Security & privacy
Trust & Security
How we protect the data you and your organisation entrust to us — in plain language, and without overstatement.
ApexForm Life builds tools that work with sensitive material: how people think, and how organisations decide. We treat the data behind that work as something we hold on your behalf, not something we own. This page explains the protections in place across Paradigm and AFOS, what we collect and why, and the control you keep over your information.
We handle personal information in line with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
Our principles
1. Collect only what's needed
We ask for the minimum required to deliver the product, and nothing more. We do not collect sensitive information through our website, and we do not knowingly collect information from anyone under 16.
2. Encrypt in transit, and encrypt sensitive data at rest
Traffic to our sites and apps travels over encrypted connections (HTTPS/TLS). Sensitive data — such as Paradigm's personal reflections, and the third-party credentials you connect to AFOS — is encrypted at rest.
3. Separate access, isolate data
Access to your information is gated by authentication and rate-limited against abuse. In AFOS, each organisation is deployed on its own isolated instance with its own database, so one organisation's data is never commingled with another's.
4. You stay in control
You can ask us to access, correct, or delete the information we hold about you, and withdraw consent, at any time. In Paradigm, that control is built into the app — down to deleting an individual voice recording.
5. We don't sell your data, and we don't train third-party AI models on it
We do not sell your personal information or share it with advertisers. Personal reflections and voice recordings in Paradigm are never used to train public or third-party AI models.
Paradigm — your personal data
Paradigm works with genuinely personal material: reflections, voice recordings, and AI-assisted interpretations of your patterns. We protect it accordingly.
- Sensitive information is collected only with your explicit consent, given during onboarding — never by default.
- Your reflections and voice recordings are never used to train public or third-party AI models.
- The app's interpretations are offered as possible readings — not facts, and not clinical assessments — and you can confirm, edit, or reject each one.
- You can review, correct, or delete any interpretation the app has stored, delete individual voice recordings and transcripts, or delete your account entirely.
- Aggregated insights used to improve the method are de-identified and never linked back to you.
Paradigm is governed by its own privacy policy, presented in full during onboarding.
AFOS — your business data
AFOS is an operations and decision system for organisations. It is built so your business's data stays yours, and stays separated.
- Access control. The dashboard is protected by a passcode that is never stored in plain text — it is hashed with a per-account random salt. Repeated failed attempts trigger an automatic lockout, and sensitive endpoints are rate-limited.
- Isolated deployments. Each customer runs on their own instance, with their own database and their own connected accounts. One organisation's data is never mixed with another's.
- Encrypted credentials. When you connect a service (for example, Stripe or your analytics), those credentials are encrypted at rest using AES-256-GCM and are never sent back to the browser.
- Your financial data stays on your instance. Imported bank statements are processed on your own server. The only exception is optional text-recognition for scanned or image-only PDFs; when enabled, a few statement pages are sent to our AI provider solely to read the text, and it can be turned off entirely.
- Optional AI features are transparent. AFOS's AI features (statement text-recognition and decision support) send only the content needed for that feature to our AI providers, and only when you choose to use them.
- Payments. Checkout runs through Stripe's hosted flow; we never handle or store raw card numbers.
Who we work with
To run our services we rely on a small set of trusted providers, each only for its specific function:
- Resend — transactional and confirmation email.
- Notion — our contact and subscriber records.
- Google Analytics — website analytics.
- LinkedIn — advertising measurement (we do not send your email address or customer data to LinkedIn).
- Railway and Cloudflare — hosting and delivery.
- OpenAI and Anthropic — the AI providers behind AFOS's optional AI features, used only when those features are used.
Some of these providers may store data outside Australia (for example, in the United States or the European Union). We take reasonable steps to ensure they protect your information consistently with our policies and applicable law.
Your rights
You can ask us to access, correct, or delete the personal information we hold about you, or to stop contacting you. Email [email protected] and we will respond within a reasonable time. If you have a concern about how we have handled your information, you can also contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
Full details are in our Privacy Policy and Terms.
An honest note
No method of transmission or storage is ever completely secure, and we do not claim otherwise. What we can commit to is limiting what we collect, how long we keep it, and who can reach it — and continuing to strengthen these protections as our products grow. If you believe you have found a security issue, please email [email protected] so we can address it quickly.
ApexForm Life Pty Ltd · ABN 11 698 784 904 · Last reviewed July 2026.