Privacy Policy
This Privacy Policy explains how SecondBrain Sharp AI Pty Ltd ("we", "us", "our") collects, uses, stores, shares, and protects information when you use our apps (each and together, the "Service"):
- Sharp (also referred to as the Bank Pricing Agent or Sharp AI), our app for mortgage pricing comparison, available in Microsoft Teams and Google Chat; and
- SecondBrain Valuations Agent, our Microsoft Teams app for ordering bank property valuations.
Sections 2 to 6 describe Sharp in Microsoft Teams. Section 7 applies to both apps. Section 7A covers Sharp in Google Chat, including where it differs. Section 8 walks through how SecondBrain Valuations Agent handles information, step by step. Sections 9 onwards apply to both.
1. Scope
This Policy covers personal information processed in connection with the Service. It does not cover websites, products, or services operated by third parties (including the bank portals the Service interacts with).
We comply with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth).
2. Information We Collect (Sharp)
We collect only what the Service needs to function. We do not use third-party analytics, advertising, or tracking SDKs in the Service.
2.1 Bank portal credentials
When you enter credentials for an Australian bank pricing portal via the Service, we collect:
- Bank portal username
- Bank portal password
- Associated bank identifier (e.g., "NAB", "Westpac")
These credentials are encrypted and held securely within the Microsoft environment, with per-client isolation, so that no organisation can access another's.
2.2 Loan scenario details
When you submit a pricing request, we process:
- Loan amount and property value
- Loan purpose (purchase, refinance, etc.)
- Repayment type and term
- LVR (calculated)
- Property state and postcode
- Bank-specific fields (e.g., offset preferences, fixed rate term)
These details are used only to submit the pricing request and generate results for you. They are processed in-memory during the request and not persisted beyond the submission history record described below.
2.3 Submission history metadata
For 30 days, we retain a record of each submission containing:
- Timestamp
- Banks queried
- Loan scenario summary
- Pricing results returned
This is stored securely within the Microsoft environment (in Australia) so you can view, clone, or re-generate reports from your last 30 days of activity. After 30 days, records auto-expire.
2.4 Microsoft Teams identity information
Microsoft Teams provides us with your organisation ID, user ID, display name, and email address as part of the bot conversation context. We use this to:
- Route requests to the correct client organisation
- Authorise which banks you can submit to
- Address you in responses
This information is provided by Microsoft and governed by your organisation's Microsoft 365 agreements.
3. How We Use Your Information (Sharp)
We use collected information only for:
- Submitting pricing requests to the Australian bank portals you select
- Returning pricing results to you via Microsoft Teams
- Maintaining a 30-day history so you can review past submissions
- Operating and supporting the Service (debugging, security investigation, technical support)
- Creating de-identified, aggregated data (which does not identify you or any borrower) to operate, improve, and develop our services, as described in our Terms of Service
We do not sell or rent personal information to third parties. We do not use your information for marketing or advertising.
4. How We Store and Protect Information (Sharp)
Encryption
Personal information is encrypted in transit and at rest.
Location
All Sharp data is stored within the Microsoft environment, in Australia, and does not leave Australia. For Sharp in Google Chat, see section 7A.
Access controls
- Per-client isolation. No cross-organisation access.
- Internal access to production systems is limited to authorised SecondBrain Sharp AI personnel and is logged.
- Bank portal credentials are never logged, never displayed in chat history, and never cached in plaintext.
5. Outbound Communication (Sharp)
To deliver the Service, we make outbound HTTPS requests to:
- Australian bank pricing portals (NAB, Westpac, St.George, ING, ANZ, CBA, Suncorp, BankWest, ME Bank) to submit the pricing requests you make
- Cloud hosting services for storage, authentication, and Teams messaging
We do not send Sharp information to any other third party.
6. Retention (Sharp)
This table covers Sharp in Microsoft Teams. For Sharp in Google Chat, see section 7A.
| Data type | Retention period |
|---|---|
| Bank portal credentials | Until you rotate or delete them via the Service, or until your organisation terminates the Service |
| Submission history | 30 days, then auto-deleted |
| Loan scenario details (request-only) | Not persisted beyond the request |
| Credential audit log (metadata only: timestamp, broker identity, action — never the credential itself) | 7 years, for security, audit, and dispute-resolution purposes |
| Microsoft Teams session data | Session duration only |
7. Microsoft Teams identity information (both apps)
Both apps receive the Microsoft Teams identity information described in section 2.4 and use it in the same way.
7A. Google Chat (Sharp)
Sharp is also available as a Google Chat app. This section explains what Sharp receives from Google and how it is used. Sections 2 to 6 describe Sharp in Microsoft Teams and apply to Sharp in Google Chat in the same way, except where this section says otherwise.
What Sharp receives from Google
Sharp, as installed from the Google Workspace Marketplace, uses Google's Chat app permission (https://www.googleapis.com/auth/chat.bot) and Google's basic profile permissions (userinfo.email and userinfo.profile). With these, Sharp receives:
- messages, commands and form entries that a person sends to Sharp;
- the sender's name, email address and Google Workspace organisation identifier, which Google includes with each message; and
- the conversation the message came from, so Sharp can reply in it.
