Privacy policy
Last updated: 11 August 2026
Reportoir is a registered trading name of Omnip Pty Ltd (ABN 99 122 415 909), an Australian company (“we”, “us”). This policy explains how we handle personal information across this website (reportoir.com) and the Reportoir application (app.reportoir.com). We handle personal information in line with the Australian Privacy Principles in the Privacy Act 1988 (Cth) and, where it applies to our users overseas, the EU/UK GDPR.
The short version: we collect only what the service needs to run, we never sell personal information, and payments are handled by Stripe so card details never touch our systems.
Information we collect
When an organisation signs up. The organisation’s name and the owner’s email address, which we use to create the organisation’s workspace and send the owner their sign-in invitation.
Payment information. Payments are processed by Stripe on Stripe’s own secure checkout pages. We never see or store card numbers. Stripe shares with us the subscription’s status and the billing email so we can manage the account. Stripe’s handling of your details is described in Stripe’s privacy policy.
Information your organisation puts into Reportoir. Subscribing organisations add the names and email addresses of the people who own projects, along with themes, initiatives, projects and the status reports those people submit. Your organisation controls this content; we store and process it to provide the service.
Technical information. Standard server logs (such as IP address and browser type) generated when you use the website or the application, used for security and troubleshooting. Neither this website nor the application uses advertising or analytics cookies or trackers; the application stores a sign-in token in your browser to keep you signed in.
Emails we send on your organisation’s behalf
Collecting status reports by email is what Reportoir does, so the application sends report requests, reminders and sign-in links to the people your organisation nominates. Those emails are sent on your organisation’s behalf, and your organisation is responsible for having a proper basis to give us those addresses. If you have received a Reportoir email and believe you shouldn’t have, contact us at hello@reportoir.com and we will resolve it with the organisation concerned.
How we use personal information
- To provide, operate and support the Reportoir service.
- To draft summaries of submitted reports using an AI service (see the Anthropic entry below) — part of how the product works, used only for your organisation’s own reports.
- To send the emails described above — report requests, reminders, sign-in links.
- To manage subscriptions, billing and renewals through Stripe.
- To respond when you contact us, and to send important service announcements.
- To keep the service secure and diagnose problems.
We do not sell personal information, and we do not use your organisation’s content for advertising.
Who we share it with
We share personal information only with the service providers that run Reportoir:
- Stripe — payment processing and subscription billing.
- Google Cloud — hosting for the application and this website.
- Twilio SendGrid — delivering the service emails described above.
- Anthropic — the AI service that drafts report summaries from the report text your organisation submits. Under Anthropic’s commercial API terms, this content is not used to train AI models.
Each provider processes data only to deliver its service to us. We may also disclose information where the law requires it.
Where your information is stored
The Reportoir application and its data are hosted on Google Cloud in Australia. Payment information is held by Stripe, which operates globally, including in the United States. Emails are delivered, and report summaries drafted, by providers that process data in the United States (SendGrid and Anthropic, above). The small service that starts a checkout from this website runs in a US Google Cloud region; it stores nothing — details pass through it to Stripe. More detail is on our security page.
Security
Information is encrypted in transit (TLS) and at rest, and access to production systems is restricted. Card details are handled entirely by Stripe, a certified PCI DSS Level 1 provider. See our security page for the full picture.
Retention and deletion
We keep your organisation’s information while the subscription is active. When an organisation closes its account — or asks us to — we delete its content within a reasonable period, keeping only what we must retain for legal, tax or accounting reasons (for example, invoice records).
Your rights
You can ask us to access, correct or delete personal information we hold about you by emailing hello@reportoir.com. We will respond within a reasonable time. If you are in the EEA or UK you may also have rights under the GDPR, including data portability and the right to object to certain processing. If you are unhappy with how we have handled your information you can complain to us first, and to the Office of the Australian Information Commissioner (oaic.gov.au).
Changes to this policy
If we change this policy we will update this page and its date above, and for significant changes we will notify subscribing organisations by email.
Contact
Omnip Pty Ltd (trading as Reportoir), ABN 99 122 415 909 — hello@reportoir.com