Last updated 21 August 2026

Privacy Policy

This Privacy Policy describes how Ovio collects, uses, discloses, stores, and protects information in connection with the Ovio website, application, connected services, support, billing, security, and operational systems.

1. Who we are

Ovio is an Australian record-keeping and tax-time preparation tool for small businesses, sole traders, and freelancers. In this policy, the terms Ovio, we, us, and our mean Loom Labs Pty Ltd (ABN 21 677 704 666), the operator of the Ovio service at ovio.au, app.ovio.au, api.ovio.au, and related Ovio domains.

2. What this policy covers

This policy explains how we collect, use, disclose, store, and protect information when you visit the public website, join an Ovio product waitlist, create an account, use Ovio, connect third-party services, send receipt material to Ovio, pay for a plan, or contact support. It may be amended as the Ovio service, our providers, or applicable requirements change.

3. Privacy law and rights

We handle personal information under applicable Australian privacy obligations, including the Australian Privacy Principles where they apply to us. You may ask to access or correct personal information we hold about you, and you may make a privacy complaint by contacting Ovio's Privacy Officer at [email protected]. We may need to verify your identity before acting on account-specific requests. If you are not satisfied with how we deal with a privacy complaint, you may be able to contact the Office of the Australian Information Commissioner.

4. Information we collect

  1. Account, sign-in, MFA, session, trusted-browser, workspace, role, permission, and billing status information.
  2. Business and workspace details you add, including categories, notes, settings, and record status.
  3. Receipt files, images, PDFs, previews, extracted fields, source details, and review decisions.
  4. Bank CSV imports, mapped transaction rows, import metadata, descriptions, amounts, dates, and matching status.
  5. Email and WhatsApp receipt ingest details, including sender, recipient alias, message identifiers, attachment metadata, media, delivery status, and security metadata.
  6. Google sign-in information, if you choose Google sign-in, including your name, email address, profile image, and Google account identifier.
  7. Stripe billing identifiers, billing contact details, plan status, payment status, payment method summary, invoice references, tax invoice details, and billing portal activity. Ovio does not store full card numbers.
  8. Website, product, analytics, referral, campaign, device, browser, page-view, interaction, and approximate location information.
  9. Ovio Request waitlist details, including your email address, submission source, submission time, and the consent wording and version shown when you joined.
  10. Support emails and other messages you send to us, including attachments and context needed to help you.
  11. Security, audit, server, observability, device, browser, IP address, request, error, and diagnostic logs.

5. How we collect information

We collect information when you provide it directly, including when you join a product waitlist, when you upload or forward receipt material, when you import bank CSV files, when you connect or use third-party services, when payment and support providers send us status updates, and when our systems create logs needed to run, secure, and improve Ovio.

6. Third-party information you provide

Receipts, invoices, bank CSV files, emails, WhatsApp messages, attachments, exports, and support requests may include personal information about customers, suppliers, employees, contractors, advisers, or other third parties. You are responsible for ensuring that you have authority, consent, or another lawful basis to provide that information to Ovio and to allow Ovio and its providers to process it for the purposes described in this policy.

7. Sensitive information

Receipts, bank records, emails, WhatsApp messages, support attachments, and other materials you provide may incidentally include sensitive information. Do not submit sensitive information to Ovio unless it is reasonably necessary for your use of the service and you are authorised to provide it. Where sensitive information is included in records you submit, we process it only as part of providing, securing, supporting, and administering Ovio, or as otherwise required or permitted by law.

8. How we use information

  1. Provide the Ovio service, including sign-in, MFA, workspaces, receipt capture, transaction import, matching, review queues, BAS/GST prep visibility, and export.
  2. Process receipt files and bank CSV rows into records you can review.
  3. Maintain account security, detect abuse, troubleshoot issues, and respond to support requests.
  4. Manage Free plan access, paid subscriptions, plan limits, invoices, payment status, and billing access.
  5. Send service messages such as security, password reset, billing, receipt-ingest, and support emails.
  6. Contact people who join the Ovio Request waitlist about Request development and availability.
  7. Send product or marketing communications where permitted by law and measure marketing campaign performance.
  8. Monitor reliability, diagnose errors, improve product quality, protect safety and security, and keep records required for legal, tax, security, and dispute purposes.

9. AI processing

Ovio uses AI to extract structured fields from receipt images and PDFs and to make bank transaction descriptions easier to review. Information from records you submit, including receipt images, PDF pages, merchant details, dates, amounts, GST fields, transaction descriptions, and surrounding review context, may be sent to AI providers for those tasks. Langfuse may process prompt, model-call, trace, error, and observability metadata needed to run, debug, monitor, and improve the reliability and product quality of Ovio AI workflows. Where practicable, improvement analysis uses aggregated or de-identified information. AI output may be incomplete or incorrect. You must review Ovio AI suggestions before relying on them. Ovio does not use AI to decide business versus personal use, infer GST when GST is not shown, lodge BAS/GST, or provide tax, accounting, legal, or financial advice. We do not use your submitted receipt, bank transaction, workspace, or business records to train general AI models.

10. Google sign-in

If you choose Google sign-in, Google may provide Ovio with basic Google account information needed for sign-in: your name, email address, profile image, and Google account identifier. Google sign-in does not give Ovio access to your Gmail.

