zorentia.
  • Office Hours
  • Customers
  • Pricing
  • Contact
LoginSign Up

Privacy Policy

How Zorentia collects, uses, protects and handles personal information.

On this page

  1. 011. Who this policy covers
  2. 022. Our privacy approach
  3. 033. Information we collect
  4. 044. How we collect information
  5. 055. Why we use information
  6. 066. AI and automated processing
  7. 077. Service providers and disclosures
  8. 088. Overseas processing
  9. 099. Cookies, browser storage and similar technology
  10. 1010. Children and young people
  11. 1111. Data retention
  12. 1212. Account deletion
  13. 1313. Security
  14. 1414. Access, correction and privacy requests
  15. 1515. Privacy complaints
  16. 1616. Data breaches
  17. 1717. Changes to this policy
  18. 1818. Contact

Related documents

Young Person Privacy NoticeGuardian Paid Account TermsInstitutional Data & Privacy ScheduleSubprocessor List

Zorentia Product Studio Pty Ltd
ABN 86 688 343 482
Version: 2026-09-05-v1
Last updated: 5 September 2026
Effective: when this version is first published in Zorentia

This Privacy Policy explains how Zorentia Product Studio Pty Ltd (Zorentia, we, us, our) handles personal information when people use Zorentia Product Studio and related services.

Zorentia handles personal information in accordance with applicable Australian privacy law. We also use the Australian Privacy Principles (APPs) as a privacy-by-design standard across the Service, whether or not every APP applies to every Zorentia activity at a particular time.

1. Who this policy covers

This policy applies to:

  • individual users;
  • students and other users provisioned by a school, university or other institution;
  • parents or legal guardians who purchase an individual paid account for a user aged 13-17;
  • institution representatives and administrators;
  • people who receive research invitations;
  • visitors to public-by-link project pages and public-feedback forms; and
  • people who contact Zorentia for support, privacy, safety or other enquiries.

2. Our privacy approach

Zorentia is designed to collect less personal information rather than more. In particular:

  • ordinary student accounts are email-based and do not require a student name, date of birth, postal address or phone number;
  • Zorentia does not use third-party advertising analytics;
  • Zorentia does not sell personal information;
  • public landing-page feedback is designed not to collect respondent names, emails or phone numbers;
  • projects are private by default;
  • there is no public Explore feed or public directory of student projects; and
  • generative AI is routed through Amazon Bedrock rather than direct generative model-provider APIs.

3. Information we collect

3.1 Individual accounts

For an ordinary individual account, we may collect:

  • email address;
  • internal user and account identifiers;
  • whether you self-identify as aged 13-17 or 18 or older;
  • legal-document versions and acceptance timestamps;
  • account, session, login and recovery information;
  • plan, credit and usage information; and
  • support or product-feedback messages you choose to send us.

We do not require your exact age or date of birth.

3.2 Guardian purchases

Where a user aged 13-17 purchases an individual paid account, we collect limited information about the adult parent or legal guardian completing the purchase, including:

  • guardian email address;
  • confirmation that the guardian is 18 or older;
  • confirmation of parental or legal authority;
  • the version of the Guardian Paid Account Terms accepted;
  • acceptance time; and
  • associated purchase or payment references.

We do not require a guardian's date of birth, postal address or phone number for this flow.

3.3 Institution customers

For institution representatives and administrators, we may collect:

  • organisation name;
  • representative or administrator name;
  • work email;
  • role or title;
  • authority confirmation;
  • billing email where used;
  • order, seat, subscription and payment references; and
  • Institutional Agreement and Data & Privacy Schedule acceptance records.

3.4 Institution-provisioned students

Institutions provision students using email, role and, where used, cohort information. Zorentia does not require the institution to provide a student's name, date of birth, postal address or phone number.

An institution administrator may see limited administrative information about users associated with that institution, such as:

  • student email;
  • cohort;
  • access status;
  • recent login or activity;
  • current milestone or stage;
  • administrative engagement status; and
  • credit usage or allowance.

Institution administrators do not receive access through the organisation dashboard to a student's raw prompts, private project ideas, generated code, private project content, research observations or private feedback content merely because they are an administrator.

3.5 Project and AI content

When you use project tools, we may collect and store information needed to provide the feature, including:

  • idea descriptions and project briefs;
  • answers to planning questions;
  • prompts and assistant messages;
  • technical plans, architecture and database designs;
  • generated SQL;
  • generated backend and frontend code;
  • generated files and package metadata;
  • research observations and testing notes;
  • deployment choices or related tool state; and
  • generation, usage, error and credit metadata.

