Privacy Policy
Last updated: 28 August 2026 · Effective: 1 May 2026
1. About this policy
This Privacy Policy explains how Genesis Chain Financial Group Pty Ltd (ABN 48 625 098 937, ACN 625 098 937) trading as CreditPolicy.ai and CreditPolicy.com.au (we, us, our) collects, holds, uses and discloses personal information.
We are bound by the Privacy Act 1988 (Cth) (Privacy Act) and the Australian Privacy Principles (APPs). This policy applies to:
- the CreditPolicy web application at creditpolicy.ai, creditpolicy.com.au, and any subdomain of those domains;
- our Model Context Protocol (MCP) server at https://creditpolicy.ai/api/mcp, including when you access it through a third-party AI assistant such as Claude, ChatGPT, Perplexity, Cursor or a similar client;
- our APIs, integrations, emails and support channels; and
- our marketing website.
Together these are the Service.
If you do not agree with this policy, please do not use the Service.
2. Who our users are
The Service is designed for licensed Australian mortgage brokers, commercial finance brokers, their staff and their licensees. It is a business tool. It is not intended for use by consumers seeking credit, and it is not intended for anyone under 18.
An important distinction runs through this policy:
- Your information — information about you as an account holder (your name, email, billing details, how you use the Service).
- Client information — personal information about your clients that you choose to put into the Service (for example, in a scenario question, a client record, a deal record or an uploaded document). We handle this on your behalf. Section 9 sets out how responsibility is split.
3. What personal information we collect
3.1 Information you give us
| Category | Examples |
|---|---|
| Account information | Name, business email address, phone number, password (hashed), brokerage or aggregator name, job role |
| Professional information | Credit licence or credit representative number, aggregator, lender panel, ABN |
| Billing information | Billing name, billing address, subscription plan, transaction records. Card numbers are entered directly with our payment processor (Stripe) and are never stored on our systems. |
| Content you submit | Questions and prompts, scenario details, notes, client records, deal records, documents you upload, feedback |
| Support and communications | Emails, chat messages, support tickets, survey responses |
3.2 Information we collect automatically
| Category | Examples |
|---|---|
| Usage data | Features used, tools called, queries run, pages viewed, session times, referring pages |
| Device and technical data | IP address, browser type and version, operating system, device identifiers, language settings |
| Log data | Request timestamps, error traces, API endpoints called, connection metadata |
| Cookies and similar technologies | Session cookies, authentication tokens, preference cookies, analytics identifiers and session-replay analytics — see section 14 |
3.3 Information from third parties
- Authentication providers — if you sign in using a third-party identity (for example a Google or Microsoft account), we receive your name, email address and a unique identifier from that provider.
- Third-party AI assistants — when you connect the Service to an AI assistant via MCP, we receive the requests that assistant sends on your behalf. See section 7.
- Payment processor — subscription status, payment success or failure, and the last four digits and card brand for receipting.
- Publicly available sources — we may verify business details against public registers such as ASIC or ABN Lookup.
3.4 Sensitive information
We do not seek sensitive information as defined in the Privacy Act (such as health information or information about racial or ethnic origin, political opinions or criminal record). Please do not enter sensitive information into the Service unless it is strictly necessary for the scenario you are assessing. If you do, you confirm you have the individual's consent for us to handle it as described in this policy.
Note that credit information and credit eligibility information about your clients may be caught by Part IIIA of the Privacy Act. See section 10.
4. How we collect personal information
We collect personal information directly from you wherever reasonably practicable — when you sign up, subscribe, use the Service, contact support, or connect an AI assistant. We collect information about your clients indirectly, from you, in the course of you using the Service.
Where we collect personal information about an individual from someone other than that individual (for example, your client), we rely on you to have given that individual notice of the matters set out in APP 5. See section 9.
5. Why we collect, hold, use and disclose personal information
We use personal information for the following purposes:
- To provide the Service — create and administer your account, authenticate you, answer your policy questions, run scenario assessments, generate comparisons, store your client and deal records, and return cited results.
- To operate the AI features — process your queries through our retrieval systems and, where applicable, third-party large language models, so we can generate answers grounded in indexed lender policy documents.
- To bill you — manage subscriptions, trials, invoices, renewals, dunning and refunds.
- To support you — respond to enquiries, troubleshoot, and provide onboarding and training.
- To secure the Service — detect, investigate and prevent fraud, abuse, unauthorised access, and breaches of our Terms; maintain audit logs.
