Australia Privacy Addendum (Privacy Act 1988)
Effective Date: April 26, 2026 Last Updated: July 21, 2026
This Addendum supplements the ConKarma Privacy Policy for individuals in Australia, in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles ("APPs"). Capitalised terms not defined here have the meaning given in the main Policy.
1. Open and Transparent Management (APP 1)
Our open and transparent management of personal information is documented in the main Privacy Policy and in this Addendum. Privacy enquiries may be directed to legal@conkarma.app with the subject "Australia privacy request".
2. Anonymity and Pseudonymity (APP 2)
You may use a pseudonym in your display name; an account email address is required for authentication and recovery, but you may use an alias email under your control.
3. Collection of Solicited Personal Information (APP 3)
We collect the categories described in the main Privacy Policy §2, by lawful and fair means and only when reasonably necessary for the Service's functions. We do not collect sensitive information (as defined in the Privacy Act) without consent and a connection to a function or activity. Adult-feature content is processed only with your explicit opt-in.
Children's data. Child-specific data is purpose-bound and minimised to what is reasonably necessary for the child's use of the Service, per the canonical COPPA Data Retention Policy. ConKarma applies parental-consent gating for children consistent with the Privacy Act and the (forthcoming) Children's Online Privacy Code.
4. Unsolicited Personal Information (APP 4)
If we receive unsolicited personal information that we could not have collected under APP 3, we will destroy or de-identify it as soon as practicable, unless it is contained in a Commonwealth record or law requires us to keep it.
5. Notification of Collection (APP 5)
Where we collect personal information directly from you, we provide notice through this Policy, in-app prompts at the point of collection (for example, when you opt into adult features), and at signup.
6. Use and Disclosure (APP 6)
We use personal information only for the primary purpose for which it was collected, or for a related secondary purpose you would reasonably expect, or where you have consented or where required or authorised by law.
7. Direct Marketing (APP 7)
We do not currently send direct-marketing communications. Should that change, you will be given a clear opt-out and a "do not contact" preference.
8. Cross-Border Disclosure (APP 8)
We disclose personal information to recipients in the United States (and, for coarse GeoIP resolution, Germany), primarily our infrastructure providers:
| Recipient | Country | Function |
|---|---|---|
| Google LLC / Google Ireland Ltd. | United States / Ireland | Firebase suite (Auth, Cloud Messaging, Crashlytics, App Check, Analytics), AdMob (adult-account-only) |
| Supabase, Inc. (with AWS as its downstream sub-processor) | United States | Managed PostgreSQL database + object storage |
| A standard SMTP relay service | United States | Transactional email |
| freeipapi.com | Germany | Coarse GeoIP resolution — receives only your IP address to return an approximate country / region / city for security and legal-compliance gating |
| Apple Inc. / Google LLC (independent controllers) | United States | App Store and Google Play billing |
Before disclosing personal information overseas we take reasonable steps to ensure the recipient does not breach the APPs in relation to that information; this includes contractual commitments to comparable safeguards. We do not rely on the consent exception (s. 16C(b)) as a substitute for those safeguards.
9. Adoption, Use, or Disclosure of Government Related Identifiers (APP 9)
We do not adopt government-related identifiers (such as TFNs) as our own identifier of an individual.
10. Quality (APP 10)
We take reasonable steps to ensure the personal information we collect is accurate, up-to-date, and complete. You can correct your information in-app or by contacting us.
11. Security (APP 11)
We protect personal information from misuse, interference, loss, unauthorised access, modification, and disclosure with administrative, technical, and physical safeguards appropriate to the risk. When personal information is no longer needed for any purpose for which it may be used or disclosed and we are not legally required to retain it, we destroy or de-identify it.
12. Access and Correction (APP 12 / APP 13)
You may access and correct your personal information through:
- Access — Settings → Export my data (machine-readable archive).
- Correction — edit fields in-app, or email legal@conkarma.app for fields not user-editable.
We respond to access and correction requests within 30 days. We will not charge for access; reasonable processing fees may apply only for non-trivial corrections (rare).
