Privacy policy
Last updated: 3 August 2026
This policy explains how Octopusden handles personal information. It is written to comply with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth), as amended by the Privacy and Other Legislation Amendment Act 2024. If you have questions or a complaint, email [email protected].
Summary
Octopusden is an automated agent that helps you find the lowest final price on the things you buy and the services you hire. To do that we collect a small amount of information you give us, plus the outcomes of actions Octopusden takes on your behalf. We use it only to run the service. We do not sell personal information. You can ask us to show you what we hold, correct it, or delete it.
Who we are
Octopusden is operated by the team behind the Octopusden agent at octopusden.app. For privacy questions, complaints, or to exercise any of the rights described below, contact [email protected]. We will respond within 30 days.
What we collect (APP 5)
We only collect what is necessary to provide the service. The categories below cover everything Octopusden holds about you.
- Account identity. If you sign in with our authentication provider (Clerk), we receive your name and email. Until you sign in, you are tracked only by a random guest identifier generated in your browser; we never link that identifier to your real identity.
- Your vault entries. Your postcode, the cashback portals you have connected, the loyalty programs you hold, and self-declared eligibility flags (for example student, defence, Costco). You enter these yourself; you can clear or change any of them at any time.
- Search and comparison data. The products and services you search for, the comparison pages Octopusden computes for you, and the True Final Price breakdowns that result.
- Service request data. When you ask Octopusden to collect quotes for a service, we collect the job description, location, scope, timing, and the name and email you ask Octopusden to use when contacting providers.
- Outbound and inbound message audit trail. Every email or form submission Octopusden sends on your behalf, plus the replies from retailers and providers, is recorded with timestamps, message identifiers, the parsed outcome, and the full body of the message. This is the legal record of the authorised-agent relationship between you and Octopusden.
- Authorisation context. When you click a button that authorises Octopusden to act (Get matched price, Submit quote request, Update vault), we record the timestamp, your IP address, your user-agent, and the consent text shown to you at that moment. This protects both you and Octopusden if the action is later questioned.
- Service provider information. If you sign up to receive Octopusden-routed quote requests, we collect your business name, contact name, email, mobile number (optional), trade type, service area, capacity, discount commitment, and self-declared licence number.
- Verification codes. One-time verification codes sent to your email are held only as a SHA-256 hash, never the plaintext, and are deleted after use or expiry.
- Usage and performance data. Events such as pages viewed, searches run, and other actions in the app, plus counts, latency and error rates. These records are tied to a random device identifier and your approximate country, not to your name or email, and they do not include the contents of the emails Octopusden sends or receives on your behalf. We use them to keep the service running and to improve it.
We do not collect sensitive information (as defined by the Privacy Act) such as health data, racial or ethnic origin, political opinions, religious beliefs, sexual orientation, or biometric information.
Why we collect it (APP 6)
Each piece of information has a purpose tied to running the service. We do not use it for anything else without your consent.
- Vault entries feed the True Final Price calculation so the comparison page reflects what you can actually pay.
- Search and comparison data lets us produce the breakdown panel and improve the comparison engine over time.
- The audit trail is the legal record that Octopusden acted on your authorised instruction, and the source of truth if a retailer or provider questions an interaction.
- Service request data is shared only with the providers you ask Octopusden to contact, plus the disclosure footer Octopusden attaches to its outbound messages.
- Authorisation context (timestamp, IP, user-agent, consent text) is held to demonstrate that you specifically authorised an action at a specific moment.
- Usage and performance data is held to keep the service reliable and to improve it.
Who we share it with (APP 6, APP 8)
Personal information is disclosed only as described below. Octopusden does not sell personal information.
- Retailers when you click Get matched price. Octopusden sends an email or fills a contact form using the name and email you provided, with a mandatory disclosure footer identifying Octopusden as your authorised agent and naming the authorisation reference.
- Service providers when you submit a quote request. Octopusden shares the job description, location, scope, timing, and your contact details with the providers you authorise Octopusden to contact.
- Service vendors that operate parts of the infrastructure. These vendors act on Octopusden's instructions only and are not permitted to use your information for their own purposes:
- Clerk - authentication when you sign in.
- Resend and Cloudflare - sending Octopusden's outbound emails and receiving the replies routed back to you.
- OpenAI - large-language-model processing: turning your search into structured intent, composing outbound emails, and parsing retailer and provider replies into structured fields.
