Privacy Policy
How AuDHD Companion handles account information, private wellbeing records and service providers.
Privacy Policy
Last updated: 10 September 2026 | Version 2.3
The short version
AuDHD Companion is a private, lived-experience-led wellbeing app for adults. We collect only the information needed to provide the features you choose to use and limited technical web-request information needed to operate, secure and understand the public website. We do not sell your information, use your private entries for targeted advertising, or give your records to employers, insurers, family members, professionals or other users. You decide what to record, what to export and what to share.
1. Who we are
AuDHD Companion is operated by AuDHD Companion, ABN 94 677 883 739. In this policy, “AuDHD Companion”, “we”, “us” and “our” refer to that Australian business. We are based in Victoria, Australia. Privacy questions and requests can be sent to hello@audhdcompanion.com.
2. What this policy covers
This policy applies when you visit our primary website at audhdcompanion.com or a domain that redirects to it, create or use an AuDHD Companion account, contact us, subscribe to a paid plan, use the installed web app, or otherwise interact with the service.
AuDHD Companion provides self-reflection, organisation and general wellbeing tools. It is not a medical service, diagnostic tool, treatment service or emergency service. Some information you choose to enter may still be sensitive or health-related, so we treat it with extra care.
3. You choose what to record
Most of the app is optional. You can leave fields blank, choose which metrics to track, use a preferred name or pseudonym, and stop recording whenever you need to. An email address is required to create and secure an account, reset your password and manage a subscription.
You do not need a formal diagnosis to use AuDHD Companion. Any neurodivergent identity or experience you record is self-described and optional.
4. Information we collect
Depending on how you use the app, we may collect and hold:
- Account information: email address, preferred display name, account identifier, password-verification status and consent records.
- Profile and preferences: timezone, optional pronouns, optional neurodivergent identity, tracking choices, reminder settings, accessibility or theme preferences and onboarding choices.
- Optional push notification information: if you enable browser or PWA push reminders, we store a browser Web Push subscription endpoint and encryption keys for that browser/device, your chosen reminder time, timezone and limited delivery metadata. Push notifications do not include your check-in, journal, medication or other wellbeing content.
- Wellbeing records you choose to enter: check-ins about sleep, mood, energy, motivation, anxiety, stress, overwhelm, sensory load, masking, social capacity, mental clarity, executive functioning, menstrual cycle, movement and other custom metrics.
- Capacity and reflection records: spoons or capacity activities, journal entries, weekly reviews and reflections, pattern observations, dismissed observations and personal notes.
- Journey and support-profile information: optional newly diagnosed journey responses and the communication, sensory, overload, regulation and practical support preferences you choose to save.
- Toolkit information: strategies you save, when you use them and any effectiveness ratings you choose to add.
- Medication and vitamin records: names, doses, schedules, start or end dates, adherence records, dose history, purpose, prescriber details and notes you choose to enter.
- Reports and exports: information needed to create user-requested PDF or CSV reports and a limited record that an export was generated.
- Support information: your support message, account email, reply email, request status and basic delivery metadata.
- Subscription information: plan type, subscription status, Stripe customer and subscription references, payment outcome and relevant dates. We do not receive or store your full card number.
- Technical, traffic and security information: information processed to keep the service working and secure and to understand public-site use, such as IP address, requested hostname and URL, referring page, approximate city or country, browser or device details, request time, response status, latency, cache information, login events and error or security records.
5. How we collect information
We collect information:
- directly from you when you register, enter records, change settings, contact support or subscribe;
- automatically through essential authentication, security, hosting, Firebase Hosting web-request logging and payment systems when you use the service; and
- from Stripe when it tells us whether a checkout, payment, subscription, cancellation or refund event has occurred.
