Skip to content

Privacy Policy

How Nrth Star collects, uses, stores and shares personal information, under the Privacy Act 1988 (Cth) and the Australian Privacy Principles.

Last updated 8 September 2026.

In short

  • The audit connects to nothing. You connect an account only after you approve a plan that needs it, and you can disconnect it at any time.
  • We read the records an automation needs to do the job you approved, and nothing else. For a mailbox that is the sender, subject, date and a short preview, never the body of a message.
  • Nothing you connect or type is used to train a model, by us or by anyone we use.
  • Your data lives in Australia. A small number of providers outside Australia process specific parts of it, and they are named below.
  • Close your account and we delete what we hold within thirty days, except what the law requires us to keep.

A summary to help you read the document. The document is what applies.

1. Who we are

Nrth Star provides software that finds where a business is losing hours to manual work, then builds, rehearses, hosts and repairs the automations that give those hours back. We are based in Australia and this policy is written under the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

This policy covers the Nrth Star website, the Nrth Star application, and the audit, planning and automation services we provide through them. Questions about it go to harrison@nrthstar.app.

Where we handle personal information on behalf of your business in the course of running an automation, your business remains responsible for having collected that information lawfully and for the purposes it is used for. We handle it under your instructions, which are the plans you approve.

2. What we collect

What we hold depends on how far you have gone with us, so it is set out by stage.

Before you have an account:

  • If you join the waiting list, the name and email address you give us, and, if you answer the question on the confirmation, what you tell us you would automate first. These are held by Loops, our email provider, which is outside Australia (see section 6).
  • The usual technical information a browser sends: IP address, browser and device type, pages visited and how you arrived.

When you create an account and run the audit:

  • Your name, email address, company name and time zone.
  • Everything you tell us in the audit conversation: how your work happens, who does what, what it costs you, and any document you hand over, such as a standard operating procedure. Documents are read in your browser and the text is sent to us; the file itself is not uploaded or stored.
  • If you use the team audit, the answers your colleagues give. Those answers are held without a name, without a timestamp and without any link to the invitation that was sent, and they are reported only by role and only where a role has at least two respondents. This is a property of how the feature is built, not a promise about how it is used.

When you approve a plan and connect an account:

  • The fact that an account is connected, the permissions you granted, which account it is (for example the address of a connected mailbox), and a cached description of the fields that account holds, so we can check an automation against it before it runs.
  • The records an automation reads, writes or sends in order to do the job you approved. For a CRM that is the deals, contacts and companies the automation is about. For a mailbox it is the sender, recipients, subject, date and a short preview of each message the automation looks at. We do not read message bodies.
  • A record of every run: what the automation read, what it decided, what it sent or changed, and when. Credentials and access tokens are removed from these records before they are written.
  • Rehearsals: before an automation is switched on we read the last thirty days of the relevant records to show you what it would have done. That reading is stored with the rehearsal so that what you approved can always be shown again.

When you pay:

  • Your billing contact and the plan you are on. Card details are collected and held by our payment provider and never touch our systems.

3. How we collect it

Directly from you, when you type into the application, answer a question in the audit, hand over a document, or approve a plan.

From the accounts you connect, through the permissions you grant on that provider's own sign-in screen. We use a managed connection service (Nango) to hold the resulting access tokens; we do not store your passwords, and we do not store the tokens ourselves.

From your colleagues, if you invite them to the team audit.

Automatically, from your browser and from the application as you use it, through cookies and analytics described in section 8.

We do not buy personal information and we do not collect it from public sources about you.

4. Why we use it

We use personal information to:

  • Run the audit and write a plan in your own words.
  • Build the automations you approve, check them against the accounts they will use, and rehearse them against your recent records before anything goes live.
  • Run those automations, keep a record of what each one did, and pause and diagnose one when a connected tool changes.
  • Operate your account: sign you in, bill you, answer your questions and tell you about things that need your attention.
  • Improve the product, using aggregated and de-identified usage information.
  • Meet our legal obligations, including tax and record-keeping law and responding to lawful requests.

We do not use the information in your connected accounts for any purpose other than the automations you have approved. We do not sell personal information, and we do not use it to build profiles for advertising.

5. Automations, AI and automated decisions

Automations act on records in your connected accounts, and some of those records are about people: your clients, their staff, your own team. Three things govern how that happens.

  • Nothing runs until you have approved it. Every automation is written out for you as a list of plain-English sentences, rehearsed against your last thirty days with every send switched off, and shown to you as a list of what it would have done, before you switch it on. You can switch it off at any time, in one click.
  • Automations do not make decisions with legal or similarly significant effects about individuals. They carry out the job you approved, such as sending a follow-up, updating a record or compiling a report. If a connected tool changes and an automation can no longer do that job safely, it pauses and waits for you rather than guessing.
  • We use large language models to hold the audit conversation, to write plans and the text inside automations (such as the wording of a follow-up email), and to classify records where a plan calls for it. The models are provided by Anthropic under commercial terms that do not permit our inputs or outputs to be used to train their models. Nothing you connect, type or hand over is used to train a model by us either.

From December 2026 the Privacy Act requires policies to describe automated decision-making. Ours is as above: automated actions on business records under a plan a person approved, never an automated decision about a person's rights or entitlements.

