Privacy Policy
Exora Health Pty Ltd (ABN 16 690 025 462)
Effective date: 11 October 2026 | Version: 2.12
At a Glance
- Your health data is stored in Australia (Sydney data centres). AI processing happens overseas - the models we use are not offered in an Australian region, so inference runs on international infrastructure under contractual protections (see Section 6)
- We never sell your data or use it for advertising
- You control who sees your data - sharing is always initiated by you, and you can revoke access at any time
- You can delete your account at any time - 30-day recovery window, then permanent deletion of your health data, documents, and personal information (audit logs retained for compliance)
- If exora is ever sold, your health records are not for sale separately - they transfer only together with the service, only to an owner continuing to run it, and you get at least 30 days to export or delete first (see Section 5)
- Verified healthcare providers keep their own copy of what they create for you - consults, notes, and documents they author during your care stay in their own file even if you revoke access or delete your account (see Section 8), and they keep a record that you shared with them at all - your name, date of birth and the dates access ran, and nothing more; family members and other non-providers keep nothing
- Our document processing AI runs on Google Cloud Gemini Enterprise under a signed Cloud Data Processing Addendum, with server-side data caching disabled - inputs and outputs are not retained by Google after a request completes, subject to one exception: prompts flagged by Google’s automated safety classifiers may be logged and reviewed. We have applied for an exemption (see Section 6). We also use OpenAI for two narrow tasks (medical-code matching and some voice transcription). Under all our commercial agreements, providers do not train AI models on your data.
- Voice dictation is transcribed on your device where your phone supports it - in that case the audio never leaves your phone at all
- We use crash reporting and product analytics inside the app (Sentry and PostHog, both EU-hosted). They receive your account identifier and which features are used - never your health information, never screen recordings (see Section 12)
- If you connect a health app or wearable, we keep daily summaries - not the continuous second-by-second readings your device collects (see Section 2)
- We do not include sensitive health details in push notifications
- Contact us at hello@exora.au with any privacy questions
Contents
- About This Policy
- What We Collect
- How We Collect It
- Why We Use It
- Who We Share It With
- Where Your Data Is Stored and Processed
- How We Protect Your Information
- How Long We Keep It
- Artificial Intelligence
- Your Rights
- Children and Young People
- Cookies and Tracking
- Changes to This Policy
- Users Outside Australia
- Complaints
- Contact Us
1. About This Policy
This privacy policy explains how Exora Health Pty Ltd (ABN 16 690 025 462) (“exora”, “we”, “us”, “our”) collects, uses, stores, discloses and protects personal information when you visit our marketing website at exora.au or use the exora platform, being our mobile app and our web app at app.exora.au (together, the “Service”).
exora is a personal health data platform that helps you organize your medical records using artificial intelligence. You upload your medical documents, and our AI extracts and structures the health information for your personal use.
Who this policy applies to. This policy applies to everyone whose personal information we hold. That includes account holders, the people whose health records are kept in a profile, healthcare providers and other people you share records with, visitors to our website, people whose personal information appears in a document that a user uploads, and people a user adds to a trip who do not have an exora profile. Section 2 explains how we handle information about people who are not exora users.
Where exora is operated from. exora is operated from Australia by an Australian company, and health records are stored in Australia. The Service is available in other countries. We apply the standard set out in this policy to every user, wherever they are located. Section 14 sets out what this means if you are outside Australia.
We are bound by the Australian Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles (APPs). Health information is classified as sensitive information under the Act, and we treat it with additional care.
exora is not a medical device, healthcare provider, or clinical decision support system. Information provided by exora, including AI-generated summaries and structured health records, is for your personal reference only and does not constitute medical advice, diagnosis, or treatment. Always consult a qualified healthcare professional for medical decisions.
Terms used in this policy. The first three carry the same meaning as in our Terms of Service.
- Health Data means medical documents you upload, the clinical information our AI extracts from them (conditions, medications, allergies, vital signs, lab results, procedures, immunizations), and any related data stored in your exora account.
- AI Processing means the use of artificial intelligence to extract, structure, organize, and summarize information from your uploaded documents and to power the AI chat assistant. In this policy it also covers the real-time voice assistant described in Section 9.
- Profile means a health record identity within your account. You may have a profile for yourself and profiles for dependents you manage. Several settings described in this policy apply to a profile rather than to an account.
- Account means the sign-in belonging to a single person, identified by an email address or phone number. One account may hold more than one profile.
- Verified healthcare provider means a user whose professional registration exora has verified, and who therefore has access to provider features. Section 8 sets out what records a verified healthcare provider retains.
2. What We Collect
Account information: Your name, email address or phone number, date of birth, and optional fields such as biological sex and gender identity. Your PIN is stored as a secure hash only. We never see or store the PIN itself. If you verify your identity through ConnectID, we receive your verified legal name and date of birth from your bank.
Health information: Medical documents you upload (PDFs, images, scans) and the clinical data our AI extracts from them, including conditions, medications, allergies, vital signs, laboratory results, procedures, and immunization records. This is sensitive information under the Privacy Act and is only collected with your express consent.
Appointment recordings (exora scribe): If you choose to record a healthcare appointment, we capture the audio of that consultation and use it to generate a text transcript and a summary, and to extract health information into your record in the same way as an uploaded document. The recording is stored in Australia and is visible only to you and to anyone you choose to share it with. Recording laws differ between states and countries, and obtaining the consent of everyone present before you record is your responsibility - see our Terms of Service. Where a verified healthcare provider records a consult with you through exora, obtaining your consent is theirs.
