Auziplan logo
Legal & compliance

Privacy Policy

This policy explains what personal data Auziplan collects when you use our financial planning application, how we use it, and the choices available to you.

Last updated: 30 July 2026

1. Who we are

Auziplan ("we", "us", "our") is a financial planning application that helps founders and operators build business plans, financial projections and pitch-ready reports. This Privacy Policy explains what personal data we collect, why we collect it, and the choices you have.

2. Data we collect

Account data: your name, email address, password (stored as a salted hash by our authentication provider), and an optional profile photo.

Business plan data: business name, country and industry, financial targets and assumptions, revenue and cost projections, exit and valuation inputs, and any branding assets (such as a logo) you upload.

Billing data: your subscription tier (Free or Pro) and billing status. Card numbers and other payment instrument details are entered directly into our payment processor's secure checkout and are never transmitted to or stored on our own servers.

Usage and device data: log data such as IP address, browser type, and pages visited, used to keep the service secure and to understand feature usage.

Content you generate: prompts and outputs from AI-assisted features (for example, marketing copy or pitch narrative generated for your plan).

Blog posts you write (Pro): the title, summary, body text, category, cover image selection, author and business name for each post in My Blog, plus its publication state and share link token. Drafts are private to your account and protected by the same row-level access rules as your plans. Once you publish a post, everything in it — including the author and business name you entered — is readable by anyone holding the share link, so treat it as public information.

3. How we use your data

To create and secure your account, and to authenticate you on each visit.

To store, calculate and display your business plans, projections, dashboards and exported reports.

To generate AI-assisted marketing and pitch content based on the plan details you provide.

To process subscription payments, apply plan limits, and send billing-related notices.

To send essential account and service emails (for example, password resets or plan-export confirmations), and, where you have opted in, product updates.

To monitor, debug and improve the reliability, performance and security of the application.

4. Legal bases for processing

Where applicable data protection law requires a legal basis, we rely on: performance of a contract (providing the service you signed up for), legitimate interests (securing and improving the product), consent (for optional cookies and marketing emails), and compliance with legal obligations (such as tax and billing records).

5. Data retention

We retain account and business plan data for as long as your account is active. If you delete a plan, it is removed from active systems immediately and purged from backups within a reasonable rolling window (typically up to 30 days). If you close your account, we delete your personal data and plan content within 30 days, except where we must retain limited billing records to meet legal or accounting obligations.

6. Export and deletion requests

You can export your business plans as PDF reports directly from the app (available on the Pro plan). You may request a full export of your account data, or request deletion of your account and associated data, at any time by emailing us at support@auziplan.com. We will action verified requests within 30 days.

7. Subprocessors we use

Hosting, authentication and database: a hosted backend platform that stores your account and plan records and manages sign-in sessions.

AI content generation: a third-party AI provider used to generate marketing and pitch copy from the details you supply within a plan.

Payment processing: a PCI-compliant payment processor that handles card entry, billing and subscription management on our behalf; we never see or store full card numbers.

Email delivery: a transactional email provider used to send account, billing and notification emails.

We review our subprocessors periodically and only work with providers who offer appropriate contractual and technical safeguards for personal data.

8. Confidentiality of your plan data — and AI training

We treat the contents of your business plans as confidential. Your plan data is used only to operate the service for you: to calculate and display your projections, generate the AI content you request within your own plan, and produce your exports.

We do not sell your data, we do not share it with advertisers, and we do not use your business plan content to train our own or any third party's AI models. Where a plan detail is sent to our AI provider to generate content you asked for, it is sent under a contract that prohibits using that input to train the provider's models.

Aggregated, de-identified industry benchmark values (for example, a typical cost ratio for an industry in a country) may be cached and reused to reduce cost and improve accuracy. These cached values never contain your business name, figures, identity or any information that could identify you or your business.

Auziplan staff do not routinely view your plan content. Access to production data is limited to what is necessary to investigate a fault or respond to a support request you have raised.

9. Sharing and collaborators

If you invite a collaborator to a plan, you are choosing to disclose that plan's contents to the email address you enter. We send that person an invitation and, once they accept with a verified email address, they can view (or edit, depending on the role you grant) that plan. Please check the address carefully before inviting.

You control access: you can change a collaborator's role or revoke their access at any time from the plan's sharing page. Revoking access removes their ability to open the plan, but does not recall material they may already have exported or copied.

10. Data breach notification

We maintain an incident response process. If we become aware of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify affected users and, where legally required, the relevant supervisory authority — without undue delay and, where applicable law sets a deadline (such as 72 hours under the GDPR or the Australian Notifiable Data Breaches scheme), within that deadline.

11. International data transfers

Our hosting, AI, payment and email subprocessors may process data in countries other than your own. Where personal data is transferred internationally, we rely on the safeguards offered by our subprocessors, such as standard contractual clauses or equivalent mechanisms, to protect your information.

12. Security

Data is encrypted in transit (TLS) and at rest at the infrastructure level. Access to production data is restricted on a least-privilege basis, and row-level access controls ensure your plans are only readable by your account. We do not store card numbers or other sensitive payment credentials on our own servers. See our Security page for more detail.

13. Your responsibilities

Keep your login credentials confidential, use a strong password, and let us know promptly if you suspect unauthorised access to your account. You are responsible for the accuracy of the business information you enter into your plans.

14. Children

Auziplan is intended for business owners, founders and professionals. It is not directed at children, and we do not knowingly collect personal data from anyone under 16.

15. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our practices or for legal reasons. We will update the "Last updated" date whenever we do.

16. Contact us

Questions about this policy or your data? Email us at support@auziplan.com.

These pages are drafted and maintained by the Auziplan team. They describe our current practices in plain language and are reviewed periodically as the product evolves.