Skip to main content
Arcus

Privacy

Privacy policy

What this company holds today, which is an inbox and a server log, what a published tool would and would not collect, how long anything is kept, and how to make us delete it.

Effective 11 August 2026Version 1.0Privacy Act 1988 (Cth)28 sections

1Who we are and what this policy covers

ARCUS AI PTY LTD (ACN 697 547 505, ABN 82 697 547 505) is an Australian proprietary company in New South Wales. It is building measurement tooling for retrieval systems. In this document "we", "us" and "our" mean that company, and "you" means whoever is reading this page or writing to the address on it.

What this policy covers

  • This website at arcusai.fyi and everything served from it.
  • Electronic mail sent to our published address, and our reply to it.
  • Any measurement tooling this company publishes in future. It is described here before publication, so that the description exists in advance of the collection rather than being drafted around it afterwards.

What it does not cover

  • Any website you reach by following a link from this one. We do not control those and we do not receive anything from them.
  • The search index, vector store, model provider or cloud platform you already run. Those are your own suppliers under your own agreements, and nothing described here changes them.
  • Documents in your corpus. Reading your documents is not part of the design, for reasons set out in the section on roles and again in the section on query sets.

Where things stand. Nothing has been published. The only personal information this company holds today is correspondence sent to it, the request logs kept by the company that hosts this website, and the transport metadata that comes attached to an email. That is the complete list, and it appears again as a table two sections further down. The rights described later in this document are not aspirational for that information. Access, correction, deletion and complaint all work today, on the timetables stated.

2What is actually happening, in short

Privacy policies are usually written to cover the largest thing an organisation might one day do. That makes them useless as a description of what is actually happening, so this section says what is actually happening, in short sentences, before the document becomes long.

  • There is no account system on this website and nothing to log in to.
  • There is no form on this website. Nothing you type into a page is transmitted anywhere, because there is nothing to type into.
  • There is no analytics product, no advertising, no tracking pixel and no session recording. This is verifiable from your own browser, and the cookie notice explains how to verify it.
  • No payment is taken here, so no payment details exist.
  • No product has shipped, so there is no product telemetry, no crash reporting and no usage data.
  • The company holds no marketing list and has never sent a marketing message.

What remains is an inbox, a server log and the ordinary metadata that carries an email from one place to another. Everything after this section is the careful version of that sentence.

3The law this policy answers to

The law that governs this policy is the Privacy Act 1988 (Cth) and, in particular, the thirteen Australian Privacy Principles set out in Schedule 1 to that Act. Throughout this document a reference to "APP 6" or similar means the corresponding Australian Privacy Principle.

Australian Privacy Principle 1, and why this document exists

APP 1 is the reason there is a privacy policy here at all. It requires an entity to manage personal information in an open and transparent way, to take reasonable steps to implement practices, procedures and systems that ensure compliance with the other principles and that allow it to deal with enquiries and complaints, and to keep a clearly expressed and up to date privacy policy. APP 1.4 then sets out what that policy has to cover: the kinds of personal information collected and held, how it is collected and held, the purposes of collection, use and disclosure, how an individual can seek access and correction, how an individual can complain and how the complaint will be handled, and whether the information is likely to be disclosed to overseas recipients and in which countries. Every one of those is answered in a numbered section below rather than left to inference.

The small business threshold, and why it does not get us out of this

Section 6D of the Privacy Act exempts most businesses with an annual turnover of $3 million or less from the Australian Privacy Principles. ARCUS AI PTY LTD was registered in 2026 and its turnover is presently below that threshold, so on a narrow reading the Act may not yet bind it.

We are not relying on that. Several of the exceptions in section 6D would in any event pull a business like ours back inside the Act as it grows, including a business that discloses personal information about another individual to anyone else for a benefit, service or advantage. More to the point, the exemption is an accident of turnover, not a statement that the information stops mattering. This policy is written as though the Australian Privacy Principles apply in full, and we will handle requests and complaints on that basis.

If we later become bound by the Act as a matter of law rather than choice, nothing in this policy changes. That is the point of writing it this way now.

Other Australian law that applies

  • Spam Act 2003 (Cth), which governs commercial electronic messages, requires consent, sender identification and a working unsubscribe facility.
  • Do Not Call Register Act 2006 (Cth), which governs unsolicited telemarketing. We do not telemarket.
  • Australian Consumer Law, Schedule 2 to the Competition and Consumer Act 2010 (Cth), which gives you consumer guarantees that cannot be excluded by anything we write.
  • Part IIIC of the Privacy Act, the Notifiable Data Breaches scheme, dealt with at its own section below.
  • Privacy and Other Legislation Amendment Act 2024 (Cth), which introduced a statutory tort for serious invasions of privacy, provided for a Children's Online Privacy Code, and added transparency obligations for certain automated decisions. Those last two are dealt with in their own sections.

