Inverted
Websites & software Work Vertical Studio
Book a call
Websites & software Work Vertical Studio
Book a call

Legal

Privacy Policy

Version 1.0 Last updated 6 October 2026 Social Mums Club Group Pty Ltd trading as Inverted AI Studio · ABN 96 678 349 310

The short version. We collect the least we can get away with. We do not sell your information, we do not run advertising trackers, and we do not use your content or your customers' data to train AI models.

There are two different situations covered here, and it matters which one you are in: information we hold about you as our own client or enquirer, and information we handle on behalf of a client through a website we built for them. Clause 2 explains the difference.

Contents

  1. 1Who we are
  2. 2Our two roles
  3. 3What we collect
  4. 4Cookies and tracking
  5. 5What we do not collect
  6. 6How we use it
  7. 7AI features
  8. 8Automated decisions
  9. 9Who we share it with
  10. 10Overseas disclosure
  11. 11Security
  12. 12How long we keep it
  13. 13Your rights
  14. 14Data breaches
  15. 15Marketing and email
  16. 16Children
  17. 17Other websites
  18. 18Changes to this policy
  19. 19Contact and complaints

1Who we are

This policy is issued by Social Mums Club Group Pty Ltd (ABN 96 678 349 310), trading as Inverted AI Studio, of 28 Chestnut Street, Wynnum, Queensland 4178, Australia.

It covers:

  • invertedai.studio — this website;
  • The Inverted platform — the private editor our clients use to manage their website content;
  • Websites and software we build, host and maintain for clients, to the extent we handle information through them;
  • Our dealings with enquirers, clients, suppliers and contractors.

1.1 Our commitment under the Privacy Act

The Privacy Act 1988 (Cth) currently exempts most businesses with an annual turnover of $3 million or less. We do not rely on that exemption as a reason to do less. We handle personal information in accordance with the Australian Privacy Principles (APPs) in Schedule 1 of the Privacy Act, and this policy is written to meet APP 1.

Where we handle information about people in the European Union or the United Kingdom, we apply the equivalent protections under the GDPR and UK GDPR.

1.2 What "personal information" means

Information or an opinion about an identified individual, or an individual who is reasonably identifiable — whether or not it is true and whether or not it is recorded. "Sensitive information" is a subset the law protects more strictly, including health information, racial or ethnic origin, political opinions, religious beliefs, sexual orientation and criminal record.

2Our two roles

This is the most important thing on the page, and most privacy policies skip it.

2.1 When we decide (we are responsible)

For information about our own enquirers, clients and client staff — the enquiry you send through this website, the account you hold on the Inverted platform, the emails we exchange, our invoices — we decide what is collected and why. This whole policy applies, and you can exercise every right in clause 13 directly against us.

2.2 When a client decides (they are responsible, we act for them)

When someone fills in a contact form on a website we built for a client, submits an enquiry, or joins a mailing list, that information belongs to our client, not to us. We store and transmit it on their instructions, as their service provider, so that the form works and the enquiry reaches them. We do not use it for our own purposes, do not sell it, and do not combine it across clients.

If you submitted something to a business whose website we built and you want to access, correct or delete it, contact that business — they hold it and they decide. Their own privacy policy governs it. If you cannot reach them, write to us and we will help you make contact and, where the client authorises it, action the request.

In GDPR terms: in clause 2.1 we are a controller; in clause 2.2 we are a processor and our client is the controller.

3What we collect

3.1 Information you give us

  • Enquiries. Your name, email address, phone number (if you provide one), and whatever you write in the message.
  • Platform accounts. Your name, email address, the organisation you act for, your role, and a password — which we never store. We store only a scrypt hash of it, from which the password cannot practicably be recovered.
  • Content you put in the platform. The text, images and files you publish to your website. These may contain personal information if you choose to put it there — staff names and photographs, for example.
  • Project and support correspondence. Emails, briefs, documents, feedback and notes exchanged while we work together.
  • Billing details. Business name, billing address, ABN and payment records. Card numbers, where payments are taken, are handled by the payment provider and never reach our systems.