6. Why we use your information
We use information only where it is reasonably needed to:
- create, authenticate and protect your account;
- save your records and display them back to you;
- personalise the metrics, reminders and features you choose, including sending optional push reminders you explicitly enable;
- generate your own observations, summaries, weekly reflections, support-profile PDF and other reports you request;
- remember toolkit use and other actions you ask the app to record;
- process subscriptions, confirm access and prevent founding offers from exceeding their stated capacity;
- respond to support, privacy and account requests;
- maintain, secure, troubleshoot and improve the service;
- understand public-site traffic, referrals, errors and performance without reading the contents of your private wellbeing entries;
- prevent fraud, misuse and unauthorised access; and
- meet legal, accounting, tax, dispute-resolution and regulatory obligations.
7. Sensitive health and wellbeing information
Check-ins, journals, journey responses, support-profile preferences, medication records and other wellbeing entries may be sensitive information. We collect this information only when you choose to enter it and consent during registration. The information is used to provide the private tracking, reflection and reporting features you requested.
You can withdraw that consent by stopping the relevant feature, deleting individual records, or deleting your account. Withdrawing consent does not undo handling that lawfully occurred before the withdrawal.
8. Suggestions, patterns and automated processing
The app may compare entries you recorded and show supportive observations or suggested strategies. These are simple, rule-based reflections based on your own information. They are not diagnoses, predictions or medical interpretations, and they do not prove that one factor caused another.
AuDHD Companion does not use your private journal, check-in or medication content to make significant decisions about your rights, employment, insurance, healthcare, access or pricing. We do not currently use your private entries to train generative artificial intelligence models.
9. Who we share information with
We do not sell personal information. We may disclose limited information to:
- Google Firebase and Google Cloud: for account authentication, database storage, hosting, backend functions, web-request logging, optional browser Web Push reminder delivery from our backend, security and service operation.
- Stripe: for checkout, recurring billing, payment processing, refunds, fraud prevention and the customer billing portal.
- Our email and support providers, including Twilio SendGrid: to deliver account, support or operational messages. Support notification emails contain only limited request details; the support message itself remains in the protected app database.
- Professional advisers or contractors: only where reasonably necessary for legal, accounting, security or technical support and subject to confidentiality or privacy obligations.
- Courts, regulators, law enforcement or other authorities: where disclosure is required or authorised by law, or reasonably necessary to protect safety, rights or the integrity of the service.
- A new operator of the service: if the business is restructured, sold or transferred, provided personal information remains protected and users are notified where required.
A professional, family member, employer or other person can only see a report or record when you choose to show, download or send it, unless we are legally required to disclose it.
10. Overseas processing
We use global technology and payment providers. We configure eligible services in Australian regions where available, and our Firebase Cloud Functions are configured to run in Sydney. However, not every service offers Australian-only processing.
Firebase Authentication is processed in the United States, and Google may process some service, support or security information in other countries where Google or its service providers operate. Stripe is a global payment provider and may process payment and account information in the United States and other countries used by its affiliates and service providers. Depending on the service involved, other likely locations may include India, Ireland, Malaysia, the Philippines, the United Kingdom, Canada and Japan.
We take reasonable steps to use reputable providers, limit the information shared to what is needed and rely on their contractual, privacy and security commitments. Privacy protections in another country may not be identical to those in Australia.
11. Payments and Stripe
Paid checkout is available only after you create or sign in to an AuDHD Companion account so the Stripe customer and subscription can be linked to the correct app account. Payments are completed on Stripe’s secure checkout pages. Stripe collects and handles card details, billing details and payment information under its own privacy terms. AuDHD Companion receives enough information to know which plan you selected, whether payment succeeded and whether your subscription is active, cancelled, unpaid or refunded. We do not store your full card number or card security code.
12. Browser storage and website traffic logs
The web app and installed web app may use essential browser storage, cached files and similar technology to keep you signed in, remember app settings, enable installation and make the service work reliably. You can clear this through your browser, although doing so may sign you out or remove downloaded app files.
We use a limited Meta conversion measurement tool to record when a new account is successfully created after a Meta advertisement. It is configured without automatic PageView tracking and we do not send journal entries, check-ins, medication information, names, email addresses or other user-entered health and wellbeing information to Meta. We do not use your private records for targeted advertising or allow advertisers to build a profile from your private AuDHD Companion records.
