Privacy Policy
Exora Health Pty Ltd (ABN 16 690 025 462)
Effective date: 20 August 2026 | Version: 2.0
At a Glance
- Your health data is stored in Australia (Sydney data centers). AI processing happens overseas - the models we use are not offered in an Australian region, so inference runs on international infrastructure under contractual protections (see Section 6)
- We never sell your data or use it for advertising
- You control who sees your data - sharing is always initiated by you, and you can revoke access at any time
- You can delete your account at any time - 30-day recovery window, then permanent deletion of your health data, documents, and personal information (audit logs retained for compliance)
- If exora is ever sold, your health records are not for sale separately - they transfer only together with the service, only to an owner continuing to run it, and you get at least 30 days to export or delete first (see Section 5)
- Verified healthcare providers keep their own copy of what they create for you - consults, notes, and documents they author during your care stay in their own file even if you revoke access or delete your account (see Section 8), and they keep a record that you shared with them at all - your name, date of birth and the dates access ran, and nothing more; family members and other non-providers keep nothing
- Our document processing AI runs on Google Cloud Gemini Enterprise under a signed Cloud Data Processing Addendum, with server-side data caching disabled - inputs and outputs are not retained by Google after a request completes, subject to one exception: prompts flagged by Google’s automated safety classifiers may be logged and reviewed. We have applied for an exemption (see Section 6). We also use OpenAI for two narrow tasks (medical-code matching and some voice transcription). Under all our commercial agreements, providers do not train AI models on your data.
- Voice dictation is transcribed on your device where your phone supports it - in that case the audio never leaves your phone at all
- We use crash reporting and product analytics inside the app (Sentry and PostHog, both EU-hosted). They receive your account identifier and which features are used - never your health information, never screen recordings (see Section 12)
- We do not include sensitive health details in push notifications
- Contact us at hello@exora.au with any privacy questions
Contents
- About This Policy
- What We Collect
- How We Collect It
- Why We Use It
- Who We Share It With
- Where Your Data Is Stored and Processed
- How We Protect Your Information
- How Long We Keep It
- Artificial Intelligence
- Your Rights
- Children and Young People
- Cookies and Tracking
- Changes to This Policy
- Users Outside Australia
- Complaints
- Contact Us
1. About This Policy
This privacy policy explains how Exora Health Pty Ltd (ABN 16 690 025 462) (“exora”, “we”, “us”, “our”) collects, uses, stores, discloses and protects personal information when you visit our marketing website at exora.au or use the exora platform, being our mobile app and our web app at app.exora.au (together, the “Service”).
exora is a personal health data platform that helps you organize your medical records using artificial intelligence. You upload your medical documents, and our AI extracts and structures the health information for your personal use.
Who this policy applies to. This policy applies to everyone whose personal information we hold. That includes account holders, the people whose health records are kept in a profile, healthcare providers and other people you share records with, visitors to our website, and people whose personal information appears in a document that a user uploads. Section 2 explains how we handle information about people who are not exora users.
Where exora is operated from. exora is operated from Australia by an Australian company, and health records are stored in Australia. The Service is available in other countries. We apply the standard set out in this policy to every user, wherever they are located. Section 14 sets out what this means if you are outside Australia.
We are bound by the Australian Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles (APPs). Health information is classified as sensitive information under the Act, and we treat it with additional care.
exora is not a medical device, healthcare provider, or clinical decision support system. Information provided by exora, including AI-generated summaries and structured health records, is for your personal reference only and does not constitute medical advice, diagnosis, or treatment. Always consult a qualified healthcare professional for medical decisions.
Terms used in this policy. The first three carry the same meaning as in our Terms of Service.
- Health Data means medical documents you upload, the clinical information our AI extracts from them (conditions, medications, allergies, vital signs, lab results, procedures, immunizations), and any related data stored in your exora account.
- AI Processing means the use of artificial intelligence to extract, structure, organize, and summarize information from your uploaded documents and to power the AI chat assistant. In this policy it also covers the real-time voice assistant described in Section 9.
- Profile means a health record identity within your account. You may have a profile for yourself and profiles for dependents you manage. Several settings described in this policy apply to a profile rather than to an account.
- Account means the sign-in belonging to a single person, identified by an email address or phone number. One account may hold more than one profile.
- Verified healthcare provider means a user whose professional registration exora has verified, and who therefore has access to provider features. Section 8 sets out what records a verified healthcare provider retains.
