Legal

Privacy Policy

How we store, maintain, use and disclose personal information.

Effective date: 8 June 2026

1. Introduction

This document sets out the privacy policy of Harrison Duske trading as Drafty (referred to in this privacy policy as ‘we’, ‘us’, or ‘our’).

Drafty is an AI email assistant for Australian mortgage brokers. Brokers connect a work inbox (Gmail or Microsoft Outlook). Drafty labels incoming mail, drafts replies into the broker’s inbox, and runs compliance checks. Brokers review and send every email themselves, Drafty does not send email on a broker’s behalf.

We take our privacy obligations seriously and we've created this privacy policy to explain how we store, maintain, use and disclose personal information.

By providing personal information to us, you consent to our storage, maintenance, use and disclosing of personal information in accordance with this privacy policy.

We may change this privacy policy from time to time by posting an updated copy on our website and we encourage you to check our website regularly to ensure that you are aware of our most current privacy policy.

2. Type of Personal Information we collect

The personal information we collect may include the following:

  • Name;
  • Email address;
  • Telephone number and other contact details;
  • Account login and authentication details (managed by our auth provider, we do not store your password in plain text);
  • Subscription and billing status;
  • Payment information (where you subscribe, card details are processed by our payment provider; we receive billing identifiers, not your full card number);
  • Information about your business or professional circumstances;
  • Connected inbox data, including email metadata (sender, recipients, subject, date, message identifiers, labels), email body text needed to classify mail and draft replies, and a sample of sent mail (typically up to 300 messages) where voice learning is enabled;
  • A voice profile derived from your sent mail (for example, tone and greeting style stored as a summary, not a permanent archive of all sent mail);
  • Usage and operational data, including message identifiers, truncated subject lines, label categories, draft metadata, AI usage logs, connection identifiers, and processing timestamps;
  • Information in connection with client surveys, questionnaires and promotions;
  • Your device identity and type, I.P. address, geo-location information, page view statistics, advertising data and standard web log information;
  • Information about third parties contained in emails in your connected inbox (including your clients' personal and financial information); and
  • Any other information provided by you to us via our website or our online presence, or otherwise required by us or provided by you.

3. How we collect personal information

We may collect personal information either directly from you, or from third parties, including where you:

  • Contact us through our website;
  • Sign up for or use Drafty;
  • Connect your work inbox via OAuth (Gmail or Outlook through our email integration partner);
  • Receive goods or services from us;
  • Submit any of our online sign up forms;
  • Communicate with us via email, telephone, SMS, social applications (such as LinkedIn) or otherwise;
  • Interact with our website, services, content and advertising; and
  • Invest in our business or enquire as to a potential purchase in our business.

We may also collect personal information from your connected inbox when new mail is received and processed through our service (including via webhooks from our email integration partner).

We may also collect personal information from you when you use or access our website or our social media pages. This may be done through use of web analytics tools, ‘cookies’ or other similar tracking technologies that allow us to track and analyse your website usage. Cookies are small files that store information on your computer, mobile phone or other device and enable and allow the creator of the cookie to identify when you visit different websites. If you do not wish information to be stored as a cookie, you can disable cookies in your web browser.

We may use Google Analytics to collect and process data, including when you use third party websites or apps. To find out more see How Google uses data when you use our partners' sites or apps.

4. Use of your personal information

We collect and use personal information for the following purposes:

  • To provide goods, services or information to you (including labelling inbox mail, drafting replies into your inbox, voice personalisation, and compliance assistance, not legal advice);
  • To process email content using AI providers solely to provide the Service for your account;
  • For record keeping and administrative purposes;
  • To provide information about you to our contractors, employees, consultants, agents or other third parties for the purpose of providing goods or services to you;
  • To improve and optimise our service offering and customer experience;
  • To comply with our legal obligations, resolve disputes or enforce our agreements with third parties;
  • To send you marketing and promotional messages and other information that may be of interest to you and for the purpose of direct marketing (in accordance with the Spam Act). In this regard, we may use email, SMS, social media or mail to send you direct marketing communications. You can opt out of receiving marketing materials from us by using the opt-out facility provided (e.g. an unsubscribe link);
  • To send you administrative messages, reminders, notices, updates, security alerts, and other information requested by you; and
  • To consider an application of employment from you.

If you are a mortgage broker, emails in your inbox may contain your clients’ personal information. We process that information on your behalf to provide the Service. You remain responsible for how you handle your clients’ personal information and for reviewing every draft before you send it.

We may disclose your personal information to cloud-providers, contractors and other third parties located inside or outside of Australia (including providers of hosting, database, authentication, email integration, AI processing, and payments). If we do so, we will take reasonable steps to ensure that any overseas recipient deals with such personal information in a manner consistent with how we deal with it.

5. Third-party access

To operate Drafty, we use trusted service providers including Supabase (database and authentication), Nylas (Gmail and Outlook connection), Anthropic and OpenAI (AI processing of email content for your account only), Vercel (hosting), and Stripe (payments, if enabled).

Email content may be sent to AI providers only as needed to classify mail, draft replies, learn your writing style, and review drafts for your account. We do not use your inbox data to train public or shared AI models for other customers. AI outputs can be inaccurate, you must review every draft before sending.

We do not sell your personal information. We do not otherwise share your personal information without your consent unless required by law.

6. Security

We take reasonable steps to ensure your personal information is secure and protected from misuse or unauthorised access. Our information technology systems are password protected, and we use a range of administrative and technical measures to protect these systems (including encrypted connections, access controls, and OAuth for inbox access, we do not store your email password). However, we cannot guarantee the security of your personal information.

7. Links

Our website may contain links to other websites. Those links are provided for convenience and may not remain current or be maintained. We are not responsible for the privacy practices of those linked websites and we suggest you review the privacy policies of those websites before using them.

8. Requesting access or correcting your personal information

If you wish to request access to the personal information we hold about you, please contact us using the contact details set out below including your name and contact details. We may need to verify your identity before providing you with your personal information. In some cases, we may be unable to provide you with access to all your personal information and where this occurs, we will explain why. We will deal with all requests for access to personal information within a reasonable timeframe.

You may also access and update certain account details through Settings in the Service, or disconnect your inbox to stop new email processing.

If you think that any personal information we hold about you is inaccurate, please contact us using the contact details set out below and we will take reasonable steps to ensure that it is corrected.

9. Complaints

If you wish to complain about how we handle your personal information held by us, please contact us using the details set out below including your name and contact details. We will investigate your complaint promptly and respond to you within a reasonable timeframe.

If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or 1300 363 992.

10. Contact us

For further information about our privacy policy or practices, or to access or correct your personal information, or make a complaint, please contact us using the details set out below:

Name: Harrison Duske

Email: Harrison@drafty.com.au