CaresLink AI data notice
Privacy, collection and retention notice
This notice explains what CaresLink AI handles during document drafting, how long it is retained and the controls available to users. It is a product notice, not a legal guarantee.
Last updated: 4 August 2026
What we collect
Registration and sign-in handle account information such as email, authentication identity and account role. Google sign-in is shown only when the related authentication service is reliably enabled.
The NDIS Case Note Companion should receive only the minimum structured facts you confirm. Before confirmation, original paste-mode working text remains in current-browser React memory and is not placed in URLs, local storage, analytics events or admin pages.
AI processing
After browser privacy review and both confirmations, the server independently validates the input. Only reviewed structured facts that pass those checks are sent to OpenAI for a controlled-format draft.
OpenAI requests use store:false. We do not describe that setting as zero data retention; the service provider may still process requests under its applicable terms and security processes.
Temporary results and saved documents
A successful result uses an opaque, account-bound claim that can be recovered or saved for 30 minutes. After expiry it cannot be claimed or saved. Expired rows are removed when a later generation or save cleanup runs; this release does not promise physical deletion at the exact 30-minute mark.
When a user saves a document, it remains until that user deletes it. Saved content is read within the account-owner boundary. Material that must become an official record should be transferred to the user's authorised record system.
Usage and product analytics
Product events contain metadata such as event name, hashed identifiers, allowlisted attribution, language, timestamps, credit reserve/commit/release status and model token counts.
Telemetry and aggregate admin views should not contain input, output, participant facts, original pasted text or free-text errors.
Deletion, contact and use boundary
Users can delete their own saved drafts in Saved Documents. For account or data questions, use the contact channel published on the CaresLink website.
Every output is a user-reviewed draft, not a completed official record, and is not clinical, legal, care, regulatory, compliance or other professional advice.