Gheorg App Privacy Policy

Gheorg App Privacy Policy

Policy last updated: 17th August 2026

This Privacy Policy describes how Gheorg collects, holds, uses, and discloses personal information, consistent with the Australian Privacy Act 1988 (Cth), the UK General Data Protection Regulation and Data Protection Act 2018, the EU General Data Protection Regulation, and the United States Children's Online Privacy Protection Act (COPPA) as administered by the Federal Trade Commission.

"Gheorg," "we," "us," and "the Company" refer to:

  • Gheorg Pty Ltd (ABN 27 636 090 036), the Australian entity that collects, holds, and processes all personal information described in this Policy and operates the underlying technology and infrastructure.

  • Gheorg Inc., a Delaware corporation that acts as the contracting party for certain transactions with US-based customers. Gheorg Inc. does not itself collect, hold, or process your personal information.

  • Gheorg Global Inc., a Delaware corporation currently being formed as the ultimate parent company of Gheorg Pty Ltd. This is a change in equity ownership only. It does not change who processes your personal information, and Gheorg Global Inc. will not itself collect, hold, or process personal information as a result of this restructuring.

If you have any questions about which entity is responsible for a particular activity described in this Policy, contact us using the details in the "Contact us" section below.

Gheorg is committed to protecting the privacy of your personal information and the personal information of your child. By providing personal information to us and having access to this Policy, you consent to our collecting, holding, using, and disclosing personal information in accordance with this Policy.

The Gheorg website has a separate privacy notice covering visitor data collected through the marketing site, distinct from this Policy, which covers the Gheorg app and platform (the Platform).

What information do we collect and how do we use it?

Free trial registration

When you sign up for a free trial of the Platform, we collect your first and last name, email address, and country. Free trial sign-up requires you to enter payment card details. We use this both to enable the trial to convert to a paid subscription if you choose to continue, and as our method of verifying that the account is being created by an adult, consistent with our obligations under COPPA. Once you log into your free trial account, we collect your child's first and last name and their year of birth. We collect these details so we can tailor communications to you, track your child's progress through activities, and respond to customer service requests.

You may provide us with a pseudonym for yourself or your child if you wish, except where we need your correct name for payment, delivery, or identity verification purposes.

Subscription and product purchases

When you subscribe to the Platform or purchase any of our products, we collect your first and last name and your payment card details. We require accurate name and payment details for these transactions, so a pseudonym is not available at this stage.

Surveys

We run surveys to collect feedback so we can improve our programs and how we communicate with you. Depending on the survey, we may collect your first and last name, email address, home address (only where the survey entitles you to a free gift), your child's age, and your opinions or other information relevant to the survey questions. We may also ask for additional information about your child's mental health so we can better understand what children need from Gheorg.

Survey information relating to health or mental health is sensitive information under the Australian Privacy Principles and special category data under the GDPR. We only collect this information with your explicit, informed consent, given separately from your general acceptance of this Policy, and only where you choose to answer the relevant survey questions. You are never obliged to complete a survey.

You may respond to surveys under a pseudonym, except that if the survey entitles you to a free gift, we need your correct name and delivery address to send it to you.

Social media and competitions

We periodically run competitions through the Platform, our website, and our social media channels. Entering a competition means we may use your personal information to administer the competition and to contact you about our products and services.

We may also offer joint promotions with third parties. These are designed to be relevant to you. You can opt out at any time using the "Unsubscribe" link at the bottom of any email, or by contacting us at support@gheorg.com.

Third-party service providers

We use third-party service providers, vendors, APIs, and plug-ins to help operate the Platform, including Google, Apple, and Firebase, and Anthropic, which provides the AI system that powers Gheorg's real-time interactions with children (see "How we use AI" below). These providers are only permitted to use information we share with them to support our operations and are not permitted to use it for their own independent purposes, except as described in the "How we use AI" section for Anthropic specifically.

Contact us at support@gheorg.com with any questions about our third-party providers.

Email communications

Our email communications comply with the Spam Act 2003 (Cth). When you sign up for a free trial, you'll automatically receive promotional and support emails. You can opt out of promotional emails at any time using the "Unsubscribe" link.

How we use AI

Gheorg's Platform uses Anthropic's Claude AI system to power real-time interactions with children, including conversational check-ins and the analysis that underpins our safety alert system. This means content from a child's live interaction with the Platform is transmitted to and processed by Anthropic, a US-based AI provider, in order to generate the Platform's responses and to assess whether a safety alert should be raised. Under our commercial terms with Anthropic, Anthropic does not retain this data for its own purposes and does not use it to train any AI model.

Separately, we use de-identified check-in and interaction data to test and validate the accuracy of our safety alert system, so that alerts continue to reliably identify children who may need support. This testing data is always de-identified before use and is not used to build a general-purpose AI product outside of improving the accuracy of Gheorg's own safety detection.

We do not use identifiable child data to train or fine-tune any AI model.

Data storage and security

Limiting access to wellness records

Wellness records and progress data are only accessible to adults logged into the parent portal, which also contains the child's portal. Adult users must authenticate with a username and password. A child user can only access their own progress and may set a 4-digit PIN to protect their own activity from other children in the household.

