Zorentia Product Studio Pty Ltd
ABN 86 688 343 482
Version: 2026-09-05-v1
Last updated: 5 September 2026
Effective: when this version is first published in Zorentia
This Privacy Policy explains how Zorentia Product Studio Pty Ltd (Zorentia, we, us, our) handles personal information when people use Zorentia Product Studio and related services.
Zorentia handles personal information in accordance with applicable Australian privacy law. We also use the Australian Privacy Principles (APPs) as a privacy-by-design standard across the Service, whether or not every APP applies to every Zorentia activity at a particular time.
1. Who this policy covers
This policy applies to:
- individual users;
- students and other users provisioned by a school, university or other institution;
- parents or legal guardians who purchase an individual paid account for a user aged 13-17;
- institution representatives and administrators;
- people who receive research invitations;
- visitors to public-by-link project pages and public-feedback forms; and
- people who contact Zorentia for support, privacy, safety or other enquiries.
2. Our privacy approach
Zorentia is designed to collect less personal information rather than more. In particular:
- ordinary student accounts are email-based and do not require a student name, date of birth, postal address or phone number;
- Zorentia does not use third-party advertising analytics;
- Zorentia does not sell personal information;
- public landing-page feedback is designed not to collect respondent names, emails or phone numbers;
- projects are private by default;
- there is no public Explore feed or public directory of student projects; and
- generative AI is routed through Amazon Bedrock rather than direct generative model-provider APIs.
3. Information we collect
3.1 Individual accounts
For an ordinary individual account, we may collect:
- email address;
- internal user and account identifiers;
- whether you self-identify as aged 13-17 or 18 or older;
- legal-document versions and acceptance timestamps;
- account, session, login and recovery information;
- plan, credit and usage information; and
- support or product-feedback messages you choose to send us.
We do not require your exact age or date of birth.
3.2 Guardian purchases
Where a user aged 13-17 purchases an individual paid account, we collect limited information about the adult parent or legal guardian completing the purchase, including:
- guardian email address;
- confirmation that the guardian is 18 or older;
- confirmation of parental or legal authority;
- the version of the Guardian Paid Account Terms accepted;
- acceptance time; and
- associated purchase or payment references.
We do not require a guardian's date of birth, postal address or phone number for this flow.
3.3 Institution customers
For institution representatives and administrators, we may collect:
- organisation name;
- representative or administrator name;
- work email;
- role or title;
- authority confirmation;
- billing email where used;
- order, seat, subscription and payment references; and
- Institutional Agreement and Data & Privacy Schedule acceptance records.
3.4 Institution-provisioned students
Institutions provision students using email, role and, where used, cohort information. Zorentia does not require the institution to provide a student's name, date of birth, postal address or phone number.
An institution administrator may see limited administrative information about users associated with that institution, such as:
- student email;
- cohort;
- access status;
- recent login or activity;
- current milestone or stage;
- administrative engagement status; and
- credit usage or allowance.
Institution administrators do not receive access through the organisation dashboard to a student's raw prompts, private project ideas, generated code, private project content, research observations or private feedback content merely because they are an administrator.
3.5 Project and AI content
When you use project tools, we may collect and store information needed to provide the feature, including:
- idea descriptions and project briefs;
- answers to planning questions;
- prompts and assistant messages;
- technical plans, architecture and database designs;
- generated SQL;
- generated backend and frontend code;
- generated files and package metadata;
- research observations and testing notes;
- deployment choices or related tool state; and
- generation, usage, error and credit metadata.
This information may be linked to your account and project so that the Service can preserve your work between sessions.
3.6 Public project pages
Projects are private by default. If you deliberately publish a project page, Zorentia stores and displays the content selected for the public page.
Zorentia removes known structured account identifiers from the public payload, but you remain responsible for not putting personal, confidential or private information into public-facing text.
Published pages are public by direct link. Zorentia uses technical controls intended to discourage search-engine indexing, but third parties may still copy, cache, screenshot or share material that you make public.
3.7 Public feedback
Public landing-page feedback is designed to be anonymous. New public-feedback forms do not request or store respondent name, email or phone number.
