state that data submitted through the API is not used to train their models.
No Model Training
We use every AI provider on its paid API tier, whose published terms state that data submitted through the API — including photographs — is not used to train the provider's foundation models. We specify the paid tiers deliberately: some providers permit training on data sent through their free tiers, so we do not use those for your child's data. We rely on those published terms alongside our own technical safeguards. We want to be precise about the limits of that assurance: we cannot independently audit a provider's internal systems, and we do not hold a separate zero-retention arrangement with them, so their published terms govern how long they hold API data.
Your child's photos are used at inference time only, and we use the AI providers on their paid API tiers, whose published terms state that data submitted through the API is not used for model training. Your child's first name is never sent to any AI provider.
Data Storage & Security
We take a defence-in-depth approach to protecting your data, with multiple layers of technical safeguards:
Australian Data Residency
All personal data and biometric data (photographs) are stored exclusively in Australian data centres (Sydney region). This includes our database (Supabase Sydney) and file storage (Supabase Storage Sydney). Your child's stored data stays in Australia. There are three transient exceptions, each a distinct transfer overseas:
- At upload, the photo is safety-screened by OpenAI (United States) before it is stored.
- At story generation, a placeholder-substituted prompt (including the child's age and pronouns, but never their name and never a photo) is sent to Anthropic (United States).
- At illustration generation, the reference photo is sent to Anthropic (United States) for appearance analysis, and then to OpenAI (United States), or Google Gemini (United States) as a fallback, to generate the image.
These transfers are transient, and we use these providers on their paid API tiers, whose published terms state that data sent through the API is not used to train their models (see “AI & Image Processing” above).
Encryption at Rest
All data is encrypted at rest. API keys and sensitive credentials are additionally encrypted using AES-256-GCM before storage. Photographs are encrypted via the storage provider's server-side encryption.
Access Controls
In production, photos are served via pre-signed URLs that expire after 15 minutes. Role-based access control (RBAC) with granular permissions ensures only authorised users can access child data.
EXIF Metadata Stripping
All uploaded images are automatically stripped of EXIF metadata, including GPS coordinates, device information, and timestamps, before storage. Stripping is enforced at the storage layer, so no upload path can bypass it, and we can run an on-demand audit across stored files to confirm none persists.
Generation Logs
AI generation prompts and responses are stored only for sample demonstration profiles, used solely for internal quality and safety review, and automatically deleted after 30 days. We do not retain generation prompts or responses created for a real child's profile.
Your child's data is stored only in Australia. At upload, each photo is transiently safety-screened by OpenAI (United States); at the moment of AI generation, their age, pronouns and reference photo are transiently processed by our providers in the United States. Their first name is not — it is replaced with a placeholder before the request leaves our servers. We use these providers on their paid API tiers, whose published terms state that this data is not used to train their models. All data is encrypted at rest, with AES-256-GCM encryption for sensitive credentials.
Your Rights Under the Australian Privacy Principles
Under the Australian Privacy Principles (APPs), you have the right to:
- Access your data (APP 12): Request a copy of all personal information we hold about you and your child profiles.
- Correct your data (APP 13): Request correction of any inaccurate, out-of-date, or incomplete personal information.
- Delete your data: Request deletion of your account and all associated data, including child profiles, photos, and generated books.
- Withdraw consent: Withdraw consent for photo usage at any time. Consent withdrawal is logged and auditable.
- Export your data: Request a portable copy of your data in a standard format.
- Complain: Lodge a complaint with the Office of the Australian Information Commissioner (OAIC) if you believe we have breached the APPs.
To exercise any of these rights, contact us at privacy@seemelearn.com.au. We will respond within 30 days as required by the APPs.
Third-Party Services
We use a limited number of third-party services to deliver SeeMe Learn. Each has been evaluated for privacy compliance:
| Service | Purpose | Data Processed |
|---|---|---|
| Supabase (Sydney) | Database | Account data, child profiles, book data |
| Supabase Storage (Sydney) | File storage | Photos, generated images, book assets |
| Redis (self-hosted, Sydney) | Job queue, session cache & rate limiting | Job metadata, session and rate-limit records (no photos). Runs on our own Australian server, not a third-party service. |
| Anthropic (Claude) | Text generation and reference-photo appearance analysis | Age, pronouns, learning level and topic — the child’s first name is replaced with a placeholder before sending. For illustrated books, the reference photo for appearance analysis. |
| OpenAI | Image generation (primary) and upload photo safety moderation | Reference and uploaded photos (inference only) |
| Google Gemini | Image generation (fallback) | Reference photos (inference only) |
| Stripe | Payments and subscription billing (United States) | Account holder’s email address, name, and an internal account reference. No child profile data or photos are sent to Stripe. |
| Resend | Transactional email delivery (United States) | Recipient email address and the content of the email, which may include the account holder’s name and, for support correspondence, ticket titles and comment extracts. No child profile data or photos are sent to Resend. |
| Browser push services (Google FCM, Apple APNs, Mozilla autopush) | Delivering opt-in “your book is ready” notifications (overseas) | Your device’s push address, and the notification itself — encrypted in transit, so the push service routes it without being able to read it. The notification says only that a book is ready: it never includes your child’s name or the book’s title, so nothing identifying appears on a locked screen. Notifications are opt-in per device and can be turned off at any time in your browser or device settings. No photos are sent to a push service. |
We do not share personal information with any parties beyond those listed above, and only to the extent necessary to provide the service. Anthropic, OpenAI, Google, Apple, Mozilla, Stripe and Resend are based in the United States; the data each one receives is listed in the table above. Your child's profile data and photographs are never sent to our payments, email or push providers.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes to our practices, technology, legal requirements, or other factors. When we make material changes:
- We will notify you via the email address associated with your account at least 14 days before the changes take effect.
- We will display a prominent notice within the application.
- The “Last Updated” date at the bottom of this page will be revised.
Your continued use of SeeMe Learn after the effective date of any changes constitutes acceptance of the updated policy.
Contact Us
If you have questions about this Privacy Policy, wish to exercise your rights under the APPs, or want to raise a privacy concern, please contact us:
If you are unsatisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) (opens in new tab).
This policy was last updated on 20 July 2026.