Privacy Policy
teo
Version 1.0 Effective 1 August 2026
1. Who we are
teo is operated by ILSA Labs Pty Ltd (ABN 65 693 769 658), an Australian company. In this policy, "we", "us" and "our" mean ILSA Labs Pty Ltd.
This policy explains what personal information we collect when you use teo, why we collect it, who we disclose it to, where it goes, and what rights you have over it.
We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
2. The short version
We collect very little, and we do not keep your conversations.
- We collect: your mobile number, your first name, your date of birth, and basic technical information needed to run the service.
- We do not store: the content of your conversations. There is no transcript, no chat history, no recording, and no message store in our database.
- The summary: at the end of a session teo generates a summary. Each participant downloads their own copy. We do not retain it.
- Where it lives: your account information is stored in Australia, in Sydney.
- What leaves Australia: what you say during a session is processed in real time by artificial intelligence and voice providers located overseas. This is explained in full in section 6, and it is the most important part of this policy.
The rest of this document is the detail.
3. What we collect
Information you give us
| What | Why we need it |
|---|---|
| Mobile number | It is your account identity, and we use it to send you a sign-in code and to deliver an invitation when someone invites you |
| First name | So that teo and the other participant can address you |
| Date of birth | To confirm you are 18 or over |
| The mobile number of a person you invite | To deliver that one invitation |
| Your acceptance of our terms | To record that you agreed, and which version you agreed to |
Information generated when you use teo
- Session metadata: when a session was created, when an invitation was sent and accepted, when a session started and ended, how long it ran, and whether a summary was generated.
- Technical information: IP address, device and browser type, and error and performance logs.
- Your preference about staying signed in on a device.
What we do not collect
We do not collect your surname, your email address, your address, your gender, your payment details, your location, or your contacts. We do not ask what your relationship to the other participant is. We do not ask what your conversation is about, beyond the topic you type at the start of a session, which is not retained after the session ends.
We do not use cookies for advertising or tracking. We use only what is necessary to keep you signed in and to keep the service working.
4. What we do not keep: conversations
This is the design principle teo is built on, so we want to be precise about it.
Our database has no table for messages. It is not that we delete conversation content after a session, or that we retain it briefly and then purge it. There is no place in our system where the words spoken in a session are written down.
During a session, what each participant types is transmitted in real time to the other participant and to the facilitator. It exists in transit and in memory for as long as the session is open. When the session ends, it is gone.
We cannot show you a past conversation. We cannot recover one. We cannot produce one in response to a request from you, from the other participant, or from anyone else, because there is nothing to produce.
5. The session summary
At the end of a session, teo generates a written summary of the discussion and anything the participants agreed.
The summary exists temporarily so that each participant can download their own copy. It is available for 24 hours and is then permanently deleted. We do not retain a copy after that point.
Once you have downloaded a summary, the copy on your device is yours. It is outside our systems and outside our control. Please treat it as what it is, a record of a private conversation involving another person.
6. How conversation content is processed, and where it goes
Please read this section. It is the part of this policy that matters most, and it is the part that most services in our position leave vague.
teo's facilitator is built on artificial intelligence models that we do not operate ourselves. For teo to work, what you say during a session must be sent to those providers to be processed. This happens in real time, in the moment, so that the facilitator can respond.
The providers involved are:
| Provider | What it receives | Where it is processed |
|---|---|---|
| Anthropic PBC | The text of what participants say during a session, in order to generate the facilitator's responses | United States |
| ElevenLabs Inc | The text of the facilitator's own responses, in order to generate speech, where a participant has turned voice on. Participants' own words are not sent to this provider | United States |
This means that although we do not store your conversation, and although your account information is held in Australia, the content of a session is disclosed to overseas recipients while the session is running.
[CONFIRM AND COMPLETE THIS PARAGRAPH BEFORE PUBLISHING. If zero-retention arrangements are in place: "We have arrangements with these providers under which the content sent to them is not retained after processing and is not used to train their models." If they are not yet in place, this paragraph must instead accurately describe the providers' standard retention terms, including how long inputs are retained and for what purpose. Do not publish this section without confirming which is true.]
We took reasonable steps to satisfy ourselves that these recipients handle information in a manner consistent with the Australian Privacy Principles before disclosing information to them. You should be aware that overseas recipients may be subject to the laws of the country they operate in, including laws that could compel disclosure to a foreign authority, and that those laws may differ from Australian law. Australian Privacy Principle 8 deals with cross-border disclosure and we are accountable for the handling of information we disclose to these recipients.
If you are not comfortable with this, please do not use teo.
