PRIVACY POLICY
Aera Australia Pty Limited
Last Updated: March 2026
1. About This Policy
This Privacy Policy explains how Aera Australia Pty Limited ('Aera Australia', 'we', 'us', 'our') collects, uses, discloses and stores personal information about you. Aera Australia operates an educational home-buying platform and mobile application (the 'Platform') that provides personalised financial coaching, savings tracking, educational modules, and AI-assisted guidance to help Australians achieve homeownership. The Platform is licensed to Aera Australia by Aera 22 Limited, a New Zealand incorporated company ('Aera NZ'), which owns and develops the underlying platform technology.
This policy applies to your use of our website at joinaera.co/au, our mobile application, and any related products or services (collectively, the 'Services'). It should be read alongside any applicable terms and conditions.
We are committed to complying with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) contained in that Act. This policy has been prepared in accordance with APP 1 (open and transparent management of personal information).
If you have any questions about this policy or wish to access or correct information we hold about you, please contact us at support@joinaera.co.
Acceptance
By applying for, accessing or using our Services, or by providing us with personal information, you acknowledge that you have read and understood this Privacy Policy and agree to the collection, use and disclosure of your information as described here.
Amendments
We may update this Privacy Policy from time to time. We will notify you of significant changes via the Platform or by email. Continued use of our Services after the effective date of any update constitutes your acceptance of the revised policy.
2. Who Collects Your Information
Your personal information is collected and held by:
Aera Australia Pty Limited
℅ Level 30, 35 Collins Street, Melbourne 3000
Email: support@joinaera.co
Aera Australia Pty Limited is an Australian incorporated company and is bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles in relation to personal information collected from Australian residents.
The Platform is operated by Aera Australia under a licence from Aera 22 Limited ('Aera NZ'), a New Zealand incorporated company that owns and develops the underlying platform technology. Because the Platform technology is owned and maintained by Aera NZ, certain aspects of platform development and maintenance may involve personnel and systems associated with Aera NZ. Where Aera NZ accesses or processes personal information in the course of providing the licensed Platform to Aera Australia, this occurs under appropriate arrangements between the two entities and subject to the obligations set out in this policy. Aera Australia remains responsible for your personal information collected in connection with your use of the Platform in Australia.
Where we share your information with related entities, mortgage brokers or other third-party service providers in Australia, those parties will handle your information in accordance with their own privacy policies and their obligations under the Privacy Act 1988 (Cth).
3. Information We Collect
The type of information we collect depends on the Services you use. We may collect:
Identity and Contact Information
- Full name, email address, phone number (including Australian mobile numbers)
- Residential location, state or territory
- Date of birth and residency status (where relevant for financial assessment)
Financial Information
- Household income, savings balances, debt levels and monthly savings rate
- Target property price and estimated borrowing capacity
- Account balance and earnings data from connected savings platforms
- Debt-to-income ratio, years to deposit, and other derived financial metrics
- Credit history and creditworthiness information, including information that may be used to assess eligibility for credit assistance services
Behavioural and Assessment Data
- Results from behavioural and financial readiness assessments completed through the Platform
- Readiness scores, coaching profiles and derived behavioural categories
- Progress through educational modules and course completions
- Platform usage patterns, milestone achievements and engagement data
AI Coaching Interaction Data
- Messages and conversations with Senna, our AI-powered coaching assistant
- Note: when you interact with Senna, we do not pass your full name, email address or phone number to the AI system. You are identified only by an anonymous identifier and first name for personalisation. If you choose to share personal details within the chat, that information may be retained as part of your conversation history.