A consult a healthcare provider sends you: When a healthcare provider records a consult through exora and sends it to you, we hold the contact detail it is sent to: a mobile number or email address the provider enters, or that you enter yourself on the page you reach by scanning their QR code. We also hold the name and, if one is given, the date of birth entered with it. We use these only to deliver that consult to you and to make sure only you can receive it: a verification code sent to that number or address, the link to the consult, and at most two reminders if you have not yet received it. This applies whether or not you already have an exora account. These details are kept as part of the provider’s record of the consult (see Section 8).
Fitness and wellness data (only if you connect a health app or wearable): If you choose to connect one, we collect the measurements it holds for you: steps, distance travelled, calories burned, resting and average heart rate, heart rate variability, blood oxygen, weight, body fat percentage, sleep sessions and their stages, and recorded workouts. You connect it yourself, you grant the permissions in your device’s own health app, and you can disconnect at any time. Section 3 lists which apps and devices this covers.
We store summaries, not raw sensor streams. Your device records these measurements continuously, often many readings a minute. We keep one row per day, one per workout and one per sleep session, and we discard the underlying samples. We do this deliberately: the daily picture is what is useful in a health record, while the continuous stream is both far more revealing about your movements and of no added benefit to you here.
Travel plans (only if you plan a trip): If you plan a trip, we keep what you tell us about it: a name for the trip, the places you are going and in what order, which are only stopovers, your travel dates, where the trip starts, which of your profiles are travelling, the kind of trip if you mention it (for example a cruise, or a pilgrimage such as Hajj, which can indicate religious belief), and whether you have marked your travel clinic visit as booked. This is only what you enter; travel planning does not use your device’s location. We also keep a record of each change you make to a trip so that you can undo it. Each traveller’s list is put together on your device from that traveller’s immunization records and from travel health advice published by governments. When you open one of those sources, its website opens and receives your visit as any website would; we do not send it your trip or your records. If you share a trip’s plan with someone, Section 5 explains what they see. Section 5 also explains what someone sees when you show them your Health Summary.
Travel documents (only if you add them to a trip): You can add a booking confirmation, e-ticket, boarding pass, itinerary, visa, or a screenshot of a booking to a trip, in chat or on the trip’s page, so that exora can fill the trip in for you. We store the files you add, privately and in Australia. Our AI reads them for what the trip needs and nothing else: the places and dates, where the trip starts, the first names of the people travelling (to match them to your profiles), and what kind of document each file is. It never takes out booking references, ticket, passport or frequent-flyer numbers, seats, prices, payment details, or addresses. Travel documents are not health records and are not added to your health record. A passport or ID page, or a file that is not about travel, is deleted as soon as it has been read. If a file is a vaccination record, we do not keep it with the trip: we offer to add it to your health records, and it is processed as a medical document only if you choose that; otherwise it is deleted within 24 hours. Travel documents can be seen only by the account that owns the trip, even where a traveller’s profile is shared with someone else, and they are not included in anything you share from exora. A travel document will often name other people travelling with you; we use their first names only to work out who is on the trip.
Information about other people: A document you upload will often contain personal information about people other than the profile it relates to: the name of your general practitioner or specialist, a person recorded as your next of kin, or a relative whose condition appears in a family history. Our AI reads the whole document, so this information is processed, and some of it is stored as part of your health record: which practitioner an appointment was with, for example, or a family history entry. We collect it because it appears in a document you have chosen to upload, and we use it only to organize and display your own record. We do not create an exora account or an independent record for those people, and we do not contact them. If you believe you are named in a document another person has uploaded and you wish to know what we hold, contact us at hello@exora.au. We will handle your request in the same way as a request from an account holder under Section 10.
People travelling with you who are not exora users: You can add someone without an exora profile to a trip, such as a friend or relative. For that person we keep only a first name and an age, and only on that trip. It is not a profile or a health record, we do not create an account for them, and we do not contact them. They are shown the general list for anyone travelling to those places. Please add someone only if they know you are planning the trip with them. Their details are deleted when you remove them from the trip, delete the trip, or delete your account.
Chat data: Messages you send to our AI health assistant and photos you share in chat for analysis. Photos shared in chat are stored on our servers alongside your chat history and are deleted when you delete the chat session or your account.
Voice-to-text input (chat composer mic): When you tap the microphone in the chat composer, your speech is converted to text. Where your device supports on-device speech recognition, this happens entirely on your phone and the audio never leaves the device. Where it does not, including older devices and the web app, the clip is uploaded and transcribed by Google Speech-to-Text in Singapore. Where a clip exceeds 60 seconds, which that service cannot process in a single request, it is transcribed by OpenAI instead. In every case the audio is transcribed and discarded immediately; we do not retain voice clips on our servers.
AI voice conversations (AI Assistant): When you opt in to AI voice conversations in Settings -> AI Assistant and explicitly accept the consent dialog the first time you use it, you can hold a spoken conversation with our AI assistant. Your microphone audio is streamed in real time to Google’s Gemini Live AI service for the duration of the conversation. We record the conversation (both your side and the assistant’s) as an audio file stored securely with your chat history so you can play it back; only you can access it. We also keep structured session metadata and the text transcript of the conversation (see Section 8). See Section 9 for the full description of how this works.
Device information: A unique identifier generated by the app (not a hardware device ID), your device name, platform (iOS or Android), app version, and push notification token if you enable notifications.
Location information (optional): If you grant location permission, we use your device’s approximate location to improve two features: suggesting nearby places when you add an appointment, and giving the AI health assistant city-level context. We use approximate (coarse) location only, never precise location, and only at the moment you use these features. We do not track you and we do not build a location history. You can decline location access and both features still work without it.
Marketing contact information: If you submit any form on our website (contact form, blog “follow along” signup, family-history-request, future EOI surfaces), we capture your email address, the form submitted, and limited submission metadata (page URL, UTM parameters, country and locale at submission, IP address, and the exact consent copy you saw). This is stored in our Sydney-hosted Supabase database (see Section 6) and used as described in Section 4.
