Chatstat Pty Ltd (ABN 72 651 491 637, ACN 651 491 637)
Last updated: July 15, 2026
Chatstat Pty Ltd is the data controller for the personal information described in this policy. Where a school, university, or workplace customer engages Chatstat to monitor content on its behalf, that customer is the controller of the monitored data and Chatstat processes it under their instructions and our Data Processing Addendum.
This policy applies to visitors to our websites, account holders (parents, guardians, and organization administrators), and people whose publicly available content or organization-authorized channel content is monitored through Chatstat ("monitored subjects").
Account information. Name, email address, phone number, time zone, language preference, login credentials, and, where you use social sign-in (Google or Facebook), the profile details those services share with us.
Billing information. Subscription and transaction records. Card details are collected and stored by our payment processor, Paddle, not on Chatstat systems. Where you subscribe through the Apple App Store or Google Play, billing is handled by Apple or Google under their terms.
Monitored subject information. The public social media handles you register, a first name or nickname you choose, an age range, and month and year of birth only. We do not collect exact dates of birth by design.
Monitored content. Publicly available posts, comments, captions, and profile changes from registered public accounts; and, for workplace customers, content from communication channels (such as Teams, Slack, and email) that the employer has authorized and configured. We do not access private messages, private accounts, or encrypted chats.
AI Guide inputs. Questions and information you choose to enter into the AI Guide.
Technical information. Device, browser, IP address, and usage data collected through cookies and similar technologies, described in our Cookie Policy.
Support communications. Messages you send us through forms, email, or in-product support.
What we do not collect or do. We do not collect exact dates of birth of monitored subjects. We do not access private messages. We do not install monitoring software on anyone's device. We do not sell personal information, and we do not disclose it to advertising networks or data brokers.
Chatstat accounts are held by adults. Monitoring of a person under 18 is established and controlled by their parent or legal guardian, or by a school under a contract that requires appropriate authorization.
When a monitored young person approaches adulthood, monitoring ends automatically from the start of the calendar month in which they turn 18 and their profile is closed. Any future monitoring of that person could only occur with their own consent as an adult.
From 18, the person's own privacy rights, including access and erasure rights, are exercisable by them directly. Flagged incident records created before they turned 18 remain subject to the retention period described below.
We use personal information to provide and operate the service, including analyzing registered public content and authorized channels for safety and wellbeing risk signals; to generate alerts, dashboards, reports, and AI Guide responses; to administer accounts, subscriptions, and support; to secure the service, prevent abuse, and maintain audit records; to improve our detection models using de-identified and aggregated data; and to meet our legal obligations.
Legal bases where the GDPR or UK GDPR applies include performance of a contract, our legitimate interests in providing a safety service and securing it, consent where we ask for it, and compliance with legal obligations. In Australia we handle personal information in accordance with the Australian Privacy Principles under the Privacy Act 1988 (Cth).
Chatstat uses machine learning and large language models to classify content into risk categories, detect pattern shifts, and generate plain-language explanations and engagement guidance. This output is decision-support information for a responsible human. It is not a diagnosis, a finding of fact, or a decision with legal effect. Our AI and Notification Disclaimer explains the capabilities and limits of these systems and forms part of how the service must be understood and used.
Enterprise customers can connect Chatstat to their own AI tools through our API and MCP server. Data leaving Chatstat through these integrations is controlled by a three-tier model:
Raw content of any person under 18 is never exposable to a third-party AI agent under any circumstance, regardless of customer configuration or plan. This restriction is enforced at the database security layer. All integration access is authenticated per customer, logged for 12 months, and covered by contractual commitments that our AI providers do not train their models on Chatstat data.
Your organization. If your monitoring is provided through a school or employer, designated staff at that organization see alerts and reports according to their role and the customer's configuration.
Service providers. We use a small set of vetted sub-processors for hosting, database, AI processing, analytics, support, and payments. The current list, including locations and safeguards, is published on our Sub-processor List page, together with links to each provider's privacy policy.
Customer-directed recipients. Where an enterprise customer connects their own AI tools through our API or MCP, the AI provider they choose receives data on that customer's instruction, subject to the tier model above.
Legal requirements. We may disclose personal information where required by law, regulation, court order, or to protect the safety of any person, and only to the extent required.
We do not disclose personal information to advertisers, advertising networks, or data brokers, and we do not sell it.
Chatstat operates from Australia and serves customers in Australia and North America. Our primary application infrastructure and database are hosted in Australia (Sydney). Content is transmitted to the United States for AI analysis through Microsoft's Azure OpenAI Service, video content is analyzed through Google's Gemini API on Google's global infrastructure, and some providers on our Sub-processor List operate globally. Where personal information is transferred across borders, we rely on appropriate safeguards, including Standard Contractual Clauses for transfers from the EU and the UK International Data Transfer Addendum for transfers from the United Kingdom, and we take reasonable steps consistent with APP 8. Customers who require regional processing can discuss configuration options with us.
| Category | Retention |
|---|---|
| Account profile and billing records | Duration of the account plus 7 years |
| Flagged incident records (all customer types) | 7 years from alert creation |
| Unflagged monitored content, individual accounts | 90 days rolling |
| Unflagged school-page content | 90 days by default, configurable up to 365 days by contracted school instruction |
| Unflagged workplace channel content | 90 days rolling |
| AI Guide conversation logs | 30 days from conversation creation |
| AI Guide saved notes | Until you delete them |
| AI Guide pinned conversations | 30 days per pin, up to 5 active pins |
| Audit and security logs, including integration access logs | 12 months |
| Backups | 35 days rolling |
| De-identified, aggregated data | Retained without time limit |
Flagged incident records are self-contained snapshots created at the time of an alert so that the underlying raw content does not need to be retained. When source content is deleted at the end of its retention period, derivative records refer to it descriptively rather than reproducing it.
Personal information is encrypted in transit and at rest. Access is role-based and least-privilege. Row-level security rules in our database enforce customer separation and the under-18 protections described above in code. We maintain audit logging, tested backups, and deletion propagation across systems. Chatstat is implementing an ISO/IEC 27001 information security management system, with certification through an accredited body in progress. No system is completely secure, and we cannot guarantee absolute security, but we design for it and we do not make claims we have not implemented.
Australia. You may request access to and correction of your personal information, and complain to us and then to the Office of the Australian Information Commissioner ( oaic.gov.au) if you are unsatisfied with our response.
EU and UK. Where the GDPR or UK GDPR applies, you have rights of access, rectification, erasure, restriction, portability, and objection, and the right to lodge a complaint with your supervisory authority.
United States. Residents of California and other states with comprehensive privacy laws have rights to know, access, correct, and delete personal information, and to opt out of sale or sharing. Chatstat does not sell or share personal information for cross-context behavioral advertising, so there is nothing to opt out of, but you may still exercise your other rights.
Monitored subjects. A monitored subject, or their guardian while they are under 18, may contact us about the data we hold. From 18, these rights are exercisable by the individual directly.
To exercise any right, email privacy@chatstat.com. We verify requests before acting on them and respond within the timeframe required by applicable law.
Our appointed Data Protection Officer is Nicola Cook of DPO Solutions for Schools, reachable via privacy@chatstat.com. UK and EU privacy inquiries are handled directly by Chatstat at privacy@chatstat.com.
Our use of cookies and similar technologies, including analytics and session tools, is described in our Cookie Policy.
We update this policy when our practices change. Material changes are notified through the service or by email, and the date at the top reflects the current version. We do not publish commitments before the systems behind them exist.
privacy@chatstat.com
Chatstat Pty Ltd, 16 Nexus Way, Southport QLD 4215, Australia