Zorentia may store technical information necessary to prevent duplicate submissions, spam and abuse, including a pseudonymous visitor identifier, text hashes, moderation status and security metadata. These technical identifiers are not shown to student project owners.
3.8 Research invitations
A user may provide recipient email addresses to send direct research or feedback invitations to people they already intend to contact.
For this feature we may process:
- recipient email;
- a sender display name chosen by the user;
- project or session reference;
- invitation status and delivery metadata;
- a one-time feedback code stored in hashed form;
- research-contact permission attestation evidence;
- feedback submitted through the invitation; and
- a temporary project one-pager PDF used for delivery where the feature requires it.
The user sending invitations must confirm that recipients have agreed to be contacted for that research and must not use the feature for unsolicited marketing.
A recipient can opt out of further research invitations. Zorentia may retain a keyed, non-plaintext suppression value so that the opt-out continues to be honoured.
3.9 Payments
Payments are processed using Square. Zorentia may store payment and subscription metadata such as:
- amount;
- purchase type;
- credit or seat quantity;
- payment status; and
- Square order, payment, customer, subscription or invoice identifiers.
Zorentia's hosted payment flow does not require card number or CVV to be entered into the Zorentia application itself.
3.10 Security scans and IDE features
If you choose to run a Zorentia IDE or security-analysis feature, the scan may transmit selected or bundled source-code files to Zorentia for analysis.
The current scan architecture processes the raw bundle temporarily rather than storing the complete raw bundle as a long-term project file. Derived security findings, redacted source context, reports and scan metadata may be retained for the periods described below.
Do not intentionally place secrets or personal information into code or scan inputs unless necessary. Zorentia uses controls intended to redact secret values before persistent findings are stored, but no automated redaction system is perfect.
3.11 Support, privacy and safety contacts
If you contact Zorentia, we collect the information you provide in the message and technical or account information reasonably necessary to investigate and respond.
Reports about a public page can be submitted without creating an account. A report generally contains the report category, optional details, publication reference and status. Zorentia does not intentionally store reporter identity or IP in the public-page report record.
4. How we collect information
We collect information:
- directly from you when you sign up, use the Service, submit content, purchase a plan, publish a page or contact us;
- from an institution when it provisions or administers your institutional access;
- from a guardian who completes a paid purchase for a 13-17-year-old;
- from your browser or device where necessary for sessions, security and abuse prevention;
- from payment, email-delivery and security service providers in connection with the services they provide; and
- from users who provide recipient email addresses for direct research invitations.
5. Why we use information
We use personal information where reasonably necessary to:
- create, authenticate, recover and secure accounts;
- provide project, generation, download, feedback, publishing and security features;
- maintain project continuity between sessions;
- administer institution memberships, cohorts, activity and credit allowances;
- process subscriptions, purchases and billing;
- send service, verification, recovery and authorised research messages;
- enforce recipient opt-outs and prevent repeated unwanted contact;
- detect abuse, spam, fraud, security issues and misuse;
- provide support and handle privacy or safety enquiries;
- maintain legal, contractual, tax and accounting evidence;
- comply with applicable law and lawful requests; and
- maintain, troubleshoot and improve the reliability and security of the Service using operational information.
We do not use student project content for third-party advertising.
6. AI and automated processing
6.1 Generative AI through Amazon Bedrock
Zorentia uses Amazon Bedrock as the production gateway for generative AI.
At the date of this policy:
- Zorentia invokes Bedrock from the AWS Sydney region (
ap-southeast-2); - Zorentia's Bedrock account data-retention mode is configured to
none; - Bedrock model invocation logging is disabled; and
- where the Bedrock Responses-compatible path exposes a storage option, Zorentia sends requests with storage disabled.
This means Bedrock service-side request/response retention is disabled under Zorentia's current production configuration. This does not mean Zorentia itself stores nothing: project inputs, project state and generated outputs may separately be stored in Zorentia's own systems so that the Service can work as described in this policy.
Current generative model families are accessed through Bedrock. Zorentia does not separately send generative project prompts to direct Anthropic, OpenAI or DeepSeek generative APIs.