This information may be linked to your account and project so that the Service can preserve your work between sessions.

3.6 Public project pages

Projects are private by default. If you deliberately publish a project page, Zorentia stores and displays the content selected for the public page.

Zorentia removes known structured account identifiers from the public payload, but you remain responsible for not putting personal, confidential or private information into public-facing text.

Published pages are public by direct link. Zorentia uses technical controls intended to discourage search-engine indexing, but third parties may still copy, cache, screenshot or share material that you make public.

3.7 Public feedback

Public landing-page feedback is designed to be anonymous. New public-feedback forms do not request or store respondent name, email or phone number.

Zorentia may store technical information necessary to prevent duplicate submissions, spam and abuse, including a pseudonymous visitor identifier, text hashes, moderation status and security metadata. These technical identifiers are not shown to student project owners.

3.8 Research invitations

A user may provide recipient email addresses to send direct research or feedback invitations to people they already intend to contact.

For this feature we may process:

  • recipient email;
  • a sender display name chosen by the user;
  • project or session reference;
  • invitation status and delivery metadata;
  • a one-time feedback code stored in hashed form;
  • research-contact permission attestation evidence;
  • feedback submitted through the invitation; and
  • a temporary project one-pager PDF used for delivery where the feature requires it.

The user sending invitations must confirm that recipients have agreed to be contacted for that research and must not use the feature for unsolicited marketing.

A recipient can opt out of further research invitations. Zorentia may retain a keyed, non-plaintext suppression value so that the opt-out continues to be honoured.

3.9 Payments

Payments are processed using Square. Zorentia may store payment and subscription metadata such as:

  • amount;
  • purchase type;
  • credit or seat quantity;
  • payment status; and
  • Square order, payment, customer, subscription or invoice identifiers.

Zorentia's hosted payment flow does not require card number or CVV to be entered into the Zorentia application itself.

3.10 Security scans and IDE features

If you choose to run a Zorentia IDE or security-analysis feature, the scan may transmit selected or bundled source-code files to Zorentia for analysis.

The current scan architecture processes the raw bundle temporarily rather than storing the complete raw bundle as a long-term project file. Derived security findings, redacted source context, reports and scan metadata may be retained for the periods described below.

Do not intentionally place secrets or personal information into code or scan inputs unless necessary. Zorentia uses controls intended to redact secret values before persistent findings are stored, but no automated redaction system is perfect.

3.11 Support, privacy and safety contacts

If you contact Zorentia, we collect the information you provide in the message and technical or account information reasonably necessary to investigate and respond.

Reports about a public page can be submitted without creating an account. A report generally contains the report category, optional details, publication reference and status. Zorentia does not intentionally store reporter identity or IP in the public-page report record.

4. How we collect information

We collect information:

  • directly from you when you sign up, use the Service, submit content, purchase a plan, publish a page or contact us;
  • from an institution when it provisions or administers your institutional access;
  • from a guardian who completes a paid purchase for a 13-17-year-old;
  • from your browser or device where necessary for sessions, security and abuse prevention;
  • from payment, email-delivery and security service providers in connection with the services they provide; and
  • from users who provide recipient email addresses for direct research invitations.

5. Why we use information

We use personal information where reasonably necessary to:

  • create, authenticate, recover and secure accounts;
  • provide project, generation, download, feedback, publishing and security features;
  • maintain project continuity between sessions;
  • administer institution memberships, cohorts, activity and credit allowances;
  • process subscriptions, purchases and billing;
  • send service, verification, recovery and authorised research messages;
  • enforce recipient opt-outs and prevent repeated unwanted contact;
  • detect abuse, spam, fraud, security issues and misuse;
  • provide support and handle privacy or safety enquiries;
  • maintain legal, contractual, tax and accounting evidence;
  • comply with applicable law and lawful requests; and
  • maintain, troubleshoot and improve the reliability and security of the Service using operational information.

We do not use student project content for third-party advertising.

6. AI and automated processing

6.1 Generative AI through Amazon Bedrock

Zorentia uses Amazon Bedrock as the production gateway for generative AI.

At the date of this policy:

  • Zorentia invokes Bedrock from the AWS Sydney region (ap-southeast-2);
  • Zorentia's Bedrock account data-retention mode is configured to none;
  • Bedrock model invocation logging is disabled; and
  • where the Bedrock Responses-compatible path exposes a storage option, Zorentia sends requests with storage disabled.