4Who decides, and where a handling role would arise

Most privacy policies for a business divide into two roles. One where the organisation decides for itself what happens to personal information, and one where it merely acts on somebody else's instructions. Australian law does not use the controller and processor labels in the way European law does, but the underlying distinction is real and it is the clearest way to describe what this company does and does not do.

Where we decide, and are answerable

For correspondence, for the request logs this website generates, and for any future information about a person who uses tooling we publish, we decide what is collected and for what purpose. Every obligation in this policy is written for that position. Every right described later is exercisable against us directly, without going through anybody else.

Where a handling role would arise, and why it has not yet

We would be handling information on somebody else's instructions if we hosted a customer's corpus, stored their query sets on our infrastructure, or ran a service that their users' questions passed through. We do none of those things, and the design described on the front page of this site is deliberately arranged so that we would not have to.

The consequence is worth stating precisely, because it is stronger than a promise. A measurement that joins on identifiers does not need the text of a question or the text of a document. Information that is never sent cannot be accessed by us, disclosed by us, lost by us or compelled from us. That is a property of an architecture rather than a commitment in a document, and a property is much harder to abandon quietly than a commitment is.

If that ever changes, and a product is published that does receive customer data, this section is where the change will be described. It will be described in the same terms as everything else here: what is received, why, for how long, and what happens when somebody asks for it back.

5What we collect

Australian Privacy Principle 3 governs collection. An organisation may collect personal information that is reasonably necessary for one or more of its functions or activities, and it must collect it by lawful and fair means and, where reasonable and practicable, directly from the individual concerned. Sensitive information as defined in section 6(1) of the Privacy Act attracts a stricter rule under APP 3.3, and generally requires consent.

Everything held today

Three categories. There is no fourth, and if one appears this table is where it will be added.

Personal information this company holds today
CategoryFieldsSourceWhy we have itKept forIf you withhold it
CorrespondenceYour email address, your name where you sign a message, the content of the message, any attachment, and our replyYou, when you write to usTo answer you, and to keep a record of what was said in case the question comes back24 months from the last message in the thread, then deletedWe cannot reply. There is no other way to reach us and no other way for us to reach you
Web server request logsIP address, timestamp, requested path, user agent string, referring page, response code and bytes servedGenerated automatically by the company that hosts this website when your browser requests a pageServing the page you asked for, and defending the site against automated abuseThe hosting provider's own cycle, currently under 30 days. Not exported to us and not searchable by identityNot possible. A server cannot send you a page without knowing where to send it
Mail transport metadataSending and receiving server addresses, routing headers, delivery timestamps and spam filtering scoresAttached automatically to any email in transit, by the mail systems on both sidesDelivering the message and filtering unsolicited mailWith the message it belongs to, on the same 24 month cycleNot possible for anybody sending email to anybody

What is never collected

  • No sensitive information within the meaning of section 6(1) of the Privacy Act. No racial or ethnic origin, political opinion, religious belief, trade union membership, sexual orientation, criminal record, health information, genetic information or biometric information. Nothing on this site asks for any of it and no field exists to hold it.
  • No government related identifier. That has its own section further down, because APP 9 deals with it specifically.
  • No payment card details, bank details or financial information. No payment is accepted here.
  • No location data beyond whatever a bare IP address implies about the network a request came from.
  • No device fingerprint, no advertising identifier and no cross site identifier of any kind.
  • No information bought, rented, scraped or otherwise obtained from a third party source. Everything above arrives either because you sent it or because a web request has to contain it.

Collecting from you rather than about you

APP 3.6 requires that personal information be collected from the individual concerned where it is reasonable and practicable to do so. Every category in the table above is collected directly from you, in the sense that it arrives because you sent a message or requested a page. We run no enrichment, no lookup against a data broker, and no process that adds information about you from a source you did not use.

What a published product would collect

Nothing is published, so nothing in this subsection is currently in operation. It is set out now so that the description exists before the collection does.

Design intent for a future measurement tool, stated in advance
Would be collectedWould not be collectedReason the line sits there
Document identifiers, their ranks and the retrieval scores your own system producedDocument text, passage contents or file names that carry meaningEvery measure this company computes is arithmetic over identifiers and ranks. Text adds nothing to the arithmetic and a great deal to what a breach would cost
A stable identifier for each question in a query setThe text of the question, unless the operator deliberately chooses to include itQuestions asked of a real system are frequently personal information about the person who asked them. Joining on identifiers makes the text optional by construction rather than by policy
An operator email address, if an account ever existsAny information about the end users of the system being measuredThe people whose questions form a query set are your users, not ours. We have no relationship with them and should not acquire one
Configuration labels, run timestamps and the computed measuresCredentials, connection strings, API keys or endpoint secretsA harness runs where those credentials already are. It has no reason to carry them anywhere else and would be built not to accept them

6Telling you at the point of collection

Australian Privacy Principle 5 requires that we tell you certain things at or before the time we collect personal information about you, or as soon as practicable afterwards. What has to be told includes who we are, how to contact us, the fact and circumstances of collection, the purposes, the consequences of not providing the information, who the information is usually disclosed to, and whether it is likely to go overseas and where.