- To improve the Service — understand which features are used, diagnose faults, measure performance, and develop new features. Where we use content for improvement we aggregate or de-identify it wherever practicable.
- To communicate with you — send service messages, policy update notifications, security notices, billing notices and, where permitted, marketing (see section 13).
- To meet our legal obligations — comply with laws, court orders, regulatory requests, and our record-keeping and tax obligations.
We do not sell personal information. We do not disclose personal information to third parties for their own marketing purposes.
6. How the AI features work, and what that means for your data
CreditPolicy answers questions by searching an index of lender credit policy documents and then using large language models to compose an answer with citations back to the source material.
To do this:
- Your query, relevant retrieved passages from the indexed policy documents, and any context you supply (for example scenario details or client record fields) are sent to our AI model providers for processing.
- The model returns generated text, which we return to you with citations.
- We retain the query and response so you can see your history, so we can support you, and so we can diagnose faults.
Our commitments about AI processing:
- Our AI model providers' terms prohibit them from using content submitted through their APIs to train their general-purpose models, and we rely on and hold them to those terms.
- We do not use your client records or uploaded documents to train models that serve other customers.
- We do not use the Service to make automated decisions that produce legal or similarly significant effects for any individual. The Service produces information and analysis. A human — you — makes every credit-related decision.
AI outputs can be wrong. Generated answers may be incomplete, out of date or incorrect, and lender policy changes frequently. You must verify any output against the lender's current policy document and the lender's own assessment before relying on it. This is reinforced in our Terms of Service.
7. Connecting third-party AI assistants (MCP)
You can connect the Service to third-party AI assistants and developer tools that support the Model Context Protocol — for example Claude (Anthropic), ChatGPT (OpenAI), Perplexity, Cursor, Visual Studio Code and others.
How the connection works. You initiate the connection from within the third-party assistant. You sign in to CreditPolicy through an OAuth 2.0 flow and expressly authorise the assistant to access the Service on your behalf. We never receive your password for the assistant, and the assistant never receives your CreditPolicy password. The assistant receives a scoped access token that you can revoke at any time from your CreditPolicy account settings, or from the assistant's own connector settings.
What data flows where. When you use a connected assistant:
- The assistant sends your prompt (and any information you include in it) to our MCP server.
- We process that request as described in this policy and return the result — policy excerpts, citations, comparisons, scenario assessments, or your own client and deal records — to the assistant.
- That returned data then sits inside your conversation with the third-party assistant, and is handled under that provider's privacy policy and terms, not ours. It may be stored in your chat history with that provider, may be processed on infrastructure outside Australia, and may be subject to that provider's own retention, logging and human-review practices.
What this means for you. If you include your client's personal information in a prompt to a third-party assistant, or ask that assistant to retrieve a client record from CreditPolicy, that personal information is disclosed to the third-party assistant's operator. You are responsible for deciding whether that disclosure is appropriate, for having the necessary consent, and for satisfying your own privacy obligations to your clients. We strongly recommend you review the privacy policy of any assistant before connecting it, and that you avoid putting client-identifying information into third-party assistants unless you have a clear basis for doing so.
Scope of access. The connector exposes read-only access to the lender policy library, and read and write access to your own client and deal records. It cannot delete records, and it cannot access billing information, payment details or other users' data.
Our role. We do not control, endorse or accept responsibility for any third-party AI assistant. We may suspend, restrict or discontinue MCP access, or access for a particular assistant, at any time.
8. Who we disclose personal information to
We disclose personal information to the following categories of recipient, and only as needed for the purposes in section 5:
| Recipient | Purpose | Location |
|---|---|---|
| Supabase | Authentication, identity, and primary application database | Sydney, Australia (AWS ap-southeast-2) |
| Vercel | Web hosting, serverless functions, content delivery, and page-speed measurement | Compute in Sydney, Australia (syd1); global content delivery network |
| OpenAI | Generating answers, comparisons, scenario assessments and document embeddings | United States |
| Google (Gemini API) | AI-assisted document and form analysis | United States and other Google infrastructure locations |
| Amazon Web Services (Amazon SES) | Transactional and notification email | European Union (Ireland, eu-west-1) |
| Stripe | Subscription billing and payment processing | United States and other locations |
| Microsoft (Clarity) | Product analytics, session replay and heatmaps | United States and other Microsoft infrastructure locations |
| Google (Tag Manager) | Tag management for analytics | United States and other Google infrastructure locations |
| Zoho (SalesIQ) | Live chat support on our website, and the chat transcript | United States and other Zoho infrastructure locations |
| Third-party AI assistants you connect | Delivering results into your assistant, at your direction | Determined by that provider — see section 7 |
| Professional advisers | Legal, accounting and audit services | Australia |
| Acquirers | In connection with an actual or proposed sale, merger or restructure of our business | Varies |
| Law enforcement, regulators, courts | Where required or authorised by law | Australia and elsewhere |
We require our service providers to protect personal information consistently with the Privacy Act and to use it only for the purposes we engage them for.