Diagnostics and product analytics: Crash reports and a record of which features you use, so we can find bugs and understand which parts of exora are useful. These carry your account identifier only, not your name, email address or IP address, and never the contents of your health records. See Section 12 for exactly what is and is not collected.
Billing information (only if you become a paying member): We store your membership status, billing interval, and current billing period, together with the reference identifiers our payment processor gives us for your customer and subscription records. We do not collect or store your card number, and we do not store your billing address; Stripe holds both.
What we do not collect: Contacts, browsing history, advertising identifiers, biometric data (Face ID and Touch ID are processed entirely on your device), or precise (GPS-level) location. We also never see or store your card details: if you become a paying member, your card is entered directly into Stripe, our payment processor (see Section 5).
3. How We Collect It
Directly from you: When you create an account, set up profiles, upload documents, send chat messages, take photos, use voice input, plan a trip, or add travel documents to one.
Automatically from your device: Device identifiers, platform information, and push notification tokens are collected when you use the app.
From your documents via AI processing: When you upload a medical document, our AI reads it and extracts structured health information. This processing is initiated by you and serves the primary purpose of organizing your health data.
From identity verification providers: If you choose to verify your identity, ConnectID returns your verified name and date of birth from your bank. This only happens when you initiate the process.
From a health app or wearable you connect: If you connect a health app or wearable, exora reads the fitness and wellness data described in Section 2 from it. You start each connection yourself, you grant the permissions in your device’s own health app, and you can disconnect at any time in Settings.
- In use today: Apple Health (iOS) and Health Connect (Android). The data is read on your device by the exora app and stored in your exora account in Australia. Neither Apple nor Google receives anything from us.
- We may also enable: a direct Garmin connection. We name it here in advance, for the same reason and in the same way as the AI providers in Section 5: it reads the same categories of data already described in Section 2, so switching it on is not a change to what we collect and will not require fresh notice under Section 13. Naming it here does not mean it is available yet. It differs in one respect - it would authorize exora to fetch your data from Garmin’s servers rather than reading it from your phone - and Garmin would then be added to the provider list in Section 5.
From other external health data sources: In future, we may enable you to connect exora to sources that hold clinical records rather than fitness measurements, such as government health records or pathology providers. Those are a different category of information, and we will update this policy before launching any such integration.
4. Why We Use It
We collect your information to provide you with a personal, AI-powered health data platform. Specifically:
- Providing the service: Storing, organizing, and displaying your health records; processing your documents through our AI pipeline; powering the AI health assistant
- Account management: Authentication, device management, push notifications (with your permission)
- Sharing: Enabling you to share your health data with people and healthcare providers you choose
- Travel planning: Putting together each traveller’s list for a trip from official travel health advice and their immunization records, and keeping the trip up to date as you change it, including from travel documents you add
- Delivering consults: Sending you a consult that a healthcare provider has shared with you, with the verification code and reminders described in Section 2
- Identity verification: Verifying your identity when you choose to use ConnectID
- Service improvement: Using aggregated, de-identified usage patterns and crash reports to fix problems and improve the platform (we do not use individual health data for this purpose: see Section 12)
- Marketing communications: Building a list of people who have submitted a form expressing interest in exora, so we can send product updates and the occasional newsletter. Every marketing email includes a one-click unsubscribe link. You can revoke at any time at exora.au/unsubscribe (use the link from any email we have sent you) or by emailing hello@exora.au.
- Legal compliance: Meeting our obligations under Australian law
What we do not use your data for: Advertising, sale to third parties, data mining, or commercial profiling. We do not use your health data to train AI models, and our AI providers do not train their models on it. If we ever wished to use de-identified data to improve our own systems, we would ask for your separate, explicit consent first (see Section 9). We do not send marketing messages unless you explicitly opt in.
When you upload a medical document, you consent to its processing by our AI systems to extract, structure, and organize your health data. We also send necessary service communications (authentication codes, security alerts, policy updates, and messages delivering a consult a healthcare provider has shared with you) via email or SMS. These are not marketing.
5. Who We Share It With
People you choose: You control who sees your health data. You can share specific records with family members, carers, or healthcare providers through exora’s sharing features. You choose the permission level and can revoke access at any time. All sharing actions are logged.
Showing your Health Summary (only if you choose to): You can show the Health Summary of a profile your account owns to someone who does not have an exora account, such as a doctor, in two ways: with someone who is with you, by swapping a code and approving them after you see the name they typed; or by sending them a link yourself, from your own phone or computer. You choose which parts of the Health Summary they see. They can read it but not download it. Sharing in person lasts 15 minutes unless you add more time. A link works for the time you choose, up to 30 days, stops after ten openings, and each opening lasts up to an hour. We ask the reader for their name and, if they like, where they work; we show you what they typed, but we do not check it. We record when they read it, which parts they opened, and their IP address, so that you can see who looked and so that we can investigate misuse. You can end it at any time, which also ends anyone reading at that moment. If the reader then creates an exora account, they keep read-only access to the parts you showed only if you agreed to that before approving them; otherwise you receive a request, which you can accept or decline. If the reader gives us their email address, we use it only to send them an invitation to create an account. Anyone who has a link can open it, so send it only to people you mean to.
