← Back

Privacy Policy, The Anthroposophy App (www.anthroposophy.app)

Version 1.2. Operator: VirgoLabs, ABN 62 345 335 476, Australia. This policy takes effect on the date of its publication at www.anthroposophy.app/privacy and remains in force until replaced by a later version.


Part A - The operator, this policy, and the Privacy Act

A.1 The platform and the operator. The Anthroposophy App is a community platform for people interested in anthroposophy, offered as a website at www.anthroposophy.app and as a mobile application, both running on one shared backend. Members can publish posts with images, comment, create and join events, courses and groups, maintain a profile, and follow one another. The platform is operated by VirgoLabs, ABN 62 345 335 476, based in Australia. References in this policy to "we", "us" and "the operator" are references to VirgoLabs, references to "the platform" cover both the website and the mobile application, and references to "member" mean a person holding an account. The operator's public identifiers for privacy purposes are the ABN above and the privacy contact in Part L.

A.2 Definitions. This policy uses the following terms in the meanings the Privacy Act 1988 (Cth) (the Privacy Act) gives them, quoted from the current compilation of the Act.

  • Personal information means "information or an opinion about an identified individual, or an individual who is reasonably identifiable: (a) whether the information or opinion is true or not; and (b) whether the information or opinion is recorded in a material form or not" (Privacy Act s 6(1)).
  • Sensitive information means, relevantly, "information or an opinion (that is also personal information) about an individual's racial or ethnic origin, political opinions, membership of a political association, religious beliefs or affiliations, philosophical beliefs, membership of a professional or trade association, membership of a trade union, sexual orientation or practices, or criminal record", together with health, genetic and certain biometric information (Privacy Act s 6(1)). Philosophical beliefs and religious beliefs or affiliations are named limbs of this definition, a point of central importance to this platform, addressed in Part C.
  • Consent means "express consent or implied consent" (Privacy Act s 6(1)).
  • An entity holds personal information "if the entity has possession or control of a record that contains the personal information" (Privacy Act s 6(1)).
  • Collection, use and disclosure carry their ordinary meanings under the Act: collection is obtaining personal information for inclusion in a record, use is handling within the entity, disclosure is making information accessible to others outside it.
  • APP entity means an agency or organisation to which the Australian Privacy Principles (the APPs, Schedule 1 to the Privacy Act) apply. OAIC means the Office of the Australian Information Commissioner.

A.3 The operator and the Privacy Act. The Act binds APP entities. An "organisation" is "an individual, a body corporate, a partnership, an unincorporated association, or a trust", excluding among others a "small business operator" (Privacy Act s 6C(1)). Section 6D(1) provides that "a business is a small business at a time (the test time) in a financial year (the current year) if its annual turnover for the previous financial year is $3,000,000 or less", and s 6D(3) provides that a small business operator is a person or entity that "(a) carries on one or more small businesses; and (b) does not carry on a business that is not a small business". The operator has confirmed that the aggregate annual turnover of all businesses it carries on is $3,000,000 or less, it does not disclose personal information about anyone for a benefit, service or advantage, and it does not provide a benefit, service or advantage to collect personal information about anyone (the trading conduct that s 6D(4) would otherwise catch, see also E.6). On those facts the operator is a small business operator and the Privacy Act does not apply to the platform automatically. The operator has chosen not to rest anything on that exemption, for the reasons in A.4.

A.4 The posture this policy adopts. This policy applies the Australian Privacy Principles as binding practice from the date it takes effect. The operator has further chosen to be treated as an organisation under s 6EA of the Act, under which a small business operator may elect, by written notice to the Information Commissioner, to have the Act apply to it as law rather than as practice; that notice will be lodged before the platform's public launch, and the Act's disciplines, including the data breach scheme in Part J, are applied from adoption whatever the registration date. The reasons are structural rather than cosmetic: the platform collects and holds sensitive information within the statutory definition, membership of an anthroposophy community platform may itself reveal a person's philosophical or religious beliefs, several classes of member data are displayed to the public by design, and community life of this kind involves families, so the information held is of a kind whose mishandling causes real harm. A privacy posture that turned on a turnover threshold would not be a defensible one for this platform.


Part B - What we collect

B.1 Information you give us directly. The platform collects twenty-three categories of personal information directly from you. Each exists in the code as at the census date in L.5, none is speculative, and no category has been omitted.

