Privacy Policy
Version: 1.05
Effective Date: 7th September 2026
At indi, we’re deeply committed to safeguarding your personal and family information. As a digital platform supporting children’s developmental health journeys, we understand that your trust in how we handle sensitive data, particularly children’s data, is foundational. This policy outlines how we manage, protect, and use that data across jurisdictions including Australia, the United States, the United Kingdom, and the European Union.
1. Scope and Applicability
This policy applies to personal and health information collected through the indi platform and related services. We align our practices with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs); the UK General Data Protection Regulation and the Data Protection Act 2018 for users in the United Kingdom; and the EU General Data Protection Regulation for users in the European Union.
Depending on the context, indi may act as a “controller” or a “processor” under privacy laws. For example, when you enter observations or upload documents, we act as a controller. In some settings (for example, where an organisation provides indi to users under an agreement), we may act as a processor for that organisation.
Anonymity and pseudonymity
Because indi involves personalised child and family health information, we generally need certain identifying details to create and maintain your account and to ensure data integrity and safety. In most cases you cannot use indi anonymously. However, where it is lawful and practical to do so (for example, browsing certain public pages or resources), you may interact with indi without identifying yourself.
2. What We Collect and How We Collect It
We may collect the following types of information:
- Parent and caregiver account details (name, email, contact information).
- Child-related developmental data, observations, milestones, and documents.
- Appointment history, care notes, and communications within the platform.
- Device data (e.g., IP address, approximate location inferred from IP, browser type) for security and functionality.
- Usage data for analytics and feature improvement.
- Mobile advertising identifiers (Apple IDFA on iOS where you grant permission, and Google Advertising ID on Android) and related attribution data, used solely to measure which marketing campaigns bring families to indi. See “Attribution and analytics partners” below.
We collect information in several ways, including:
- Directly from you when you create an account, complete forms, enter observations, upload documents, book appointments, or communicate with us.
- From others you authorise, such as healthcare providers or educators who you connect to your indi account.
- Automatically when you use the platform, through technologies such as cookies, SDKs and similar tools that help us keep the service secure, understand usage patterns, and improve performance. For details on the cookies our website uses, the tracking technologies our app uses, and how to control them, see our Cookie & Tracking Policy.
You are responsible for ensuring you have appropriate authority to share information, especially when adding details about another person (e.g., your child, a partner, or an educator).
When we collect personal information, we aim to do so directly from you and to let you know, at or before the time of collection (or as soon as practicable afterwards), what we are collecting, why we are collecting it, and how it will be used and disclosed. This may be done through this Privacy Policy, in-app notices, just-in-time prompts, or other communications.
3. How We Use and Share Information
We use personal information to:
- Deliver personalised developmental support and milestone tracking.
- Support care appointment scheduling, reminders, and secure messaging.
- Improve the platform by analysing how it is used.
- Monitor, evaluate, and improve the safety and quality of indi’s AI-enabled features, in accordance with this Privacy Policy.
- Respond to your requests or provide customer support.
- Comply with legal obligations, such as health record access rights or court orders.
We do not sell or rent your data.
Safety, Quality, and Improvement of Our AI Features
indi uses information entered into the platform to monitor and improve the quality, safety, and reliability of its AI-enabled features. This includes reviewing what is sent to and returned by those features, so that we can detect when a response is inaccurate, unsafe, or not behaving as intended. It is not used to make automated decisions about your child without appropriate safeguards.
This safety and quality monitoring is carried out on information in the form you entered it, which can include health information about your child. We do not de-identify it first, because reviewing the actual content is what allows us to identify an unsafe or incorrect response. Access is limited to personnel who need it for this purpose.
We do not review every response. Every response you tell us was unhelpful or wrong is queued for review, as is any response flagged by our automated safety checks. A single answer often cannot be judged on its own, so the reviewer may also read the messages around it in the same conversation, in order to audit how our AI came to that response.
When a response is reviewed, the reviewer records what they found and what was done about it. That record sits with your child’s record, is visible only to indi staff with access to our internal administration tools, and is deleted when the conversation it concerns is deleted.
The review described above is carried out by our own people, inside indi itself — the same system that already holds your child’s record. Your child’s conversation is not sent to a separate service for that review.
We also use monitoring and error-reporting services that detect faults automatically. These are third-party service providers, which may process this information outside Australia under a data processing agreement and, where applicable, standard contractual clauses. See International Data Transfers below.
We do not use identifiable personal information to train AI models, and our AI providers do not use information sent through our platform to train theirs.
Participation in model improvement is optional. You can opt out at any time through your account settings. Safety and quality monitoring is part of operating the service safely and continues regardless of that choice. If you cannot access your account settings, you can request this via privacy@projectindi.com. Opting out will not affect your ability to use indi’s core services.