How that obligation is met here, and where

There is no app, no store listing and no permission dialog on this site, so the usual three places an APP 5 notice appears do not exist. The notice therefore has to be carried by the page itself, and it is carried in three ways.

  • In the collection table above. Each category names its fields, its source, its purpose, its retention period and the consequence of withholding it. That is APP 5 in tabular form rather than buried in a paragraph.
  • At the point of writing to us. The only deliberate act of collection on this site is you sending an email. The contact page states what happens to a message before you send one, and links here.
  • Here. This document is linked from the footer of every page on this website, including this one.

The consequences of not providing information

APP 5.2(e) specifically requires that we tell you what happens if you do not provide information. For correspondence the answer is simple and complete: we cannot reply to a message that has no reply address. Nothing else is withheld, degraded or restricted, because there is nothing else here to withhold.

You are not required to identify yourself to read this site. Nothing on it is gated, and no part of it behaves differently depending on who is reading.

7Dealing with us anonymously

Australian Privacy Principle 2 gives you the option of dealing with us anonymously or under a pseudonym, unless that is impracticable or we are required by law to deal with an identified individual.

Here that option is close to absolute. This website has no account system, no sign in, no gated content and no form. You can read every page of it, including this one, without giving us anything at all. We do not know who our readers are, we have no way of finding out, and we have not built anything that would tell us.

Where you write to us, a pseudonymous address is perfectly acceptable. We will answer a question from a made up name at a throwaway address exactly as we would answer one from a corporate address, and we will not ask who you are as a condition of replying.

The one place the option genuinely narrows is a request to access or correct personal information. To answer that we have to be satisfied that you are the person the information is about, since giving one person's correspondence to another would itself be a breach. What that means in practice is set out in the access and correction section, and it is a lower bar than most organisations set.

8Information we did not ask for

Australian Privacy Principle 4 deals with personal information we receive without having asked for it.

The realistic way it happens here is an email about retrieval quality with a real query log attached, or a spreadsheet of sample questions taken straight from a live system. Questions asked by real people are frequently personal information about those people, and an attachment of them is the single most likely piece of unsolicited personal information this company will ever receive. When we receive personal information we did not solicit, we decide within a reasonable period whether we could have collected it under APP 3. If we could not, and the information is not contained in a Commonwealth record, we destroy it or de-identify it as soon as practicable, provided it is lawful and reasonable to do so.

In practice an unsolicited attachment containing other people's information is deleted from the inbox, the deleted items folder empties it, provider backups age it out on their ordinary cycle, and we reply saying what we deleted and asking for a de-identified version if the conversation is worth continuing.

9Use and disclosure

Australian Privacy Principle 6 governs what may be done with personal information once it is held. The rule is that information collected for one purpose may be used or disclosed for that primary purpose, and for a secondary purpose only where you would reasonably expect it and the secondary purpose is related to the primary one, or where you have consented, or where a specific exception in the Act applies.

The complete list of what we use it for

  • Answering your message, and any follow up in the same thread.
  • Keeping a record of what was said, so that a question raised again in six months gets a consistent answer.
  • Delivering the pages of this website and keeping it available.
  • Investigating a suspected security incident affecting this site.
  • Complying with a legal obligation, or responding to a lawful request.

That list is exhaustive. If a use is not on it, it is not happening.

What we do not do

  • We do not sell personal information. Not to data brokers, not to advertisers, not as part of an audience product, and not as an asset in any transaction.
  • We do not build a profile of you, here or across anybody else's products.
  • We do not use correspondence to target advertising, because there is no advertising anywhere in this business.
  • We do not add correspondents to a mailing list. Writing to us subscribes you to nothing, which is dealt with again in the direct marketing section because it is the most common quiet breach of the Spam Act by small companies.
  • We do not train anything on your correspondence. No model is trained, fine tuned or evaluated on messages sent to this company, and no message is passed to a third party model provider.

The last bullet deserves emphasis given what this company does. Measuring retrieval systems does not require a corpus of email, and the correspondence in our inbox will not become one.

Disclosure to law enforcement, courts and regulators

We may disclose personal information where the Act permits it. That includes where the disclosure is required or authorised by or under an Australian law or a court or tribunal order, where a permitted general situation under section 16A exists (which covers a serious threat to life, health or safety, and suspected unlawful activity), and to an enforcement body where the disclosure is reasonably necessary for an enforcement related activity.