Account: (1) your email address, held by the authentication service and used for sign-in, confirmation and password reset; (2) your password, held only in hashed form by the authentication service and never readable by the operator.

Profile: (3) a unique handle; (4) a display name; (5) a profile photo; (6) a free-text bio; (7) your home country; (8) your home region or state; (9) your home locality, down to suburb and postcode; (10) your chosen fields of interest. Items (7) to (9) are optional, and Part E states exactly how much of them is ever shown publicly.

Records about your account: (11) a record of the Terms of Use version you accepted and when.

Content and submissions: (12) posts, including titles, bodies and audience settings; (13) comments; (14) events and courses you create, including titles, descriptions, times, venues and attachments; (15) groups you create, including names, descriptions and locations; (16) blog and explore-page content, where you are an administrator author; (17) free-text suggestions you submit, for new fields or locations; (18) images you upload; (19) documents you upload; (20) reports you file about content or conduct, including your free-text reason.

Relationships and preferences: (21) whom you follow; (22) your saves, your group memberships and your pending join requests; (23) your notification and feed preferences.

B.2 Information about you that others provide. It would be false to state that all personal information on the platform is collected directly from the person it concerns, and this policy does not state it. The platform also collects information about you indirectly, in the following measured ways: another member may mention or tag you in a post or comment; an event organiser may add you to a private event's invitee list; a post author may name you on the list of followers permitted to see a restricted post; a group owner may add you to, or approve you into, a group; another member may file a moderation report about you or your content, with a free-text reason; moderators and administrators create moderation actions, ban records and appeal records about members; and the free text of any post, comment, event or group description may name or describe you, whether or not you hold an account. Where the platform holds information about a person collected in these ways, this policy applies to it, and the notification measures in L.4 are the practicable notice of that collection.

B.3 Cookies and device storage. The website sets authentication session cookies through the Supabase client library (named in the pattern sb-<project>-auth-token), which are essential to staying signed in. The website also stores a small number of values in your browser's localStorage, where they stay on your device and are transmitted to no one: your chosen browse countries (aia_web_countries, with a legacy key aia_web_country), your chosen display language (anthro-lang), the unsent draft of a post you are composing (compose_draft_v1), and whether you have seen or dismissed the install-as-app hint (anthro_install_dismissed, anthro_ios_install_dismissed, anthro_ios_visit_count). If you install the website as an app, a service worker keeps copies of the site's static interface files in your browser's cache so pages can load offline; it caches only files on an explicit static allowlist, never your signed-in content and never anything from the platform's data service. The mobile application stores your authentication session on the device in AsyncStorage. No analytics, advertising or tracking cookie, and no third-party tracking script or SDK, exists on either surface.

B.4 What we do not collect. The platform collects no date of birth, no payment details, no government identifiers, no device advertising identifiers, no location telemetry from your device (your home location is only what you type into your profile), and no push notification tokens (a push preference exists in the settings screens, the delivery machinery behind it is not built). No analytics or behavioural tracking service receives your data. If any of these positions changes, this policy will be revised before the change ships.

B.5 Data sources that are not about you. Place reference data (countries, regions, localities) derives from the GeoNames geographical database, used under a CC BY 4.0 licence and imported into the platform's own database. No member data is sent to GeoNames.


Part C - Sensitive information

C.1 Why this Part leads. The Privacy Act's definition of sensitive information names "religious beliefs or affiliations" and "philosophical beliefs" as protected limbs (s 6(1), quoted in A.2). Anthroposophy is a spiritual and philosophical movement, so the fact of holding an account here, your chosen fields of interest, the groups you join, the events you attend and the content you write may each reveal, or support an inference about, your philosophical or religious beliefs. Sensitive information attracts a higher collection standard than ordinary personal information, this is central to the platform rather than incidental, and the platform's posture is to treat all member data connected to participation in the community to the sensitive-information standard, rather than to argue item by item about which fields qualify.

C.2 The collection standard. APP 3.3 provides that an APP entity "must not collect sensitive information about an individual unless the individual consents to the collection of the information and the information is reasonably necessary" for one or more of the entity's functions or activities. Collection here rests on your express consent: you create the account, you choose each profile field, and you choose each group, each event and each post. Joining an anthroposophy community may itself reveal your beliefs, so the signup flow on both surfaces presents a consent statement saying so, and creating an account records your agreement to the collection and handling of that information as this policy describes. Participation is not possible without holding the account data, and each sensitive-adjacent item beyond it is individually optional.