12a. Emergency Check-In Geolocation (Opt-In)
When you (or a verified parent on a child's behalf) turn on Emergency location sharing in Settings AND toggle "Share my location with this alert" on a specific emergency check-in, the app may include your latitude and longitude with that check-in. This is opt-in per check-in — no background tracking. We collect this only with your explicit consent and connection to the safety function (APP 3); we take reasonable steps to protect it (APP 11). Retention horizon for Australian users: 30 days (rest-of-world default), after which the coordinates are deleted while the "safe" / "need help" record itself remains without location. Revocation in Settings → Emergency location sharing deletes any retained coordinates within minutes.
13. Notifiable Data Breach Scheme (Part IIIC of the Privacy Act)
If we suffer an eligible data breach likely to result in serious harm to an Australian individual, we will notify the Office of the Australian Information Commissioner (OAIC) and the affected individuals as soon as practicable, in line with Part IIIC of the Privacy Act.
14. Complaints
If you believe we have breached the APPs, please contact us first at legal@conkarma.app with the subject "APP complaint" so we can investigate. If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC) at https://www.oaic.gov.au.
15. Adult-zone (Ember) — APP 3 consent + APP 11 retention
For Australian users on the Ember zone, adult-zone content is "sensitive information" under the Privacy Act 1988 (s. 6) (information about an individual's sexual orientation or practices) and is therefore collected only with your consent and a connection to a function of the Service (APP 3). It is secured and retained under APP 11 (security of personal information, and destruction or de-identification once it is no longer needed):
- Default 3-year retention. Adult-zone rows default to a 3-year retention window from creation, hard-deleted on window close (no soft-delete tombstone). You may set the window to anything from 90 days to 10 years in Settings → Ember privacy; you control the duration.
- Adult-zone usage analytics (separate opt-in, default OFF). Only if you give the separate adult-analytics consent do we send anonymised, surface-level Ember usage metadata to Google Analytics 4 — which feature was used and a coarse action verb, under a pseudonymous GA4 client identifier only, with no personal information and no content-level detail (we log that a feature was used, never which specific act, scene, or content). Because it concerns sexual practices it is sensitive information, collected only with your consent and a connection to a function of the Service (APP 3); it is the consent-gated adult stream carried by the Google "Analytics" sub-processor row in §8. Google Signals, ads-personalisation, and Google data-sharing are OFF for this stream and it is never used for advertising (APP 6); it is de-identified or destroyed once no longer needed (APP 11). You may withdraw this consent at any time in Settings → Ember privacy, independently of your adult-zone access.
- APP 11 destruction. When the window closes or you revoke adult-zone consent, the rows are irreversibly destroyed within 30 days, including any attendant cached bitmaps and search-index entries — consistent with APP 11.2 (destruction / de-identification once no longer needed).
- Per-device enable. Adult-zone access is OFF by default on every non-primary device; you opt in per device. The audit log of changes is retained alongside the user record for the same period as the account.
- Backup-exclusion toggle (Settings → Ember privacy) lets you opt the Ember subset out of iCloud / Drive backups.
- Export-inclusion toggle lets you opt adult-zone rows into your data export (default OFF — exports stay sharing-safe).
- APP 6 use & disclosure. Adult-zone data is never used outside the consented adult-zone purpose; cross-zone use is blocked by the boot-time validator and zone-tagged schema constraints (zone-isolation guarantees #1, #2, #4).
- Withdrawing consent. If you withdraw your adult-zone consent (off-toggle in Settings → Ember privacy), we hard-delete every adult-zone row attributable to you within 30 days; the relevant rows are also excluded from any pending data export.
- ADR-120 — no automated processing without consent. No automated content model processes Ember content without your explicit consent.
16. Governing Law and Consumer Liability Fallback
Nothing in the Terms of Service or this Addendum limits, excludes, or modifies the consumer guarantees or other rights and remedies that you have under the Australian Consumer Law (the ACL, Schedule 2 to the Competition and Consumer Act 2010 (Cth)) and that cannot lawfully be excluded.
- Arbitration / class-action waiver. The arbitration and class-action waiver in Terms of Service §17 does not apply to the extent that the ACL's mandatory protections would render it unenforceable; in those circumstances those protections prevail.
- Limitation of liability. The Limitation of Liability in Terms of Service §15 is subject to its statutory carve-outs, including the non-excludable consumer guarantees under the ACL. Where a failure to comply with a consumer guarantee can be remedied and is not a major failure, our liability is limited (at our election) to re-supplying the relevant services or paying the cost of re-supply, to the extent permitted by the ACL.
17. Changes
Material changes to this Addendum are communicated via in-app notice and updated Last Updated date.