To understand whether the browser-installed web app is being used, the app may increase one of two combined counters: a supported browser confirming installation, or a first detected launch in standalone app mode. A small flag is kept in that browser so the same event is not counted on every opening. The application database stores only the combined totals and does not attach them to your account, journal, check-ins, medication information or search activity. Normal Firebase and Google Cloud request logs may still process technical request information as described in this policy.
The public Ask page searches only the editorially approved question index already downloaded to your browser. The wording you type is not saved to your AuDHD Companion account, written to the Knowledge Engine or used to build a behavioural profile. Opening an Ask page can still create an ordinary Firebase Hosting request log containing the page URL and technical request information described below.
Firebase Hosting exports web-request logs to Google Cloud Logging. A log may include the source IP address, hostname and URL requested, referring page, approximate city or country, browser or device details, response status, latency and cache information. We use these logs to understand public-site traffic, investigate errors, maintain security and improve performance. They are technical request records, not a tool for reading the content of your private journal, check-ins or medication records.
13. How we protect your information
We use technical and organisational safeguards designed for the sensitivity of the information, including secure connections, Firebase Authentication, owner-based database access rules, restricted backend access, secret management and payment processing through Stripe.
Your private records are not visible to other users. Authorised personnel may access limited information only where reasonably necessary to operate, secure or support the service, investigate a problem, comply with law or complete a request from you. App records are not end-to-end encrypted, and no online service can promise absolute security.
14. How long we keep information
We generally keep your account and app records while your account is active so the service can work as expected. Support, security and operational records are kept only for as long as reasonably needed for the purpose they were collected, including resolving issues, preventing misuse and meeting legal obligations.
When information is no longer needed, we take reasonable steps to delete or de-identify it. Some limited billing, tax, fraud-prevention, dispute or deletion-confirmation records may need to be retained after account deletion. Service-provider backups and logs may also take time to cycle out under the provider’s normal retention process.
Firebase Hosting web-request logs are currently configured to follow Google Cloud Logging’s default retention and are ordinarily deleted after 30 days, unless a different retention period is later configured or a particular record must be kept longer for security, dispute or legal reasons.
15. Exporting and deleting your information
You can use the app to:
- view and update your profile and records;
- download available CSV or PDF exports;
- delete individual entries; and
- delete your account through Profile → Account deletion.
Account deletion removes your Firebase login and the personal app records linked to your account. Any active Stripe subscription is cancelled as part of the deletion process. Deletion does not automatically create a refund, without limiting rights you may have under Australian Consumer Law. Stripe and other providers may retain limited transaction or security records where required by law or their legitimate compliance obligations.
16. Access and correction
Most information can be accessed, corrected, exported or deleted inside the app. You can also email hello@audhdcompanion.com to request access to, or correction of, personal information we hold about you. We may need to verify your identity before acting on the request. We will respond within a reasonable period and explain any lawful reason if a request cannot be completed in full.
17. Privacy questions and complaints
Please email hello@audhdcompanion.com with the subject “Privacy” or “Privacy complaint”. Tell us what happened and what outcome you are seeking. We will acknowledge the complaint, investigate it fairly and aim to provide a substantive response within 30 days.
If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner through its privacy complaint process at oaic.gov.au.
18. Marketing
We will not add you to marketing simply because you created an account. Marketing messages will only be sent where you have separately opted in or where otherwise permitted by law, and they will include a way to unsubscribe. Essential service messages — such as password resets, billing notices, security messages and important policy updates — are not marketing.
19. Adults only
AuDHD Companion is intended for people aged 18 and over. We do not knowingly offer accounts to children. If we learn that an account belongs to a person under 18, we may suspend it and take reasonable steps to delete the associated information. Please contact us if you believe a child has created an account.
20. Changes to this policy
We may update this policy as the app, our providers or privacy requirements change. The latest version and date will always appear here. If a change materially affects how we handle sensitive information, we will provide a clear notice and seek fresh consent where appropriate.
21. Contact
Privacy contact: hello@audhdcompanion.com
Location: Victoria, Australia
AuDHD Companion provides self-reflection, organisation and general wellbeing tools. It does not provide medical advice, diagnosis, treatment or emergency support.