2. What We Collect
Account information: Your name, email address or phone number, date of birth, and optional fields such as biological sex and gender identity. Your PIN is stored as a secure hash only. We never see or store the PIN itself. If you verify your identity through ConnectID, we receive your verified legal name and date of birth from your bank.
Health information: Medical documents you upload (PDFs, images, scans) and the clinical data our AI extracts from them, including conditions, medications, allergies, vital signs, laboratory results, procedures, and immunization records. This is sensitive information under the Privacy Act and is only collected with your express consent.
Information about other people: A document you upload will often contain personal information about people other than the profile it relates to: the name of your general practitioner or specialist, a person recorded as your next of kin, or a relative whose condition appears in a family history. Our AI reads the whole document, so this information is processed, and some of it is stored as part of your health record: which practitioner an appointment was with, for example, or a family history entry. We collect it because it appears in a document you have chosen to upload, and we use it only to organize and display your own record. We do not create an exora account or an independent record for those people, and we do not contact them. If you believe you are named in a document another person has uploaded and you wish to know what we hold, contact us at hello@exora.au. We will handle your request in the same way as a request from an account holder under Section 10.
Chat data: Messages you send to our AI health assistant and photos you share in chat for analysis. Photos shared in chat are stored on our servers alongside your chat history and are deleted when you delete the chat session or your account.
Voice-to-text input (chat composer mic): When you tap the microphone in the chat composer, your speech is converted to text. Where your device supports on-device speech recognition, this happens entirely on your phone and the audio never leaves the device. Where it does not, including older devices and the web app, the clip is uploaded and transcribed by Google Speech-to-Text in Singapore. Where a clip exceeds 60 seconds, which that service cannot process in a single request, it is transcribed by OpenAI instead. In every case the audio is transcribed and discarded immediately; we do not retain voice clips on our servers.
AI voice conversations (AI Assistant): When you opt in to AI voice conversations in Settings -> AI Assistant and explicitly accept the consent dialog the first time you use it, you can hold a spoken conversation with our AI assistant. Your microphone audio is streamed in real time to Google’s Gemini Live AI service for the duration of the conversation. We record the conversation (both your side and the assistant’s) as an audio file stored securely with your chat history so you can play it back; only you can access it. We also keep structured session metadata and the text transcript of the conversation (see Section 8). See Section 9 for the full description of how this works.
Device information: A unique identifier generated by the app (not a hardware device ID), your device name, platform (iOS or Android), app version, and push notification token if you enable notifications.
Location information (optional): If you grant location permission, we use your device’s approximate location to improve two features: suggesting nearby places when you add an appointment, and giving the AI health assistant city-level context. We use approximate (coarse) location only, never precise location, and only at the moment you use these features. We do not track you and we do not build a location history. You can decline location access and both features still work without it.
Marketing contact information: If you submit any form on our website (contact form, blog “follow along” signup, family-history-request, future EOI surfaces), we capture your email address, the form submitted, and limited submission metadata (page URL, UTM parameters, country and locale at submission, IP address, and the exact consent copy you saw). This is stored in our Sydney-hosted Supabase database (see Section 6) and used as described in Section 4.
Diagnostics and product analytics: Crash reports and a record of which features you use, so we can find bugs and understand which parts of exora are useful. These carry your account identifier only, not your name, email address or IP address, and never the contents of your health records. See Section 12 for exactly what is and is not collected.
What we do not collect: Contacts, browsing history, advertising identifiers, biometric data (Face ID and Touch ID are processed entirely on your device), precise (GPS-level) location, or payment information.
3. How We Collect It
Directly from you: When you create an account, set up profiles, upload documents, send chat messages, take photos, or use voice input.
Automatically from your device: Device identifiers, platform information, and push notification tokens are collected when you use the app.
From your documents via AI processing: When you upload a medical document, our AI reads it and extracts structured health information. This processing is initiated by you and serves the primary purpose of organizing your health data.
From identity verification providers: If you choose to verify your identity, ConnectID returns your verified name and date of birth from your bank. This only happens when you initiate the process.
From external health data sources: In future, we may enable you to connect exora to external health data sources such as government health records or pathology providers. If we do, you will initiate and authorize each connection yourself, and you will be able to disconnect at any time. We will update this policy before launching any such integration.