9. Your clients' personal information — how responsibility is split
When you enter your client's personal information into the Service, you remain the entity with the relationship to that individual and the primary privacy obligations to them. We handle that information on your behalf and under your instructions.
By using the Service, you represent and warrant that:
- you have collected your client's personal information lawfully and fairly;
- you have given your client the notice required by APP 5, including that you use third-party software providers and, where relevant, AI-assisted analysis tools to assess their scenario;
- you have any consent required under the Privacy Act, Part IIIA of the Privacy Act, and the Privacy (Credit Reporting) Code, for you to disclose that information to us and, where you choose to use a connected AI assistant, to that assistant's operator;
- you will not enter personal information that is not reasonably necessary for the scenario or record; and
- you will comply with your own privacy policy and your aggregator's and licensee's requirements.
You indemnify us in respect of claims arising from your failure to do these things, as set out in our Terms of Service.
If you receive a request from your client for access to, or correction of, their information held in the Service, you can action it yourself in the application. We will assist you on request.
We do not accept responsibility for Client Data you choose to enter. You are responsible for its accuracy and the lawfulness of its collection and disclosure (including any APP 5 notices and any consents required under Part IIIA and the Privacy (Credit Reporting) Code), and for satisfying your obligations to your client. Where you disclose Client Data to a third‑party AI assistant via MCP, that disclosure is yours and is governed by that provider's terms and privacy policy.
10. Credit information
We are not a credit provider, a credit reporting body, or a credit-related service provider under Part IIIA of the Privacy Act, and we do not obtain credit reports or credit eligibility information from credit reporting bodies.
However, information you enter about your client's financial position, credit history, defaults or repayment history may constitute credit information or credit eligibility information in your hands. Where that is so, your handling of it — including your decision to enter it into the Service or into a connected AI assistant — is governed by Part IIIA and the Privacy (Credit Reporting) Code, and remains your responsibility. We handle it as confidential information under this policy and our Terms.
11. Security
We take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure. These include:
- encryption in transit (TLS) and encryption at rest;
- OAuth 2.0 authentication with scoped, revocable access tokens for connected assistants;
- row-level access controls so users can only reach their own client and deal records;
- hashed and salted password storage;
- access logging and audit trails;
- least-privilege access for our personnel, granted only where needed for support or maintenance;
- regular patching of our infrastructure and dependencies.
No method of transmission or storage is completely secure. We cannot guarantee absolute security, and you use the Service at your own risk. You must keep your account credentials confidential and notify us immediately at privacy@creditpolicy.ai if you suspect unauthorised access.
Eligible data breaches. We comply with the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act. If we suffer an eligible data breach that is likely to result in serious harm, we will notify the Office of the Australian Information Commissioner (OAIC) and affected individuals as required. Where a breach affects your clients' information, we will notify you promptly so you can meet your own obligations.
12. Overseas disclosure
Our core application data — authentication, your account, and your client and deal records — is hosted in Australia (Sydney). However, some of our service providers, and some of the AI assistants you may choose to connect, store or process personal information outside Australia — principally in the United States (AI model processing, billing and analytics) and the European Union (transactional email), and potentially other jurisdictions where those providers operate infrastructure.
Before disclosing personal information to an overseas recipient, we take reasonable steps under APP 8.1 to ensure the recipient does not breach the APPs, including by putting contractual protections in place. By using the Service you acknowledge that:
- personal information may be disclosed to overseas recipients listed in section 8; and
- where you connect a third-party AI assistant, the data returned into that assistant is disclosed at your direction and under that provider's terms, which may involve overseas processing outside our control.
Overseas recipients may be subject to the laws of their own jurisdictions.
13. Direct marketing
We may send you marketing communications about the Service where you have consented or where you would reasonably expect it, consistent with APP 7 and the Spam Act 2003 (Cth).