Sharing a trip plan (only if you choose to): You can share a trip’s plan by sending a link yourself, from your own phone or computer, or by showing it to someone with you using a code that you approve. The person reading it does not need an exora account. They see the trip (its name, places and dates) and the plan for each traveller you choose: that traveller’s name, their date of birth, the vaccinations on their record, and the official travel health advice set against them. If you choose, you can also add the Health Summary of any of those travellers, for example for a doctor or travel clinic: their allergies, conditions, medicines and immunizations, which the reader can read but not download, and which ends when the share ends. Nothing else from anyone’s health record is included, and your travel documents never are. You can only include profiles your account owns. Anyone else on the trip appears only as a number of other travellers, never by name. We ask the reader for their name and, if they like, where they work; we show you what they typed, but we do not check it. We record when the plan was opened and the reader’s IP address, so that you can see who looked and so that we can investigate misuse. A link works for the time you choose, up to 30 days, and stops after ten openings; sharing in person lasts 15 minutes unless you add more time. You can turn either off at any time, which also ends anyone reading at that moment. Anyone who has the link can open it, so send it only to people you mean to.
Service providers we currently use: These are the providers operating exora today, and what each one receives:
- Supabase - database and file storage (data hosted in Sydney, Australia)
- Google Cloud Platform - infrastructure (worker compute, OCR, storage in Sydney, Australia)
- Google Maps Platform (Places) - powers nearby-place suggestions when you add an appointment; receives your approximate location and search text only when you use that feature
- Google Cloud Gemini Enterprise (Vertex AI) - AI inference for document understanding, chat (text), narrative generation, and voice-to-text transcription. Routed via Google Cloud’s global endpoint under our signed Cloud Data Processing Addendum, with project-level data caching disabled. Inputs and outputs are not retained by Google after a request completes, except where flagged by Google’s automated abuse-monitoring classifiers. Section 6 sets out the detail, and the exemption we have applied for.
- Google AI Studio (Gemini Live API) - AI inference for real-time AI voice conversations (Beta). This is a different Google product to Gemini Enterprise above. Audio is streamed to Google’s global infrastructure (currently US-based for the model we use); the Cloud Data Processing Addendum that covers our Gemini Enterprise usage does not extend here. Use is gated behind explicit per-profile opt-in and informed consent (see Section 9). We are evaluating migration of this flow to Vertex AI Sydney once Google publishes the live-audio model variant there; this policy will be updated when that happens.
- Google Speech-to-Text (Singapore) - converts a dictated voice clip to text when your device cannot do it locally. Receives the audio clip only, and only for that request
- OpenAI - two narrow uses only: generating the mathematical representations we use to match your clinical terms to standard medical codes, and transcribing a dictated voice clip in the small number of cases the paths above cannot handle. It does not process your chat messages and it does not receive your documents
- Sentry (European Union) - crash and error reporting inside the app. Receives your account identifier, the error, and where in the app it happened. Never health information (see Section 12)
- PostHog (European Union) - product analytics inside the app. Receives your account identifier and which features are used. Never health information, and screen recording is switched off (see Section 12)
- Vercel - hosts our marketing website and API routes (stateless transit layer for app data; app data is stored in Australia). Also provides cookieless aggregate analytics for the marketing website (see Section 12)
- ConnectID - identity verification (Australia only)
- Expo - push notification delivery routing
- Resend - email delivery for sign-in codes, messages delivering a consult a healthcare provider has shared with you, and marketing emails (receives your email address and the message; never your health records)
- Twilio - SMS delivery for sign-in codes and messages delivering a consult a healthcare provider has shared with you (receives your phone number and the message text; never your health records)
- Stripe - payment processing for paid memberships. Receives your email address and your exora account identifier, so that it can manage your subscription and send you receipts. You enter your card and billing details directly into Stripe, including the billing address it needs to calculate GST; exora never sees or stores either. It never receives health data.
Providers we may use. We identify these providers in advance so that we can change AI provider without first amending this policy. Naming a provider here does not mean that it currently receives your data. The list above records the providers actually in use, and we maintain it.
- Anthropic (Claude) - not currently used. If activated it would serve the same purposes Google Gemini Enterprise does today (document understanding, chat, and narrative generation) under equivalent commercial terms: no training on your data, and retention only for the provider’s own abuse monitoring. It would replace or sit alongside an existing provider for those tasks, not receive anything we do not already send for them. Extending AI processing to a category of data not already described in this policy would be a material change requiring notice under Section 13.
Any provider we activate from this list is bound by the same conditions as those above, and we update the current-use list when it happens. If we ever needed to share your data in a way that is not already described in this policy, that would be a material change and you would receive at least 14 days notice under Section 13.
Moving processing away from a third party, for example by running a model on our own infrastructure, reduces who receives your data rather than extending it, and does not require advance notice.
Message delivery providers (Resend, Twilio) receive your email address or phone number and the text of the message, never your health records. A message delivering a consult does not contain the consult itself. A text message says only that an exora link is ready or gives a verification code. An email may name the healthcare provider who shared the consult, which indicates that you consulted them.
Who cannot access your data: Other exora users (unless you share with them), advertisers, data brokers, insurance companies, or employers.
Access by exora staff: A small number of authorized exora personnel can access your records where necessary to run the service: for example, to provide support, investigate a problem, protect safety, or maintain the platform. This access is limited to those who need it, is recorded in an audit log, and is subject to confidentiality obligations. We do not access your health information for any other purpose.
We may disclose your personal information if required by law or legal process (such as a court order). If we receive a legal request for your data, we will notify you before disclosing it unless we are legally prohibited from doing so.
If exora is sold, merges, or closes. exora may one day be acquired, merge with another company, or cease trading. If that happens, personal information held in the Service may transfer to the new owner as part of the business. The following applies.
We will tell you before your information is transferred, and give you at least 30 days to export your records or delete your account first.
The acquirer is bound by this policy as it stands at the time of the transfer. If it later wishes to change how your information is handled, it must give you notice under Section 13, and you may leave with your data.
We will not sell your health records as a separate asset. Health data transfers only together with the Service that holds it, and only to an owner continuing to operate that Service. We will not sell, licence or transfer health records to a data broker, an advertising business, an insurer, or any buyer acquiring them for their own use rather than to run exora.