11. WhatsApp receipt forwarding

Where WhatsApp receipt forwarding is enabled, Ovio receives receipt photos, files, sender details, message content, media, delivery status, and security metadata through the WhatsApp Business Platform or Cloud API. Ovio may also send service replies through WhatsApp about receipt delivery, routing, or processing. WhatsApp is operated by Meta, and Meta may process sender, message, media, delivery, device, and diagnostic data globally under Meta's and WhatsApp's own terms, privacy policies, infrastructure, retention rules, and cross-border processing arrangements. You can stop using WhatsApp receipt forwarding by not sending further messages, disconnecting the receipt source where available, replying STOP where supported, or contacting [email protected].

12. Cookies, analytics, and security technologies

Ovio uses cookies and similar technologies for sign-in sessions, trusted browsers, security checks, and site operation. We use Sentry, Langfuse, server logs, and product measurement technologies to understand errors, AI workflow reliability, website and product usage, referral sources, campaign performance, and feature quality. We may use other analytics or marketing measurement providers as those systems change. We may use local or session storage for interface state or preferences. Ovio uses httpOnly cookies rather than browser storage for auth tokens. We may use Cloudflare Turnstile to reduce automated abuse. Do not block security cookies if you need to sign in or use protected parts of Ovio.

13. Marketing and service messages

We may send service messages about security, account access, billing, receipt ingest, support, product changes, and legal updates. These are not marketing messages and may be required to provide Ovio. We may also send product or marketing communications where permitted by law. Marketing communications will identify the sender and include a functional unsubscribe or opt-out method where required by Australian spam laws. You can opt out of marketing communications, but not required service or account messages. If you join the Ovio Request waitlist, we may contact you about Request development and availability. You can opt out of those updates at any time using the method included in the message or by contacting us.

14. Sharing and service providers

We share information with service providers only as needed to run Ovio, secure it, process user-directed records, provide support, manage billing, measure product or marketing performance, or meet legal obligations. Providers may have their own terms, privacy policies, retention practices, subprocessors, and cross-border processing arrangements. We may also disclose information in connection with a restructure, financing, merger, acquisition, sale, or transfer of the Ovio business or assets. We do not sell personal information. Current providers that may process account, business, receipt, billing, support, security, or operational information include:

  1. DigitalOcean for hosting and managed PostgreSQL database services.
  2. DigitalOcean for marketing API hosting and its persistent waitlist storage, and Cloudflare for Turnstile bot checks, DNS, and proxy/security services where enabled.
  3. Resend for inbound receipt email and transactional email.
  4. OpenAI for AI-assisted receipt extraction and transaction-description assistance.
  5. Langfuse for AI prompt management and model-call observability.
  6. Stripe for checkout, subscriptions, invoices, payment status, tax invoice details, payment events, and the hosted billing portal. See Stripe's Privacy Policy.
  7. Twilio for SMS MFA and related verification messages.
  8. Sentry for error monitoring and production diagnostics.
  9. Meta and WhatsApp for WhatsApp Business Platform or Cloud API receipt messaging, service replies, media, message status, and delivery data where WhatsApp receipt forwarding is used.
  10. Google for Google sign-in only.
  11. Apple iCloud custom email for human support email at [email protected].

15. Storage, security, and overseas disclosure

We use technical and organisational safeguards appropriate for an early-stage SaaS product, including private file storage, time-limited file links, server-side file validation, hashed passwords, httpOnly auth cookies, MFA support, scoped application access, webhook signature checks, and operational logging. Providers may process or store data in Australia, the United States, the European Union, the United Kingdom, Singapore, or other countries where they or their subprocessors operate, and those locations may change as provider infrastructure changes. Where Australian privacy law requires reasonable steps before disclosing personal information overseas, we take reasonable steps in the circumstances to ensure overseas recipients handle it consistently with the Australian Privacy Principles or that another permitted basis applies. Ovio personnel and contractors may access information only where reasonably needed for operations, support, security, billing, legal, or abuse-handling purposes.

16. Notifiable data breaches

If we suspect a data breach, we will assess it under applicable law. If we identify an eligible data breach under Australia's Notifiable Data Breaches scheme, including where unauthorised access, disclosure, or loss of personal information is likely to result in serious harm and remedial action has not prevented that risk, we will notify affected individuals and the Office of the Australian Information Commissioner as soon as practicable where required.

17. Retention, export, and deletion requests

We keep information while your account is active and for as long as reasonably needed for service operation, billing, security, backups, legal compliance, dispute handling, tax and accounting records, fraud prevention, product integrity, and legitimate business records. Waitlist entries are kept while they are useful for the stated product-update purpose or until you ask us to remove them, subject to records we must retain. You can request access, correction, export, or deletion by contacting us. Deleting an account, workspace, connected service, or receipt source may not immediately remove information from backups, logs, billing records, security records, legal records, or records we are legally required or reasonably entitled to keep. Disconnecting a connected service stops future collection from that connection but does not automatically delete records already imported into Ovio.

18. Access, correction, and complaints

You can ask us to access or correct personal information we hold about you. If you have a privacy complaint, email Ovio's Privacy Officer at [email protected] with enough detail for us to investigate. We aim to respond within 30 days where practicable and may need to verify your identity before acting on account-specific requests. If you are not satisfied with our response, you may be able to complain to the Office of the Australian Information Commissioner.

19. Children, anonymity, and business use

Ovio is designed for business record keeping by adults, small businesses, sole traders, and freelancers. It is not directed at children. Some public website browsing or general enquiries may be possible without identifying yourself, but most Ovio features require an identified account, workspace, billing status, and security records. Do not use Ovio if you are not able to enter into these arrangements or do not have authority to provide the business records you submit.

20. Changes and contact

We may update this policy as Ovio, our providers, or legal requirements change. The latest version will be posted on this page with a new last-updated date. Contact Ovio's Privacy Officer at [email protected].