Every marketing message includes a functional unsubscribe. You can also opt out at any time by emailing privacy@creditpolicy.ai. Opting out of marketing does not stop service messages — billing notices, security alerts, policy update notifications and changes to these documents — which are part of providing the Service.
We do not provide your personal information to other organisations for their direct marketing.
14. Cookies and analytics
We use cookies and similar technologies to keep you signed in, remember your preferences, secure the Service, and understand how it is used. Categories:
- Strictly necessary — authentication, session management, security. These cannot be disabled without breaking the Service.
- Preference — remembering your settings.
- Analytics and performance — understanding feature usage, diagnosing errors, and measuring how quickly pages load. We use Microsoft Clarity, which records anonymised session replays (clicks, scrolls and page interactions) and generates heatmaps, Google Tag Manager for analytics tag management, and Vercel Speed Insights, which measures page-loading speed. Speed Insights sets no cookies and does not identify you: it reports timings for the page you loaded, not a profile of your visit.
- Support — our live chat widget, Zoho SalesIQ, sets cookies so a conversation survives a page refresh and so a returning visitor's chat history stays with them. If you are signed in, we pass your name, email address, brokerage name and subscription plan to SalesIQ so the person helping you can see who they are talking to.
When you first visit, a consent banner lets you accept or decline analytics cookies. If you decline, we do not load Clarity, Google Tag Manager or Speed Insights, and we turn off SalesIQ's page-by-page visitor tracking — the chat widget itself stays available, so declining does not cost you a support channel. Strictly necessary cookies are used regardless, because the Service cannot function without them.
Most browsers also let you block or delete cookies. Blocking strictly necessary cookies will prevent you from signing in.
We do not currently respond to "Do Not Track" browser signals.
15. Data retention
We retain personal information only for as long as we need it for the purposes in section 5, or as required by law.
| Data | Retention |
|---|---|
| Account information | For the life of the account, then 12 months after closure |
| Client and deal records | For the life of the account, then deleted or de-identified within 90 days of closure, unless you ask us to delete them sooner |
| Query and response history | 24 months, then deleted or de-identified |
| Billing and tax records | 7 years, as required by Australian tax law |
| Security and audit logs | 12 months |
| Marketing records | Until you opt out, plus a suppression record so we do not re-contact you |
You can request deletion of your data at any time — see section 16. Some records must be retained to meet legal obligations, and backups are overwritten on a rolling cycle rather than deleted on demand.
16. Access, correction and deletion
You have a right under APP 12 and APP 13 to ask for access to the personal information we hold about you, and to ask us to correct it if it is inaccurate, out of date, incomplete, irrelevant or misleading.
Most information is available directly in your account settings. For anything else, email privacy@creditpolicy.ai. We will:
- acknowledge your request within 5 business days;
- respond within 30 days;
- verify your identity before releasing information;
- provide access free of charge, except that we may charge a reasonable, disclosed fee for the cost of retrieval where a request is substantial.
If we refuse access or correction, we will tell you why in writing and how to complain.
17. Complaints
If you think we have breached the APPs or mishandled your personal information, contact us first at privacy@creditpolicy.ai with the details. We will acknowledge within 5 business days and aim to resolve the complaint within 30 days.
If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner:
- Online: oaic.gov.au/privacy/privacy-complaints
- Phone: 1300 363 992
- Post: GPO Box 5218, Sydney NSW 2001
18. Children
The Service is not directed at, and must not be used by, anyone under 18. We do not knowingly collect personal information from children. If we learn we have, we will delete it.
19. Anonymity and pseudonymity
Under APP 2 you have the option of dealing with us anonymously or under a pseudonym for general enquiries. This is not practicable for the Service itself, because we must identify account holders to authenticate them, bill them, secure their data and meet our legal obligations.
20. Changes to this policy
We may update this policy at any time. The current version is always at creditpolicy.ai/privacy with the "Last updated" date at the top. If we make a change that materially affects how we handle your personal information, we will notify you by email or in-app notice before it takes effect. Continuing to use the Service after a change takes effect means you accept the updated policy.
21. Contact us
Privacy Officer Genesis Chain Financial Group Pty Ltd trading as CreditPolicy.ai and CreditPolicy.com.au ABN 48 625 098 937 | ACN 625 098 937 Registered / office: Ground Floor, 100 Douglas Parade, Williamstown VIC 3016, Australia Email: privacy@creditpolicy.ai General: hello@creditpolicy.ai Victoria, Australia