3.2 Information collected automatically

  • Server logs. Our hosting provider records IP address, timestamp, the page requested, HTTP status, user agent and referring URL for every request. These are standard operational and security records.
  • Website analytics. This website records anonymous events — pages viewed, how far down a page people read, which section they were in, and the hostname of the referring site (for example "google.com"). It sets no cookies, assigns no persistent identifier, and does not follow you to other sites. It honours your browser's Do Not Track setting: if that is on, nothing is sent at all.
  • Error reports. When something breaks, we record the error message, the page it happened on, the browser type and a stack trace, so we can fix it. Reports are stripped of message content and form input.
  • Platform session records. When you sign in we create a session. We store a SHA-256 hash of the session token, the sign-in time, and the time the session was last used — enough to expire it correctly and to detect a stolen session, and not enough to reconstruct the token.
  • Sign-in attempt counts. We count recent failed sign-in attempts against an email address and an IP address, so that a password cannot be guessed at speed. These counters are short-lived.

3.3 Information from others

We may receive your details from a mutual contact who refers you, from a client who asks us to set up an account for you, or from a public business register when verifying an ABN. We do not buy marketing lists.

4Cookies and tracking

4.1 This website

invertedai.studio sets no cookies. There is no advertising pixel, no remarketing tag, no social media tracker and no cross-site analytics. This is why you are not being asked to dismiss a consent banner.

4.2 The platform

The Inverted platform sets one cookie, which is strictly necessary for it to function:

CookiePurposeLifetime
inverted_session Keeps you signed in. Marked HttpOnly, Secure and SameSite=Lax, so it cannot be read by JavaScript and is not sent on cross-site requests. Expires 30 days after sign-in, or 14 days after your last activity, whichever comes first.

The platform also uses your browser's local storage to remember small preferences — a chosen tab, a collapsed panel, a light or dark theme. That data stays in your browser, is never sent to us, and can be cleared from your browser settings at any time.

4.3 Fonts

This website loads the Inter typeface from Google Fonts. Doing so discloses your IP address and browser details to Google, which Google states it uses to serve the font and does not use for profiling or advertising. If you would rather not, a content blocker set to block fonts.googleapis.com will stop it; the site will fall back to your system font and remain fully usable.

4.4 Client websites

Websites we build for clients may use cookies and analytics chosen by that client. Those are the client's decision and are covered by the client's own privacy policy, not this one.

5What we do not collect

  • We do not sell, rent or trade personal information. Not to anyone, not ever.
  • We do not collect sensitive information unless you volunteer it in a message, and we ask that you do not.
  • We do not run advertising or remarketing trackers on our own properties.
  • We do not build profiles of individuals across websites.
  • We do not use your content, your customers' data, or anything you write in the platform to train artificial intelligence models — ours or anyone else's.
  • We do not store card numbers or bank credentials.

6How we use it

We use personal information only for the purposes it was collected for, purposes you would reasonably expect, and purposes required by law. Specifically:

  • To answer you. Replying to an enquiry and following up about it.
  • To deliver the work. Scoping, building, testing, deploying and supporting what you engaged us for.
  • To run the platform. Authenticating you, saving and publishing your content, sending you invitations and password resets, and showing you who changed what.
  • To keep things secure. Detecting and preventing abuse, fraud, credential-stuffing and unauthorised access.
  • To bill and keep records. Invoicing, accounting and tax.
  • To improve what we build. Using aggregate, anonymous usage patterns to decide what to fix and what to build next.
  • To meet legal obligations. Responding to lawful requests, enforcing our terms, and establishing or defending legal claims.

Where the GDPR applies, our lawful bases are: performance of a contract (delivering the services); legitimate interests (securing our systems, improving our product, responding to business enquiries); legal obligation (tax and record-keeping); and consent (marketing email, which you can withdraw at any time).

7AI features

7.1 What is sent, and to whom

The Inverted platform includes a copy assistant that drafts and rewrites website text. When you use it, the text you are working on and the instruction you type are sent to Anthropic PBC (United States) and processed by a Claude model through Anthropic's API.

7.2 The limits we apply

  • It is sent only when you ask for it — using the assistant is a deliberate action, not a background process.
  • We send the content being edited and your instruction. We do not send your account credentials, your customers' records, or content from other clients.
  • Under Anthropic's commercial API terms, inputs and outputs are not used to train their models, and are retained only briefly for abuse monitoring before deletion.
  • We do not retain prompts and responses beyond what is needed to show you the result and, where you accept it, to save it as your content.

7.3 Your part

Do not enter personal information that does not need to be published, credentials, or confidential material into the assistant. If it should not appear on the page, it should not go in the prompt.