If exora becomes insolvent, an external administrator’s powers are set by law and may exceed what we can promise here. We would seek to give you notice and an export window, and would put the commitment above to the administrator, but we cannot guarantee an administrator’s decisions. We say so plainly because a promise that depends on our continued solvency is worth less than one that does not, and you are entitled to know which this is.
6. Where Your Data Is Stored and Processed
Stored in Australia. Your health records, documents, and account data are stored in Sydney, Australia, using Supabase (on AWS ap-southeast-2) and Google Cloud Platform (australia-southeast1).
AI processing happens overseas. This applies to every AI request, not to a subset of them. The Gemini models exora depends on are not offered in Google’s Australian region, so inference runs on Google’s global endpoint, which does not guarantee a processing location. When our AI processes your documents, chat messages, or voice conversations, content is sent to third-party AI providers. Our primary provider for document and chat AI is Google Cloud Gemini Enterprise. For real-time AI voice conversations (a Beta feature gated behind your explicit consent), we additionally use Google AI Studio’s Gemini Live API. We also use OpenAI for medical-code matching and some voice transcription, and Google Speech-to-Text for voice dictation that cannot be handled on your device. Where each one processes: Sentry and PostHog in the European Union; Google Speech-to-Text in Singapore; Gemini Enterprise on Google’s global endpoint, which may be any region Google operates; Gemini Live currently on US-based infrastructure; OpenAI in the United States. A provider’s corporate domicile does not determine where processing occurs: Vercel, for example, is incorporated in the United States but serves our API routes from Sydney. We may change, add, or remove AI providers based on quality, reliability, and cost. Per-provider terms:
- Google Cloud Gemini Enterprise (our primary provider): processed under our signed Cloud Data Processing Addendum. Server-side data caching is explicitly disabled at the project level, and your data is not used to train Google’s models. Inputs and outputs are not retained after a request completes, with one exception: Google runs automated safety classifiers over generative AI traffic, and where a request is flagged, Google may log that prompt and authorized Google personnel may review it. Flagged data is stored for a limited period and is not used for training. We applied to Google on 2 August 2026 for an exemption from this logging, and will update this policy with the outcome.
- Google AI Studio - Gemini Live API (voice conversations only): Real-time audio is streamed from our Sydney proxy server to Google’s global Gemini Live endpoint, which currently routes to US-based infrastructure for the audio model we use. As of this policy version, this flow is not covered by our Gemini Enterprise Cloud Data Processing Addendum. We use a paid AI Studio account, under which Google’s terms state that submitted prompts and responses are not used to improve or train its products. On the free tier they may be. Live API sessions carry a documented default retention of up to 24 hours. You can disable voice for any profile in Settings -> AI Assistant.
- OpenAI: processed under their commercial API terms; data is not used for AI model training; OpenAI may retain API data for up to 30 days for safety and abuse monitoring. We have requested zero data retention for our account.
- All providers: data is processed and returned to us, and is not used to train AI models. Retention is limited to the specific abuse-monitoring cases described above; no provider keeps your data as a matter of course.
We rely on signed contractual protections (Cloud Data Processing Addendum with Google; commercial terms of service with OpenAI, and data processing terms with Sentry and PostHog) as our safeguard under APP 8 of the Privacy Act. If a provider breaches the APPs in handling your data, exora remains accountable under section 16C of the Privacy Act.
Our API routes are hosted on Vercel, which may process requests through servers in multiple regions during transit. All data is stored in Australia; Vercel acts as a stateless transit layer only.
All infrastructure providers maintain standard operational logs (including IP addresses and request metadata) for security monitoring and debugging, subject to their own retention policies.
7. How We Protect Your Information
We employ the following measures to protect your information:
- Encryption: All data is encrypted in transit (TLS) and at rest by our infrastructure providers
- Access controls: Row-Level Security on all clinical database tables ensures other users cannot access your data. Authorized staff and back-end systems access it only through controlled, audited pathways (see “Access by exora staff” in Section 5)
- User-isolated storage: Each user’s documents are stored in their own folder
- Authentication: Sign-in uses one-time codes sent to your email address or phone. We do not use passwords and do not store any
- Biometric unlock: Face ID and Touch ID are processed on your device; biometric data never leaves your device
- Session security: Authentication tokens are rotated on every use
- Audit logging: Changes to your health data, and staff access to your records, are recorded in an audit log
- Infrastructure certification: Our database provider (Supabase) maintains SOC 2 Type II certification
No system is completely secure. If we ever experience a data breach affecting your personal information, we will notify you and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme.
8. How Long We Keep It
While your account is active: Your health data, documents, and chat history are retained for as long as your account exists. You can delete individual records at any time.
When you delete your account: All data is removed from live systems immediately and becomes inaccessible. Your account enters a 30-day recovery window during which you can reactivate by signing back in. After 30 days, an automated process permanently deletes all your data, including health records, documents, processing data, chat history, and storage files.
What survives deletion: Audit log entries are retained for at least 7 years after account deletion for compliance purposes. These logs contain user identifiers, timestamps, records of data changes, and records of administrative access to accounts. They are not anonymised. Aggregated processing metrics (which do not contain health data) are also retained. We also keep a record of which version of this policy and of our Terms of Service you accepted, and when, as evidence of that agreement; it contains no health information.
Records kept by your healthcare providers: When a verified healthcare provider you connect with records a consult, uploads a document, or writes a note for you on exora, exora retains a copy of that item on the provider’s behalf, as part of the provider’s own record of the care they provided. Healthcare providers are legally required to keep such records. A provider’s copy contains only the items that provider authored or uploaded, never your wider health record, and captures your name and date of birth as at the time it was created. It is retained even if you revoke the provider’s access, delete the item from your own record, or delete your exora account. If the provider sent the consult to you by text, email or QR code, the mobile number or email address it was sent to, and the name and date of birth entered with it, are kept as part of that copy. To request removal of a provider’s copy, contact that provider directly. Family members and other non-provider contacts do not retain copies. exora retains these copies as a convenience to providers and is not the provider’s system of record; providers remain responsible for meeting their own record-keeping obligations.