Where such a disclosure is made to an enforcement body we make a written note of it, as APP 6.5 requires. Where the law allows us to tell you that a request was made, we will tell you. Where it does not, we will not pretend that no request was ever received.

10Direct marketing and the Spam Act

Australian Privacy Principle 7 restricts the use of personal information for direct marketing. The Spam Act 2003 (Cth) sits on top of it for anything sent by email, SMS or instant message, and it is a strict regime. A commercial electronic message needs consent, whether express or reasonably inferred, accurate identification of the sender, and a functional unsubscribe facility that stays live for at least 30 days and is actioned within 5 working days.

Our position, which is easy to state

There is no marketing list. No commercial electronic message has ever been sent under this company name, and none is planned. There is no newsletter, no product announcement list, no launch notification and no waiting list, which means there is nothing here that could be sent to you.

Writing to our published address does not subscribe you to anything. That single sentence is the most commonly violated rule in this area, because adding a correspondent to a list feels harmless and is not lawful without a basis for inferring consent. We do not do it.

If that ever changes

  • It will be opt in. An empty box you have to tick, never a pre ticked one and never a consequence of doing something else.
  • The consent will be recorded with a timestamp and the exact wording you agreed to, because a consent that cannot be evidenced is not a consent.
  • The first message will say where the address came from and when it was given.
  • Every message will carry a working unsubscribe link, and unsubscribing will take effect immediately rather than within the five working days the Act allows.

There is no advertising anywhere in this business

No advertising is served on this website. No advertising network, exchange or measurement provider is present on any page. No product this company might publish would carry advertising, because measurement tooling with advertising in it would be an absurd object. This paragraph exists so that the absence is a stated fact rather than something a reader has to infer from silence.

11Who else could see it, and where they are

The shortest useful version of this section is that four suppliers exist, none of them receives anything we chose to send them, and every one of them touches personal information only as a by product of moving bytes from one place to another.

Every third party that could come into contact with personal information
WhoWhat forWhat they seeWhere
The hosting and content delivery provider for this websiteServing pages and absorbing automated abuseRequest logs, meaning IP address, path, user agent, referrer and response code. No content, because there is no content to sendA global edge network. Requests from Australia are normally served from within Australia, and the provider's own account and log infrastructure is in the United States
The email provider that carries our mailboxReceiving and sending mail at the published addressThe full content of any message you send us, as any mail provider necessarily does, plus the transport metadata attached to itUnited States, with regional processing
The domain registrar and DNS providerHolding the domain name registration and answering DNS queriesNothing about you. DNS queries reveal the domain being looked up, not who looked it upUnited States
Google FontsServing the two typefaces this site usesYour IP address, your user agent string and the referring page, at the moment a font file is requestedUnited States and a global edge network

No advertising network, analytics provider, tag manager, session recorder, chat widget, customer relationship system, marketing platform or data enrichment service appears anywhere in that table, because none is used. There is no fifth row waiting in a different document.

What we will not do with a supplier

  • We do not give a supplier permission to use personal information for its own purposes, and we do not accept a discount in exchange for allowing it.
  • We do not add a supplier that would appear in the table above without updating the table, and the update happens before the change goes live rather than afterwards.
  • We do not disclose correspondence to a supplier for any purpose other than carrying it. Nobody in that table is asked to read anything.

Business transfer

If this company were sold, wound up, or merged, personal information could pass to a successor. Where that happens we will publish a notice on this website before the transfer takes effect where we lawfully can, the successor will be bound by this policy until it publishes its own, and anybody who would prefer their correspondence deleted rather than transferred can say so and it will be deleted.

12Sending personal information overseas

Australian Privacy Principle 8 governs disclosure of personal information to a recipient outside Australia. Section 16C of the Act makes us accountable for an overseas recipient's act or practice: if an overseas recipient we disclosed information to does something that would have breached the Australian Privacy Principles, that act is taken to have been done by us, and we are liable for it.

We treat that as the operative rule rather than the exceptions, which is why the list of overseas recipients is short and named rather than described as "our trusted partners".

How we meet APP 8

Before disclosing personal information overseas we take reasonable steps to ensure the recipient does not breach the Australian Privacy Principles, principally by contract. The relevant contractual terms are the data processing terms published by each provider, which bind them to process the data only on our instructions, to keep it secure, to assist with individual rights requests, and to notify us of a breach.

We do not rely on the APP 8.2(a) exception for recipients in countries with substantially similar laws, because assessing that for each jurisdiction is a judgement we are not qualified to make and getting it wrong shifts the risk onto you.

Where the data actually goes

The countries in which personal information may be held or accessed are named in the recipients table in this policy. That table is the authoritative list. If a provider changes region we update the table.

13Government related identifiers

Australian Privacy Principle 9 restricts an organisation from adopting, using or disclosing a government related identifier, which includes a tax file number, Medicare number, driver licence number or passport number.