Technical and Device Information
- Device type, operating system, app version and device identifiers
- Push notification tokens (used to send you alerts and updates)
- App usage data, session information, and feature interaction logs
- IP address and approximate geolocation derived from your device or network
- Cookies and similar tracking technologies when you use our website
Property and Shortlist Data
- Properties you shortlist or express interest in through the Platform
Communications
- Messages and support requests you send to us
- Responses to surveys, feedback forms or promotions
4. How We Collect Information
We collect personal information when you:
- Register for or use our Platform or Services
- Complete financial benchmarking or behavioural assessments
- Engage with Senna, our AI coaching assistant
- Complete educational modules or quizzes
- Contact us by email, phone or through the app
- Shortlist properties or interact with property features
- Connect a savings account or provide financial data
- Subscribe to newsletters or participate in promotions
- Apply for employment with us
We may also collect information from third parties, including savings platforms you connect to the Platform, licensed mortgage brokers and financial service providers you engage with through us, and from publicly available sources.
If you provide us with personal information about another person (for example, a joint applicant), you confirm that you have obtained that person's consent to provide their information to us and have informed them of the terms of this Privacy Policy.
You are not required to provide personal information to us. However, if you choose not to provide certain information, we may be unable to provide the relevant Services or the quality of those Services may be affected.
5. How We Use Your Information
We use your personal information to:
- Assess your eligibility for and provide our Services
- Generate personalised financial benchmarks, readiness scores and coaching recommendations
- Power the Senna AI coaching assistant with relevant contextual information about your financial journey (using anonymised identifiers)
- Track your progress through educational content and milestone achievements
- Match your profile to relevant property opportunities
- Communicate with you about your account, progress and the Services
- Send you notifications, reminders and coaching prompts (where you have enabled these)
- Verify your identity and conduct checks required by applicable law
- Refer you to licensed mortgage brokers or related financial service providers where you request this
- Improve, develop and test the Platform and our AI systems
- Conduct internal analytics and research on platform performance
- Comply with our legal obligations under Australian and New Zealand law
- Send you marketing communications about our Services (where you have provided consent)
We handle your information in accordance with APP 6, which requires that we use or disclose personal information only for the primary purpose for which it was collected, or for a secondary purpose where you would reasonably expect such use, where you have consented, or where otherwise permitted by law.
6. Disclosure of Your Information
Service Providers and Technology Partners
We engage third-party service providers to operate and improve our Services. Key providers include:
- Supabase, Inc: Our primary database and infrastructure provider. Your data is stored on servers located in Sydney, Australia (AWS ap-southeast-2 region). Supabase processes personal data under a Data Processing Addendum. As your data is stored in Australia, no cross-border transfer to Supabase's infrastructure occurs for primary storage.
- OpenAI, LLC (USA): We use OpenAI's language models to power the Senna AI assistant. Only your first name, anonymised identifiers and non-personally-identifiable contextual information are passed to OpenAI. Data processed by OpenAI may be transferred to and stored in the United States. We have taken reasonable steps under APP 8 to ensure OpenAI handles this information appropriately.
- Twilio Inc (USA): For sending SMS notifications. Phone numbers are shared with Twilio for message delivery.
- Resend (USA): For sending transactional emails.
- Ortto (Australia): Our customer data platform for engagement and analytics.
- Firebase / Google LLC (USA): For push notifications and device authentication.
- Cloudflare, Inc (USA): For web infrastructure and content delivery.
- Pipedrive (Estonia): Our CRM platform used to manage customer relationships. Account and progress data may be synced to Pipedrive.
Mortgage Brokers and Financial Service Providers
Where you request a referral or introduction to mortgage advice, we may share your personal information (including financial benchmark data) with licensed Australian mortgage brokers holding an Australian Credit Licence (ACL) or who are authorised credit representatives. These brokers operate under their own privacy policies and are independently bound by the Privacy Act 1988 (Cth) and the National Consumer Credit Protection Act 2009.
You will be informed before we share your information with any specific broker or lender, and you may choose not to proceed.
Savings Platform Partners
If you connect a savings account, relevant balance and earnings data may be shared or synchronised with that platform in accordance with your instructions.