C.3 The consequence of public display. Part E describes which classes of member data are displayed to the public. Where you place information revealing your beliefs into a public field, a public post or a public group, that sensitive information is disclosed to anyone on the internet, without an account, by design. You control this through what you choose to publish and through each post's audience setting, and the platform does not add belief labels to anyone's data of its own motion.


Part D - Why we collect it and how we use it

D.1 Purposes of collection. The platform collects the categories in Part B for the following primary purposes: operating the service (accounts, sign-in, profiles, feeds filtered by country, events, courses, groups, comments, follows, saves); showing your content to the audiences you select; sending service messages (email confirmation, password reset, and the notifications you have enabled in your preferences); moderating the community (receiving reports, reviewing content, recording moderation actions, applying and lifting bans, running appeals); maintaining the integrity of the service (rate limits, terms-acceptance records); and meeting legal obligations.

D.2 The use and disclosure discipline. APP 6.1 provides that where an entity "holds personal information about an individual that was collected for a particular purpose (the primary purpose), the entity must not use or disclose the information for another purpose" without consent or another permitted basis. The operator's commitments under that discipline are these: your personal information is not sold, rented or traded to anyone; it is not used for third-party marketing, profiling or advertising; it is not disclosed for any benefit, service or advantage to the operator; and any new purpose will be put to you for consent, or notified through a revision of this policy, before it begins. These commitments also underpin the position in A.3, since the platform does not trade in personal information.


Part E - Who can see your information

E.1 Disclosure to the public. The website has no login wall, its public pages are readable by anyone on the internet without an account, and search engines can index them. Six classes of member data are disclosed to the public in this way, each verified in the platform's access rules:

1. Member profiles, including handle, display name, photo, bio, fields of interest, join date, and, where you have set them, your home country and your home region or state. Nothing finer is shown: your suburb and postcode are never displayed on your public profile, and the database rule that backs public profile reads does not include your locality at all. Every location field is optional, and you can leave them all empty. 2. Public posts, with the author's name, handle and photo. 3. Public events and courses, with the organiser's identity, title, description, times and location. 4. Public groups, with name, description and location. 5. Comments on any publicly visible content, with the commenter's identity. 6. Published blog posts, explore pages, announcements and featured items.

Attachment records (file name, type, size) on public content are also publicly readable. The underlying image or document bytes are not directly public, they are fetched through time-limited signed links that only signed-in members can mint, and any such link remains usable by anyone who holds it for its one-hour life.

E.2 Disclosure to other members. Members additionally see, according to the audience rules of each item: restricted posts they are permitted to see, private events they are invited to, group content of groups they belong to, who follows whom, group member lists, mention tags, and invitee lists, in each case limited to the relevant counterparties by the platform's access rules. The home locality you have optionally set on your profile remains readable to signed-in members under those rules, at the suburb level you provided.

E.3 Disclosure to moderators and administrators. Moderators and administrators see reported content, reporter identities and report reasons within their moderation scope, they record actions about members (clearances, removals, escalations, bans, appeal outcomes) with free-text notes, and those records are retained as the platform's moderation history.

E.4 Disclosure to service providers. The platform runs on Supabase, a hosted backend service providing the database, authentication and file storage, so every category in Part B is held on Supabase infrastructure; where that data lives is set out in Part F. Transactional email (sign-up confirmation, password reset, and the notifications you have enabled) is sent through Resend, an email delivery provider in the United States, which handles your email address and the content of those messages for delivery. Mail you send to the platform's contact addresses in Part L is received into mailboxes hosted by Proton AG in Switzerland.

The website offers a translation control. Where you choose a display language, the text of the pages you view, which can include members' posts, comments, profiles, and event and group descriptions, is sent by the platform's own server to Google Cloud Translation (Google LLC, United States), and the translation is returned to your browser. The request carries the text being translated and the language pair, it does not carry your name, account or email address, and translated text is cached in your own browser for the session rather than stored by the operator. The mobile application contains the same translation capability in its code, and it is not enabled there as at this policy's date.

Uploaded images are screened against databases of known child sexual abuse material. Screening runs on the shared backend that serves both the website and the mobile application, so an image uploaded through either surface is screened after it is stored, and the website additionally checks an image before upload. The operator uses Project Arachnid Shield, operated by the Canadian Centre for Child Protection in Canada; Microsoft PhotoDNA (United States) is a named alternative that is not in use. When an image is screened, the image data is sent to the screening provider for matching against known illegal material, and for no other purpose. Beyond the providers named in this clause, no third party receives member data, and this policy will be revised before any new service provider is added.