We do not collect any government related identifier. We have no reason to, our products have no age verification or identity verification step that would need one, and no field in any system we operate is intended to hold one.

If you send us one anyway, for instance by attaching a photograph of a licence to an email, it is treated as unsolicited personal information under the section above and destroyed.

14Keeping information accurate

Australian Privacy Principle 10 requires that personal information we collect is accurate, up to date and complete, and that information we use or disclose is also relevant.

Most of what we hold is machine generated and therefore accurate in the narrow sense that it faithfully records what a device reported. The category most likely to go stale is anything you told us yourself, such as an email address in a support thread. We do not periodically re-verify those, because doing so would mean contacting people who have finished dealing with us.

The practical remedy is the correction right under APP 13, described below, which you can use at any time and free of charge.

15Security, and what we do not hold

Australian Privacy Principle 11 requires us to take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure, and to destroy or de-identify it when it is no longer needed for any purpose for which it may be used or disclosed.

What "reasonable steps" means for a company this size

  • Transport encryption on every connection. This website is served over HTTPS only, and mail to the published address travels over TLS wherever the sending server offers it.
  • Encryption at rest for stored data, provided by the underlying platform.
  • Multi-factor authentication on every administrative account that exists, which means the mailbox, the domain registration, the hosting account and the code repositories. There is no fifth account.
  • Access on a need to know basis. The number of people who can open the mailbox is small, and the list is reviewed whenever anybody joins or leaves.
  • No live system to breach. There is no hosted service, no account system, no customer database and no administrative console behind this site, so what has to be defended is a set of static files, one mailbox and a code repository.
  • Collecting less. The most reliable security control available to a company of this size is not holding the data, which is why the table of what this company holds has three rows in it.

What we do not have, stated plainly

ARCUS AI PTY LTD does not hold ISO/IEC 27001 certification, a SOC 2 Type I or Type II report, an IRAP assessment, or any other independent security accreditation, and will not represent otherwise until one is genuinely held. We have not engaged a third party to conduct a penetration test. We do not employ a full time security engineer.

We say this because the alternative is a paragraph of confident language that means nothing. No system is perfectly secure, and a company that tells you otherwise is either mistaken or selling something.

16How long anything is kept

Australian Privacy Principle 11.2 requires that personal information be destroyed or de-identified once it is no longer needed for any purpose for which it may be used or disclosed, unless it is contained in a Commonwealth record or we are required by law to retain it. Retention is therefore not a matter of preference. Keeping something indefinitely because storage is cheap is a breach of the principle rather than a neutral choice.

How long each category is kept, and the reason for each period
CategoryPeriodReason for that periodWhat happens at the end
Correspondence and attachments24 months from the last message in the threadLong enough that a question raised again a year later gets a consistent answer, short enough that an inbox does not become an archive nobody has readDeleted from the mailbox and from the deleted items folder. Provider backups age out on the provider's own cycle
Correspondence forming part of a privacy request or complaint7 years from resolutionRecords of how a request under the Privacy Act was handled may be needed if the handling is later examined by the CommissionerDeleted
Web server request logsUnder 30 daysThe hosting provider's own retention cycle. Abuse investigation needs days, not monthsAged out by the provider. Not exported to us at any point
Anything relating to a notifiable data breach assessment7 years from the assessmentPart IIIC assessments and the reasons for a decision not to notify must be capable of being explained afterwardsDeleted
Accounting records that happen to contain a name5 years from the end of the transaction, as section 286 of the Corporations Act 2001 requiresA statutory obligation, not a preference. It overrides a deletion request for those specific recordsDeleted at the end of the statutory period

A deletion request under the section below is honoured against everything except the last two rows, and where a statutory period blocks deletion we will say which one and when it expires rather than refusing without a reason.

17Access and correction

Australian Privacy Principle 12 gives you the right to ask for access to the personal information we hold about you. Australian Privacy Principle 13 gives you the right to ask us to correct it. Both are exercised the same way.

How to ask

Email contact@arcusai.fyi with "Privacy request" in the subject line, and tell us what you want. Because the only substantial thing we hold is correspondence, a request is usually satisfied by us exporting the threads associated with your email address and sending them to that address.

Verifying who you are

We have to be satisfied that you are the person the information is about, or an authorised representative, because handing one person's correspondence to another is itself a breach. For correspondence, sending the request from the address the correspondence is associated with is normally sufficient and no further proof is asked for.

We will not ask you to send a copy of a driver licence, a passport or any other identity document. Collecting an identity document to verify a privacy request creates a far more sensitive record than the one being requested, which is the wrong trade. If we cannot verify a request without doing that, we will say so and explain what we can offer instead.