- Bright Data - running the product and price searches across retailer websites using your search terms.
- DigitalOcean - hosting, managed Postgres databases and file storage, all in the Australian (Sydney) region.
- Google Analytics 4 - usage analytics (events such as pages viewed, searches run and other actions) to measure and improve the service.
- Government bodies or law enforcement only if compelled by law (for example a valid warrant or court order) and only to the extent required.
Cross-border disclosure (APP 8)
Some of the service vendors above process data outside Australia. Clerk, Resend, Cloudflare, OpenAI and Google Analytics process data in the United States, and Bright Data operates internationally. In each case the disclosure is limited to what the vendor needs to perform its function for Octopusden - for example, email body text and structured fields are sent to OpenAI solely so the language-model service can return structured output back to Octopusden. All hosting, databases and file storage for the service remain in DigitalOcean's Australian (Sydney) region.
Because these vendors are overseas, they may not be bound by the Australian Privacy Principles, and Australian law may not apply to them in the same way. By using Octopusden you consent to this overseas disclosure for the purpose of running the service. We take reasonable steps to use reputable vendors that handle your information securely.
Automated decisions (APP 1.7, from 10 December 2026)
Octopusden uses automated systems, including large language models, to act on your behalf. So you understand how those decisions are made:
- What personal information is used. The name and email you provide, your search terms, the product or service details, and the retailer or provider reply text.
- Decisions made by automated systems. Composing the outbound email Octopusden sends on your behalf, and parsing incoming replies into structured outcomes, are produced with significant use of an automated system.
- A human-run check before anything is sent. Every Octopusden-sent message passes an automated accuracy and policy check before dispatch, and you always see the True Final Price breakdown - which is computed deterministically, with every contributing layer shown - before you authorise a Get matched price or quote-request action. You can choose not to proceed.
If you would like a human review of any automated decision Octopusden made on your behalf, email [email protected]. We will respond within 30 days with the inputs that produced the decision and a human review of the outcome.
How long we keep it (APP 11)
Retention periods reflect the purpose of each category.
- Vault entries are kept while your account is active. You can clear or delete any entry at any time.
- Search and comparison data is kept while your account is active so historical comparisons remain visible to you. You can ask us to delete your history at any time.
- Audit trail rows for messages Octopusden sent on your behalf are retained for seven years. This is the record that Octopusden acted on your authority, and the period reflects standard Australian business record-keeping (for example the seven-year company record-keeping requirement) and the limitation period for civil claims, during which such a record may be needed.
- Authorisation context (IP, user-agent, consent text) is retained alongside the audit row it supports.
- Verification code hashes are deleted as soon as the code is consumed or has expired.
- Usage and performance data is kept only for as long as it is operationally useful and is tied to a random device identifier, not to your name or email.
Your rights (APP 12, APP 13)
You have the following rights at any time. Email [email protected] to exercise any of them.
- Access. Ask us for a copy of the personal information we hold about you. We will respond within 30 days. There is no fee.
- Correction. Ask us to correct anything we hold that is inaccurate, out of date, incomplete, irrelevant, or misleading.
- Deletion. Ask us to delete personal information we hold about you that is not subject to a legal retention requirement. We action these requests manually and will confirm when it is done.
- Withdraw consent. Stop using a feature, or remove an entry from your vault, at any time.
- Complain. Lodge a complaint with the Office of the Australian Information Commissioner (OAIC) if you believe we have mishandled your information. We ask that you contact us first so we can attempt to resolve the issue.
Security (APP 11)
We hold personal information in managed Postgres databases in DigitalOcean's Sydney region with encryption in transit and at rest. Verification codes are stored as one-way hashes and never in plaintext. Access to the production environment is limited to the operators who run the service. Outbound email is sent over authenticated, signed channels (SPF, DKIM, DMARC).
If a data breach occurs that is likely to result in serious harm, we will notify the affected individuals and the OAIC as required by the Notifiable Data Breaches scheme under the Privacy Act.
Children
Octopusden is not directed at children. We do not knowingly collect information from anyone under 18. If you believe a child has given us information, contact us and we will delete it.
Updates to this policy (APP 1)
We update this policy whenever the way Octopusden handles personal information changes. The "Last updated" date at the top reflects the latest version. Material changes are summarised in a banner on the homepage for at least 30 days before they take effect.
How to complain to the regulator
If we have not resolved your privacy complaint to your satisfaction, you can contact the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.