Privacy Policy

Last updated: 6 October 2026
Operator: SecondBrain Sharp AI Pty Ltd (ACN 698 698 029 · ABN 52 698 698 029)
Registered office: 11 Cameron Avenue, Artarmon NSW 2064, Australia

This Privacy Policy explains how SecondBrain Sharp AI Pty Ltd ("we", "us", "our") collects, uses, stores, shares, and protects information when you use our apps (each and together, the "Service"):

Sections 2 to 6 describe Sharp in Microsoft Teams. Section 7 applies to both apps. Section 7A covers Sharp in Google Chat, including where it differs. Section 8 walks through how SecondBrain Valuations Agent handles information, step by step. Sections 9 onwards apply to both.


1. Scope

This Policy covers personal information processed in connection with the Service. It does not cover websites, products, or services operated by third parties (including the bank portals the Service interacts with).

We comply with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth).


2. Information We Collect (Sharp)

We collect only what the Service needs to function. We do not use third-party analytics, advertising, or tracking SDKs in the Service.

2.1 Bank portal credentials

When you enter credentials for an Australian bank pricing portal via the Service, we collect:

These credentials are encrypted and held securely within the Microsoft environment, with per-client isolation, so that no organisation can access another's.

2.2 Loan scenario details

When you submit a pricing request, we process:

These details are used only to submit the pricing request and generate results for you. They are processed in-memory during the request and not persisted beyond the submission history record described below.

2.3 Submission history metadata

For 30 days, we retain a record of each submission containing:

This is stored securely within the Microsoft environment (in Australia) so you can view, clone, or re-generate reports from your last 30 days of activity. After 30 days, records auto-expire.

2.4 Microsoft Teams identity information

Microsoft Teams provides us with your organisation ID, user ID, display name, and email address as part of the bot conversation context. We use this to:

This information is provided by Microsoft and governed by your organisation's Microsoft 365 agreements.


3. How We Use Your Information (Sharp)

We use collected information only for:

  1. Submitting pricing requests to the Australian bank portals you select
  2. Returning pricing results to you via Microsoft Teams
  3. Maintaining a 30-day history so you can review past submissions
  4. Operating and supporting the Service (debugging, security investigation, technical support)
  5. Creating de-identified, aggregated data (which does not identify you or any borrower) to operate, improve, and develop our services, as described in our Terms of Service

We do not sell or rent personal information to third parties. We do not use your information for marketing or advertising.


4. How We Store and Protect Information (Sharp)

Encryption

Personal information is encrypted in transit and at rest.

Location

All Sharp data is stored within the Microsoft environment, in Australia, and does not leave Australia. For Sharp in Google Chat, see section 7A.

Access controls


5. Outbound Communication (Sharp)

To deliver the Service, we make outbound HTTPS requests to:

We do not send Sharp information to any other third party.


6. Retention (Sharp)

This table covers Sharp in Microsoft Teams. For Sharp in Google Chat, see section 7A.

Data typeRetention period
Bank portal credentialsUntil you rotate or delete them via the Service, or until your organisation terminates the Service
Submission history30 days, then auto-deleted
Loan scenario details (request-only)Not persisted beyond the request
Credential audit log
(metadata only: timestamp, broker identity, action — never the credential itself)
7 years, for security, audit, and dispute-resolution purposes
Microsoft Teams session dataSession duration only

7. Microsoft Teams identity information (both apps)

Both apps receive the Microsoft Teams identity information described in section 2.4 and use it in the same way.


7A. Google Chat (Sharp)

Sharp is also available as a Google Chat app. This section explains what Sharp receives from Google and how it is used. Sections 2 to 6 describe Sharp in Microsoft Teams and apply to Sharp in Google Chat in the same way, except where this section says otherwise.

What Sharp receives from Google

Sharp, as installed from the Google Workspace Marketplace, uses Google's Chat app permission (https://www.googleapis.com/auth/chat.bot) and Google's basic profile permissions (userinfo.email and userinfo.profile). With these, Sharp receives:

Sharp does not request or have access to Gmail, Google Drive, Calendar, Contacts, your organisation's directory or any admin setting. It cannot read messages that are not sent to it.

How we use it

We use this information only to:

We do not sell this information or use it for advertising. We do not send it to any third-party artificial intelligence service, and we do not use it to develop, improve or train artificial intelligence or machine-learning models.