Request logs are a special case worth stating honestly. They are keyed to an IP address rather than to a person, we have no way to connect an IP address to you, and they are not exported to us in the first place. A request for them will get that explanation rather than a search we cannot perform.

Timing and cost

We respond within 30 days. Access is free. There is no charge for making a request, no charge for a correction, and no charge for an export in an ordinary format. If a request ever imposed a genuine cost, for example producing something in an unusual format, we would tell you the charge before doing any work and it would not be excessive. Charging for a correction is prohibited outright by APP 13.5 and we would not do it.

When access can be refused

The grounds in the Act are narrower than people expect. They include where giving access would have an unreasonable impact on the privacy of other individuals, where the request is frivolous or vexatious, where the information relates to existing or anticipated legal proceedings and would not be discoverable, where giving access would reveal our commercially sensitive decision making process, and where access would be unlawful.

The realistic one here is the first. A thread involving three people cannot be handed to one of them in full. In that case we give you the parts that are about you and redact the rest, rather than refusing outright.

If we refuse in whole or in part, we will give you written reasons, name the ground we rely on, and tell you how to complain. Where part of the information can be given, or given in another way that meets your need, we will offer that instead of a flat refusal.

Correction

If information we hold is inaccurate, out of date, incomplete, irrelevant or misleading, we will correct it. Where we have disclosed it to somebody else and you ask us to tell them about the correction, we will take reasonable steps to do so unless that is impracticable or unlawful.

If we refuse to correct something, APP 13.4 gives you a right that is frequently overlooked. You may ask us to attach a statement to the record saying that you consider the information inaccurate, incomplete, out of date, irrelevant or misleading, and we must take reasonable steps to make that statement apparent to anyone who later looks at the record. We will do that on request, and we will not argue about the wording of your statement.

18Deleting what we hold

The Privacy Act contains no general right to erasure of the kind the European regulation created. What it contains instead is APP 11.2, which obliges us to destroy or de-identify personal information once it is no longer needed. In practice that produces a similar outcome and this company treats a deletion request as a request it will honour rather than one it will assess.

How to ask, and what happens

  1. Email contact@arcusai.fyi with "Delete my data" in the subject line, from the address the correspondence relates to.
  2. We locate every thread associated with that address.
  3. We delete them from the mailbox and from the deleted items folder, and we confirm to you in writing that it is done.
  4. Backups held by the mail provider age out on the provider's own cycle. We cannot reach inside a provider backup to remove a single message, and we will not claim otherwise. Nothing is restored from a backup for any ordinary purpose.

The whole process completes within 30 days and normally within a few business days, since the volume involved is small.

What survives a deletion request, and why

  • A record that a deletion request was made and actioned, consisting of the date and the fact of it. Deleting the evidence that we complied would leave us unable to demonstrate compliance.
  • Anything a statute requires us to keep, currently only accounting records under section 286 of the Corporations Act 2001. We will name the provision and the expiry date rather than refusing vaguely.
  • Web server request logs, which are keyed to an IP address rather than to you, are not searchable by identity and age out inside 30 days anyway.

There is no account to delete because there are no accounts, and there is no product data to delete because no product has shipped.

19Personal information inside a query set

This section exists because of what the company does rather than because of what it currently holds, and because the risk it describes is the most significant privacy question in this business.

The problem

A query set is a collection of real questions asked of a real system. Real questions are frequently personal information. Somebody asking an internal knowledge base about their own leave entitlement, a support system about a fault at their address, or a medical information system about a symptom has put personal information, and sometimes sensitive information within the meaning of section 6(1) of the Privacy Act, into the text of a question. An evaluation tool that hoovers up query text hoovers up all of it.

How the design answers it

  • The join is on identifiers. Every measure this company computes is arithmetic over ranks and identifiers. Question text is not an input to any of them. A tool built this way does not need the text and so does not ask for it.
  • Question text is optional and off. Where an operator wants the text alongside the numbers for their own reading, that is their decision about their own data, taken deliberately, in their environment.
  • De-identification is the operator's step, and it happens first. A query set assembled from live traffic should be de-identified before it becomes a query set. That is the operator's obligation to their own users and we will say so rather than implying that using our tool discharges it.
  • Document text is never an input. Relevance judgements are made by a person reading documents where those documents already are. The judgement that comes back is a grade against an identifier.

Where responsibility would sit

If a customer ever sent us query text containing personal information, we would be handling it on their instructions. They would remain the organisation with the relationship to the individual and the obligation to them. We would be obliged to handle it only for the agreed purpose, to secure it under APP 11, to assist with access and correction requests directed at them, and to tell them without delay about any breach affecting it. Where any of it moved outside Australia, section 16C would make us accountable for what the overseas recipient did with it, which is the strongest reason of all for not receiving it in the first place.

