Legal

Privacy Policy

What we collect, why we collect it, who else can see it, how long we keep it, and how to get it back or have it deleted.

Version 1.0 · Effective 6 August 2026 · Applies to www.coreproofai.com

1. Who we are

CoreProofAI is a survey and design software business based in Australia. This website is operated by Phillip Willis, trading as CoreProofAI.

When you deal with this website, you are dealing with us directly. There is no sales agency, no reseller and no data broker in between.

Our position on the Privacy Act, stated plainly. Under the Privacy Act 1988 (Cth), businesses with an annual turnover of $3 million or less are generally exempt from the Australian Privacy Principles. On turnover, that exemption currently applies to us.

We do not rely on it. We handle personal information as though the Australian Privacy Principles apply, because a business asking you to trust it with survey records and site photographs should not be arguing about whether it has to. Where this policy says we will do something, treat it as a commitment we intend to be held to.

2. What we collect

Only what you type into a form, plus anonymous traffic measurement. We do not buy personal information from anyone, and we do not build profiles of visitors.

Information you give us

WhereWhatRequired?
CoreProof Field waitlistName, email address. Optionally organisation, the kind of work you do, which device you would use, and which tier you are waiting for.Name and email only
Contact formName, email address, and optionally organisation, phone number, what you are interested in, and whatever you write in the message box.Name and email only
Intake Pack downloadName, email address, and optionally organisation and the program you have in mind.Name and email only
Readiness CheckYour answers to five questions about your program, plus the contact details you provide if you ask us to send or discuss the report.Answers are not sent to us unless you submit them
Please do not send us confidential or personal information about other people through these forms. If you want to discuss a real program involving third-party data, tell us and we will set up a proper channel first.

Information collected automatically

We use Cloudflare Web Analytics to count visits. It is cookieless and privacy-first: it does not use client-side state to track you across sites, and it does not fingerprint individuals. We see aggregate numbers, such as how many people opened the pricing page, not who they were.

This website sets no advertising cookies and runs no advertising or social media trackers. That is why you are not being shown a cookie consent banner.

Our hosting provider processes technical information such as IP addresses in the ordinary course of serving and protecting the site. We do not use that information to identify you.

3. Why we collect it

  • To tell you when CoreProof Field is released. If you join the waitlist, that is what the waitlist is for.
  • To answer you. If you send an enquiry, we need somewhere to reply.
  • To send you the thing you asked for, such as the Intake Pack or your Readiness Report.
  • To understand which parts of the site are useful, in aggregate, so we build the right things first.
What we will not do with your email address. We will not add you to a newsletter you did not ask for, run an automated marketing sequence at you, sell or rent your details, or share them with a third party for their own marketing. If you join the Field waitlist, you should expect essentially one email: the one telling you it is out.

4. Who else sees it

We use a small number of service providers to run this site and our email. They process information on our behalf, under their own terms and privacy policies.

ProviderWhat it handlesTheir policy
Web3FormsDelivers form submissions from this website to our inbox.web3forms.com/privacy
CloudflareHosts this website and provides the cookieless analytics.cloudflare.com/privacypolicy
Microsoft 365Our email. Anything you send us is stored in our mailbox.privacy.microsoft.com
GoDaddyDomain registration and DNS only. Does not receive form data.godaddy.com/legal

We may also disclose personal information where we are required to by law. If that ever happens and we are permitted to tell you, we will.

If the business is ever sold or restructured, personal information may transfer with it. Any buyer would be bound by this policy for information collected under it.

5. Where it goes

Our providers operate globally, so your information may be stored or processed outside Australia, including in the United States and other countries where those providers run infrastructure.

We choose established providers with published privacy commitments, and we keep the number of them deliberately small. We cannot, however, guarantee that an overseas recipient will handle your information in a way that meets Australian standards in every respect, and you should read this section as a disclosure rather than a promise about foreign law.

6. How long we keep it

Real periods, not placeholders. We would rather commit to a number and stick to it.

InformationKept for
Waitlist entriesUntil CoreProof Field is released, then 12 months, unless you ask us to remove you sooner. If Field has not been released within 24 months of you joining, we will delete the list or write and ask whether you still want to be on it.
Enquiries and contact form messages24 months after our last exchange with you.
Intake Pack and Readiness Check submissions24 months, unless the conversation becomes an engagement, in which case they are kept as part of the client record.
Client records under a signed engagement7 years after the engagement ends, to meet Australian record-keeping and tax obligations.
AnalyticsAggregate only, retained by Cloudflare under their retention settings. No personal information to delete.

When a period ends we delete the information or de-identify it. Deletion from backups may take longer, but we do not restore deleted personal information from a backup for any purpose other than disaster recovery.

7. How we protect it

  • This site is served over HTTPS; form submissions are encrypted in transit.
  • Our mailbox is protected by multi-factor authentication.
  • Access is limited to people who need it. Today that is a very short list.
  • We collect as little as we can get away with, because the safest record is the one we never made.

No system is perfectly secure, and we will not pretend otherwise. If a data breach occurs that is likely to cause you serious harm, we will tell you and notify the Office of the Australian Information Commissioner, applying the Notifiable Data Breaches scheme as our standard whether or not we are legally required to.

8. AI and this website

The name says AI, so this deserves a direct answer rather than a footnote.

Nothing you submit on this website is sent to an AI service. No form submission, no Readiness Check answer, and no message you write is passed to a language model or any other machine-learning service. We do not use anything you send us to train a model, and we do not permit our providers to.

AI tools are used internally to help build our software and to help encode engineering standards into rules. That is development work, and it is separate from anything you type into this site.

The CoreProof products themselves are deterministic: outputs come from rules that cite the clause they came from and are reviewed by a qualified person. Where AI has been involved in producing anything a customer relies on, we disclose it. If you are assessing us and want the detail, ask and we will provide our internal AI and third-party material disclosure record.

9. Access, correction and deletion

You can ask us at any time to:

  • Tell you what we hold about you;
  • Correct anything that is wrong or out of date;
  • Delete it, including removing you from the waitlist;
  • Send you a copy of what you gave us.

Email intake@coreproofai.com. We aim to respond within 5 business days and to complete the request within 30 days.

There is no charge. We may need to confirm your identity first, and we will only ask for what is necessary to do that. If we cannot action a request in full, for example because we must retain a record to meet a legal obligation, we will tell you why in writing.

You do not need an account, a form, or a particular form of words. An email saying "take me off the waitlist" is enough.

10. Complaints

If you think we have mishandled your personal information, tell us first at intake@coreproofai.com. We will acknowledge it within 5 business days and give you a written response within 30 days.

If you are not satisfied with our response, you can contact the Office of the Australian Information Commissioner: oaic.gov.au, or 1300 363 992.

11. Changes to this policy

We will update this policy as the business changes. The version number and effective date at the top always tell you which version you are reading.

If a change materially reduces the protections described here, and we hold your email address, we will email you before it takes effect rather than quietly republishing the page.

One change is already coming. CoreProofAI is in the process of being incorporated as an Australian proprietary company. When that completes, this policy will be reissued in the company's name with its ACN, and the company will assume the commitments made here.

12. Contact

Privacy questions, access requests, corrections, deletions and complaints all go to the same place, and a person reads it.

intake@coreproofai.com

CoreProofAI · Australia