This means Bedrock service-side request/response retention is disabled under Zorentia's current production configuration. This does not mean Zorentia itself stores nothing: project inputs, project state and generated outputs may separately be stored in Zorentia's own systems so that the Service can work as described in this policy.

Current generative model families are accessed through Bedrock. Zorentia does not separately send generative project prompts to direct Anthropic, OpenAI or DeepSeek generative APIs.

6.2 OpenAI moderation

A limited text-moderation function uses OpenAI's Moderation API directly. Zorentia limits this request to the text requiring moderation and does not deliberately attach student email, user UUID, institution details, project bundles or code.

According to OpenAI's published API data controls at the date of this policy, the /v1/moderations endpoint is not used to train OpenAI models and has no abuse-monitoring or application-state retention. The moderation request may be processed outside Australia.

6.3 Automated product indicators

Zorentia uses automated logic for functions such as:

  • milestone or current-stage indicators;
  • engagement status;
  • pitch clarity or similar project-quality indicators;
  • spam classification;
  • security findings; and
  • credit reservation, charging and restoration.

These functions help operate or explain the Service. Zorentia does not use them to automatically determine a student's academic grade or competency, or to automatically terminate a student's account because of an engagement or project score.

7. Service providers and disclosures

Zorentia may disclose or make information available to service providers where reasonably necessary to provide the Service. Current key providers are listed in the Subprocessor List and include:

  • Amazon Web Services (hosting, database, storage, email delivery, Redis infrastructure and Bedrock AI);
  • OpenAI (limited text moderation only);
  • Square (payment processing); and
  • Cloudflare Turnstile (bot and abuse prevention).

We may also disclose information where reasonably necessary to comply with law, respond to a lawful request, protect rights or safety, investigate fraud or security incidents, or complete a genuine corporate transaction subject to appropriate safeguards.

We do not sell personal information.

8. Overseas processing

Zorentia's primary application and database infrastructure is hosted in Australia, principally in AWS Sydney. The current Claude geographic inference profile used from Sydney may route within AWS Sydney and Melbourne.

Some service providers may process information outside Australia. Depending on the service and provider configuration, relevant countries may include the United States, Canada, Japan, Ireland, France, Spain, the United Kingdom and other locations in which those providers or their service providers operate.

In particular:

  • limited OpenAI moderation text may be processed outside Australia, including in the United States or Europe;
  • Square states that information may be processed or stored in countries including the United States, Canada, Japan, Ireland, France, Spain and the United Kingdom; and
  • Cloudflare provides a global security network and may process technical anti-bot signals in multiple locations.

Where Australian privacy law requires particular safeguards for overseas disclosures, Zorentia will take reasonable steps appropriate to the circumstances.

9. Cookies, browser storage and similar technology

Zorentia does not use third-party advertising cookies or third-party behavioural analytics.

The Service uses essential or functional cookies and browser storage, including:

ItemPurposeTypical duration
Session cookieKeeps you signed in using a server-side sessionUp to about 30 days unless ended earlier
CSRF cookie/tokenProtects authenticated actions against cross-site request forgeryUsually aligned with the session
Public-feedback visitor identifierDuplicate/spam prevention on public feedbackUp to about 365 days
Sidebar/UI preferenceRemembers a display preferenceAbout 7 days
Pre-login redirectReturns you to the intended page after loginShort-lived / cleared after use
Local/session storage project keysRemembers selected workspace, project or in-flight job state on the deviceUntil cleared, overwritten or the browser session ends, depending on the key

Cloudflare Turnstile may process security signals such as IP address, browser or device characteristics, TLS-related signals, sitekey and origin to distinguish people from automated traffic. Turnstile is not used to read the content of Zorentia form entries.

10. Children and young people

Zorentia's minimum account age is 13.

For users aged 13-17:

  • we do not require an exact date of birth;
  • a Young Person Privacy Notice explains key privacy information in shorter language;
  • an adult parent or legal guardian must contract for an independent paid account; and
  • institution-provisioned use is governed through the institution's agreement rather than the consumer guardian purchase flow.

We design Zorentia with child and student privacy in mind and will update our practices where required as Australian children's privacy requirements develop and become applicable.

If we become aware that an account belongs to a person under 13, we may restrict the account and take reasonable steps to delete or de-identify personal information that is not required to be retained by law.

11. Data retention

We keep information only for as long as reasonably necessary for the purpose for which it is held, subject to legal, security, accounting and operational requirements.