6. Who we share it with

We share personal information only with the providers we need to run the service, each for the purpose listed, under terms that restrict them to that purpose:

  • Supabase (database, authentication and sign-in emails). Our database is hosted in Sydney, Australia.
  • Vercel (hosting of the website and the application). United States.
  • Trigger.dev (running scheduled and background jobs, such as checking a connected account for changes). United States.
  • Nango (holding the access tokens for the accounts you connect and making the calls to those accounts on our behalf). United States.
  • Anthropic (the language models described in section 5). United States. Inputs are not used for training.
  • PostHog (product analytics for the website and the application, described in section 8). United States.
  • Loops (the waiting-list emails, if you joined one). United States.
  • Our payment provider, for billing.

We also disclose personal information where the law requires it, for example to a regulator or under a court order, and we will tell you when we are allowed to.

The accounts you connect are separate. When an automation sends an email through your mailbox or updates a record in your CRM, that information goes to that provider under your own agreement with them, not under this policy.

7. Overseas disclosure

Your data is stored in Australia. The providers named in section 6 that are located in the United States process the parts of it listed against their names, and access to it from the United States is a disclosure under APP 8.

Before disclosing personal information overseas we take reasonable steps to ensure the recipient handles it in a way consistent with the APPs: each provider is bound by contract to use the information only to provide its service to us, to keep it secure, and not to use it for its own purposes. We do not otherwise send personal information outside Australia.

8. Cookies and analytics

Our website and application use PostHog to understand how they are used: which pages are visited, which controls are pressed, and how far people get. PostHog sets a cookie on your device to recognise a returning visitor and to join a visit to the website with a later sign-in to the application. The cookie contains an identifier, not your name.

We do not send PostHog anything you type. What it records is which pages were visited and which controls were pressed. And we honour the Do Not Track signal: if your browser sends it, we do not record your visit at all.

You can also block or delete cookies in your browser. The website works without them; the application needs a cookie to keep you signed in.

We do not use advertising cookies or share analytics with advertisers.

9. Security

We take reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification and disclosure. Among them:

  • Access tokens for your connected accounts are held by a managed connection service and are never written to our database or to the record of any run.
  • Credentials are removed from every execution record before it is stored, and any response that might contain one is discarded rather than kept.
  • Each workspace's data is isolated at the database level, so one customer's records cannot be joined to another's.
  • An automation cannot write to a connected account or send anything until it has passed our checks, been rehearsed, and been approved and switched on by you.
  • Sign-in is by a link sent to your email address; we do not hold passwords.
  • Data is encrypted in transit and at rest.

No system is perfectly secure. If we become aware of a data breach that is likely to result in serious harm to anyone whose information we hold, we will notify the affected people and the Office of the Australian Information Commissioner as the Notifiable Data Breaches scheme requires.

10. Retention and deletion

We keep personal information for as long as we need it for the purposes in section 4, then delete or de-identify it. In particular:

  • Disconnect an account and we revoke our access to it, delete the cached description of its fields and the stored account identity, and any automation that depended on it stops and tells you so. Records already held in execution records and rehearsals are kept as part of the history of what those automations did.
  • Delete an automation and it is switched off and removed from every screen. The record of what it did while it ran is kept, because being able to show what an automation sent, and to whom, is something you may need long after the automation is gone.
  • Close your account and we delete the personal information we hold about you and your workspace within 30 days, apart from what we are required by law to keep. Tax and billing records are kept for the period Australian tax law requires, and then destroyed.
  • Rehearsals are kept for as long as the automation they were run for exists, because they are the record of what you were shown before you approved it.
  • Analytics events are retained by our analytics provider for its standard period and are not linked to your account beyond the identifier described in section 8.

11. Access and correction

You can ask for a copy of the personal information we hold about you, or ask us to correct it, by writing to harrison@nrthstar.app. We will respond within thirty days. Most of what we hold about you is visible in the application, and you can change your own details there.

If we refuse a request we will tell you why in writing and how to complain about the refusal. We do not charge for access requests.

Information inside the accounts you connect belongs to those accounts. To correct a record in your CRM, correct it there; the next time an automation reads it, it will read the corrected version.

12. Direct marketing

We send you email about your account and your automations: sign-in links, things that need your attention, and notices about these documents. Those are not marketing and you cannot opt out of them while you have an account.

We send marketing email, such as product updates, only to people who have asked for it, and every such email carries an unsubscribe link that works. We comply with the Spam Act 2003 (Cth) and we do not share your address with anyone else for marketing.

Emails sent by your automations through your own mailbox are sent by you, to your own contacts, under your own obligations. See our Terms of Service.

13. Children

Nrth Star is a business service and is not directed at people under 18. We do not knowingly collect personal information from children. If you believe a child has given us personal information, write to harrison@nrthstar.app and we will delete it.

14. Complaints

If you think we have handled your personal information in a way that breaches the APPs, write to harrison@nrthstar.app with the details. We will acknowledge your complaint within seven days, investigate it, and respond within thirty days.

If you are not satisfied with our response you can complain to the Office of the Australian Information Commissioner at oaic.gov.au or on 1300 363 992.

15. Changes to this policy

We update this policy when what we collect or how we use it changes. The date at the top is the date of the version in force. For a change that affects how we use information you have already given us, we will tell you by email before it takes effect.

16. Contact

Privacy enquiries, access and correction requests and complaints go to harrison@nrthstar.app. A person reads that inbox.

Questions about this document: harrison@nrthstar.app