Records of who you shared with: When you give a verified healthcare provider access to your record, exora keeps a record of that access on the provider’s behalf: your name, your date of birth, and the dates their access started and ended. This forms part of the provider’s own record of who they treated and when they were able to see your information. This record contains nothing else - no health information, no documents, and no part of your wider record. In the provider’s app it appears as an inactive entry showing your name, your date of birth and those dates, with a button to ask you for access again. You can decline, and you can block a provider from asking you at all. It is retained even if you revoke that provider’s access or delete your exora account. Where a provider holds a record of access but has never created anything for you, you can ask us to remove it and we will. Where they have created something, that item is part of their own clinical record and you should contact them directly, as described above.
An identity check you carried out for someone else: If you vouched for another person’s identity on exora, that vouch belongs to their verification record, not yours, and it stays with them if you delete your exora account. It keeps your name and, where you vouched as a registered practitioner, your profession and registration number, because that is what gives the check its weight. Removing it would quietly downgrade another person’s verified status because you left. It holds no health information, and we do delete what we captured about you at the time of the check, including your device and network details.
Backup retention: Automated database backups are kept for 7 days on a rolling basis. Uploaded documents are stored in file storage and retained for as long as your account is active. They are not included in database backups and are permanently deleted when your account is deleted.
AI provider retention: Google Cloud Gemini Enterprise (our primary provider) does not retain API data; server-side caching is disabled at the project level under our Cloud Data Processing Addendum. OpenAI may retain API data for up to 30 days for safety monitoring under their commercial API terms; we have requested zero data retention for our account.
Appointment recordings: The audio of a recorded appointment is deleted automatically 30 days after it is recorded. While it is still available the app shows you the date it will go, and you can download a copy to keep or delete it sooner yourself. The transcript, the summary, and any health information extracted from the recording are part of your health record and are kept for as long as your account exists.
Fitness and wellness data: Kept for as long as your account exists. Disconnecting a health app or wearable stops any further data being collected; the daily summaries, workouts and sleep sessions already in your record remain part of that record, and are deleted when you delete the profile they belong to or your account.
Travel plans: Kept until you delete the trip or your account. The record of changes to a trip, and any traveller without an exora profile, are kept with the trip and deleted with it. A trip is also deleted if every profile travelling on it is deleted and no one else is on it.
Shared Health Summaries and trip plans: A link you create stops working when its time runs out, after ten openings, or when you turn it off. The record of who read a Health Summary or trip plan you shared, and when, is kept so that you can see it, until the profile it is filed under or your account is deleted.
Travel documents: Kept with their trip until you delete them, the trip, or your account. A file you add that is not saved to a trip is deleted within 24 hours. About a week after a trip ends, the app asks you once whether to keep that trip’s documents or delete them. Deleted travel documents are permanently removed from storage, usually within a day.
Local device data: Voice recordings stored on your device are automatically deleted after 7 days. Cached session data is cleared when you sign out.
AI voice conversations: When you have a real-time voice conversation with the AI assistant, we keep three things: (1) an audio recording of the conversation (both your side and the assistant’s) stored securely with your chat history so you can replay it, accessible only to you; (2) session metadata (start time, end time, reason for ending, the volume of data transferred, and any error states) in our audit log, for security and abuse-detection purposes; and (3) the text transcript in your chat history. The recording and transcript follow your chat history: if you delete the conversation, they are deleted too (after the 30-day recovery window), and they are removed when you delete your account. We currently retain voice recordings indefinitely while we improve our voice transcription. We will review this retention period and amend this policy accordingly. Audio is never used to train AI models.
Marketing contact information: Retained for as long as you remain subscribed. When you unsubscribe (one-click via any marketing email or at exora.au/unsubscribe), we keep the row marked as unsubscribed so we have proof of your consent revocation and so we never accidentally re-subscribe you. To request full deletion of the row itself, email hello@exora.au; we will action it within 30 days.
9. Artificial Intelligence
What our AI does. When you upload a medical document, our AI reads the full content of that document, including any names, dates and other personal details it contains, to identify health information (conditions, medications, allergies, vital signs, lab results, procedures, immunizations) and organize it into your structured health record. Our AI chat assistant can answer questions about your health data. You can also send photos for AI analysis and use voice input that is transcribed by AI. When you plan or change a trip in chat, our AI reads what you write, and the trip as it stands, to fill in the trip (where, when and who is going) for you to check and confirm; nothing is saved or changed until you do. When you add travel documents to a trip, a separate AI reader used only for travel reads them in the same way, taking out only what Section 2 describes; the chat assistant itself does not see them, and they are not processed as medical documents unless you choose to add a vaccination record to your health records. The travel list itself is not written by AI: it relays what governments publish for your destinations and sets it against your records. It is not medical advice, and you should go through it with your doctor or a travel clinic.
AI providers. Document understanding (entity extraction, structuring, narrative generation) and chat run primarily on Google Cloud Gemini Enterprise with Gemini models. Document scanning OCR runs on Google Cloud Vision. Voice dictation is transcribed on your device where possible, and otherwise by Google Speech-to-Text. We also use OpenAI for matching your clinical terms to standard medical codes, and as a fallback for voice transcription. We may change, add, or remove providers based on quality, reliability, and cost. The current list of providers and what data each receives is in Section 5.
