Scope and the laws we work under
Australian Privacy Act, New Zealand Privacy Act, and United States state law.
Kwirl Australia Pty Ltd is an APP entity under the Privacy Act 1988 (Cth) and handles personal information in line with the thirteen Australian Privacy Principles and the Notifiable Data Breaches scheme.
For users in New Zealand we also comply with the Privacy Act 2020 and its thirteen Information Privacy Principles, including the notification duties to the Office of the Privacy Commissioner.
For users in the United States we comply with applicable state privacy laws, including the California Consumer Privacy Act as amended by the CPRA, and the equivalent statutes in Colorado, Connecticut, Virginia, Texas and Utah. We do not sell personal information as those laws define selling, and we do not share it for cross-context behavioural advertising.
What we collect
Account details, what you publish, what you apply to, and how you use the product.
We collect what you give us and what the product needs to run. We do not buy personal information from data brokers and we do not scrape your other profiles to enrich your record.
- Account information: name, email, password hash, phone number where you add one for verification, and your city.
- Showcase content: work history, case studies, images, video intro, skills, endorsements and anything else you publish.
- Job search information: applications, saved roles, salary expectations, right-to-work status, and your open-to-work signal.
- Kira conversations: what you ask, what it drafts, and the facts you let it remember. You can read and delete these in settings.
- Usage and device information: pages viewed, features used, IP address, browser and device type, and crash logs.
- Billing information for paid plans: company name, billing address and tax details. Card numbers go straight to our payment provider and never touch our servers.
- Sensitive information: we only collect health, disability or accessibility information where you volunteer it for an adjustment request, and we only use it for that request.
Why we use it
To run the service you asked for, to match you to roles, to keep the platform safe, and to bill you.
We use personal information to operate your account, deliver applications, run matching, produce your analytics, prevent fraud and abuse, meet our legal obligations, and to contact you about the service.
We use aggregated and de-identified data to publish market statistics, such as response-rate benchmarks and salary bands by role. Those outputs cannot be traced back to an individual.
We do not use your Kira conversations to train third-party foundation models. Model training on your content only happens if you switch it on, and it is off by default. See the AI Policy for detail.
Who sees it
Employers see what you publish and what you send them. Nobody else buys it.
An employer sees your showcase as you have configured its visibility, plus the application you sent to their role. Your open-to-work signal is shown only to organisations with a live role that plausibly matches you, and never on a public profile.
We use service providers to run the platform — cloud hosting, email delivery, error monitoring, payment processing and customer support tooling. They act on our instructions under contract and cannot use your information for their own purposes.
We disclose personal information where the law requires it: a valid court order, a regulator exercising statutory power, or where disclosure is necessary to prevent a serious threat to life, health or safety.
Where your data lives and cross-border transfer
Primary storage is in Australia. Some providers process data overseas.
Production data is stored in Australian regions of our cloud provider.
Some of our processors operate in the United States (for example Cloud Functions that run alongside the Australian datastore). Where personal information leaves Australia we take reasonable steps under APP 8 to ensure the recipient handles it consistently with the Australian Privacy Principles, through contractual clauses and vendor assessment. For New Zealand users the equivalent step is taken under IPP 12.
A list of our sub-processors and the countries they operate in is available on request from privacy@kwirl.com.au.
How long we keep personal information
Only as long as needed. Soft-deleted content is removed after about 30 days.
We keep personal information only for as long as needed for the purposes in this policy, including to operate Kwirl, meet legal and accounting requirements, resolve disputes, and enforce our agreements (Australian Privacy Principle 11.2).
Unless a longer period is required by law: your account and core product data (posts, likes, active chats, applications) stay while your account is open; content you delete in the app is hidden immediately and permanently removed about 30 days later; profile views, notifications and opted-in Kira activity signals are kept for up to 90 days; feed ranking signals for about 14 days; moderation reports for 24 months; and billing records as required by tax and company law.
The full record-by-record schedule is in our Data Retention and Deletion Policy. If you apply to a job, the employer may keep their own copy under their policies — contact them to request deletion of that copy.
Your rights
Access, correction, deletion, portability, and a right to complain.
You can access and correct most information directly in settings. For anything you cannot reach yourself, email privacy@kwirl.com.au and we will respond within 30 days.
- Access: ask for a copy of the personal information we hold about you.
- Correction: fix anything inaccurate, out of date or incomplete.
- Deletion: close your account and have your data deleted on the timetable in the Data Retention and Deletion Policy.
- Portability: export your showcase, applications and Kira memory as JSON at any time.
- Opt-out rights: United States users may opt out of targeted advertising and profiling, and may nominate an authorised agent to act for them. Kwirl does not sell personal information.
Direct marketing and communications
Product email you can leave. Legal and security email you cannot.
Marketing email carries an unsubscribe link and honours it within five business days, as required by the Spam Act 2003 (Cth) and the Unsolicited Electronic Messages Act 2007 (NZ).
We will still send you transactional messages you cannot opt out of: security alerts, billing receipts, changes to these policies, and notices we are legally required to give.
Complaints
Come to us first, then the regulator in your country.
Send a complaint to privacy@kwirl.com.au. We acknowledge within five business days and aim to resolve within 30 days.
If you are not satisfied, you can escalate. In Australia, to the Office of the Australian Information Commissioner at oaic.gov.au. In New Zealand, to the Office of the Privacy Commissioner at privacy.org.nz. In the United States, to your State Attorney General, or the California Privacy Protection Agency if you are a California resident.
Questions about this policy
Write to legal@kwirl.com.au for anything on this page, privacy@kwirl.com.au for a privacy request, or security@kwirl.com.au to report a vulnerability. Postal mail reaches us at Kwirl Australia Pty Ltd, Australia.