Sharp does not request or have access to Gmail, Google Drive, Calendar, Contacts, your organisation's directory or any admin setting. It cannot read messages that are not sent to it.
How we use it
We use this information only to:
- check that the person belongs to an organisation that is set up on Sharp and is on that organisation's list of authorised users (anyone else receives a refusal message);
- carry out the pricing request the person asked for, using their own lender logins; and
- reply in Google Chat with the results, and keep the records described below so that we can support the organisation and investigate faults.
We do not sell this information or use it for advertising. We do not send it to any third-party artificial intelligence service, and we do not use it to develop, improve or train artificial intelligence or machine-learning models.
Who can see it
Our staff do not read Google Chat messages or request records except where needed to investigate a fault or a security issue, where the organisation asks us to (for example, in a support request), or where the law requires it. That access is limited to authorised SecondBrain Sharp AI personnel.
Where it is held and how it is protected
Sharp's Google Chat service, the records it keeps and its operational logs are held on Google Cloud in Sydney, Australia (australia-southeast1). To carry out a pricing request, the loan details are sent to Sharp's bank-connection services on Microsoft Azure in Australia (Australia East). Lender logins are held in the organisation's own secure vault in Microsoft Azure in Australia (Australia East), never in Google. Information is encrypted in transit and at rest.
Sharing
We share information received from Google only as needed to perform the request the person made, for example sending the loan details they entered to the lenders they chose. We do not transfer it to anyone else, except as required by law.
Retention and deletion
Records of each request (the sender's email address, the conversation, the loan details entered and the results returned) are kept until the organisation asks us to delete them, including when it stops using Sharp. After 7 days, Sharp no longer uses a request's loan details. One-time sign-in codes are deleted once used. Operational logs are kept for 30 days.
An organisation can ask us to delete its information at any time by emailing the contact in section 13. An organisation's Google Workspace administrator can also remove Sharp from their Google Workspace at any time.
Google API Services User Data Policy
Sharp's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
8. SecondBrain Valuations Agent
SecondBrain Valuations Agent handles more personal information than Sharp, because a valuation order names the borrower and the person who gives the valuer access to the property. This section follows an order from start to finish and explains what happens to information at each step. Sections 9 onwards also apply.
8.1 Setting up your account
When you type onboard, we collect your name, email address, phone number and the lenders you use. When you type password, you enter your own logins for the lenders' valuation portals (PropertyHub by Cotality, CBA and Bankwest).
Your lender logins are encrypted and stored in a Microsoft Azure Key Vault in Australia. Each brokerage has its own vault, so no brokerage can reach another's logins. We use your logins only to lodge your own orders, and you can change or remove them at any time with the password command.
8.2 Filling in an order
When you type template, the order form asks for:
- the property address;
- the borrower's first name and surname;
- the access contact's name, email address and phone number;
- the loan amount and estimated property value (both optional); and
- the lenders you choose and the valuation type.
8.3 Nothing is sent to a lender until you confirm
After the form, the Service shows a review card with everything you entered. No order is lodged with any lender until you confirm that card.
8.4 Lodging the order
When you confirm, the Service signs in to each lender's valuation portal with your login and lodges the order with the details from your form. Each lender receives only the order you placed with it.
If a lender's portal page does not behave as expected, the Service may save a screenshot of that page so we can fix the problem. These screenshots can show the order details.
8.5 Results and history
The Service sends you a result card with a section for each lender, showing the lender's reference number and the valuation type. Where the lender returns an automated valuation (AVM), the value is added to the card.
We keep a record of each order so that the status and history commands can show your past orders, and so you can clone or export one.
8.6 Mailbox access
With your brokerage's consent, the Service reads your Microsoft 365 mailbox for two kinds of email only:
- one-time sign-in codes that lenders email, used once to sign in to the lender's portal for you; and
- valuation and automated valuation (AVM) result emails from Cotality, used to add the result to your order.
It does not read, keep or use any other email.
8.7 Who receives the information
We do not sell personal information or use it for advertising. Order details go to the lenders' valuation portals you choose, to lodge your orders. The Service is hosted on Microsoft Azure in the Australia East region, where your information is stored.
9. Your Rights Under Australian Privacy Law
You have the right to:
- Access the personal information we hold about you
- Correct information that is inaccurate or out-of-date
- Request deletion of your information (subject to legal retention requirements)
- Complain to us about how we handle your information
To exercise these rights, contact us at james@secondbrain.com.au.
If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (oaic.gov.au).
10. Data Breach Notification
In the event of an eligible data breach under the Notifiable Data Breaches scheme, we will assess the breach and notify affected individuals and the OAIC as soon as practicable, in accordance with our Incident Response Plan and the Privacy Act 1988 (Cth).
11. Children's Privacy
The Service is intended for use by mortgage brokers in a professional context. It is not directed to children under 18 and we do not knowingly collect information from children.
12. Changes to This Policy
We may update this Policy as the Service evolves. Material changes will be communicated via the Service or directly to client organisations. The "Last updated" date at the top of this Policy reflects the most recent change.
13. Contact
For privacy questions, requests, or complaints:
SecondBrain Sharp AI Pty Ltd
11 Cameron Avenue, Artarmon NSW 2064, Australia
Email: james@secondbrain.com.au
Phone: +61 481 761 659