E.5 Disclosure required or authorised by law. The operator will disclose personal information where required or authorised by Australian law, including to courts, law enforcement and regulators with lawful authority, and, in respect of illegal content, to the eSafety Commissioner and police where the law requires or permits it.

E.6 No sale. The operator does not sell, rent or trade personal information, and does not disclose it to any person for a benefit, service or advantage.


Part F - Overseas disclosure

F.1 The rule. APP 8.1 provides that before an APP entity discloses personal information to a person "who is not in Australia or an external Territory", the entity "must take such steps as are reasonable in the circumstances to ensure that the overseas recipient does not breach the Australian Privacy Principles". Under s 16C of the Act, an entity that discloses personal information to an overseas recipient is, in certain circumstances, accountable for the recipient's acts, which are "taken to have been done by the APP entity". The OAIC's APP guidelines add that providing information to an overseas cloud provider may be a "use" rather than a "disclosure" where a binding contract limits handling, subcontractors carry the same obligations, and the entity retains effective control of the information (APP Guidelines ch 8, paragraphs 8.10 and 8.14).

F.2 Where your data lives. Production data is hosted in Supabase's Sydney region (ap-southeast-2), so the primary copy of all platform data remains in Australia. Supabase is operated by a corporate group headquartered in the United States, so even with Australian-region hosting, technical support access, sub-processing and backup arrangements may involve access from outside Australia. The operator treats that possibility as overseas handling and discloses it here, without resting anything on the finer question whether the arrangement is a "use" or a cross-border "disclosure" under the guidelines above: either way you are told, and either way the operator holds itself to the discipline in F.1.

F.3 Countries. APP 1.4 asks a privacy policy to state the countries in which overseas recipients are likely to be located, if practicable. They are: Australia, for primary hosting (Supabase, Sydney region); the United States, for Supabase's corporate group, for Resend (transactional email) and for Google LLC (translation, when you request it); Switzerland, for Proton AG, which hosts the operator's contact mailboxes; and Canada, for the Canadian Centre for Child Protection (Project Arachnid Shield), to which uploaded image data is sent for screening against known child sexual abuse material. Microsoft PhotoDNA (United States) is a named alternative that is not in use.


Part G - Security

G.1 The standard. APP 11.1 provides that an entity holding personal information "must take such steps as are reasonable in the circumstances to protect the information: (a) from misuse, interference and loss; and (b) from unauthorised access, modification or disclosure".

G.2 Measures in place. The platform enforces its visibility model in the database itself, through row-level access rules evaluated on every read, rather than only in the user interface. Uploaded files live in a private storage bucket, are addressed by randomised paths, and are served through signed links that expire after one hour. Passwords are hashed by the authentication service and are never held readable. Posting, commenting and creating content require a confirmed email address. Moderation machinery (reports, automatic hiding of reported content pending review, moderator actions, bans, a three-level appeal ladder) operates on both surfaces, and report filing is rate-limited.

G.3 Honest limitations. The following limitations exist as at this policy's date, and none is concealed by this policy. A signed file link, once minted by any member, is usable by anyone who holds it until it expires. Access to a file object outside your own uploads is granted only after the platform re-checks, under your own session, whether you may see the content it is attached to; that check is made server-side before a link is minted. The moderation history is kept in an ordinary database table without append-only or tamper-evidence guarantees. Uploaded images are screened against databases of known child sexual abuse material through the provider named in E.4, in addition to report-based moderation. That screening matches only material already known to the provider, so it is not a guarantee that every unlawful image is detected. Screening runs after an image is stored, so a just-uploaded image is briefly unscreened until the next screening pass, typically within a minute and longer if the provider is temporarily unreachable; a matched image is removed and the incident recorded. A file attached to content you delete without deleting your account may persist in storage until an administrative removal runs, as H.2 describes. A security posture that described none of this would misdescribe the platform.


Part H - Retention and deletion

H.1 Deleting your account. Both surfaces provide an account deletion control, and its measured behaviour is as follows. Your personal posts are deleted, together with their attachment records. Your comments are retained, detached from your identity, and shown as authored by "deleted user". Posts you made in a group's name are retained with the group. Groups and events for which you are the sole organiser are frozen rather than deleted, so that other members may take them up. Moderation records that reference you are retained with your identifier removed. Your profile and your sign-in record are deleted. This asymmetry, individual contributions removed, communal fabric retained, is deliberate, it is stated to you on the deletion screen, and it is restated here so that no one deletes an account expecting comments and group history to vanish.