4. Why We Use It
We collect your information to provide you with a personal, AI-powered health data platform. Specifically:
- Providing the service: Storing, organizing, and displaying your health records; processing your documents through our AI pipeline; powering the AI health assistant
- Account management: Authentication, device management, push notifications (with your permission)
- Sharing: Enabling you to share your health data with people and healthcare providers you choose
- Identity verification: Verifying your identity when you choose to use ConnectID
- Service improvement: Using aggregated, de-identified usage patterns and crash reports to fix problems and improve the platform (we do not use individual health data for this purpose: see Section 12)
- Marketing communications: Building a list of people who have submitted a form expressing interest in exora, so we can send product updates and the occasional newsletter. Every marketing email includes a one-click unsubscribe link. You can revoke at any time at exora.au/unsubscribe (use the link from any email we have sent you) or by emailing hello@exora.au.
- Legal compliance: Meeting our obligations under Australian law
What we do not use your data for: Advertising, sale to third parties, data mining, or commercial profiling. We do not use your health data to train AI models, and our AI providers do not train their models on it. If we ever wished to use de-identified data to improve our own systems, we would ask for your separate, explicit consent first (see Section 9). We do not send marketing messages unless you explicitly opt in.
When you upload a medical document, you consent to its processing by our AI systems to extract, structure, and organize your health data. We also send necessary service communications (authentication codes, security alerts, policy updates) via email or SMS. These are not marketing.
5. Who We Share It With
People you choose: You control who sees your health data. You can share specific records with family members, carers, or healthcare providers through exora’s sharing features. You choose the permission level and can revoke access at any time. All sharing actions are logged.
Service providers we currently use: These are the providers operating exora today, and what each one receives:
- Supabase - database and file storage (data hosted in Sydney, Australia)
- Google Cloud Platform - infrastructure (worker compute, OCR, storage in Sydney, Australia)
- Google Maps Platform (Places) - powers nearby-place suggestions when you add an appointment; receives your approximate location and search text only when you use that feature
- Google Cloud Gemini Enterprise (Vertex AI) - AI inference for document understanding, chat (text), narrative generation, and voice-to-text transcription. Routed via Google Cloud’s global endpoint under our signed Cloud Data Processing Addendum, with project-level data caching disabled. Inputs and outputs are not retained by Google after a request completes, except where flagged by Google’s automated abuse-monitoring classifiers. Section 6 sets out the detail, and the exemption we have applied for.
- Google AI Studio (Gemini Live API) - AI inference for real-time AI voice conversations (Beta). This is a different Google product to Gemini Enterprise above. Audio is streamed to Google’s global infrastructure (currently US-based for the model we use); the Cloud Data Processing Addendum that covers our Gemini Enterprise usage does not extend here. Use is gated behind explicit per-profile opt-in and informed consent (see Section 9). We are evaluating migration of this flow to Vertex AI Sydney once Google publishes the live-audio model variant there; this policy will be updated when that happens.
- Google Speech-to-Text (Singapore) - converts a dictated voice clip to text when your device cannot do it locally. Receives the audio clip only, and only for that request
- OpenAI - two narrow uses only: generating the mathematical representations we use to match your clinical terms to standard medical codes, and transcribing a dictated voice clip in the small number of cases the paths above cannot handle. It does not process your chat messages and it does not receive your documents
- Sentry (European Union) - crash and error reporting inside the app. Receives your account identifier, the error, and where in the app it happened. Never health information (see Section 12)
- PostHog (European Union) - product analytics inside the app. Receives your account identifier and which features are used. Never health information, and screen recording is switched off (see Section 12)
- Vercel - hosts our marketing website and API routes (stateless transit layer for app data; app data is stored in Australia). Also provides cookieless aggregate analytics for the marketing website (see Section 12)
- ConnectID - identity verification (Australia only)
- Expo - push notification delivery routing
- Resend - email delivery for authentication messages and marketing emails (receives your email address only; never receives health data)
- Twilio - SMS delivery for authentication messages (receives your phone number only)
Providers we may use. We identify these providers in advance so that we can change AI provider without first amending this policy. Naming a provider here does not mean that it currently receives your data. The list above records the providers actually in use, and we maintain it.
- Anthropic (Claude) - not currently used. If activated it would serve the same purposes Google Gemini Enterprise does today (document understanding, chat, and narrative generation) under equivalent commercial terms: no training on your data, and retention only for the provider’s own abuse monitoring. It would replace or sit alongside an existing provider for those tasks, not receive anything we do not already send for them. Extending AI processing to a category of data not already described in this policy would be a material change requiring notice under Section 13.
