Plans are liveFour annual plans, and a 14-day trial of Growth for every new organisation — no card, and it stops on its own. See what each plan includes

Legal

Privacy policy

Last updated 25 September 2026

byAUTO Pty Ltd operates BidNomy and handles personal information in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. This page says what we collect, why, and what you can ask us to do about it.

What we collect

  • Account information — your name, work email address, organisation name and role. Provided by you at sign-up.
  • Authentication data — a hashed credential or an OAuth identifier, held by our authentication provider, not by us in readable form.
  • Organisation and team — the organisation name, who is in it, each person’s role, and who invited whom. An invitation holds the invitee’s email address and who sent it for 14 days.
  • Workspace content — saved searches, pursuits, tasks, tags, custom fields, notes, saved prompts and their runs, notification channels, and the files you upload with the text extracted from them.
  • Billing — a Stripe customer id and subscription id, the billing email, the plan and its status, and a log of the events Stripe sends us. Never card numbers: those go to Stripe and never reach us.
  • Usage records — pages viewed, searches run, exports taken and AI requests made, kept for security, billing accuracy and product decisions.
  • Records you open — which published records you opened and when, so Explore can show your Recently viewed list and what your organisation follows. Your organisation sees these only as totals (“opened by 3 people on your team”), never who opened what, and never another organisation’s. You can turn it off, or clear it, on your account page; when you leave an organisation your opens stay in its totals without your name.

What we do not collect

We do not build profiles of individual public servants. Where a published record names a contact officer, that name stays inside the record as its publisher released it; it is not extracted into a person-level database, and there is no people-search feature.

Why we hold it

  • to give you access to the service and keep the account secure;
  • to run your organisation, its seats and its invitations;
  • to send the alerts and reports you asked for;
  • to apply the limits of your plan and to take payment;
  • to answer support requests;
  • to decide what to build next, using aggregate figures.

Government records are not personal information about you

The procurement records in the product are published by Australian Government agencies as open data. They are subject to their publishers’ terms, not this policy. This policy covers information about you as a user of the service.

Who else sees it

These are the processors we use. Each is bound by contract to use the data only to provide its service.

ProcessorWhat it doesWhere
CloudflareDelivers the website and the portalEdge, worldwide
Amazon Web ServicesHosts the API and the AI agentsSydney
SupabaseDatabase, uploaded files and sign-inSydney
Microsoft AzureHolds the government recordsSydney
AnthropicRuns the AI modelsUnited States
OpenAIRuns the AI models if the fallback is switched onUnited States
StripeTakes payments and holds card detailsUnited States, Australia
Microsoft 365Sends alerts, invitations and reportsAustralia

Your workspace is held in Sydney. Two disclosures leave Australia: the text of an AI request goes to a model provider in the United States, and payment goes through Stripe, which also operates in the United States. Under Australian Privacy Principle 8 we take reasonable steps to see that an overseas recipient handles the information consistently with the Australian Privacy Principles. We do not sell personal information and we do not share it for advertising.

Data you send elsewhere

Some features send workspace data wherever you point them. A notification channel posts pursuit and task details to a webhook, a Slack workspace, an email address or a Jira project of your choosing. An API key lets your own script or AI client read what you can read, through the API or the Model Context Protocol server. Those are disclosures you have directed, to a destination you control, and we cannot see what happens to the data once it arrives. Revoke the key or switch the channel off to stop it.

AI features

The question you ask, the records the agent reads to answer it and any document you attached are sent to the model provider to generate the answer. Prompts and uploaded documents are not used to train models. AI and your data sets out exactly what is sent, what is never sent, and where your words are kept.

How long we keep it

WhatHow long
AI conversationsUntil you delete them
Saved-prompt runs and their reportsKept, with the prompt that was sent
Uploaded documents and their extracted textUntil you delete the file
Invitation records14 days, when the link expires
Stripe event log7 years, with the tax records
Usage records12 months
Records you open12 months after you last opened it; shared with your organisation as totals, never by name
Account, organisation and workspace dataWhile the account is open, then 30 days

Deleting a conversation, a file or a pursuit removes it when you press delete. Closing the account removes the rest within 30 days, except where a record must be kept by law.

Your rights

You can ask for a copy of what we hold about you, ask us to correct it, or ask us to delete it. Write to admin@byauto.com and we will respond within 30 days. If you are not satisfied with our response you can complain to the Office of the Australian Information Commissioner.

Cookies

Signing in sets one cookie, the Supabase authentication session, so you stay signed in from page to page. If you pick a light or dark theme, that choice is kept in your own browser under govai-theme, which is local storage rather than a cookie and is never sent to us. There is nothing else: no analytics, no advertising and no cross-site tracking.

Changes

If this policy changes materially we will tell account holders by email before the change takes effect. The current version always sits at /legal/privacy.