We may share your information with trusted third parties where necessary to provide our services, including:
- Cloud hosting and storage providers that securely store data.
- Analytics services that help us understand how the platform is used.
- Monitoring and observability services that help us operate and secure the platform and monitor the safety and quality of our AI features. Information you enter, including health information, may be processed by these services for that purpose.
- Communication and notification providers that support email, SMS, or in-app messaging.
- Healthcare providers or organisations you explicitly connect to your indi account, in line with your instructions and consent.
- Professional advisors and insurers, where required for legal, regulatory, or risk management purposes.
- Law enforcement or regulatory authorities, where we are legally required to do so, or where disclosure is necessary to prevent or lessen a serious threat to life, health, or safety.
We require third parties who handle your information to be bound by data processing terms addressing security and privacy — whether negotiated with us or published by the provider — and we assess each provider before and during the engagement.
Attribution and analytics partners
We use AppsFlyer, an SDK provided by AppsFlyer Ltd., in our mobile apps to measure the effectiveness of our marketing. AppsFlyer helps us understand which campaigns and referral sources bring families to indi, so we can reach more parents who would benefit from the service.
When you use our mobile app, AppsFlyer may receive your mobile advertising identifier (Apple IDFA on iOS, where you have granted App Tracking permission, or Google Advertising ID on Android), device type and operating system, IP address, a pseudonymous account identifier we assign to your indi account, and a limited set of in-app events (such as sign-up, subscription start, and in-app purchase) for attribution purposes. AppsFlyer does not receive children’s health information, observations, documents, or other content you enter about your family.
AppsFlyer processes this data on our behalf under a data processing agreement. Their privacy practices are available at appsflyer.com/legal/services-privacy-policy. You can opt out of AppsFlyer attribution at appsflyer.com/optout.
On iOS, we will not access your IDFA unless you allow App Tracking when prompted. You can change this at any time in your device Settings under Privacy & Security → Tracking. On Android, you can reset or limit ad personalisation in your device Settings under Google → Ads.
Our public website also uses advertising and measurement cookies, including the Meta Pixel, and only where you have accepted marketing cookies. Each is listed individually, with its provider, purpose and duration, in our Cookie Policy. They are not used in the indi app, and they do not receive health information, observations, or documents.
4. Unsolicited and Inappropriate Information
indi is designed for specific, family-related health and developmental purposes. If we receive personal information that we did not request, or that appears unrelated to our services:
- We will assess whether we are permitted to retain it in line with this Privacy Policy and applicable law.
- If we are not permitted to keep it, we will take reasonable steps to destroy or de-identify the information as soon as practicable.
If we become aware that information has been entered without appropriate authority or consent, we may seek verification, limit access, or remove that information in accordance with applicable laws.
5. International Data Transfers
This section explains where in the world your information goes when you use indi, and what protects it when it leaves Australia. Australian Privacy Principles 1 and 5 require us to tell you which countries your information is likely to be disclosed to. Article 13 of the UK GDPR, and of the EU GDPR, requires us to tell you about transfers outside the United Kingdom or the European Union and the safeguards that apply. Australian Privacy Principle 8, and Chapter V of the UK and EU GDPR, govern the protections that must be in place for those transfers.
Where your information is processed
indi is an Australian company, but our platform is hosted in the United States. Your account, your child’s profile, your observations and any documents you upload are stored in the United States by our database and hosting providers.
As at the date of this Privacy Policy, our service providers process information in the following places:
- United States — our database, file storage and authentication provider; our application hosting; our AI, speech-to-text, analytics, error-reporting and observability providers; our email, payment and subscription providers; and our internal business tools.
- Israel, the European Union, the United States, the United Kingdom, Germany, India, Japan, Hong Kong and China — AppsFlyer Ltd. is our mobile attribution provider, which tells us which advertising campaigns are effective at reaching families who need indi, as described in section 3. AppsFlyer is incorporated in Israel. Its published subprocessor list records that the data it processes on our behalf is hosted with cloud providers located in the European Union, and that AppsFlyer group companies in Germany, the United Kingdom, the United States, Israel, India, Japan, Hong Kong and China may access it to support and maintain the service.
- United States and Ireland — Meta, in connection with the advertising cookies used on our public website, as described in section 3.
- Worldwide — our content delivery and security provider operates edge infrastructure worldwide and may handle limited connection information, such as your IP address, in the location closest to you.
We may add new providers, and existing providers may change where they process information, after this Policy is published. Where that happens we will update this section in the next revision of the Policy.
The basis for disclosing information overseas
Before information is disclosed to an overseas recipient, we seek to have at least one of the following in place:
- a written agreement — usually a data processing agreement — binding the recipient to handle your information securely and consistently with applicable privacy law;
- the UK International Data Transfer Addendum, or the European Commission’s Standard Contractual Clauses, where the recipient handles information about users in the United Kingdom or the European Union; or
- a formal adequacy decision, where the recipient operates from a country recognised by the United Kingdom or the European Commission as providing an adequate level of protection.