Any provider we activate from this list is bound by the same conditions as those above, and we update the current-use list when it happens. If we ever needed to share your data in a way that is not already described in this policy, that would be a material change and you would receive at least 14 days notice under Section 13.
Moving processing away from a third party, for example by running a model on our own infrastructure, reduces who receives your data rather than extending it, and does not require advance notice.
Authentication delivery providers (Resend, Twilio) receive only your email or phone number for delivering login codes. They do not receive health data.
Who cannot access your data: Other exora users (unless you share with them), advertisers, data brokers, insurance companies, or employers.
Access by exora staff: A small number of authorized exora personnel can access your records where necessary to run the service: for example, to provide support, investigate a problem, protect safety, or maintain the platform. This access is limited to those who need it, is recorded in an audit log, and is subject to confidentiality obligations. We do not access your health information for any other purpose.
We may disclose your personal information if required by law or legal process (such as a court order). If we receive a legal request for your data, we will notify you before disclosing it unless we are legally prohibited from doing so.
If exora is sold, merges, or closes. exora may one day be acquired, merge with another company, or cease trading. If that happens, personal information held in the Service may transfer to the new owner as part of the business. The following applies.
We will tell you before your information is transferred, and give you at least 30 days to export your records or delete your account first.
The acquirer is bound by this policy as it stands at the time of the transfer. If it later wishes to change how your information is handled, it must give you notice under Section 13, and you may leave with your data.
We will not sell your health records as a separate asset. Health data transfers only together with the Service that holds it, and only to an owner continuing to operate that Service. We will not sell, license or transfer health records to a data broker, an advertising business, an insurer, or any buyer acquiring them for their own use rather than to run exora.
If exora becomes insolvent, an external administrator’s powers are set by law and may exceed what we can promise here. We would seek to give you notice and an export window, and would put the commitment above to the administrator, but we cannot guarantee an administrator’s decisions. We say so plainly because a promise that depends on our continued solvency is worth less than one that does not, and you are entitled to know which this is.
6. Where Your Data Is Stored and Processed
Stored in Australia. Your health records, documents, and account data are stored in Sydney, Australia, using Supabase (on AWS ap-southeast-2) and Google Cloud Platform (australia-southeast1).
AI processing happens overseas. This applies to every AI request, not to a subset of them. The Gemini models exora depends on are not offered in Google’s Australian region, so inference runs on Google’s global endpoint, which does not guarantee a processing location. When our AI processes your documents, chat messages, or voice conversations, content is sent to third-party AI providers. Our primary provider for document and chat AI is Google Cloud Gemini Enterprise. For real-time AI voice conversations (a Beta feature gated behind your explicit consent), we additionally use Google AI Studio’s Gemini Live API. We also use OpenAI for medical-code matching and some voice transcription, and Google Speech-to-Text for voice dictation that cannot be handled on your device. Where each one processes: Sentry and PostHog in the European Union; Google Speech-to-Text in Singapore; Gemini Enterprise on Google’s global endpoint, which may be any region Google operates; Gemini Live currently on US-based infrastructure; OpenAI in the United States. A provider’s corporate domicile does not determine where processing occurs: Vercel, for example, is incorporated in the United States but serves our API routes from Sydney. We may change, add, or remove AI providers based on quality, reliability, and cost. Per-provider terms:
- Google Cloud Gemini Enterprise (our primary provider): processed under our signed Cloud Data Processing Addendum. Server-side data caching is explicitly disabled at the project level, and your data is not used to train Google’s models. Inputs and outputs are not retained after a request completes, with one exception: Google runs automated safety classifiers over generative AI traffic, and where a request is flagged, Google may log that prompt and authorized Google personnel may review it. Flagged data is stored for a limited period and is not used for training. We applied to Google on 2 August 2026 for an exemption from this logging, and will update this policy with the outcome.
- Google AI Studio - Gemini Live API (voice conversations only): Real-time audio is streamed from our Sydney proxy server to Google’s global Gemini Live endpoint, which currently routes to US-based infrastructure for the audio model we use. As of this policy version, this flow is not covered by our Gemini Enterprise Cloud Data Processing Addendum. We use a paid AI Studio account, under which Google’s terms state that submitted prompts and responses are not used to improve or train its products. On the free tier they may be. Live API sessions carry a documented default retention of up to 24 hours. You can disable voice for any profile in Settings -> AI Assistant.