Your data and AI training. Your health data is not used to train AI models. Our AI providers process your data solely to return results to you, under their commercial API terms. Providers may temporarily retain data for safety monitoring (see Section 8). We do not currently use your data to train or improve exora’s own AI systems. In future, we may offer you the opportunity to contribute de-identified data to improve our systems. Any such use would require your separate, explicit consent.
AI accuracy. AI-extracted information may contain errors, omissions, or misinterpretations. Data quality indicators shown in the app reflect processing confidence and do not constitute clinical validation. Medical codes are AI-assigned and have not been verified by a healthcare professional. Always verify important health information with your healthcare provider and against your original documents.
No automated decisions. Our AI organizes and summarizes your health information. It does not make medical decisions, diagnoses, or treatment recommendations. No automated decisions are made by our systems that affect your legal rights or interests. Using exora does not create a doctor-patient or healthcare provider relationship.
Emergencies. The exora app is not designed for medical emergencies. If you are experiencing a medical emergency, call 000 (Australia) or your local emergency number immediately.
AI voice conversations (Beta). A separate Beta feature lets you hold a real-time spoken conversation with our AI assistant about a specific profile’s health records. This is structurally different from the voice-to-text chat input (where a single clip is transcribed and discarded). Here, your microphone audio is streamed continuously, the AI’s spoken response is streamed back, and the conversation can include multiple back-and-forth turns.
How the connection works. Your device establishes an authenticated connection to our server in Sydney, which holds our credentials for the Google service so that they are never present on your device. Your microphone audio passes through that server to Google’s Gemini Live API, and the assistant’s response audio returns by the same route. We retain session metadata (start time, duration, reason for ending, and the volume of data transferred) and the text transcript for audit and abuse-detection purposes. We also record the conversation, both sides, as an audio file stored with your chat history so that you can replay it; only you can access that recording. Section 8 sets out how long each of these is kept.
Per-profile opt-in. Voice conversations are OFF by default for every profile. To enable them, the profile owner navigates to Settings -> AI Assistant and toggles “AI voice conversations” on. The setting follows the profile, not the account holder. If you share a profile with someone else, voice availability on that profile is the owner’s choice.
Informed consent before first use. The first time you actually start a voice conversation for a profile, you will see a consent dialog summarising what data is sent, where it is processed, what is retained, and that you can withdraw the feature at any time in Settings. You must tap “I understand and consent” before any audio leaves your device. Acceptance is recorded with a timestamp.
Withdrawing voice access. Toggle the feature off in Settings -> AI Assistant at any time. Existing session logs, transcripts, and voice recordings remain in your audit log and chat history under your control (you can delete individual chat sessions, which deletes their recordings too). Disabling voice does not delete past records; we recommend reviewing the relevant section of this policy for our retention details.
Region of processing. As of this policy version, real-time voice conversations are processed by Google’s Gemini Live API in their global infrastructure, currently routing to US-based servers for the audio model we use. We are evaluating migration to Vertex AI in Sydney once the live-audio model is published in the Australian region. This policy will be updated when that change occurs.
Why this is treated differently from text chat. Document understanding and text chat run on Google Cloud Gemini Enterprise (Vertex AI) under our signed Cloud Data Processing Addendum. That contract does not extend to the Gemini Live API on Google AI Studio. We have made the live-voice feature available in Beta while we evaluate the data residency and contractual options available to us. The per-profile opt-in, the consent dialog and the audit logging exist so that your choice to use it is an informed one.
The voice assistant is not a medical professional. Everything in this section also applies to voice: the AI organizes and summarizes your information; it does not provide medical advice, diagnoses, or treatment recommendations. Do not rely on the voice assistant in a medical emergency. Call 000, or your local emergency number, instead.
10. Your Rights
Under the Australian Privacy Principles, you have the right to:
Access your data. You can view all your health data in the app. To request a full copy of your personal information, contact us at hello@exora.au. We will respond within 30 days.
Correct your data. You can edit your profile information in the app. For AI-extracted health records, you can add notes, delete inaccurate records, or re-upload corrected documents. If you believe any other information we hold is inaccurate, contact us and we will correct it.
Delete your data. You can delete individual records in the app, or delete your entire account from Settings. Account deletion removes all your data (see Section 8 for details).
Control sharing. You choose who to share your health data with, what to share, and for how long. You can revoke access at any time.
Withdraw consent. Consent for AI processing is given each time you upload a document, start a chat, or connect a device, so you withdraw it by not doing those things - there is no standing permission sitting switched on. Routine updates continue on records you have already added: a medication is marked finished once its prescribed course has ended, and duplicate visits are merged. To stop that as well, delete the data. Because holding your records is itself processing under privacy law, we cannot keep your records and not process them - so deleting your data, a profile, or your account is what ends processing completely.
Deal with us anonymously or by pseudonym. You may deal with us anonymously or under a pseudonym for general enquiries. This is not possible where we need to identify you in order to provide the Service, such as where you hold an account containing health records, or where the law requires us to identify you.
Complain. See Section 15.
How to make a request. The remainder of this section explains how to exercise the rights above. Send any request to hello@exora.au. Before acting on a request concerning an account, we will take reasonable steps to confirm that you are the account holder. This protects you against someone else obtaining or deleting your records. We do not charge a fee for access, correction or deletion. Where you ask for a copy of your personal information, we provide it in a commonly used, machine-readable format.
When we may refuse a request. We may decline a request where the law permits or requires us to do so: for example, where granting access would have an unreasonable impact on another person’s privacy, where the request is frivolous or vexatious, or where the information relates to an anticipated legal proceeding. If we refuse a request, we will tell you why in writing and explain how to complain.
If you are outside Australia. The law where you live may give you rights in addition to, or different from, those set out above. Section 14 explains how we handle those requests.
11. Children and Young People
exora requires a minimum age of 14 to create an independent account in Australia. This aligns with the age at which individuals gain control of their own My Health Record.