None of this is live. No customer data of any kind has been received by this company, because there is no product to receive it. The paragraphs above describe a boundary drawn before the code exists, which is the only time a boundary is cheap to draw.

20Children and young people

This website is a technical description of measurement tooling for engineering teams. It is not directed at children, it is not designed to appeal to children, and it contains nothing a child would have a reason to use. There is no game, no social feature, no chat, no user generated content and no messaging of any kind anywhere on it.

The Australian position on capacity

The Privacy Act does not fix an age at which a person can consent for themselves. The guidance published by the Office of the Australian Information Commissioner is that an organisation should assess capacity individually where practicable, and that as a general rule an individual aged 15 or over is presumed to have capacity unless there is something specific to suggest otherwise. We apply that presumption.

The Privacy and Other Legislation Amendment Act 2024 (Cth) provides for a Children's Online Privacy Code, to be developed by the Information Commissioner and to apply to services likely to be accessed by children. We will comply with that Code to the extent it applies to us once it is registered and in force. We will update this section at that point rather than guessing at its terms in advance.

What that means in practice here

  • We do not knowingly collect personal information from a child under 15 without the consent of a parent or guardian.
  • There is no age gate, because there is nothing here to gate and an age gate that collects a birth date collects more information than it protects.
  • No advertising is served here, so the question of advertising to a child does not arise.

If you believe a child's personal information has reached us, write to contact@arcusai.fyi. We will delete it without requiring proof of a legal relationship beyond what is needed to be satisfied the request is genuine, and we will confirm when it is done.

21Automated decisions

The Privacy and Other Legislation Amendment Act 2024 (Cth) inserts a requirement that a privacy policy disclose the kinds of personal information used in substantially automated decisions that significantly affect an individual's rights or interests, together with the kinds of decisions being made that way. That requirement commences on 10 December 2026. This section is written in advance of that date rather than on it.

Our position

No automated decision made by this company significantly affects anybody's rights or interests. Nothing we run decides whether a person gets credit, a job, a service, a benefit, a place, a price or a legal entitlement. There is no scoring of individuals, no ranking of individuals and no automated assessment of an individual at any point.

Two pieces of automated processing do exist, and neither comes close to the threshold.

  • Spam filtering on the mailbox. The mail provider scores incoming messages and may route one to a junk folder. If you write and get no reply within the stated period, that is the most likely explanation, and sending a plain text message without attachments usually resolves it.
  • Automated abuse mitigation on the website. The hosting provider may challenge or block a request that looks automated. The consequence is that a page fails to load, which is an inconvenience rather than an effect on your rights, and it is reversible by writing to us.

A distinction worth drawing, given what this company builds

Measuring how well a retrieval system ranks documents is not an automated decision about a person. The subject of every measure this company computes is a document and a question, not an individual. Should a product ever make an automated decision that affects a person, this section will describe it before the processing begins rather than after.

22Data breaches and the notification scheme

Part IIIC of the Privacy Act establishes the Notifiable Data Breaches scheme. It applies to an eligible data breach, meaning unauthorised access to, unauthorised disclosure of, or loss of personal information where a reasonable person would conclude the access or disclosure would be likely to result in serious harm to any of the individuals to whom the information relates, and the risk has not been prevented by remedial action.

The process we follow

  1. Contain. Stop the access, revoke the credential, take the affected component offline if that is what it takes.
  2. Assess. Where we suspect an eligible data breach may have occurred, we carry out a reasonable and expeditious assessment and complete it within 30 days of becoming aware of the grounds for suspicion, which is the period section 26WH allows.
  3. Remediate. If remedial action means serious harm is no longer likely, the breach is not notifiable and we record why.
  4. Notify. If it is an eligible data breach, we prepare a statement for the Commissioner and notify the Office of the Australian Information Commissioner (OAIC), GPO Box 5218, Sydney NSW 2001, telephone 1300 363 992, oaic.gov.au as soon as practicable. We then notify affected individuals, or if that is not practicable, publish the statement on this website and take reasonable steps to publicise it.

What a notification will contain

Our identity and contact details, a description of the breach, the kinds of information concerned, and the steps we recommend you take. We will not pad it with reassurance that has not been earned, and we will say what we do not yet know.

If you think a breach has happened

Write to contact@arcusai.fyi with "Security" in the subject line. We would rather chase a false alarm than miss a real one, and we will not treat a good faith report as hostile.

23The statutory tort of serious invasion of privacy

A statutory tort of serious invasion of privacy commenced on 10 June 2025 under Schedule 2 to the Privacy and Other Legislation Amendment Act 2024. It allows an individual to sue for intrusion upon seclusion or misuse of information, where the invasion was intentional or reckless, where a person in the plaintiff's position would have had a reasonable expectation of privacy, and where the invasion is serious.

This is a right you have against anyone, including us, and it exists independently of the complaints process described below. We mention it because most privacy policies do not, and a right you do not know about is not much of a right.

