Legal
Last updated: 7 July 2026 · MyDetailAI, ABN 85 452 541 440 (sole trader, NSW, Australia)
This policy explains what personal information MyDetailAI ("we", "us") collects, why we collect it, and how it is handled, in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
We use a small number of service providers to run MyDetailAI. Your information is only shared with them to the extent needed to provide the service:
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database and authentication (accounts, profiles, projects, usage) | Sydney, Australia |
| Stripe | Payment processing and subscription management | United States / global |
| Google Cloud (Vertex AI) | AI text and image generation for chat and drawings | United States |
| Anthropic (Claude) | AI generation of 3D scene descriptions | United States |
| Railway | Application hosting | United States |
| Cloudflare | DNS, network security, and email routing | Global network |
| Resend | Sending account verification emails | United States |
Some of these providers are located overseas (principally the United States). By using the platform you consent to this overseas disclosure as described in APP 8. Each provider is bound by its own privacy and security commitments.
We do not sell your personal information to anyone.
Descriptions you submit and questions you ask are sent to our AI providers (Google, Anthropic) to generate your output. Uploaded images are sent to Google for analysis. We recommend you do not include sensitive personal information in descriptions, questions, or uploaded images — the service does not need it.
Generated scene descriptions may be cached (keyed to the description text, not to your identity) so identical requests can be served without a fresh AI call.
We use browser local storage (not tracking cookies) to keep you signed in, remember your profile and preferences on your device, and store your recent generation history for quick access. We do not use third-party advertising or analytics trackers.
Passwords are hashed by our authentication provider and are never visible to us. All traffic is encrypted in transit (HTTPS, enforced). Database access is restricted by row-level security so account data is only accessible to the authenticated owner. We review our security posture regularly.
Under the Australian Privacy Principles you may request access to the personal information we hold about you, ask us to correct it, or ask us to delete it. Email [email protected] and we will respond within a reasonable period. If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC).
We may update this policy as the platform evolves. The "last updated" date above reflects the current version. Material changes will be noted on the platform.