Outside Australia, the minimum age to create an independent account is 14, or a higher age where the law of the country you live in requires one.
Parents and guardians can manage health records for children of any age through dependent profiles on their account. The parent or guardian declares their authority when creating a dependent profile and controls all data and sharing for that profile.
We do not knowingly allow children below the minimum age for their region to create independent accounts. If we discover an account was created by someone under the minimum age, we will work with the child’s parent or guardian to resolve the situation, which may include closing the account or migrating data to a parent-managed dependent profile.
12. Cookies and Tracking
We do not use advertising cookies, tracking pixels, or cross-site tracking.
Our web app uses essential cookies only for authentication and session management. These are necessary for the app to function and do not track you across other websites.
Marketing website analytics. Our marketing website at exora.au uses Vercel Web Analytics and Speed Insights to measure aggregate visitor traffic and page performance. These tools are cookieless and do not identify you individually. They collect: the page URL visited, the referring website, your approximate country (derived from your IP address, which is then discarded and not stored), device type, browser, operating system, and Core Web Vitals performance metrics. The data is aggregated and used solely to understand how our marketing site performs and to improve it. Vercel acts as our data processor.
In-app crash reporting and product analytics. Inside the exora apps we use two tools: Sentry for crash and error reporting, and PostHog for product analytics. Both are hosted in the European Union rather than the United States. Both are configured to collect substantially less than their default settings allow, because those defaults are not appropriate for a health application.
What they receive: your account identifier, which features and controls you use, and, when something goes wrong, the technical details of the error and where in the app it occurred.
What they do not receive: your name, email address or IP address; any part of your health records; the contents of your documents, chat messages or search terms. Specifically, and because these are the settings that would otherwise capture patient information:
- Session replay is switched off. This feature records on-screen content, which in a health application would include health information.
- Autocapture is switched off. This feature automatically records taps and the text visible on screen.
- Performance tracing is switched off, so we do not sample the network requests the app makes.
- Error reports are stripped of request contents, cookies, headers and diagnostic messages before they are sent.
We use this information to identify crashes and to understand which parts of exora are used. It is not used for advertising, is never sold or shared with third parties, and is not used to train AI models. If you would like your analytics and crash data deleted, email hello@exora.au.
13. Changes to This Policy
We may update this policy to reflect changes in our practices or legal requirements.
Material changes (changes to what data we collect, how we use it, or who we share it with, other than a new optional feature described below): We will give you at least 14 days advance notice via in-app notification and/or email before the changes take effect.
New optional features: When we add a feature that collects or uses information only if you choose to use it, we may update this policy to describe it when the feature becomes available, without advance notice. Nothing changes for information you have already given us, and nothing is collected until you use the feature. If you do not agree, you can simply not use it.
Minor changes (clarifications, formatting, correcting errors): We may update the policy without advance notice.
The date at the top of this policy indicates when it was last updated. Previous versions are available on request by contacting hello@exora.au. Continued use of exora after changes take effect constitutes acceptance of the updated policy. If you do not agree with the changes, you may delete your account before they take effect.
14. Users Outside Australia
exora is operated from Australia and is designed principally for Australian users. Our apps are available in other countries, and this section explains what that means for you.
Your information is held in Australia. If you use exora from outside Australia, your personal information is transferred to and stored in Australia and is handled under Australian law. Section 6 sets out where processing occurs, including the AI processing that takes place outside Australia for all users.
The standard we apply. We apply the Australian Privacy Principles to every user regardless of location. We do not operate a lower standard for users outside Australia.
The law where you live may give you additional rights. Privacy law in your country may give you rights that the Australian Privacy Principles do not, such as rights to data portability, to restrict processing, or to object to processing. Where the law requires us to honour such a request, we will do so. Contact us at hello@exora.au and tell us where you are located, so that we can identify which law applies to your request.
The language of this policy. This policy is written in English. We publish translations in other languages for your convenience, and we work to keep them accurate. If a translation differs from the English version, the English version applies. This does not limit any right you have under the law where you live to receive information in your own language.
Complaints from outside Australia. You may complain to us first under Section 15. You may also be able to complain to the privacy regulator where you live:
- European Economic Area: the supervisory authority for your country. A list is maintained by the European Data Protection Board at edpb.europa.eu
- United Kingdom: the Information Commissioner’s Office, ico.org.uk
- New Zealand: the Office of the Privacy Commissioner, privacy.org.nz
- Canada: the Office of the Privacy Commissioner of Canada, priv.gc.ca, or your provincial privacy commissioner
- Brazil: the Autoridade Nacional de Proteção de Dados, gov.br/anpd
- Elsewhere: contact us and we will tell you which regulator, if any, oversees our handling of your information in your country
15. Complaints
If you have a concern about how we handle your personal information:
Step 1 - Contact us. Email our Privacy Officer at hello@exora.au. We will acknowledge your complaint within 5 business days.
Step 2 - Investigation. We will investigate your complaint and provide a substantive response within 30 days. If we need more time, we will let you know.
Step 3 - Escalation. If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC). If you are outside Australia, Section 14 also lists the privacy regulator for your country. The OAIC’s contact details are:
- Website: www.oaic.gov.au
- Phone: 1300 363 992
- Online complaint form: www.oaic.gov.au/privacy/privacy-complaints
- Post: GPO Box 5288, Sydney NSW 2001
16. Contact Us
Exora Health Pty Ltd
ABN 16 690 025 462
Privacy Officer: hello@exora.au
For questions about this privacy policy, how we handle your data, or to exercise any of your rights, contact us at the email address above.
Governing law. This privacy policy is governed by the laws of Australia. Nothing in this policy limits any right you have under the law of the country where you live that cannot be excluded by agreement.
See also our Terms of Service for the rules governing your use of exora.