Logo
  • Solutions
    ParentsSchoolsUniversitiesWorkplacesIntegrators/
    Platform Partners
  • Features
  • Pricing
    Parent PricingSchool PricingUniversity PricingWorkplace Pricing
  • Learn More
    Start-Up GuideFAQBlogOur StoryContact us
  • Health Check
  • Sign InSign Up

Privacy Policy

Chatstat Pty Ltd (ABN 72 651 491 637, ACN 651 491 637)

Last updated: July 15, 2026

Chatstat Pty Ltd is the data controller for the personal information described in this policy. Where a school, university, or workplace customer engages Chatstat to monitor content on its behalf, that customer is the controller of the monitored data and Chatstat processes it under their instructions and our Data Processing Addendum.

Summary of key points

  • We analyze publicly available social media content and, where an organization enables it, content in workplace communication channels that the employer controls. We never access private messages, and we never install software on a monitored person's device.
  • We do not sell personal information. We do not share personal information with advertisers or advertising networks, and we do not use it for targeted advertising.
  • We deliberately collect the minimum needed. For monitored young people we collect month and year of birth only, never the exact date.
  • Raw content belonging to anyone under 18 is never made available to any third-party AI agent, under any configuration. This rule is enforced in our database security layer, not just in policy.
  • Automated analysis supports human judgment. Chatstat does not make solely automated decisions that produce legal or similarly significant effects about any person, and it does not diagnose anyone.
  • Questions or requests: privacy@chatstat.com

Who this policy covers

This policy applies to visitors to our websites, account holders (parents, guardians, and organization administrators), and people whose publicly available content or organization-authorized channel content is monitored through Chatstat ("monitored subjects").

What we collect

Account information. Name, email address, phone number, time zone, language preference, login credentials, and, where you use social sign-in (Google or Facebook), the profile details those services share with us.

Billing information. Subscription and transaction records. Card details are collected and stored by our payment processor, Paddle, not on Chatstat systems. Where you subscribe through the Apple App Store or Google Play, billing is handled by Apple or Google under their terms.

Monitored subject information. The public social media handles you register, a first name or nickname you choose, an age range, and month and year of birth only. We do not collect exact dates of birth by design.

Monitored content. Publicly available posts, comments, captions, and profile changes from registered public accounts; and, for workplace customers, content from communication channels (such as Teams, Slack, and email) that the employer has authorized and configured. We do not access private messages, private accounts, or encrypted chats.

AI Guide inputs. Questions and information you choose to enter into the AI Guide.

Technical information. Device, browser, IP address, and usage data collected through cookies and similar technologies, described in our Cookie Policy.

Support communications. Messages you send us through forms, email, or in-product support.

What we do not collect or do. We do not collect exact dates of birth of monitored subjects. We do not access private messages. We do not install monitoring software on anyone's device. We do not sell personal information, and we do not disclose it to advertising networks or data brokers.

Children and monitored young people

Chatstat accounts are held by adults. Monitoring of a person under 18 is established and controlled by their parent or legal guardian, or by a school under a contract that requires appropriate authorization.

When a monitored young person approaches adulthood, monitoring ends automatically from the start of the calendar month in which they turn 18 and their profile is closed. Any future monitoring of that person could only occur with their own consent as an adult.

From 18, the person's own privacy rights, including access and erasure rights, are exercisable by them directly. Flagged incident records created before they turned 18 remain subject to the retention period described below.

How we use personal information

We use personal information to provide and operate the service, including analyzing registered public content and authorized channels for safety and wellbeing risk signals; to generate alerts, dashboards, reports, and AI Guide responses; to administer accounts, subscriptions, and support; to secure the service, prevent abuse, and maintain audit records; to improve our detection models using de-identified and aggregated data; and to meet our legal obligations.

Legal bases where the GDPR or UK GDPR applies include performance of a contract, our legitimate interests in providing a safety service and securing it, consent where we ask for it, and compliance with legal obligations. In Australia we handle personal information in accordance with the Australian Privacy Principles under the Privacy Act 1988 (Cth).

Automated analysis and AI

Chatstat uses machine learning and large language models to classify content into risk categories, detect pattern shifts, and generate plain-language explanations and engagement guidance. This output is decision-support information for a responsible human. It is not a diagnosis, a finding of fact, or a decision with legal effect. Our AI and Notification Disclaimer explains the capabilities and limits of these systems and forms part of how the service must be understood and used.

AI integrations and the Chatstat MCP

Enterprise customers can connect Chatstat to their own AI tools through our API and MCP server. Data leaving Chatstat through these integrations is controlled by a three-tier model:

  • Tier 1 (default). Structured metadata only: alert identifier, timestamp, risk category, severity band, affected user role, recommended action category, and source platform name. No names, handles, content, quotes, or identifiers.
  • Tier 2 (opt-in, administrator-gated). Tier 1 plus short excerpts of up to 280 characters with personal identifiers redacted server-side before release. Never available for subjects under 18.
  • Tier 3 (enterprise-only, double-gated). Raw flagged content, available only under an enterprise plan with a signed Tier 3 addendum, a verified adult subject, customer-scoped authentication, and a data protection impact assessment on file.

