Australian Privacy Principles
Privacy
1. Controller
Konduct is the owner of the property. Vaultborn Studios operates this pitch vault. Privacy questions: pitch@vaultborn.watch.
This notice is written to align with the Australian Privacy Principles. A small-business exemption under the Privacy Act 1988 (Cth) may apply depending on turnover and activities. We still follow this notice.
2. What we collect — and what we do not
We do not collect government identity documents, biometric templates, facial scans, or payment cards on this version of the site.
We store a one-way hash of each access code, a short hint (the last four characters), an optional studio label, and whether the code has been spent. We store a one-way hash of a session token and an expiry time.
We do not ask for your name, date of birth, or address to open the vault. If you email us, we receive whatever you put in the message.
Server logs operated by our host may include IP address and browser type as part of ordinary security. We do not use that to build a marketing profile.
3. Why
Codes and sessions exist so the vault stays closed to the public and so each code can be used only once. Age confirmation is a declaration you make; it is not an identity check.
We do not sell personal information. We do not use tracking pixels or advertising cookies on this version.
4. Overseas storage
The site and database may be hosted outside Australia (including the United States). If personal information is stored there, APP 8 may apply. We only send what the vault needs: hashed codes and hashed session tokens.
5. Retention
Spent code hashes are kept so a used code cannot be opened again. Session tokens expire after thirty days. Email you send is kept only as long as the evaluation requires.
6. Access, correction, complaint
Write to pitch@vaultborn.watch. You may also complain to the Office of the Australian Information Commissioner (oaic.gov.au).