8Automated decisions

From 10 December 2026, APP 1 requires an entity to disclose in its privacy policy where it uses personal information in computer programs that make, or substantially help make, decisions significantly affecting an individual's rights or interests. We are stating our position now rather than waiting.

We do not make any decision that significantly affects your rights or interests by automated means. We do not use automated profiling, scoring or eligibility assessment. Decisions about who we work with, what we charge, and whether an account is suspended are made by a person.

Two automated processes exist and neither falls into that category, but both are worth naming:

  • Sign-in rate limiting. Repeated failed sign-ins temporarily slow further attempts. It is a security control, it is time-limited, and it never results in permanent loss of access — a password reset restores it.
  • Spam filtering on enquiry forms. Hidden fields and timing checks discard submissions that were not typed by a person. If a genuine enquiry is ever caught, emailing us directly always works.

The AI copy assistant in clause 7 generates draft text. It makes no decision about any person.

9Who we share it with

9.1 Service providers

We use these providers to run the services. Each may handle personal information to the extent described, and each is bound by its own contractual and security obligations.

ProviderWhat it doesWhere
Vercel Inc.Hosting and content delivery for this website, the platform and client sites. Processes request logs.USA, with edge delivery worldwide
Managed PostgreSQL providerThe database: accounts, site content, enquiries captured through client sites.Australia or Singapore, depending on the deployment
S3-compatible object storageImages and files uploaded through the platform.Australia or Singapore, depending on the deployment
Resend, Inc.Transactional email — invitations, password resets, enquiry notifications.USA
Anthropic PBCThe AI copy assistant described in clause 7.USA
Google LLCServes the Inter typeface on this website (clause 4.3).USA

We review this list as our stack changes and will update this page when it does. A project may add providers specific to it — a payment processor, a booking system, a mapping service — and those are identified in that project's own documentation and the client's privacy policy.

9.2 Professional advisers

Our accountants, lawyers and insurers, where genuinely necessary and under a duty of confidence.

9.3 Legal and safety

We may disclose personal information where required or authorised by law, to respond to a valid request from a court, regulator or law enforcement agency, or where we reasonably believe it is necessary to prevent a serious threat to someone's life, health or safety. We will tell you where we are lawfully able to.

9.4 Business transfers

If our business is merged, restructured or sold, personal information may transfer to the acquirer as part of it, subject to this policy continuing to apply. We will notify affected clients before any such transfer takes effect.

9.5 With your consent

Anything else, only with your consent.

10Overseas disclosure

As clause 9.1 shows, some of our providers are in the United States and some infrastructure may be in Singapore. This is a disclosure of personal information to overseas recipients for the purposes of APP 8.

Before disclosing, we take reasonable steps to ensure the recipient handles the information consistently with the APPs — by contract, by relying on the provider's published data processing terms, and by selecting providers who commit to recognised safeguards such as the EU Standard Contractual Clauses. You should be aware that information held overseas may be subject to lawful access by authorities in that country, and that enforcement of Australian privacy law against a foreign recipient may be difficult.

If keeping all data onshore is a requirement for you, tell us before we start. It is usually achievable and is better decided up front than retrofitted.

11Security

We take reasonable technical and organisational steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure. In concrete terms:

  • Everything is served over HTTPS; the platform is not reachable over plain HTTP.
  • Passwords are hashed with scrypt at parameters meeting current OWASP guidance. We cannot see your password and could not tell you what it is.
  • Session tokens are stored only as SHA-256 hashes, compared in constant time, and expire on both an absolute and an idle timer.
  • Session cookies are HttpOnly, Secure and SameSite=Lax; cross-origin writes are refused.
  • Sign-in and password-reset attempts are rate limited, and reset tokens are single-use and time-limited. Setting a new password invalidates every existing session.
  • Sign-in responses do not reveal whether an email address has an account.
  • Access to production systems is limited to those who need it, and client data is segregated per site.
  • Data is encrypted in transit, and at rest by our hosting and storage providers.

No system is perfectly secure, and we do not claim otherwise. If you find a vulnerability, please tell us at team@invertedai.studio before disclosing it publicly. We will acknowledge within two business days, keep you updated, and we will not pursue anyone who reports a genuine issue in good faith without accessing or destroying other people's data.