- OpenAI: processed under their commercial API terms; data is not used for AI model training; OpenAI may retain API data for up to 30 days for safety and abuse monitoring. We have requested zero data retention for our account.
- All providers: data is processed and returned to us, and is not used to train AI models. Retention is limited to the specific abuse-monitoring cases described above; no provider keeps your data as a matter of course.
We rely on signed contractual protections (Cloud Data Processing Addendum with Google; commercial terms of service with OpenAI, and data processing terms with Sentry and PostHog) as our safeguard under APP 8 of the Privacy Act. If a provider breaches the APPs in handling your data, exora remains accountable under section 16C of the Privacy Act.
Our API routes are hosted on Vercel, which may process requests through servers in multiple regions during transit. All data is stored in Australia; Vercel acts as a stateless transit layer only.
All infrastructure providers maintain standard operational logs (including IP addresses and request metadata) for security monitoring and debugging, subject to their own retention policies.
7. How We Protect Your Information
We employ the following measures to protect your information:
- Encryption: All data is encrypted in transit (TLS) and at rest by our infrastructure providers
- Access controls: Row-Level Security on all clinical database tables ensures other users cannot access your data. Authorized staff and back-end systems access it only through controlled, audited pathways (see “Access by exora staff” in Section 5)
- User-isolated storage: Each user’s documents are stored in their own folder
- Authentication: Sign-in uses one-time codes sent to your email address or phone. We do not use passwords and do not store any
- Biometric unlock: Face ID and Touch ID are processed on your device; biometric data never leaves your device
- Session security: Authentication tokens are rotated on every use
- Audit logging: Changes to your health data, and staff access to your records, are recorded in an audit log
- Infrastructure certification: Our database provider (Supabase) maintains SOC 2 Type II certification
No system is completely secure. If we ever experience a data breach affecting your personal information, we will notify you and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme.
8. How Long We Keep It
While your account is active: Your health data, documents, and chat history are retained for as long as your account exists. You can delete individual records at any time.
When you delete your account: All data is removed from live systems immediately and becomes inaccessible. Your account enters a 30-day recovery window during which you can reactivate by signing back in. After 30 days, an automated process permanently deletes all your data, including health records, documents, processing data, chat history, and storage files.
What survives deletion: Audit log entries are retained for at least 7 years after account deletion for compliance purposes. These logs contain user identifiers, timestamps, records of data changes, and records of administrative access to accounts. They are not anonymised. Aggregated processing metrics (which do not contain health data) are also retained.
Records kept by your healthcare providers: When a verified healthcare provider you connect with records a consult, uploads a document, or writes a note for you on exora, exora retains a copy of that item on the provider’s behalf, as part of the provider’s own record of the care they provided. Healthcare providers are legally required to keep such records. A provider’s copy contains only the items that provider authored or uploaded, never your wider health record, and captures your name as at the time it was created. It is retained even if you revoke the provider’s access, delete the item from your own record, or delete your exora account. To request removal of a provider’s copy, contact that provider directly. Family members and other non-provider contacts do not retain copies. exora retains these copies as a convenience to providers and is not the provider’s system of record; providers remain responsible for meeting their own record-keeping obligations.
Records of who you shared with: When you give a verified healthcare provider access to your record, exora keeps a record of that access on the provider’s behalf: your name, your date of birth, and the dates their access started and ended. This forms part of the provider’s own record of who they treated and when they were able to see your information. This record contains nothing else - no health information, no documents, and no part of your wider record. In the provider’s app it appears as an inactive entry showing your name, your date of birth and those dates, with a button to ask you for access again. You can decline, and you can block a provider from asking you at all. It is retained even if you revoke that provider’s access or delete your exora account. Where a provider holds a record of access but has never created anything for you, you can ask us to remove it and we will. Where they have created something, that item is part of their own clinical record and you should contact them directly, as described above.
Backup retention: Automated database backups are kept for 7 days on a rolling basis. Uploaded documents are stored in file storage and retained for as long as your account is active. They are not included in database backups and are permanently deleted when your account is deleted.
AI provider retention: Google Cloud Gemini Enterprise (our primary provider) does not retain API data; server-side caching is disabled at the project level under our Cloud Data Processing Addendum. OpenAI may retain API data for up to 30 days for safety monitoring under their commercial API terms; we have requested zero data retention for our account.
