Privacy Policy
Last updated: 31 August 2026
1. Introduction
Bluesoul Technology Pty Ltd (ABN 21 612 440 865), trading as justonce.ai ("we", "us", or "our"), is an Australian company committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use the justonce.ai service (the "Service"), including our website, applications, and related services.
By using the Service, you consent to the practices described in this policy. If you do not agree with this policy, please do not access or use the Service.
2. Information We Collect
2.1 Account Information
When you create an account via our authentication provider (Auth0), we collect your name, email address, and profile picture. We do not store your password; authentication is managed entirely by Auth0.
2.2 Memory Content
The core of justonce.ai is storing your personal knowledge. This may include documents, notes, emails, bookmarks, and other content you choose to save ("Memory Content"). You control what content you store in the Service.
2.3 Automatically Collected Information
When you use the Service, we may automatically collect certain information, including:
- Usage data (features used, search queries, interaction patterns)
- Device information (browser type, operating system, screen resolution)
- IP addresses and approximate location data
- Referral URLs and pages visited
2.4 Sensitive Information
Your Memory Content may include sensitive information such as government identifiers, financial details, or health information. We do not scan for or separate out sensitive values: all Memory Content is treated with the same protections — encrypted at rest as described in Section 4, processed only to provide the Service, and never used to train AI models.
3. How We Use Your Information
We use the information we collect to:
- Provide, operate, and maintain the Service
- Improve and personalise your experience, including AI-powered categorisation and semantic search
- Process and respond to your requests and enquiries
- Detect, prevent, and address security issues and fraudulent activity
- Send you service-related communications, such as account notifications and security alerts
- Comply with legal obligations and enforce our Terms of Service
4. Encryption and AI Processing
How your Memory Content is protected, and how it is processed:
- Encryption at Rest: The title, summary and body of every memory are encrypted with AES-256-GCM, an industry-standard authenticated encryption algorithm, before being written to storage — under a Data Encryption Key issued for the space the memory belongs to. Documents you upload are encrypted under a key issued for your account. A limited number of older records created before this encryption was introduced are migrated to it as they are next saved; until then they are protected by our cloud provider's storage-level encryption.
- Key Management: Data Encryption Keys are themselves encrypted under a master Key Encryption Key that we hold and manage, kept out of the database. We generate and manage these keys on your behalf; you do not hold them.
- AI Processing: To categorise, summarise and index your Memory Content, it is processed by AI models (see Section 6), including any sensitive information it contains. There is no automated step that detects or removes sensitive values before this processing. This processing is used solely to provide the Service to you, and your Memory Content is never used to train AI models.
- Private Memory Engine: The memory engine that stores distilled memories runs on a private network with no public DNS record and is not reachable from the internet.
You can review, correct, and delete any of your memories at any time through the web app.
5. Data Storage and Security
We take data security seriously and employ industry-standard measures to protect your information:
- Infrastructure hosted on Microsoft Azure with enterprise-grade security controls
- All data encrypted at rest and in transit (TLS 1.2+)
- Comprehensive audit logging of access to sensitive data and administrative actions
- Regular security assessments and vulnerability scanning
- Role-based access controls for internal systems
6. Data Sharing
We do not sell, rent, or trade your personal information.
We may share limited information with the following third-party service providers, solely to operate the Service:
- Auth0 (Okta): Authentication and identity management
- SendGrid (Twilio): Transactional email delivery
- Anthropic (Claude): AI processing for categorisation, summarisation, and entity extraction. Your Memory Content is sent to Anthropic to provide these features and is not used to train models
- Intercom: Customer support messaging and our help centre. When you contact us by chat or email, your name, email address, account identifier, plan, and the content of the conversation are processed by Intercom (hosted in the United States) so we can reply to you. Your Memory Content is never shared with Intercom
We may also disclose your information if required by law, regulation, legal process, or governmental request, or to protect the rights, property, or safety of Bluesoul Technology, our users, or others.
7. Your Rights
Under applicable Australian privacy law, you have the right to:
- Access the personal information we hold about you
- Correct inaccurate or incomplete information
- Delete your personal information and Memory Content
- Export your data in a portable format (data portability)
- Lodge a complaint with the Office of the Australian Information Commissioner (OAIC) if you believe your privacy has been breached
To exercise any of these rights, please contact us at privacy@justonce.ai. We will respond to your request within 30 days.
8. Cookies and Tracking
We use a minimal set of cookies:
- Authentication cookies: To maintain your logged-in session securely
- Security cookies: To protect against cross-site request forgery and other threats
- Analytics cookies: We use Google Analytics 4 on our public website (justonce.ai) to understand which pages help people and which don't — pages viewed, links and buttons clicked, and how far down a page people read. Google sets
_gacookies for this. We send advertising storage, ad personalisation and ad-user-data as denied for every visitor, so this data is not used to build advertising profiles. - Advertising measurement cookies: We run ads on Reddit, and use the Reddit Pixel on the public website to measure whether they work — a page visit, a sign-up click, or a form submission. Reddit sets a
_rdt_uuidcookie for this. It follows the same consent choice as analytics below, and is never loaded until you accept where consent is required. See Reddit's privacy policy. - Session replay (Microsoft Clarity): We record how pages are used — cursor movement, clicks, scrolling and navigation — so we can see where the site trips people up. It follows the same consent choice as analytics, and is never loaded until you accept where consent is required. Inside the app every page region is masked, so recordings show layout and interaction but not the contents of your memories; on this website the email fields in our contact and newsletter forms are masked the same way. See Microsoft's privacy statement.
Your choice. If you are in the EU, EEA, UK or Switzerland, analytics and advertising-measurement cookies are switched off until you accept them, and we show a banner asking. Everywhere else they are on by default and you can decline from the same banner. Declining is remembered on your device, and analytics still works in a cookieless mode that cannot identify you.
Beyond the Reddit Pixel described above we do not use advertising trackers, and we do not participate in cross-site tracking networks. Analytics, session replay and advertising measurement now run inside the app as well as on this website, so we can tell whether the people arriving from an ad go on to find the product useful. Inside the app they are limited to which page was viewed, when, and whether an account was created — every page region is masked in recordings, and the contents of your memories are never measured, recorded or sent anywhere.
9. Children's Privacy
The Service is not intended for individuals under the age of 16. We do not knowingly collect personal information from children under 16. If we become aware that we have collected personal information from a child under 16, we will take steps to delete that information promptly.
10. International Data Transfers
Your data is primarily stored in Australian Azure data centre regions. In some cases, data may be processed in other regions where our third-party providers operate. Where data is transferred internationally, we ensure appropriate safeguards are in place in accordance with the Australian Privacy Principles and any applicable data protection laws.
11. Changes to This Policy
We may update this Privacy Policy from time to time. For material changes, we will notify you via email at the address associated with your account. The "Last updated" date at the top of this page indicates when this policy was last revised. Your continued use of the Service after any changes constitutes your acceptance of the updated policy.
12. Contact Us
If you have any questions or concerns about this Privacy Policy, please contact us:
- Email: privacy@justonce.ai
- Post: Bluesoul Technology Pty Ltd, Sydney, NSW, Australia