Legal and Regulatory Disclosure
We may disclose your information where required or permitted by law, including to the Australian Information Commissioner, the Australian Securities and Investments Commission (ASIC), the Australian Prudential Regulation Authority (APRA), law enforcement agencies, government departments, courts and our professional advisers.
Business Transfers
If we are involved in a merger, acquisition, or sale of all or part of our business, your personal information may be transferred as part of that transaction, subject to appropriate confidentiality arrangements.
7. Cross-Border Disclosure of Personal Information
Some of our service providers are located outside Australia. In addition, because the Platform is licensed from and maintained by Aera NZ, personal information may be accessed from New Zealand in the course of platform development, maintenance and support. By using our Services, you acknowledge that your personal information may be disclosed to overseas recipients, including in the United States and New Zealand.
Before disclosing personal information to overseas recipients, we take reasonable steps under APP 8 to ensure that the overseas recipient does not breach the APPs in relation to that information. In relation to Aera NZ, appropriate contractual arrangements are in place between the two entities governing the handling of personal information accessed in connection with platform licensing and maintenance. For third-party service providers, this includes entering into data processing agreements that contain APP-equivalent obligations.
Our primary data storage is with Supabase on AWS ap-southeast-2 (Sydney), which means your information is stored domestically. Overseas transfers are limited to specific service providers for defined purposes as described in Section 6.
Where we cannot ensure that an overseas recipient will handle your information in accordance with the APPs, we will seek your consent before making the disclosure.
8. Credit-Related Information
We may collect and use credit-related information where relevant to connecting you with financial services. This may include information about your creditworthiness, credit history and eligibility for credit products.
Where we handle credit information in connection with credit assistance provided by licensed mortgage brokers, that credit information will be handled in accordance with Part IIIA of the Privacy Act 1988 (Cth) and any applicable credit reporting policy of the relevant broker or lender.
We may use credit reporting bodies to obtain credit-related information about you in accordance with APP 3 and the credit reporting provisions of the Privacy Act 1988 (Cth). You have rights under that Act in relation to credit-related information, including the right to request access and correction.
9. AI-Powered Services
Our Platform includes Senna, an AI coaching assistant powered by large language models and a retrieval-augmented knowledge base. When you use Senna:
- You are identified to the AI system only by an anonymous identifier and your preferred first name. We do not pass your full name, email address or phone number to the AI.
- Contextual information about your financial situation, learning progress and behavioural profile is used to personalise responses. This information is derived from your Platform data.
- Conversation history is stored in our database and may be used to maintain context across sessions.
- If you voluntarily share personal details (such as your name or contact information) within a chat message, that information may be retained as part of the conversation record.
- AI responses are generated automatically. They are intended as general educational guidance only and do not constitute financial, legal, credit or professional advice. Senna is not a licensed financial adviser and does not provide credit assistance.
- We may use anonymised and aggregated conversation data to improve our AI systems and knowledge base.
Our use of automated decision-making (including AI-generated readiness scores and coaching recommendations) is designed to personalise your experience. These outputs inform but do not replace human judgment in any decisions that materially affect you.
10. Cookies and Tracking Technologies
Our website uses cookies and similar technologies to maintain your session, understand usage patterns and support analytics. You may disable cookies through your browser settings, although some features may not function correctly if you do.
Our mobile application does not use browser cookies but may use equivalent device-level identifiers for session management and analytics purposes.
11. Data Storage and Security
Where Your Data is Stored
Your personal information is primarily stored on servers located in Sydney, Australia, operated by Supabase using Amazon Web Services (AWS ap-southeast-2 region). This means your primary data storage is within Australia.
Some information is also processed by service providers located outside Australia, as described in Sections 6 and 7. We take reasonable steps to ensure those providers protect your information appropriately.
