TazzieDevil Privacy Policy

Version 2.1 — Last updated 4 October 2026 — © 2026 Todd Goodwin. All Rights Reserved.

Bound by the Privacy Act 1988 (Cth) and Australian Privacy Principles where they apply. ACL rights prevail on conflict.
  1. 1.Who we are

    TazzieDevil (the Service) is operated by Todd Goodwin, Queensland, Australia. Privacy contact: toddg@anchoraiguard.com.

  2. 2.Data we collect

    Account: name, email, password hash, tier, Stripe customer id. Content: conversations, prompts, uploaded files, generated media, agent sessions. Operational: usage counters, auth events, tool runs, device sessions. Billing metadata via Stripe — card numbers go directly to Stripe and never touch our servers. We collect no government identifiers and offer no children product.

  3. 3.How we use it

    To provide, secure, and improve the Service: authentication, quota enforcement, media rendering, support, fraud prevention, and aggregated reliability measurement. We do not sell personal information and do not share it for third-party advertising.

  4. 4.Where it lives and who processes it

    Primary sub-processor: Cloudflare — Workers, D1, KV, R2, Vectorize, Workers AI (default inference path), Browser Rendering, Email Sending, Queues. Payments: Stripe, sole payments processor. Customer-configured AI only: if you supply your own provider key (OpenAI, Anthropic, Google, Groq, OpenRouter, DeepSeek, Mistral), prompts go to that provider under their terms; by default nothing leaves Workers AI. We update this clause before adding any processor.

    Because these providers operate global networks, your personal information may be processed outside Australia. We do not control where they locate that infrastructure. If you have data-residency rights (including in the EU/UK), contact us and we will tell you what we can about processing locations.

    Where you supply your own AI provider key, your prompts and outputs are sent to that provider under their privacy policy and we do not control how they handle your data. Cloudflare may access data for operational purposes (for example, investigating abuse, maintaining reliability, or complying with law); such access is governed by Cloudflare's privacy policy.

    Certain decisions are automated: quota enforcement, tier-based model routing, safety gating, and fraud screening. If an automated decision affects you in a way you consider significant or unfair, contact us and ask for a human review; we will consider it in good faith.

  5. 5.AI outputs and your content

    Your prompts and files are processed to generate outputs; you own the outputs subject to third-party rights (see Terms clause 8). We do not use your private content to train third-party models.

  6. 6.Retention — the schedule

    Account, conversations, files, media, sessions: account lifetime, then 30-day grace after deletion, then purge. Backups roll off within 90 days. Billing and tax records: 7 years per Australian tax law. Security and auth logs: 12 months. Support emails: 24 months. Legal-hold material kept only while the hold lasts.

  7. 7.Deletion, access, and portability

    Request access, correction, deletion, or a portable copy of your data at toddg@anchoraiguard.com. We respond within 30 days. Portable copies are provided in a structured, machine-readable format (JSON, and your media as files) via a time-limited link. Where deletion is refused or limited (tax records, active legal hold), we tell you why. You may complain to the OAIC if unsatisfied.

  8. 8.Browser storage

    We use local storage and session storage in your browser to maintain login state, device sessions, and console preferences. We do not use third-party advertising cookies, and we do not sell data through advertising networks.

  9. 9.Security

    TLS 1.3 in transit; D1 at-rest encryption; per-tenant row scoping; per-user sandboxes; deny-by-default tool gates; TOTP MFA available; provider keys AES-GCM encrypted; media URLs owner-credentialed. Eligible data breaches notified per the Notifiable Data Breaches scheme.

  10. 10.Children

    We do not knowingly collect personal information from children under 15. The Service is not directed at children, and a person aged 15–17 may use it only through a parent or legal guardian account (see Terms clause 3). If you believe a child has given us personal information, contact toddg@anchoraiguard.com and we will delete it.

  11. 11.Changes to this policy

    Material changes get at least 14 days in-product or email notice. Continued use after is acceptance.

© 2026 Todd Goodwin — All Rights Reserved. Not legal advice — have an Australian solicitor review before relying on this policy in a dispute.