Privacy policy
Version 0.1 · drafted 9 August 2026
Draft — not legally reviewed, and not in force.
These documents describe how Break Up Buddy actually behaves today, so they are useful for review. They have not been checked by a lawyer, and they are not the terms anyone is currently bound by.
Still needing legal input before this goes near a real client:
- Whether the program is a health service under state law, which would impose stricter obligations than the Australian Privacy Principles alone.
- A retention schedule, and a data breach response program.
- Whether the limitation of liability is enforceable alongside the Australian Consumer Law.
- The duty of care owed by a volunteer Anchor, and who carries it.
The short version
We hold some of the most private things about you: how you are sleeping, what is happening with money and lawyers, how you rate your own state each day, and what you write down. We keep it because the program cannot work without it.
Your journal is yours. Your Anchors never see a word of it. They see how you rated the day and whether you have been checking in, and nothing else.
Your messages are stored. If a concern is ever raised about your safety, the program team can read the conversation. We think that is the right trade, but you should know it before you write.
Who we are
Break Up Buddy is a twelve-week peer-support program for men after a separation. It is not a health service, not counselling and not a crisis line. We are based in Australia and this policy is written against the Australian Privacy Principles.
What we collect
Everything below is collected from you, or created by your use of the program.
If you are a Client
- Your name, email address, phone number, location and date of birth.
- An emergency contact, if you give us one.
- Your answers to the twelve intake questions — including housing, legal and financial pressure, sleep, exercise, health (which may include a mental health diagnosis), how you are functioning, and what you want out of the twelve weeks.
- Your twelve-week program and how it was generated.
- Each daily check-in: your mood from one to five, which practices you kept, and anything you wrote in the journal field.
- Messages between you and each of your Anchors.
- Any concern raised about you, and the note describing it.
- Notes written about you by the program team, and a record of when an Anchor logged speaking with you.
If you are an Anchor
- Your name, email, location and phone number.
- Your full application, including your professional background, your availability and capacity, your boundaries, and what you wrote about how you would respond to someone talking about self-harm.
- Which clients you support, and for how long.
- The catch-ups you log, and any concerns you raise.
Some of this is health information under Australian law. We treat all of it that way.
Who can see it
Your Anchors
An Anchor can see your record only while they are actively paired with you. If a pairing ends, or an Anchor is suspended, their access is cut off immediately — to the whole record, not just to anything new.
They can see:
- Your name, your program and which week you are in.
- The goal you wrote at intake.
- Your daily mood ratings, your streak and how often you have checked in.
- Messages in your conversation with them — not your conversations with your other Anchors.
- Notes the program team has explicitly chosen to share with your care team.
They cannot see:
- Anything you write in your journal. Not ever.
- Your full intake answers.
- Notes the team has marked as internal.
- Any other client. Clients cannot see each other either.
The program team
Administrators can see every client record: your intake answers, your program, your check-in history, concerns raised, and — through the administration system — the content of your messages. That access exists for safeguarding. Your journal is not shown on any screen we have built, though we should be straight with you that nothing currently prevents an administrator reading it directly from the database.
Other Anchors of yours
If you have more than one Anchor, they can all see the log of who has spoken to you and when. That is deliberate: it stops two people ringing you on the same evening while a fortnight goes by with nobody calling.
Nobody else
We do not sell your information, and we do not share it for advertising. We currently use no analytics, no error tracking and no third-party services that would receive your data. If that changes, this policy changes first.
Phone numbers
An Anchor's phone number is only shown to you if they have chosen to share it. Your number is visible to the program team and, where you have given it, to your Anchors.
When we would break confidence
If we believe you or someone else is at risk of serious harm, we may contact emergency services or the emergency contact you gave us, without asking you first. That is the only circumstance in which we would go outside the people described above, other than where the law requires it.
How it is protected
- Access is checked on every page, by role and by whether you are actually connected to the record. Trying to reach a record you have no relationship with returns "not found" rather than "not allowed", so nobody can confirm who is on the program by guessing addresses.
- Records use non-sequential identifiers, so the size of the program and the identity of the people on it cannot be worked out from a URL.
- Sessions expire after twelve hours. Connections are encrypted in transit.
What we have not built yet
We would rather say this than imply otherwise. As of this draft, the following do not exist, and must before the program takes on real clients:
- A retention schedule. Nothing currently expires or is deleted after a set period.
- Self-service access, correction or export. You would have to ask us.
- A defined erasure process. Accounts can be deleted, but "delete the account" and "erase the person, including from backups" are not the same thing, and the second is not specified.
- An audit log of who read what. Changes are recorded; reads are not. We consider this the most significant gap.
- Field-level encryption of journals, messages and concern notes, beyond whatever the database and host provide.
- A backup and breach-response policy.
Asking about your information
You can ask us what we hold about you, ask us to correct it, or ask us to delete your account. Write to privacy@breakupbuddy.example. Until the items above are built, we will do this by hand.
If we get it wrong you can complain to the Office of the Australian Information Commissioner.
Changes
If we change how your information is used, we will say so here and tell anyone on the program at the time. We will not quietly widen who can see what.