H.2 Files. When you delete your account, the files you uploaded are deleted from storage as part of the deletion. When you delete an individual post or other item without deleting your account, the platform's records pointing to its files are removed at once; the underlying file object may persist in storage until an administrative removal runs, and during that time it is linked from nowhere on the platform, sits at a randomised, unguessable path, and is reachable only through a signed link that expires within an hour of being minted. You can require the immediate removal of any specific file by writing to administrator@anthroposophy.app, and the operator will remove it within the response period in Part I, except where material must be preserved for a lawful purpose.

H.3 Notifications. In-app notifications are purged after 90 days.

H.4 The destruction standard. APP 11.2 requires an entity to take reasonable steps "to destroy the information or to ensure that the information is de-identified" once it is no longer needed for a permitted purpose. The retention positions above, comments de-identified rather than destroyed, communal content retained, moderation history retained for platform integrity, orphaned content files pending administrative removal, are the operator's implementation of that standard, and they are re-examined whenever this policy is revised.


Part I - Access and correction

I.1 Access. APP 12.1 provides that if an entity "holds personal information about an individual, the entity must, on request by the individual, give the individual access to the information", and for organisations the response is due "within a reasonable period after the request is made". The platform gives you this directly: from your account on the website you can download a copy of your data at any time. The export assembles everything in your account that the platform's access rules let you read, your profile and account details, the posts, comments, events, courses and groups you created, your group memberships, whom and what you follow, your saved items, your notification and feed preferences, your in-app notifications, your terms acceptances, the reports you filed, the details of the files you uploaded, records where others mentioned or invited you, your own ban records and appeals, and any blog posts you submitted, reads every category through to completeness, and hands the file to your browser on the spot; nothing is emailed and no third party is involved. Four things are not in that file, and the export names them rather than omitting them silently: the free-text suggestions you submitted (the system lets you write these but not read them back), reports other people filed, moderation actions recorded about you by moderators, and the contents of the files themselves, whose names and details are listed. Each can be requested, together with anything else the platform holds about you, through the privacy contact in Part L. On the mobile application, the request-a-copy control files your request with the operator, who fulfils it by the same standard. Every access request, made in-product or by email, is acknowledged within 7 days and answered within 30 days.

I.2 Correction. APP 13.1 requires an entity to take reasonable steps to correct personal information that is "inaccurate, out of date, incomplete, irrelevant or misleading", on its own satisfaction or on request. You can correct your profile, posts, events and groups directly in the product at any time. Anything you cannot edit yourself, including information about you supplied by others under B.2, can be raised through the privacy contact in Part L, and the operator will correct or annotate it within the same 30-day period.


Part J - Data breaches

J.1 The scheme. Part IIIC of the Privacy Act establishes the Notifiable Data Breaches scheme. An eligible data breach arises where there is unauthorised access to, unauthorised disclosure of, or loss of personal information, and a reasonable person would conclude that it is likely to result in serious harm to any individual to whom the information relates (s 26WE(2)). An entity aware of reasonable grounds to suspect an eligible breach must assess it, taking "all reasonable steps" to complete the assessment within 30 days (s 26WH(2)). Where an eligible breach is confirmed, the entity must prepare a statement (identity, description of the breach, kinds of information, recommended steps) and give a copy to the Commissioner as soon as practicable (s 26WK(2)), and must notify affected individuals of its contents as soon as practicable (s 26WL(3)).

J.2 Applicability and commitment. The scheme binds APP entities, so once the s 6EA registration described in A.4 takes effect it applies to the operator as law. The operator applies its discipline from adoption in any event: contain the incident, assess within 30 days, notify the OAIC and affected members as soon as practicable where serious harm is likely, and record the incident and the decisions taken. Given the sensitive character of the data (Part C), the working assumption in any breach assessment here is that disclosure of membership or belief-revealing content is capable of serious harm, so the threshold question will be approached with that weighting rather than neutrally.