Local device data: Voice recordings stored on your device are automatically deleted after 7 days. Cached session data is cleared when you sign out.
AI voice conversations: When you have a real-time voice conversation with the AI assistant, we keep three things: (1) an audio recording of the conversation (both your side and the assistant’s) stored securely with your chat history so you can replay it, accessible only to you; (2) session metadata (start time, end time, reason for ending, the volume of data transferred, and any error states) in our audit log, for security and abuse-detection purposes; and (3) the text transcript in your chat history. The recording and transcript follow your chat history: if you delete the conversation, they are deleted too (after the 30-day recovery window), and they are removed when you delete your account. We currently retain voice recordings indefinitely while we improve our voice transcription. We will review this retention period and amend this policy accordingly. Audio is never used to train AI models.
Marketing contact information: Retained for as long as you remain subscribed. When you unsubscribe (one-click via any marketing email or at exora.au/unsubscribe), we keep the row marked as unsubscribed so we have proof of your consent revocation and so we never accidentally re-subscribe you. To request full deletion of the row itself, email hello@exora.au; we will action it within 30 days.
9. Artificial Intelligence
What our AI does. When you upload a medical document, our AI reads the full content of that document, including any names, dates and other personal details it contains, to identify health information (conditions, medications, allergies, vital signs, lab results, procedures, immunizations) and organize it into your structured health record. Our AI chat assistant can answer questions about your health data. You can also send photos for AI analysis and use voice input that is transcribed by AI.
AI providers. Document understanding (entity extraction, structuring, narrative generation) and chat run primarily on Google Cloud Gemini Enterprise with Gemini models. Document scanning OCR runs on Google Cloud Vision. Voice dictation is transcribed on your device where possible, and otherwise by Google Speech-to-Text. We also use OpenAI for matching your clinical terms to standard medical codes, and as a fallback for voice transcription. We may change, add, or remove providers based on quality, reliability, and cost. The current list of providers and what data each receives is in Section 5.
Your data and AI training. Your health data is not used to train AI models. Our AI providers process your data solely to return results to you, under their commercial API terms. Providers may temporarily retain data for safety monitoring (see Section 8). We do not currently use your data to train or improve exora’s own AI systems. In future, we may offer you the opportunity to contribute de-identified data to improve our systems. Any such use would require your separate, explicit consent.
AI accuracy. AI-extracted information may contain errors, omissions, or misinterpretations. Data quality indicators shown in the app reflect processing confidence and do not constitute clinical validation. Medical codes are AI-assigned and have not been verified by a healthcare professional. Always verify important health information with your healthcare provider and against your original documents.
No automated decisions. Our AI organizes and summarizes your health information. It does not make medical decisions, diagnoses, or treatment recommendations. No automated decisions are made by our systems that affect your legal rights or interests. Using exora does not create a doctor-patient or healthcare provider relationship.
Emergencies. The exora app is not designed for medical emergencies. If you are experiencing a medical emergency, call 000 (Australia) or your local emergency number immediately.
AI voice conversations (Beta). A separate Beta feature lets you hold a real-time spoken conversation with our AI assistant about a specific profile’s health records. This is structurally different from the voice-to-text chat input (where a single clip is transcribed and discarded). Here, your microphone audio is streamed continuously, the AI’s spoken response is streamed back, and the conversation can include multiple back-and-forth turns.
How the connection works. Your device establishes an authenticated connection to our server in Sydney, which holds our credentials for the Google service so that they are never present on your device. Your microphone audio passes through that server to Google’s Gemini Live API, and the assistant’s response audio returns by the same route. We retain session metadata (start time, duration, reason for ending, and the volume of data transferred) and the text transcript for audit and abuse-detection purposes. We also record the conversation, both sides, as an audio file stored with your chat history so that you can replay it; only you can access that recording. Section 8 sets out how long each of these is kept.
Per-profile opt-in. Voice conversations are OFF by default for every profile. To enable them, the profile owner navigates to Settings -> AI Assistant and toggles “AI voice conversations” on. The setting follows the profile, not the account holder. If you share a profile with someone else, voice availability on that profile is the owner’s choice.
Informed consent before first use. The first time you actually start a voice conversation for a profile, you will see a consent dialog summarising what data is sent, where it is processed, what is retained, and that you can withdraw the feature at any time in Settings. You must tap “I understand and consent” before any audio leaves your device. Acceptance is recorded with a timestamp.