Security Measures
We implement appropriate technical and organisational measures to protect personal information against unauthorised access, loss, misuse, disclosure or alteration. Our measures include:
- All data encrypted at rest using AES-256 encryption
- All data transmitted over encrypted connections (TLS)
- Access controls based on the principle of least privilege
- Row-level database security ensuring users can only access their own data
- Network-level access restrictions and audit logging
Despite these measures, no method of transmission over the internet is completely secure. You use our Services and transmit data at your own risk. We will notify you and the Office of the Australian Information Commissioner (OAIC) of any eligible data breach in accordance with the Notifiable Data Breaches scheme under the Privacy Act 1988 (Cth).
12. Data Retention
We retain your personal information for as long as necessary to provide our Services and fulfil the purposes in this policy, subject to any legal obligations to retain information for specified periods.
In general:
- Account data is retained for the duration of your account and for a reasonable period after closure to meet legal obligations
- Financial benchmark data is retained while you are an active user and for a period thereafter as required by law
- Behavioural assessment results are retained to support ongoing coaching and progress tracking
- AI conversation history is retained to maintain coaching continuity across sessions
- Credit-related and financial service referral records are retained for the periods required under applicable Australian law
You may request deletion of your personal information at any time by contacting us at support@joinaera.co. We will process such requests in accordance with APP 11.2, subject to any obligations requiring us to retain the data.
13. Push Notifications and Marketing
We may send you push notifications through our mobile app and transactional emails about your account and our Services. You can manage notification preferences within the app settings at any time.
Where you have consented to receiving marketing communications, we may send you information about our Services. You may withdraw consent at any time by contacting us at support@joinaera.co or by using the unsubscribe function in our marketing emails. We comply with the Spam Act 2003 (Cth) in relation to commercial electronic messages sent to Australian users.
14. Your Rights Under the Australian Privacy Principles
Under the Privacy Act 1988 (Cth) and the APPs, you have the right to:
- Request access to the personal information we hold about you (APP 12). We will provide access within a reasonable time and may charge a reasonable fee to cover our costs.
- Request correction of personal information that is inaccurate, out of date, incomplete, irrelevant or misleading (APP 13). If we decline to correct information, we will give you written reasons and notify you of your right to complain.
- Know whether we hold information about you and, if so, the general nature of that information
- Request that we not use your information for direct marketing purposes (APP 7)
- Request deletion of your personal information, subject to legal retention obligations
- Lodge a complaint if you believe we have interfered with your privacy
To exercise any of these rights, please contact us at:
Aera Australia Pty Limited
Email: support@joinaera.co
We will respond to access and correction requests within 30 days. If we are unable to meet this timeframe, we will notify you.
If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC):
Office of the Australian Information Commissioner
GPO Box 5218, Sydney NSW 2001
Phone: 1300 363 992
Website: https://www.oaic.gov.au
15. Children
Our Services are intended for adults aged 18 and over. We do not knowingly collect personal information from individuals under 18. If you believe we have inadvertently collected information about a person under 18, please contact us at support@joinaera.co and we will take steps to delete that information promptly.
16. Links to Third-Party Sites
Our Platform may contain links to third-party websites or services. This Privacy Policy does not apply to those sites. We encourage you to review the privacy policies of any third-party services before providing personal information to them.
17. Complaints
If you have a complaint about how we have handled your personal information, please contact us in the first instance at support@joinaera.co. We will acknowledge your complaint within 5 business days and aim to resolve it within 30 days.
If you are not satisfied with our response, you may refer your complaint to the Office of the Australian Information Commissioner (OAIC) at https://www.oaic.gov.au or by calling 1300 363 992.
18. Contact Us
If you have any questions about this Privacy Policy or the way we handle your personal information, please contact:
Aera Australia Pty Limited
Level 30, 35 Collins Street, Melbourne 3000
Email: support@joinaera.co
Website: joinaera.co/au
Last Updated: March 2026
Subscript
Superscript
Emphasis
Bold text
- Item A
- Item B
- Item C
Unordered list
- Item 1
- Item 2
- Item 3
Ordered list
Block quote
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur.
Heading 6
Aera Australia Pty Limited | This policy applies to Australian residents and users of the Aera platform in Australia