Current principal retention rules include:

DataCurrent approach
Active account and project dataRetained while needed to provide the account/project; removed through account deletion subject to limited retained evidence
Verification recordsDeleted about 24 hours after creation
Recovery recordsDeleted within about 24 hours after expiry
Expired server sessionsDeleted within about 24 hours after expiry
Research invitation codeValid for 14 days
Research invite recipient/contact linkagePlaintext contact and feedback-code lookup retired about 30 days after use or expiry; anonymous project linkage may remain with the project
Research email PDFNormally purged after 1 day once delivery is terminal; hard maximum 7 days from creation
Public-page reportsUp to 365 days, unless needed longer for an active issue or legal reason
Security scan run/transient recordsUp to 90 days
Derived security reportsUp to 365 days, unless deleted earlier with the account
Payment/tax recordsGenerally at least 5 years where required for Australian tax or accounting purposes, and longer where law reasonably requires
Legal acceptance/contract evidenceGenerally up to 7 years after the relevant account or contract ends, unless a longer or shorter period is required or justified
Recipient suppression hashRetained for as long as reasonably necessary to honour the recipient's opt-out
RDS rolling backups7 days

Automated cleanup may occur on a scheduled basis, so deletion can occur shortly after a stated cutoff rather than at the exact second it is reached.

When active-system data is deleted, residual copies can remain in encrypted rolling backups until the backup expires. Zorentia does not ordinarily modify historical backups to remove a single record.

12. Account deletion

Eligible individual users can use the account-deletion process. The process is designed to remove active account, project, publication, public-feedback, invitation, security-scan and related operational records associated with the account.

Limited pseudonymised or non-plaintext records may remain where reasonably required for:

  • accounting, payment or tax evidence;
  • proof of legal acceptance;
  • security or fraud audit purposes; or
  • enforcing a research-recipient opt-out.

Institution-managed users may need to be offboarded by the institution before the independent deletion path becomes available.

13. Security

Zorentia uses technical and organisational safeguards appropriate to the nature of the information and the Service. Measures include access controls, session security, hashing of access credentials and one-time codes, restricted administrative access, rate limits, redaction of secrets in persistent security findings, logging controls and encrypted cloud infrastructure.

No system is completely secure. Users should keep their credentials safe, avoid submitting unnecessary secrets or highly sensitive personal information, and promptly report suspected compromise.

14. Access, correction and privacy requests

You may ask Zorentia to provide access to, correct or delete personal information that we hold about you, subject to applicable law, identity verification, technical limitations and lawful retention obligations.

Use the Privacy / data option on the Zorentia Contact page. We may need information reasonably necessary to verify that the request relates to you.

If you use Zorentia through an institution, some requests may need coordination with the institution where the institution supplied or controls the relevant membership information. Zorentia will not use that relationship to avoid obligations that apply directly to Zorentia.

15. Privacy complaints

If you believe Zorentia has mishandled personal information, use the Privacy / data option on the Contact page and explain the issue. We will review the complaint and respond within a reasonable period.

If the Privacy Act applies to the matter and you are not satisfied with our response, you may have the right to complain to the Office of the Australian Information Commissioner (OAIC).

16. Data breaches

Zorentia maintains an internal data-breach response process. If the Notifiable Data Breaches scheme or another notification obligation applies to an incident, Zorentia will assess and notify affected individuals, institutions and regulators where required by law.

Not every security incident is a legally notifiable data breach.

17. Changes to this policy

We may update this Privacy Policy as the Service, law or our information-handling practices change. The current version and last-updated date will be displayed in the Service.

Where a material change affects information already collected or requires a new consent or acknowledgement, Zorentia will take reasonable steps appropriate to the circumstances, which may include asking users to accept or acknowledge a new version.

18. Contact

Privacy questions, access/correction requests and complaints can be submitted through the Privacy / data option on the Zorentia Contact page.

Zorentia Product Studio Pty Ltd
ABN 86 688 343 482
New South Wales, Australia

ZORENTIA.
Sydney, AustraliaEst. 2025

Legal

01Terms of Use02Privacy Policy03Young Person Privacy Notice04Guardian Paid Account Terms05Institutional Agreement06Institutional Data & Privacy Schedule07Acceptable Use Policy08Subprocessor List

Acknowledgement of Country

Zorentia acknowledges the Gadigal People of the Eora Nation, the Traditional Custodians of the land on which we work in Sydney. We pay our respects to Elders past, present, and emerging.

Company

© 2025 Zorentia
Product Studio Pty Ltd

ABN 86 688 343 482