Withdrawing voice access. Toggle the feature off in Settings -> AI Assistant at any time. Existing session logs, transcripts, and voice recordings remain in your audit log and chat history under your control (you can delete individual chat sessions, which deletes their recordings too). Disabling voice does not delete past records; we recommend reviewing the relevant section of this policy for our retention details.
Region of processing. As of this policy version, real-time voice conversations are processed by Google’s Gemini Live API in their global infrastructure, currently routing to US-based servers for the audio model we use. We are evaluating migration to Vertex AI in Sydney once the live-audio model is published in the Australian region. This policy will be updated when that change occurs.
Why this is treated differently from text chat. Document understanding and text chat run on Google Cloud Gemini Enterprise (Vertex AI) under our signed Cloud Data Processing Addendum. That contract does not extend to the Gemini Live API on Google AI Studio. We have made the live-voice feature available in Beta while we evaluate the data residency and contractual options available to us. The per-profile opt-in, the consent dialog and the audit logging exist so that your choice to use it is an informed one.
The voice assistant is not a medical professional. Everything in this section also applies to voice: the AI organizes and summarizes your information; it does not provide medical advice, diagnoses, or treatment recommendations. Do not rely on the voice assistant in a medical emergency. Call 000, or your local emergency number, instead.
10. Your Rights
Under the Australian Privacy Principles, you have the right to:
Access your data. You can view all your health data in the app. To request a full copy of your personal information, contact us at hello@exora.au. We will respond within 30 days.
Correct your data. You can edit your profile information in the app. For AI-extracted health records, you can add notes, delete inaccurate records, or re-upload corrected documents. If you believe any other information we hold is inaccurate, contact us and we will correct it.
Delete your data. You can delete individual records in the app, or delete your entire account from Settings. Account deletion removes all your data (see Section 8 for details).
Control sharing. You choose who to share your health data with, what to share, and for how long. You can revoke access at any time.
Withdraw consent. You can withdraw your consent for health data processing at any time by deleting your data or your account.
Deal with us anonymously or by pseudonym. You may deal with us anonymously or under a pseudonym for general enquiries. This is not possible where we need to identify you in order to provide the Service, such as where you hold an account containing health records, or where the law requires us to identify you.
Complain. See Section 15.
How to make a request. The remainder of this section explains how to exercise the rights above. Send any request to hello@exora.au. Before acting on a request concerning an account, we will take reasonable steps to confirm that you are the account holder. This protects you against someone else obtaining or deleting your records. We do not charge a fee for access, correction or deletion. Where you ask for a copy of your personal information, we provide it in a commonly used, machine-readable format.
When we may refuse a request. We may decline a request where the law permits or requires us to do so: for example, where granting access would have an unreasonable impact on another person’s privacy, where the request is frivolous or vexatious, or where the information relates to an anticipated legal proceeding. If we refuse a request, we will tell you why in writing and explain how to complain.
If you are outside Australia. The law where you live may give you rights in addition to, or different from, those set out above. Section 14 explains how we handle those requests.
11. Children and Young People
exora requires a minimum age of 14 to create an independent account in Australia. This aligns with the age at which individuals gain control of their own My Health Record.
Outside Australia, the minimum age to create an independent account is 14, or a higher age where the law of the country you live in requires one.
Parents and guardians can manage health records for children of any age through dependent profiles on their account. The parent or guardian declares their authority when creating a dependent profile and controls all data and sharing for that profile.
We do not knowingly allow children below the minimum age for their region to create independent accounts. If we discover an account was created by someone under the minimum age, we will work with the child’s parent or guardian to resolve the situation, which may include closing the account or migrating data to a parent-managed dependent profile.
12. Cookies and Tracking
We do not use advertising cookies, tracking pixels, or cross-site tracking.
Our web app uses essential cookies only for authentication and session management. These are necessary for the app to function and do not track you across other websites.
Marketing website analytics. Our marketing website at exora.au uses Vercel Web Analytics and Speed Insights to measure aggregate visitor traffic and page performance. These tools are cookieless and do not identify you individually. They collect: the page URL visited, the referring website, your approximate country (derived from your IP address, which is then discarded and not stored), device type, browser, operating system, and Core Web Vitals performance metrics. The data is aggregated and used solely to understand how our marketing site performs and to improve it. Vercel acts as our data processor.