12How long we keep it

WhatHow longWhy
Enquiries that do not become projects24 monthsPeople come back, and we want the earlier context
Platform accounts and contentWhile the account is active; deleted from active systems within 90 days of terminationRunning the service; a grace period for change of mind
Session recordsDeleted on sign-out or expiry; expired rows purged regularlyNo reason to keep them
Failed sign-in countersHoursRate limiting only
Server and error logsUp to 90 daysDebugging and security investigation
BackupsRolling, up to 35 daysDisaster recovery; deleted data disappears as backups age out
Invoices and financial records7 yearsRequired by Australian tax law
Project files and correspondence7 years after the engagement endsWarranty, professional records and defending claims

When information is no longer needed for any purpose for which it may be used or disclosed, and we are not required by law to retain it, we destroy it or de-identify it.

13Your rights

You may ask us to:

  • Tell you what we hold about you, and give you a copy;
  • Correct anything inaccurate, out of date, incomplete or misleading;
  • Delete it, where we are not required to keep it;
  • Export your platform content in a machine-readable format;
  • Stop marketing to you, at any time;
  • Deal with us anonymously or under a pseudonym, where that is lawful and practicable. For a general question it usually is; for an account on the platform it is not, because the platform has to know who made a change.

Where the GDPR applies you also have rights to restrict or object to processing, to data portability, and to lodge a complaint with your local supervisory authority.

13.1 How to ask

Email team@invertedai.studio. We may need to verify your identity first — that protection exists for you. We respond within 30 days and normally much sooner, and we do not charge for access requests, though we may charge a reasonable cost for a complex or repeated one and will tell you before doing any work.

If we refuse access or correction, we will tell you in writing why and how to complain.

13.2 If your request relates to a client's website

See clause 2.2. We will pass your request to the client and help where we can, but the decision is theirs.

14Data breaches

We maintain a data breach response plan. If a breach occurs that is likely to result in serious harm, we will assess it promptly and, consistently with the Notifiable Data Breaches scheme, notify affected individuals and the Office of the Australian Information Commissioner as soon as practicable.

Where a breach affects personal information we hold on a client's behalf under clause 2.2, we will notify that client without undue delay and give them the information they need to meet their own obligations.

15Marketing and email

Most of our email is transactional — a reply to your enquiry, a password reset, a notification that someone submitted a form on your site. Those are not marketing and continue regardless of marketing preferences, because you need them.

If we send commercial email, we comply with the Spam Act 2003 (Cth): we send it only with your consent (express, or inferred from an existing business relationship), we identify ourselves clearly, and every message carries a working unsubscribe link that we action within five business days. You can also just reply and ask.

We do not supply your address to anyone else for their marketing.

16Children

Our services are for businesses. The platform is not offered to anyone under 18, and this website is not directed at children. We do not knowingly collect personal information from a child. If you believe we have, tell us and we will delete it.

Where a client's website is directed at families or children, we will work with that client on the additional protections their situation requires.

17Other websites

Our site and client sites link to other websites. We are not responsible for their privacy practices, and this policy does not apply to them. Read their policy before giving them anything.

18Changes to this policy

We may update this policy. The version number and date at the top always identify the current version. Where a change materially affects how we handle your personal information, we will notify platform account holders and current clients by email at least 14 days before it takes effect. Other changes take effect when published.

19Contact and complaints

For any privacy question, request or complaint:

Privacy Officer — Social Mums Club Group Pty Ltd trading as Inverted AI Studio
ABN 96 678 349 310
28 Chestnut Street, Wynnum, Queensland 4178, Australia
team@invertedai.studio

19.1 How we handle a complaint

Put it in writing to the address above with enough detail for us to investigate. We will acknowledge within 5 business days, investigate, and give you a written response within 30 days. If we need longer we will tell you why and when to expect an answer.

19.2 If you are not satisfied

You may take the matter to the Office of the Australian Information Commissioner:

  • Online: oaic.gov.au/privacy/privacy-complaints
  • Phone: 1300 363 992
  • Post: GPO Box 5218, Sydney NSW 2001

In the EU or UK, you may complain to your local data protection authority.

This policy is published under APP 1.3 and is available free of charge to anyone who asks, in an alternative format on request.

© 2026 Social Mums Club Group Pty Ltd trading as Inverted AI Studio. All rights reserved.

Back to top

Inverted

Websites, apps and custom software for growing businesses — designed properly, and looked after once they're live.

Book a call
Websites & software Work Vertical Studio How a build runs Terms Privacy
© 2026 Inverted AI Studio