24Cookies on this website

This website sets no cookies of its own. There is no analytics, no advertising, no tracking pixel, no session recording and no attempt to recognise a returning reader. There is no consent banner either, because there would be nothing for consent to attach to.

Two things nonetheless reach beyond the page. A strictly necessary security cookie may be set by the company that hosts this site in order to tell automated traffic from human traffic, and two typefaces are requested from Google's font servers. Both are described in full, with names, lifetimes and what each discloses, in the cookie notice.

Australia has no separate cookie consent regime and no local equivalent of the European ePrivacy Directive. What applies instead is the Privacy Act itself. Where a cookie collects information about an individual who is reasonably identifiable, that information is personal information and the Australian Privacy Principles apply to it in the ordinary way, which means APP 3 for whether it may be collected, APP 5 for telling you, APP 6 for what may then be done with it and APP 11 for keeping it safe.

25Complaints

Step one: tell us

Email contact@arcusai.fyi with "Privacy complaint" in the subject line. Set out what happened and what you want done. We acknowledge within 5 business days and respond substantively within 30 days. If it will take longer, we will tell you why and give you a date.

Step two: the Commissioner

If you are not satisfied with our response, or we do not respond within 30 days, you can complain to the Office of the Australian Information Commissioner (OAIC), GPO Box 5218, Sydney NSW 2001, telephone 1300 363 992, oaic.gov.au.

The OAIC will normally expect you to have complained to us first and given us 30 days, but it can accept a complaint without that in appropriate cases. There is no fee. You do not need a lawyer and you do not need our agreement.

What we will not do

We will not require you to sign a non-disclosure agreement as a condition of us dealing with a privacy complaint, and we will not treat making a complaint as a breach of our terms of use.

26If you are outside Australia

This policy is written to Australian law because that is the law that binds us. If you are outside Australia, some additional rights may apply to you, and we do not want the absence of a mention to be read as a refusal.

European Economic Area and United Kingdom

Where the General Data Protection Regulation or the UK GDPR applies to our processing, you have rights of access, rectification, erasure, restriction, portability and objection, and a right to complain to your national supervisory authority. Where we rely on legitimate interests, you may object and we will stop unless we can demonstrate compelling legitimate grounds that override your interests. Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.

Send any such request to contact@arcusai.fyi and say which law you are relying on, so we apply the right timetable. We answer GDPR requests within one month.

California

Under the California Consumer Privacy Act as amended, you have rights to know, delete, correct and opt out of the sale or sharing of personal information. We do not sell personal information and we do not share it for cross context behavioural advertising as those terms are defined in that Act. There is no advertising anywhere on this website and none in anything this company intends to build, so there is no sharing to opt out of in the first place. Global Privacy Control signals sent by your browser to this website are honoured.

Everywhere else

If a right exists where you live and you tell us about it, we will deal with the request on its merits rather than on whether we are technically obliged to.

27Changes to this policy

This policy will change, because a company that is building something eventually builds it. When it changes, the effective date and the version number in the header of this page change with it.

How a change is announced

  • A change that materially reduces your rights, or materially expands what is collected, gets a notice at the top of this page for at least 30 days before it takes effect, and it takes effect only after that period.
  • A correction of a typographical error, a broken link or a clarification that does not alter meaning is made without notice, and the version number moves to a minor increment.
  • No change is applied retrospectively. Information collected under one version continues to be handled under the version in force when it was collected, where the two differ.

Previous versions are not published as separate pages, but they are kept. If you want to know what this document said on a particular date, ask and we will send you that version rather than paraphrasing it.

This policy is a professionally structured document written to Australian law. It is not legal advice, and it is not a substitute for advice from an Australian legal practitioner about your own circumstances.

28How to contact us

All privacy matters reach one address.

Contact points for privacy matters
MatterSubject lineResponse
Access to your personal information (APP 12)Privacy request30 days
Correction of your personal information (APP 13)Privacy request30 days
Deletion of the information we hold about youDelete my data30 days
Complaint about our handling of personal informationPrivacy complaintAcknowledged in 5 business days, answered in 30 days
Suspected security incident or data breachSecuritySame or next business day
Anything elseAnything sensible5 business days

Email: contact@arcusai.fyi

Entity: ARCUS AI PTY LTD, ACN 697 547 505, ABN 82 697 547 505, an Australian proprietary company, New South Wales.

We do not publish a postal address on this website. If you need to serve a document, the company's registered office is recorded against ACN 697 547 505 on the register maintained by the Australian Securities and Investments Commission, which is the address that has legal effect for service.

If you would rather not deal with us at all, you can go straight to the Office of the Australian Information Commissioner (OAIC), GPO Box 5218, Sydney NSW 2001, telephone 1300 363 992, oaic.gov.au.