In-app crash reporting and product analytics. Inside the exora apps we use two tools: Sentry for crash and error reporting, and PostHog for product analytics. Both are hosted in the European Union rather than the United States. Both are configured to collect substantially less than their default settings allow, because those defaults are not appropriate for a health application.
What they receive: your account identifier, which features and controls you use, and, when something goes wrong, the technical details of the error and where in the app it occurred.
What they do not receive: your name, email address or IP address; any part of your health records; the contents of your documents, chat messages or search terms. Specifically, and because these are the settings that would otherwise capture patient information:
- Session replay is switched off. This feature records on-screen content, which in a health application would include health information.
- Autocapture is switched off. This feature automatically records taps and the text visible on screen.
- Performance tracing is switched off, so we do not sample the network requests the app makes.
- Error reports are stripped of request contents, cookies, headers and diagnostic messages before they are sent.
We use this information to identify crashes and to understand which parts of exora are used. It is not used for advertising, is never sold or shared with third parties, and is not used to train AI models. If you would like your analytics and crash data deleted, email hello@exora.au.
13. Changes to This Policy
We may update this policy to reflect changes in our practices or legal requirements.
Material changes (changes to what data we collect, how we use it, or who we share it with): We will give you at least 14 days advance notice via in-app notification and/or email before the changes take effect.
Minor changes (clarifications, formatting, correcting errors): We may update the policy without advance notice.
The date at the top of this policy indicates when it was last updated. Previous versions are available on request by contacting hello@exora.au. Continued use of exora after changes take effect constitutes acceptance of the updated policy. If you do not agree with the changes, you may delete your account before they take effect.
14. Users Outside Australia
exora is operated from Australia and is designed principally for Australian users. Our apps are available in other countries, and this section explains what that means for you.
Your information is held in Australia. If you use exora from outside Australia, your personal information is transferred to and stored in Australia and is handled under Australian law. Section 6 sets out where processing occurs, including the AI processing that takes place outside Australia for all users.
The standard we apply. We apply the Australian Privacy Principles to every user regardless of location. We do not operate a lower standard for users outside Australia.
The law where you live may give you additional rights. Privacy law in your country may give you rights that the Australian Privacy Principles do not, such as rights to data portability, to restrict processing, or to object to processing. Where the law requires us to honor such a request, we will do so. Contact us at hello@exora.au and tell us where you are located, so that we can identify which law applies to your request.
The language of this policy. This policy is written in English. We publish translations in other languages for your convenience, and we work to keep them accurate. If a translation differs from the English version, the English version applies. This does not limit any right you have under the law where you live to receive information in your own language.
Complaints from outside Australia. You may complain to us first under Section 15. You may also be able to complain to the privacy regulator where you live:
- European Economic Area: the supervisory authority for your country. A list is maintained by the European Data Protection Board at edpb.europa.eu
- United Kingdom: the Information Commissioner’s Office, ico.org.uk
- New Zealand: the Office of the Privacy Commissioner, privacy.org.nz
- Canada: the Office of the Privacy Commissioner of Canada, priv.gc.ca, or your provincial privacy commissioner
- Brazil: the Autoridade Nacional de Proteção de Dados, gov.br/anpd
- Elsewhere: contact us and we will tell you which regulator, if any, oversees our handling of your information in your country
15. Complaints
If you have a concern about how we handle your personal information:
Step 1 - Contact us. Email our Privacy Officer at hello@exora.au. We will acknowledge your complaint within 5 business days.
Step 2 - Investigation. We will investigate your complaint and provide a substantive response within 30 days. If we need more time, we will let you know.
Step 3 - Escalation. If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC). If you are outside Australia, Section 14 also lists the privacy regulator for your country. The OAIC’s contact details are:
- Website: www.oaic.gov.au
- Phone: 1300 363 992
- Online complaint form: www.oaic.gov.au/privacy/privacy-complaints
- Post: GPO Box 5288, Sydney NSW 2001
16. Contact Us
Exora Health Pty Ltd
ABN 16 690 025 462
Privacy Officer: hello@exora.au
For questions about this privacy policy, how we handle your data, or to exercise any of your rights, contact us at the email address above.
Governing law. This privacy policy is governed by the laws of Australia. Nothing in this policy limits any right you have under the law of the country where you live that cannot be excluded by agreement.
See also our Terms of Service for the rules governing your use of exora.