Child and parent data can only be accessed by Gheorg staff and the third-party providers described in this Policy. We do not share data with any other third party without your explicit permission, except as described under "Disclosure of information to third parties" below.

How long we keep your information

We retain personal information only for as long as necessary for the purposes described in this Policy, or as required by law. The following retention periods apply. These are provisional defaults pending final sign-off from Gheorg's clinical and legal advisers, and are consistent with the retention approach used across Gheorg's other privacy documentation.

Data category Retention period Account and profile data (parent and child name, email, year of birth) While the account is active. If a trial isn't converted or a subscription lapses, retained for 24 months in case of reactivation, then deleted or de-identified. Check-in and interaction data (including AI-processed content) While the account is active. De-identified or deleted within 12 months of account closure or subscription expiry. Payment and transaction records 7 years, to meet Australian and US tax and financial record-keeping requirements. Survey responses tied to a free gift (including home address) Deleted within 90 days of gift dispatch. General survey responses 24 months, then deleted or de-identified. De-identified data used for safety-alert testing or research Retained indefinitely. Because this data is properly de-identified, it is no longer personal information; if it becomes re-identifiable, it is treated as personal information again and subject to the relevant category above. Marketing and email engagement data Removed from active marketing use within 30 days of unsubscribe. A suppression record is kept to honour your opt-out.

If you ask us to delete your data earlier than these defaults, contact our support team and we will action your request, generally within 30 days.

Keeping data secure

Parent and child data is stored on Amazon Web Services (AWS). Wherever technically feasible, we store your data in the country in which it was collected. In some circumstances, technical or operational requirements may mean data is stored or processed in a different country, including the United States, where Anthropic processes live interaction content as described above. Access to our servers is limited to the application itself and to authorised Gheorg developers via secure shell.

All data transferred through the Platform is protected by SSL/TLS encryption in transit.

International transfers

Where personal information is disclosed to or processed by an overseas recipient, such as Anthropic (United States), we take reasonable steps to ensure that recipient handles your data consistently with the Australian Privacy Principles, the GDPR, and UK GDPR, as applicable. We do not currently have Standard Contractual Clauses executed with all overseas recipients. Where required, we intend to put appropriate transfer safeguards, including Standard Contractual Clauses, in place, and will update this Policy when that work is complete.

Data breach notification

If we experience a data breach that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner in accordance with the Notifiable Data Breaches scheme, and will meet equivalent notification obligations under the GDPR and UK GDPR where applicable.

Disclosure of information for research purposes

Gheorg is committed to improving mental health outcomes for children, and research is central to that goal. We only give researchers access to de-identified data, limited to information entered into the app and surveys, which will never contain personal information. All partner researchers must agree to comply with this Policy before receiving access.

Disclosure of information to third parties

Gheorg does not sell or trade your personal information. We disclose personal information only to:

  • the third-party providers named in this Policy, who help us operate the Platform and are bound to keep your information confidential;

  • researchers, as described above, and only in de-identified form; and

  • others where required by law, to enforce our policies, or to protect the rights, property, or safety of Gheorg, our users, or others.

Changes to this Privacy Policy

We may update this Policy to comply with applicable law, reflect changes in our practices, or for any other reason. We'll communicate material changes to you, and encourage you to check this page periodically. Continued use of the Platform after a change takes effect means you accept the updated Policy.

Access, correction, and your rights

Gheorg takes reasonable steps to keep the personal information we hold accurate, up to date, and relevant. You can request access to, correction of, or erasure of your personal information, or object to how we use it, by contacting our Privacy Officer at support@gheorg.com.

You can also make some changes yourself: log into your account and go to "My Account" to update or remove your name and email address. For anything else, including restricting processing or deleting all your information, contact our Privacy Officer.

If you're in the UK or EU, you additionally have the right to data portability, to object to processing based on legitimate interests, and to lodge a complaint with your local supervisory authority (in the UK, the Information Commissioner's Office; in the EU, your national data protection authority). If you're in Australia, you can lodge a complaint with the Office of the Australian Information Commissioner if you're not satisfied with our response.

We aim to respond to verified requests within 30 days.

Legal basis for processing (UK and EU users)

Where the GDPR or UK GDPR applies, we process your personal information on the following bases: performance of our contract with you (to deliver the Platform), your consent (for marketing communications and for sensitive information such as mental-health-related survey responses), and our legitimate interests (for security, fraud prevention, and improving the safety and accuracy of the Platform), balanced against your rights and interests.

If information or consent is not provided

If you don't provide required personal information or consent, we may not be able to provide the Platform or service you're seeking, or to handle related enquiries such as progress reports.

Cookies

The Gheorg Platform itself does not use advertising or tracking cookies. Our marketing website uses only strictly necessary, functional cookies. It does not use advertising or analytics cookies such as Meta Pixel or similar tools.

Contact us

All requests to access, update, or delete personal data, and any questions or concerns about your personal data or this Privacy Policy, should be directed to our Privacy Officer at support@gheorg.com. We'll respond as quickly as we can.

Policy last updated: 17th August 2026