Part K - Children

K.1 The honest position. The platform is intended for adults aged 18 and over. Signup on both the website and the mobile application requires ticking a statement that reads "I am 18 or older and I accept the Terms of Use". Neither surface collects a date of birth, and neither performs technical age verification, so the control on both surfaces is self-attestation; this policy does not claim an age gate that does not exist. Content concerning children may appear in material adults post about community and family life, such content is subject to the moderation and reporting machinery in G.2, and it can be reported to the safety contact in L.1.


Part L - General provisions

This Part applies to every reader of this policy, whether a member, a visitor, or a person who holds no account and appears in content under B.2.

L.1 Contact. Privacy enquiries, access requests, correction requests and complaints go to the privacy contact: privacy@anthroposophy.app. Reports of illegal or harmful content go to the safety contact: safety@anthroposophy.app, which is also linked in-product as "Report illegal content". Requests for the removal of a specific stored file under H.2 go to administrator@anthroposophy.app. This document is self-contained, and every route appears here rather than by reference elsewhere.

L.2 Complaints. A complaint about the handling of your personal information should be made to the privacy contact first, the operator will acknowledge it within 7 days and respond substantively within 30 days, and if you are not satisfied with the response you may complain to the Office of the Australian Information Commissioner at www.oaic.gov.au, which accepts complaints online. The s 6EA registration described in A.4 places the operator within the Act's complaint machinery, and the operator's own commitment above applies regardless.

L.3 Changes to this policy. This policy carries a version number and a date, material changes will be notified in-product before they take effect, and the current version will remain available on the website at all times. No change operates retrospectively to authorise a use or disclosure this policy did not permit when the information was collected.

L.4 Collection notice. APP 5.1 requires an entity, at or before the time of collection or as soon as practicable after, to take reasonable steps to notify the matters in APP 5.2, including the entity's identity, the purposes of collection, usual disclosures, access and correction, complaint routes, and the likelihood of overseas disclosure. This policy is the platform's standing notice of those matters: identity in A.1, purposes in D.1, disclosures in Part E, overseas position in Part F, access and correction in Part I, complaints in L.2. For information collected indirectly under B.2, the practicable notice is this policy together with the platform's mention notifications, which alert a member when they are tagged.

L.5 Interpretation. Headings organise, they do not limit. Factual statements about the platform's behaviour derive from a code-level census of both codebases dated 10 July 2026, supplemented by direct verification of the website's data export, translation, contact routes and device storage on 11 July 2026, and re-verification of the screening, auto-hide-threshold and storage-access claims in Parts E, F and G on 15 July 2026, and removal of the example-content (demo) view and its anthro-mode cookie verified 25 July 2026, and they speak as at the latest date. The Schedule and the Adoption Record below form part of this policy.


Schedule - Legislative sources

Each provision quoted in this policy was fetched from the source shown on 10 July 2026, and the quoted words were checked against the fetched text. The Federal Register of Legislation text was read from the current compilation of the Privacy Act 1988 (compilation in force 4 June 2026).

