Privacy policy
Last updated 13 September 2026
Emidox is operated by Ebiblo Pty Ltd (ABN 60 155 467 833), Sydney, New South Wales. We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), and we apply them whether or not the Act requires it of us. This policy explains what we collect, why, where it goes, and how to exercise your rights.
1. What we collect
- Account details — your name, email address and sign-in method (email, Apple or Google). If you sign in with Apple or Google we receive only the details you allow them to share.
- Your agents — prompts, settings, triggers, and the sources and destinations you connect.
- Material that passes through an agent — what a source received and what the agent produced. This may contain personal information about other people, for example a person who submits a form or posts a comment. You are responsible for having a lawful basis to collect it; we hold it only to run your agents and to let you inspect and repeat a run.
- API keys and connected-account tokens — stored encrypted, never displayed in full, and used only to run your agents.
- Usage and technical information — pages visited, agents run, device and browser type, IP address and approximate location, so the Service works and we can see what is used.
- Correspondence — messages you send through the contact page.
We do not ask for, and ask you not to submit, sensitive information as the Act defines it (such as health, racial or religious information) unless a use case genuinely needs it and the people concerned have consented.
2. How we collect it
Directly from you when you create an account, build an agent or contact us; from the platforms you connect, within the permissions you grant; from the sources your agents read; and automatically through cookies and logs when you use the Service. You can use the public parts of the website without identifying yourself.
3. Why we use it
To provide and run the Service and your agents; to bill you for a paid plan; to support you and answer your questions; to keep the Service secure and detect misuse; to understand how the Service is used and improve it; and to meet our legal obligations. We do not use your material to train AI models, ours or anyone else's.
4. Direct marketing
We send product news only to people who subscribe. Every message has an unsubscribe link, and you can also ask us to stop through the contact page. We do not sell or rent your details, and we do not pass your address to anyone else for their marketing.
5. Who we share it with
- AI providers — the content of a run goes to the provider whose key you added (for example OpenAI, Anthropic, Google or DeepSeek) under their own terms and privacy policy.
- Destinations you choose — an agent's output is sent to the account, address or app you set as its output.
- Metered sources — a service such as Apify sees the requests you ask it to make.
- Service providers — hosting, storage, payment processing (Stripe) and analytics providers who work for us under contract and may only use the information to provide their service.
- Ebiblo — if you use Ebiblo with the same sign-in, the two products share your account details so you sign in once. Each product holds its own data.
- Where the law requires — to a court, regulator or law-enforcement body under a lawful request, or to protect our rights or someone's safety.
6. Overseas disclosure
Some of the providers above — in particular AI model providers, hosting and payment processors — are located or store data outside Australia, including in the United States. By adding a provider's key or connecting a platform you consent to your material being sent to that provider in the country where it operates. We take reasonable steps to ensure the providers we choose handle information in a way consistent with the APPs, but they are bound by their own laws and terms.
7. How we protect it
Keys and tokens are encrypted at rest. Access to production data is limited to people who need it to run the Service. We use reputable hosting with access controls, encrypted connections, and logging. No system is perfectly secure; if a data breach is likely to result in serious harm we will notify you and the Office of the Australian Information Commissioner as the Notifiable Data Breaches scheme requires.
8. How long we keep it
Account details are kept while your account is open. Run data is kept so a run can be repeated and inspected; deleting an agent deletes its runs. Deleting your account deletes your agents, runs, keys and tokens, apart from records we must keep by law (for example billing records, kept for seven years) or need to resolve a dispute. Backups roll off within a short period after deletion.
9. Cookies and analytics
We use a sign-in cookie, a preference cookie for dark mode, and analytics that record page views and feature use in aggregate. We do not use advertising cookies. You can block cookies in your browser; the Service will still work, but you will need to sign in each visit.
10. Access, correction and deletion
You can see and change your account details and agents in the app, and delete your account from the profile menu. For anything else — a copy of the personal information we hold about you, a correction, or deletion — ask through the contact page. We will respond within 30 days, and will not charge for a reasonable request. If we refuse a request we will tell you why and how to complain.
11. Complaints
If you believe we have handled your personal information in breach of the APPs, contact us through the contact page and we will investigate and respond within 30 days. If you are not satisfied with our response you can complain to the Office of the Australian Information Commissioner at oaic.gov.au.
12. Changes to this policy
We will post changes here and update the date above. Where a change materially affects how we handle your information we will tell you in the app or by email before it takes effect.
13. Contact
Ebiblo Pty Ltd, Sydney, New South Wales, Australia — through the contact page.