We remain responsible for overseas recipients
Section 16C of the Privacy Act 1988 (Cth) makes us accountable for what an overseas recipient does with your information as if we had done it ourselves, apart from limited exceptions. Our position is that we take reasonable steps under APP 8.1 and remain accountable — we do not seek to pass that accountability to the recipient.
What we do not send overseas
Some limits are fixed by the agreements we hold with these providers rather than by our configuration alone:
- Our mobile attribution provider is contractually limited to device and campaign information and may not be configured to collect beyond it. It does not receive health information, observations, or documents.
- The advertising cookies on our public website record page views on that website only. They receive no account identifier, no in-app activity, and no health information.
- Our speech-to-text provider is contractually excluded from using your audio to improve its models, and does not retain it after transcription.
- We never receive or store your card number; our payment providers handle it.
6. Your Rights
Depending on your jurisdiction, you may have rights to:
- Access your data and receive a copy in a portable format.
- Correct or update information about you or your child.
- Request deletion of your account or specific data points, subject to legal and clinical record-keeping obligations.
- Withdraw consent for certain types of data processing.
- Object to automated decision making or profiling, where used.
- Lodge a complaint with your local privacy authority (see “Complaints and Contact” below).
- Opt out of the use of your information for AI model improvement.
To exercise any of these rights, please contact us via the details provided below. We may require verification of your identity before fulfilling requests. We aim to respond within a reasonable period (typically within 30 days) and will inform you if we are unable to comply with your request and explain why.
7. Children’s Data
indi is specifically designed to support parents and legal guardians. We do not permit direct use by children under 16. All child-related data must be entered by a verified parent, guardian, or authorised caregiver. You must not enter information about a child without proper authority and consent.
If we become aware that child data has been entered without appropriate consent, we will take steps to verify or remove the data in accordance with applicable laws.
8. Data Security, Retention, and Destruction
We use encryption, role-based access controls, and secure cloud infrastructure to safeguard your information. We take reasonable steps to protect personal information from loss, misuse, unauthorised access, modification, or disclosure.
We retain personal information only for as long as it is reasonably necessary to:
- provide the indi services you have requested,
- support your ongoing relationship with us, and
- meet legal, regulatory, and clinical record-keeping requirements.
When personal information is no longer required for these purposes, we take reasonable steps to destroy it or permanently de-identify it, unless we are required by law to retain it for a longer period.
Despite our efforts, no digital service is completely immune to risks. You are also responsible for keeping your account credentials confidential and ensuring secure use on your devices.
Where information has already been used to improve an AI feature, it may not be possible to fully remove its influence from a model that has been trained. Opting out stops your information being used for that purpose from that point forward.
9. Responsible Use Reminder
indi is a powerful tool to assist with early developmental observations and coordination, but it is not a diagnostic service or a replacement for professional advice. Please use the platform ethically, with care and respect for the privacy of those you’re recording information about.
Misuse of the platform, including entering unverified or inappropriate content, may lead to account suspension or legal action under applicable health and privacy laws.
10. Complaints and Contact
If you have questions, feedback, or would like to exercise your rights, please reach out:
Email: privacy@projectindi.com
We take privacy concerns seriously and will work with you to resolve any complaint.
If you are not satisfied with our response, you may lodge a complaint with the relevant privacy authority. In Australia, this is the Office of the Australian Information Commissioner (OAIC):
- Web: oaic.gov.au
- Phone (within Australia): 1300 363 992
For users in other jurisdictions, you may also have the right to contact your local data protection authority.
11. Updates to This Policy
We may update this Privacy Policy to reflect changes in law or service offerings. Significant changes will be communicated via the app or email. Your continued use of indi after any update constitutes acceptance of the new terms.
Change history
- Version 1.05 (7th September 2026)
- Described how information is shared with analytics, monitoring and observability providers, and with third parties generally.
- Clarified that safety and quality monitoring of our AI features is carried out on information in the form you entered it rather than on de-identified information, and that this monitoring continues whether or not you take part in model improvement.
- Set out which AI responses are reviewed by a person — those you tell us were unhelpful or wrong, and those flagged by our automated safety checks — and that the reviewer may read the surrounding conversation to audit how a response was reached.
- Said that reviewing a response creates a record which is deleted with the conversation it concerns, and that this review is carried out inside indi rather than by sending your child’s conversation to a separate service.
- Rewrote the international transfers section to name the countries your information is disclosed to, the basis on which it may be disclosed, and what we do not send overseas.
- Replaced the description of where our mobile attribution provider processes information with what its published subprocessor list records.
- Pointed to the Cookie Policy for the advertising cookies used on our public website.