Raw content of any person under 18 is never exposable to a third-party AI agent under any circumstance, regardless of customer configuration or plan. This restriction is enforced at the database security layer. All integration access is authenticated per customer, logged for 12 months, and covered by contractual commitments that our AI providers do not train their models on Chatstat data.

Who we disclose personal information to

Your organization. If your monitoring is provided through a school or employer, designated staff at that organization see alerts and reports according to their role and the customer's configuration.

Service providers. We use a small set of vetted sub-processors for hosting, database, AI processing, analytics, support, and payments. The current list, including locations and safeguards, is published on our Sub-processor List page, together with links to each provider's privacy policy.

Customer-directed recipients. Where an enterprise customer connects their own AI tools through our API or MCP, the AI provider they choose receives data on that customer's instruction, subject to the tier model above.

Legal requirements. We may disclose personal information where required by law, regulation, court order, or to protect the safety of any person, and only to the extent required.

We do not disclose personal information to advertisers, advertising networks, or data brokers, and we do not sell it.

International transfers

Chatstat operates from Australia and serves customers in Australia and North America. Our primary application infrastructure and database are hosted in Australia (Sydney). Content is transmitted to the United States for AI analysis through Microsoft's Azure OpenAI Service, video content is analyzed through Google's Gemini API on Google's global infrastructure, and some providers on our Sub-processor List operate globally. Where personal information is transferred across borders, we rely on appropriate safeguards, including Standard Contractual Clauses for transfers from the EU and the UK International Data Transfer Addendum for transfers from the United Kingdom, and we take reasonable steps consistent with APP 8. Customers who require regional processing can discuss configuration options with us.

How long we keep personal information

CategoryRetention
Account profile and billing recordsDuration of the account plus 7 years
Flagged incident records (all customer types)7 years from alert creation
Unflagged monitored content, individual accounts90 days rolling
Unflagged school-page content90 days by default, configurable up to 365 days by contracted school instruction
Unflagged workplace channel content90 days rolling
AI Guide conversation logs30 days from conversation creation
AI Guide saved notesUntil you delete them
AI Guide pinned conversations30 days per pin, up to 5 active pins
Audit and security logs, including integration access logs12 months
Backups35 days rolling
De-identified, aggregated dataRetained without time limit

Flagged incident records are self-contained snapshots created at the time of an alert so that the underlying raw content does not need to be retained. When source content is deleted at the end of its retention period, derivative records refer to it descriptively rather than reproducing it.

How we protect personal information

Personal information is encrypted in transit and at rest. Access is role-based and least-privilege. Row-level security rules in our database enforce customer separation and the under-18 protections described above in code. We maintain audit logging, tested backups, and deletion propagation across systems. Chatstat is implementing an ISO/IEC 27001 information security management system, with certification through an accredited body in progress. No system is completely secure, and we cannot guarantee absolute security, but we design for it and we do not make claims we have not implemented.

Your rights

Australia. You may request access to and correction of your personal information, and complain to us and then to the Office of the Australian Information Commissioner ( oaic.gov.au) if you are unsatisfied with our response.

EU and UK. Where the GDPR or UK GDPR applies, you have rights of access, rectification, erasure, restriction, portability, and objection, and the right to lodge a complaint with your supervisory authority.

United States. Residents of California and other states with comprehensive privacy laws have rights to know, access, correct, and delete personal information, and to opt out of sale or sharing. Chatstat does not sell or share personal information for cross-context behavioral advertising, so there is nothing to opt out of, but you may still exercise your other rights.

Monitored subjects. A monitored subject, or their guardian while they are under 18, may contact us about the data we hold. From 18, these rights are exercisable by the individual directly.

To exercise any right, email privacy@chatstat.com. We verify requests before acting on them and respond within the timeframe required by applicable law.

Data protection officer and representatives

Our appointed Data Protection Officer is Nicola Cook of DPO Solutions for Schools, reachable via privacy@chatstat.com. UK and EU privacy inquiries are handled directly by Chatstat at privacy@chatstat.com.

Cookies

Our use of cookies and similar technologies, including analytics and session tools, is described in our Cookie Policy.

Changes to this policy

We update this policy when our practices change. Material changes are notified through the service or by email, and the date at the top reflects the current version. We do not publish commitments before the systems behind them exist.

Contact

privacy@chatstat.com
Chatstat Pty Ltd, 16 Nexus Way, Southport QLD 4215, Australia

Logo
Social IconSocial IconSocial IconSocial IconSocial IconSocial Icon
About
Our StoryCareers
Contact

Chatstat Pty Ltd (ABN 72 651 491 637)

Support: support@chatstat.comAustralia +61 7 3778 2602USA +1 650 388 9589UK +44 20 4630 0298
Legal
Privacy PolicyCookie PolicyTerms of ServiceAcceptable Use PolicyAI DisclaimerSub-processor ListLegal NoticeSecurityCookie settings