Privacy Policy
Effective date: August 2026
Not Designed for Sensitive Information
CHAIOS apps are planning and coordination tools only. They are not designed or intended for storing sensitive personal data such as government-issued identity documents, tax file numbers, legal contracts, financial credentials, confidential compliance records, or health information beyond basic personal tracking. We strongly recommend you do not store highly sensitive or regulated information within the Services. It is always best practice to only share what is necessary and to consult qualified professionals for legal, regulatory, or compliance requirements.
1. Introduction
CHAIOS ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and disclose information when you use the CHAIOS mobile application and web application (collectively, the "Services").
CHAIOS develops applications to support personal and professional planning, coordination, and organisation. Our Services are not designed for storing sensitive personal identification documents, confidential legal or compliance records, or other highly sensitive data. Please refer to our Terms of Use for the full scope and limitations of the Services.
By creating an account or using our Services, you agree to the collection and use of information as described in this policy.
2. Information We Collect
Account information: When you register, we collect your name, email address, and password (stored securely via Supabase Auth).
App data: Information you enter about events, guests, budgets, tasks, businesses, and other planning-related content you choose to record within the Services.
Uploaded files: CHAIOS stores only one category of files on its own servers: images uploaded by businesses to their Business Directory listing (logos, banner images, and gallery photos). These are stored in our Supabase file storage (vendor-assets bucket) so they can be displayed publicly on the listing. All other files — such as document attachments — remain on your device and are never transmitted to our servers.
How busy we are, and how fast: We measure page counts and load times through Vercel, who host our sites, so we know we have enough capacity at peak times and get an early warning when something is slowing down. It sets no cookies, does not fingerprint your device, and builds no profile of you — it records that a page was loaded and how long it took, not who loaded it. The same tool counts how many people start and finish the ISO readiness tool, including which readiness band the result fell into, so we can tell whether it is useful. No personally identifiable information is included.
Where you came from: If you reach us through one of our own social posts, you may land on a page such as chaios.au/fb. That page adds a short code — fb, ig — to the link through to the app, and if you then create an account we record that code against it, once, so we know which posts are worth writing. No cookie is set, nothing is stored on your device, the code is never shared, and it is not used to build a profile of you.
Error reports: When something goes wrong we record what happened so we can fix it: the error message, the page you were on, your browser type, and the email address of the signed-in account. The account is included so we can follow up with you about a fault rather than watch it anonymously. An error report never contains the contents of what you were saving.
Forwarded booking confirmations (optional, off by default): If you turn on booking forwarding in the Travel module, CHAIOS gives you a private email address. Anything you forward to it is read for travel details — dates, airports, flight numbers, the hotel name — and we keep those details, the subject line, and the sender's domain. We do not keep the message itself, its attachments, or the sender's full address. See section 6a for the part of this that is outside our control.
3. What We Recommend You Do Not Store
While CHAIOS applies appropriate security measures (see our Trust & Security page), the Services are not designed, assessed, or warranted as a secure platform for highly sensitive or regulated data categories. We strongly advise against storing:
- Government-issued identification documents (passports, driver licences, tax file numbers)
- Legal contracts, deeds, or instruments requiring secure custody
- Financial account credentials, banking information, or card numbers
- Sensitive compliance or regulatory records that carry legal obligations
- Medical or clinical health records beyond basic personal wellness tracking
- Confidential business information subject to legal privilege or regulatory obligations
For any information in the above categories, please use a purpose-built, audited, and certified solution appropriate to the sensitivity and regulatory requirements of that data.
4. File Storage
CHAIOS uses file storage in one specific context: Business Directory listings. When a business partner uploads a logo, banner, or gallery images for their public listing, those files are stored in our secure Supabase storage bucket (vendor-assets) and served publicly as part of the directory.
For all other content — such as vision board inspiration images — files are encoded and stored as data directly within your record in the database. They are not uploaded to any separate storage bucket.
Record attachments (contracts, quotes, photos) remain on your device only and are never transmitted to our servers.
5. How We Use Your Information
- To provide, maintain, and improve the Services
- To authenticate your account and maintain security
- To respond to support enquiries and feedback
- To send transactional emails (e.g. account verification, password reset)
- To analyse aggregate, anonymised usage patterns
We do not sell your personal information to third parties.
As Nexus grows, some outbound links to products or services may earn us a small affiliate commission. Any such links are labelled where they appear, and they are never selected using your personal information — we do not build a profile of you to target them.
6. Data Sharing
We share data with the following third-party service providers, solely to operate the Services:
- Supabase — database, authentication, and file storage for Business Directory listing images. All data is hosted in a SOC 2-compliant environment.
- Resend — transactional email, and receiving forwarded booking confirmations if you turn that on. See 6a.
We do not share your data with advertisers or data brokers. Each provider is bound by their own privacy policy and data processing agreements.
6a. Forwarded booking confirmations — an exception, stated plainly
The Travel module can give you a private email address to forward booking confirmations to. It is off unless you turn it on, and it is the only part of CHAIOS that receives content from outside the app.
What CHAIOS keeps:the travel details we read out of the message, its subject line, and the sender's domain — never the message body, never attachments, never the sender's full address.
What we cannot control: the email arrives at our email provider, Resend, before CHAIOS ever sees it. Resend holds a copy on servers in the United States. They do not publish a retention period for received email, and they do not offer us a way to remove it — so we cannot tell you it has been erased. Your CHAIOS account data is otherwise stored in Australia; this feature is the exception, and we would rather say so here than let you find out later.
What you control: the address works only for you, and only while it exists. Changing it stops the previous address working immediately, turning it off makes mail sent to it be ignored, and deleting an import removes everything CHAIOS read from that email.
7. Data Retention
Your account data is retained for as long as your account is active. If you delete your account, we will delete your personal data within 30 days, unless we are required to retain it by law.
8. Security
We implement industry-standard security measures including encrypted connections (HTTPS/TLS), password hashing, and Supabase Row Level Security to ensure only authorised users can access your data. However, no method of transmission over the internet is 100% secure, and the Services are not designed as a certified secure vault for sensitive or regulated data. See our Trust & Security page for full details.
9. Your Rights
Depending on your location, you may have the right to:
- Access the personal data we hold about you
- Request correction or deletion of your data
- Object to or restrict processing of your data
- Export your data in a portable format
To exercise these rights, contact us at support@chaios.au.
10. Children's Privacy
CHAIOS is not directed at children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us and we will delete it.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by updating the effective date above and, where appropriate, by sending an email notification.
12. Contact
If you have questions about this Privacy Policy, please contact us at support@chaios.au or visit our Contact page.