6.2 OpenAI moderation
A limited text-moderation function uses OpenAI's Moderation API directly. Zorentia limits this request to the text requiring moderation and does not deliberately attach student email, user UUID, institution details, project bundles or code.
According to OpenAI's published API data controls at the date of this policy, the /v1/moderations endpoint is not used to train OpenAI models and has no abuse-monitoring or application-state retention. The moderation request may be processed outside Australia.
6.3 Automated product indicators
Zorentia uses automated logic for functions such as:
- milestone or current-stage indicators;
- engagement status;
- pitch clarity or similar project-quality indicators;
- spam classification;
- security findings; and
- credit reservation, charging and restoration.
These functions help operate or explain the Service. Zorentia does not use them to automatically determine a student's academic grade or competency, or to automatically terminate a student's account because of an engagement or project score.
7. Service providers and disclosures
Zorentia may disclose or make information available to service providers where reasonably necessary to provide the Service. Current key providers are listed in the Subprocessor List and include:
- Amazon Web Services (hosting, database, storage, email delivery, Redis infrastructure and Bedrock AI);
- OpenAI (limited text moderation only);
- Square (payment processing); and
- Cloudflare Turnstile (bot and abuse prevention).
We may also disclose information where reasonably necessary to comply with law, respond to a lawful request, protect rights or safety, investigate fraud or security incidents, or complete a genuine corporate transaction subject to appropriate safeguards.
We do not sell personal information.
8. Overseas processing
Zorentia's primary application and database infrastructure is hosted in Australia, principally in AWS Sydney. The current Claude geographic inference profile used from Sydney may route within AWS Sydney and Melbourne.
Some service providers may process information outside Australia. Depending on the service and provider configuration, relevant countries may include the United States, Canada, Japan, Ireland, France, Spain, the United Kingdom and other locations in which those providers or their service providers operate.
In particular:
- limited OpenAI moderation text may be processed outside Australia, including in the United States or Europe;
- Square states that information may be processed or stored in countries including the United States, Canada, Japan, Ireland, France, Spain and the United Kingdom; and
- Cloudflare provides a global security network and may process technical anti-bot signals in multiple locations.
Where Australian privacy law requires particular safeguards for overseas disclosures, Zorentia will take reasonable steps appropriate to the circumstances.
9. Cookies, browser storage and similar technology
Zorentia does not use third-party advertising cookies or third-party behavioural analytics.
The Service uses essential or functional cookies and browser storage, including:
| Item | Purpose | Typical duration |
|---|---|---|
| Session cookie | Keeps you signed in using a server-side session | Up to about 30 days unless ended earlier |
| CSRF cookie/token | Protects authenticated actions against cross-site request forgery | Usually aligned with the session |
| Public-feedback visitor identifier | Duplicate/spam prevention on public feedback | Up to about 365 days |
| Sidebar/UI preference | Remembers a display preference | About 7 days |
| Pre-login redirect | Returns you to the intended page after login | Short-lived / cleared after use |
| Local/session storage project keys | Remembers selected workspace, project or in-flight job state on the device | Until cleared, overwritten or the browser session ends, depending on the key |
Cloudflare Turnstile may process security signals such as IP address, browser or device characteristics, TLS-related signals, sitekey and origin to distinguish people from automated traffic. Turnstile is not used to read the content of Zorentia form entries.
10. Children and young people
Zorentia's minimum account age is 13.
For users aged 13-17:
- we do not require an exact date of birth;
- a Young Person Privacy Notice explains key privacy information in shorter language;
- an adult parent or legal guardian must contract for an independent paid account; and
- institution-provisioned use is governed through the institution's agreement rather than the consumer guardian purchase flow.
We design Zorentia with child and student privacy in mind and will update our practices where required as Australian children's privacy requirements develop and become applicable.
If we become aware that an account belongs to a person under 13, we may restrict the account and take reasonable steps to delete or de-identify personal information that is not required to be retained by law.
11. Data retention
We keep information only for as long as reasonably necessary for the purpose for which it is held, subject to legal, security, accounting and operational requirements.