7. Other service providers
We also use the following providers to operate teo.
| Provider | Purpose | What it holds | Location |
|---|---|---|---|
| Supabase | Database and account authentication | Account information, session metadata | Australia (Sydney) |
| Twilio | SMS delivery for sign-in codes and invitations | Mobile numbers, message content of the SMS | United States, with delivery via Australian carriers |
| Vercel | Website and application hosting | Technical and request logs | Server processing configured to Australia (Sydney); some network and edge functions operate globally |
| Upstash | Temporary session state | Short-lived operational data, no conversation content | [CONFIRM REGION] |
[ADD ANY ANALYTICS OR ERROR-MONITORING PROVIDER HERE, OR STATE THAT NONE IS USED. If you use Vercel Analytics, Sentry, or anything similar, it belongs in this table with what it collects and where.]
We do not sell your personal information. We do not disclose it to advertisers, data brokers, or marketing companies. We have no advertising on teo.
8. Why we collect what we collect
We collect and use personal information to:
- create and secure your account, and verify that you are the holder of your mobile number
- confirm that you are 18 or over
- deliver an invitation when you ask us to send one
- run a session, including generating the facilitator's responses
- generate a summary for participants to download
- keep the service working, diagnose faults, and protect against fraud, abuse and misuse of our systems
- keep a record that you accepted our terms
- comply with our legal obligations
We do not use your personal information for any other purpose without your consent, unless we are permitted or required to by law.
9. Disclosure to others
Apart from the service providers listed in sections 6 and 7, we disclose personal information only where:
- you ask us to, or would reasonably expect us to, for the purpose we collected it
- it is required or authorised by an Australian law, a court, or a tribunal
- it is necessary to lessen or prevent a serious threat to the life, health or safety of any individual, or to public health or safety
- it is reasonably necessary to investigate suspected unlawful activity or serious misconduct
- we sell or transfer our business, in which case account information may transfer with it, subject to this policy
If we receive a legal request for the content of a conversation, we will respond that no such content exists, because it does not.
10. Security
We take reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification and disclosure. These include:
- encryption of data in transit and at rest
- row-level access controls on our database, so that a person can only reach their own records
- one-time code authentication with no stored passwords
- rate limiting and abuse protection on sign-in and invitation endpoints
- access to production systems restricted to authorised personnel with multi-factor authentication
- logging of administrative actions
- storage of credentials outside our source code
- regular backups of account information, with restoration tested
No system is completely secure. If a data breach occurs that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner in accordance with the Notifiable Data Breaches scheme.
11. Where your information is stored
Account information and session metadata are stored in Australia, in Amazon Web Services' Sydney region (ap-southeast-2), through our database provider Supabase.
Conversation content is not stored anywhere. It is processed as described in section 6.
12. How long we keep things
| What | How long |
|---|---|
| Conversation content | Not retained. It exists only during the session |
| Session summary | 24 hours, then permanently deleted |
| Account information | While your account is open, and for 7 days after you ask us to delete it |
| Session metadata | 24 months |
| Terms acceptance record | For as long as we may need it to establish that you agreed, and for 7 years after your account is closed |
| Technical and security logs | 90 days |
| Declined or unaccepted invitations | Expire after 24 hours and are then deleted |
Where we are required by law to retain something for longer, we will do so and no longer.
13. Your rights
Access. You may ask us for a copy of the personal information we hold about you. We will respond within 30 days. There is no charge. Note that this will not include conversation content, because we do not hold any.
Correction. If information we hold is inaccurate, out of date, incomplete or misleading, you may ask us to correct it.
Deletion. You may ask us to delete your account and the information associated with it. We will do so within 7 days, except where we are required by law to retain something.
Anonymity. teo cannot be used anonymously. A verified mobile number is how we identify an account, deliver an invitation, and confirm that two distinct people are present in a session.
To exercise any of these rights, contact us at support@helloteo.com.au.
14. Complaints
If you think we have breached the Australian Privacy Principles or mishandled your personal information, please tell us first at support@helloteo.com.au. We will acknowledge your complaint within 5 business days and respond substantively within 30 days.
If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner:
Website: oaic.gov.au Phone: 1300 363 992 Post: GPO Box 5218, Sydney NSW 2001
15. Children
teo is for adults aged 18 and over. We do not knowingly collect personal information from anyone under 18.
We ask for date of birth at sign-up, and where a person indicates they are under 18 we do not create an account and no information is retained. If you believe we hold information about a person under 18, contact us at support@helloteo.com.au and we will delete it.
16. Changes to this policy
We may update this policy. Each version carries a version number and an effective date.
If a change materially affects how we handle your personal information, we will notify you before it takes effect.
17. Contact us
ILSA Labs Pty Ltd ABN 65 693 769 658
Version 1.0, effective 1 August 2026.