#ProvisionWords verifiedSource
1Privacy Act s 6(1) "personal information""information or an opinion about an identified individual, or an individual who is reasonably identifiable" plus limbs (a)-(b)OAIC APP Guidelines ch B, cross-checked against legislation.gov.au C2004A03712
2Privacy Act s 6(1) "sensitive information"full limb list including "religious beliefs or affiliations" and "philosophical beliefs"OAIC APP Guidelines ch B, cross-checked as above
3Privacy Act s 6(1) "consent""express consent or implied consent"OAIC APP Guidelines ch B
4Privacy Act s 6(1) "holds""possession or control of a record that contains the personal information"OAIC APP Guidelines ch B
5Privacy Act s 6C(1) "organisation"individual, body corporate, partnership, unincorporated association, trust, excluding a small business operatorlegislation.gov.au C2004A03712
6Privacy Act s 6D(1)"A business is a small business at a time (the test time) in a financial year (the current year) if its annual turnover for the previous financial year is $3,000,000 or less."legislation.gov.au C2004A03712
7Privacy Act s 6D(3)"(a) carries on one or more small businesses; and (b) does not carry on a business that is not a small business"legislation.gov.au C2004A03712
8Privacy Act s 6D(4)(c)-(d)"discloses personal information about another individual to anyone else for a benefit, service or advantage"; "provides a benefit, service or advantage to collect personal information about another individual from anyone else"legislation.gov.au C2004A03712
9Privacy Act s 6D(7)-(8)consent carve-outs preserving small-business status, "with the consent of the other individual"legislation.gov.au C2004A03712
10Privacy Act s 6EAsmall business operator may elect by written notice to the Commissioner to be treated as an organisationlegislation.gov.au C2004A03712; OAIC small-business guidance (Privacy Opt-In Register)
11Privacy Act s 16Coverseas recipient's act "taken to have been done by the APP entity" in certain circumstancesOAIC APP Guidelines ch 8, paragraph 8.60
12Privacy Act s 26WE(2)eligible data breach: unauthorised access, unauthorised disclosure, or loss, likely to result in serious harm, reasonable-person standardOAIC, Data breach preparation and response, Part 4
13Privacy Act s 26WH(2)"all reasonable steps" to complete the assessment within 30 days of becoming awareOAIC, Data breach preparation and response, Part 4
14Privacy Act s 26WK(2)prepare a statement and give a copy to the Commissioner as soon as practicableOAIC, Data breach preparation and response, Part 4
15Privacy Act s 26WL(3)notify affected individuals as soon as practicableOAIC, Data breach preparation and response, Part 4
16APP 1.3-1.4duty to have a clearly expressed, up-to-date privacy policy, and its required contentsOAIC, Read the Australian Privacy Principles
17APP 3.3"must not collect sensitive information about an individual unless the individual consents ... and the information is reasonably necessary"OAIC, Read the Australian Privacy Principles
18APP 5.1-5.2notification at or before collection or as soon as practicable after; matters listOAIC, Read the Australian Privacy Principles
19APP 6.1primary purpose rule, "must not use or disclose the information for another purpose"OAIC, Read the Australian Privacy Principles
20APP 8.1"take such steps as are reasonable in the circumstances to ensure that the overseas recipient does not breach the Australian Privacy Principles"OAIC, Read the Australian Privacy Principles; APP Guidelines ch 8
21APP Guidelines ch 8, paragraphs 8.10 and 8.14 (guidance, not statute)routing in transit "would usually be considered a 'use'"; cloud provision may be a use where contract, flow-down and effective-control conditions holdOAIC APP Guidelines ch 8
22APP 11.1"protect the information: (a) from misuse, interference and loss; and (b) from unauthorised access, modification or disclosure"OAIC, Read the Australian Privacy Principles
23APP 11.2"destroy the information or to ensure that the information is de-identified"OAIC, Read the Australian Privacy Principles
24APP 12.1 and response period"must, on request by the individual, give the individual access to the information"; organisations respond "within a reasonable period after the request is made"OAIC, Read the Australian Privacy Principles
25APP 13.1correction where "inaccurate, out of date, incomplete, irrelevant or misleading"OAIC, Read the Australian Privacy Principles

Adoption Record

The operator's standing decisions under this policy, recorded so that the policy's commitments can be checked against them.

  • Operator. VirgoLabs, ABN 62 345 335 476, Australia.
  • Posture. Voluntary compliance with the Australian Privacy Principles from adoption; written notice under s 6EA of the Privacy Act to be lodged with the Information Commissioner before public launch. The operator has confirmed that the aggregate annual turnover of all businesses it carries on is $3,000,000 or less, which is why registration, rather than automatic application, is the route by which the Act comes to bind the platform as law.
  • Contacts. Privacy: privacy@anthroposophy.app. Safety: safety@anthroposophy.app. File removal: administrator@anthroposophy.app. Contact mailboxes hosted by Proton AG, Switzerland.
  • Hosting and providers. Database, authentication and storage: Supabase, Sydney region (ap-southeast-2), primary data in Australia. Transactional email: Resend, United States. Translation, at the reader's request: Google Cloud Translation, United States.
  • Screening. Uploaded images are screened against known child sexual abuse material; provider Project Arachnid Shield (Canadian Centre for Child Protection, Canada); Microsoft PhotoDNA (United States) is a named alternative that is not in use.
  • Files. Uploaded files are deleted as part of account deletion; files orphaned by content deletion are removed administratively, and immediately on request; lawful-preservation holds excepted.
  • Age. 18 and over, by self-attestation on both surfaces; no date of birth collected.
  • Public profile granularity. Home location is shown publicly at no finer than region or state and country; suburb and postcode are never displayed publicly.
  • Response periods. Acknowledgement within 7 days; substantive response within 30 days.

Version 1.2. Published by VirgoLabs (ABN 62 345 335 476) at www.anthroposophy.app/privacy.

The Anthroposophy AppThe Anthroposophy App