Current principal retention rules include:
| Data | Current approach |
|---|---|
| Active account and project data | Retained while needed to provide the account/project; removed through account deletion subject to limited retained evidence |
| Verification records | Deleted about 24 hours after creation |
| Recovery records | Deleted within about 24 hours after expiry |
| Expired server sessions | Deleted within about 24 hours after expiry |
| Research invitation code | Valid for 14 days |
| Research invite recipient/contact linkage | Plaintext contact and feedback-code lookup retired about 30 days after use or expiry; anonymous project linkage may remain with the project |
| Research email PDF | Normally purged after 1 day once delivery is terminal; hard maximum 7 days from creation |
| Public-page reports | Up to 365 days, unless needed longer for an active issue or legal reason |
| Security scan run/transient records | Up to 90 days |
| Derived security reports | Up to 365 days, unless deleted earlier with the account |
| Payment/tax records | Generally at least 5 years where required for Australian tax or accounting purposes, and longer where law reasonably requires |
| Legal acceptance/contract evidence | Generally up to 7 years after the relevant account or contract ends, unless a longer or shorter period is required or justified |
| Recipient suppression hash | Retained for as long as reasonably necessary to honour the recipient's opt-out |
| RDS rolling backups | 7 days |
Automated cleanup may occur on a scheduled basis, so deletion can occur shortly after a stated cutoff rather than at the exact second it is reached.
When active-system data is deleted, residual copies can remain in encrypted rolling backups until the backup expires. Zorentia does not ordinarily modify historical backups to remove a single record.
12. Account deletion
Eligible individual users can use the account-deletion process. The process is designed to remove active account, project, publication, public-feedback, invitation, security-scan and related operational records associated with the account.
Limited pseudonymised or non-plaintext records may remain where reasonably required for:
- accounting, payment or tax evidence;
- proof of legal acceptance;
- security or fraud audit purposes; or
- enforcing a research-recipient opt-out.
Institution-managed users may need to be offboarded by the institution before the independent deletion path becomes available.
13. Security
Zorentia uses technical and organisational safeguards appropriate to the nature of the information and the Service. Measures include access controls, session security, hashing of access credentials and one-time codes, restricted administrative access, rate limits, redaction of secrets in persistent security findings, logging controls and encrypted cloud infrastructure.
No system is completely secure. Users should keep their credentials safe, avoid submitting unnecessary secrets or highly sensitive personal information, and promptly report suspected compromise.
14. Access, correction and privacy requests
You may ask Zorentia to provide access to, correct or delete personal information that we hold about you, subject to applicable law, identity verification, technical limitations and lawful retention obligations.
Use the Privacy / data option on the Zorentia Contact page. We may need information reasonably necessary to verify that the request relates to you.
If you use Zorentia through an institution, some requests may need coordination with the institution where the institution supplied or controls the relevant membership information. Zorentia will not use that relationship to avoid obligations that apply directly to Zorentia.
15. Privacy complaints
If you believe Zorentia has mishandled personal information, use the Privacy / data option on the Contact page and explain the issue. We will review the complaint and respond within a reasonable period.
If the Privacy Act applies to the matter and you are not satisfied with our response, you may have the right to complain to the Office of the Australian Information Commissioner (OAIC).
16. Data breaches
Zorentia maintains an internal data-breach response process. If the Notifiable Data Breaches scheme or another notification obligation applies to an incident, Zorentia will assess and notify affected individuals, institutions and regulators where required by law.
Not every security incident is a legally notifiable data breach.
17. Changes to this policy
We may update this Privacy Policy as the Service, law or our information-handling practices change. The current version and last-updated date will be displayed in the Service.
Where a material change affects information already collected or requires a new consent or acknowledgement, Zorentia will take reasonable steps appropriate to the circumstances, which may include asking users to accept or acknowledge a new version.
18. Contact
Privacy questions, access/correction requests and complaints can be submitted through the Privacy / data option on the Zorentia Contact page.
Zorentia Product Studio Pty Ltd
ABN 86 688 343 482
New South Wales, Australia