Who can see it

Our staff do not read Google Chat messages or request records except where needed to investigate a fault or a security issue, where the organisation asks us to (for example, in a support request), or where the law requires it. That access is limited to authorised SecondBrain Sharp AI personnel.

Where it is held and how it is protected

Sharp's Google Chat service, the records it keeps and its operational logs are held on Google Cloud in Sydney, Australia (australia-southeast1). To carry out a pricing request, the loan details are sent to Sharp's bank-connection services on Microsoft Azure in Australia (Australia East). Lender logins are held in the organisation's own secure vault in Microsoft Azure in Australia (Australia East), never in Google. Information is encrypted in transit and at rest.

Sharing

We share information received from Google only as needed to perform the request the person made, for example sending the loan details they entered to the lenders they chose. We do not transfer it to anyone else, except as required by law.

Retention and deletion

Records of each request (the sender's email address, the conversation, the loan details entered and the results returned) are kept until the organisation asks us to delete them, including when it stops using Sharp. After 7 days, Sharp no longer uses a request's loan details. One-time sign-in codes are deleted once used. Operational logs are kept for 30 days.

An organisation can ask us to delete its information at any time by emailing the contact in section 13. An organisation's Google Workspace administrator can also remove Sharp from their Google Workspace at any time.

Google API Services User Data Policy

Sharp's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.


8. SecondBrain Valuations Agent

SecondBrain Valuations Agent handles more personal information than Sharp, because a valuation order names the borrower and the person who gives the valuer access to the property. This section follows an order from start to finish and explains what happens to information at each step. Sections 9 onwards also apply.

8.1 Setting up your account

When you type onboard, we collect your name, email address, phone number and the lenders you use. When you type password, you enter your own logins for the lenders' valuation portals (PropertyHub by Cotality, CBA and Bankwest).

Your lender logins are encrypted and stored in a Microsoft Azure Key Vault in Australia. Each brokerage has its own vault, so no brokerage can reach another's logins. We use your logins only to lodge your own orders, and you can change or remove them at any time with the password command.

8.2 Filling in an order

When you type template, the order form asks for:

8.3 Nothing is sent to a lender until you confirm

After the form, the Service shows a review card with everything you entered. No order is lodged with any lender until you confirm that card.

8.4 Lodging the order

When you confirm, the Service signs in to each lender's valuation portal with your login and lodges the order with the details from your form. Each lender receives only the order you placed with it.

If a lender's portal page does not behave as expected, the Service may save a screenshot of that page so we can fix the problem. These screenshots can show the order details.

8.5 Results and history

The Service sends you a result card with a section for each lender, showing the lender's reference number and the valuation type. Where the lender returns an automated valuation (AVM), the value is added to the card.

We keep a record of each order so that the status and history commands can show your past orders, and so you can clone or export one.

8.6 Mailbox access

With your brokerage's consent, the Service reads your Microsoft 365 mailbox for two kinds of email only:

It does not read, keep or use any other email.

8.7 Who receives the information

We do not sell personal information or use it for advertising. Order details go to the lenders' valuation portals you choose, to lodge your orders. The Service is hosted on Microsoft Azure in the Australia East region, where your information is stored.


9. Your Rights Under Australian Privacy Law

You have the right to:

To exercise these rights, contact us at james@secondbrain.com.au.

If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (oaic.gov.au).


10. Data Breach Notification

In the event of an eligible data breach under the Notifiable Data Breaches scheme, we will assess the breach and notify affected individuals and the OAIC as soon as practicable, in accordance with our Incident Response Plan and the Privacy Act 1988 (Cth).


11. Children's Privacy

The Service is intended for use by mortgage brokers in a professional context. It is not directed to children under 18 and we do not knowingly collect information from children.


12. Changes to This Policy

We may update this Policy as the Service evolves. Material changes will be communicated via the Service or directly to client organisations. The "Last updated" date at the top of this Policy reflects the most recent change.


13. Contact

For privacy questions, requests, or complaints:

SecondBrain Sharp AI Pty Ltd
11 Cameron Avenue, Artarmon NSW 2064, Australia
Email: james@secondbrain.com.au
Phone: +61 481 761 659

This Privacy Policy is provided in good faith and aims to be a complete description of our practices. If you spot anything inconsistent with the Service's actual behaviour, please contact us so we can investigate.