Privacy Policy
What we collect, why we collect it, where it goes, and what you can ask us to do about it.
Version 1.2 · Effective 13 September 2026 · Last reviewed 13 September 2026
On this page
- Who we are
- Our commitment under Australian law
- If you visit this website
- If you enquire, or become a client
- If you use the practice platform
- Sensitive and health information
- Where your information goes
- Disclosure outside Australia
- AI, scoring and automated decisions
- How long we keep things
- Security
- Access, correction and deletion
- If something goes wrong
- Complaints
- Changes to this policy
1. Who we are
Lazuro Learning is an Australian sole trader business (ABN 84 970 894 650) operated by Jared Fraser. We design custom learning experiences, deliver training, offer a set of browser-based builders called Lazuro Tools (including the Conversation Builder), and operate an online conversation practice platform at app.lazurolearning.com.
In this policy, "we", "us" and "our" mean Lazuro Learning. "Personal information" has the meaning given in the Privacy Act 1988 (Cth): information or an opinion about an identified individual, or an individual who is reasonably identifiable.
You can contact us about anything in this policy at jaredfras1@gmail.com.
2. Our commitment under Australian law
We handle personal information in accordance with the Australian Privacy Principles (APPs) in the Privacy Act 1988 (Cth).
Some small businesses are currently outside parts of the Privacy Act. We do not rely on that. We have chosen to comply with the APPs in full, for three reasons: our clients are universities, government agencies and corporates who are bound by the Act and by state privacy laws themselves; the platform may handle sensitive information; and we think it is the right way to treat people who are asked to practise difficult conversations honestly.
Where we work with a public sector client, we will also comply with the privacy legislation that applies to that client, including state legislation such as the Privacy and Personal Information Protection Act 1998 (NSW) or the Privacy and Data Protection Act 2014 (Vic), as set out in our agreement with them.
3. If you visit this website
This site (lazurolearning.com) does not use tracking cookies or advertising pixels. We do not build profiles of visitors and we do not sell or share information about you with advertisers. The one thing stored in your browser is your own work: a Lazuro Tools sign-in on the account page, and drafts the builders keep locally so you don't lose them. Neither leaves your browser except to the services described here.
Three things still happen automatically when you load a page:
- Server logs. Our hosting provider records standard technical information about requests, including IP address, browser type, the page requested and the time. This is used to keep the site running and to investigate faults and abuse.
- Visit counts. We use Vercel Web Analytics to count visits. It sets no cookies and does not identify you or follow you between sites. It records the page viewed, the site that referred you, and your country, browser and device type, and we only ever see those as totals.
- Web fonts. Our pages load typefaces from Google Fonts. This means your browser makes a request to Google's servers, and your IP address is visible to Google in the process. We do not send Google any other information about you.
Demonstration modules on this site
The interactive pieces in our showcase run in your browser. Anything you type into them, such as a search inside The UNIVERSEity or the structure you build in the Universe Builder, stays on your device and is not transmitted to us or to anyone else.
The exceptions are the features that use AI. When you try a conversation in the Conversation Builder or in the live demo on our home page, use a writing assistant inside one of the builders, or use the AI practice demonstration, what you have written and what you type are sent through our service (run on Cloudflare) to Anthropic to generate a reply. We do not store it. When you try a conversation with voice, the character's lines are also sent to ElevenLabs to be spoken, and if you speak your side, your microphone audio goes from your browser straight to ElevenLabs to be turned into text while the microphone is on. We don't receive or record that audio; the text is handled like anything you type. We keep short-lived counts against your connection's IP address, or your account, to enforce the free daily allowance and the voice allowance. A Conversation Builder draft is kept only in your own browser until you save it to an account.
4. If you enquire, or become a client
When you complete the contact form, book a call, or email us, we collect the information you choose to give us. Typically that is your name, email address, organisation, and whatever you tell us about your project.
We use it to respond to you, to scope and deliver work, to send invoices, and to keep the records a business is required to keep. We do not add enquirers to a marketing list without asking.
Our contact form is processed by Formspree, which forwards submissions to us by email. Enquiry correspondence is held in our business email and accounting records.
5. If you use the practice platform
Who decides what happens to your data
When an organisation such as your employer or university engages us, that organisation decides who gets an account, which scenarios are assigned, how long records are kept, and who can see what. We hold and process that information on their instructions, under our agreement with them.
If you are a learner and you want to know why you have been assigned something, or you want your records removed, your organisation is the right first point of contact. You can also come to us directly and we will help, but for some requests we will need their authority to act.
What we collect from learners
- Account details. Name, email address, the organisation you belong to, and your role in the platform.
- What you type or say. The transcript of each practice conversation.
- Your audio, in transit only. If you use voice mode, your microphone audio is streamed to our speech to text provider for transcription. We do not record or store the audio itself. Only the resulting text is saved.
- Results. The AI generated debrief for each session, including competency ratings, whether you achieved each objective, and the evidence cited for those judgements.
- Activity. When sessions start and finish, how many turns they take, which assignments are complete, and technical usage records we use to control cost and prevent abuse.
What administrators at your organisation can see
By default, administrators see participation, completion and aggregate patterns, not the transcript of your conversation. Practice is meant to be somewhere you can get it wrong.
An organisation can choose to enable transcript visibility for its administrators. Where that is switched on, learners are told before they begin. If you are unsure which applies to you, ask your administrator, or ask us.
Embedded and anonymous use
Some scenarios are embedded into an LMS such as Blackboard, Canvas or Moodle, or into a SCORM package, and can be used without signing in. In that case we do not collect your name or email, and the session is not linked to your identity by us. We still process and store the transcript and the debrief for that session, and we still record technical usage information.
Be aware that the system you reached the scenario through, such as your university's LMS, may know who you are even though we do not.
Lazuro Tools accounts and the Conversation Builder
To save conversations, share them or use the writing assistants, you sign in to a Lazuro Tools account with your email address. We keep that address, a licence identifier, and the status of your subscription. Payments are handled by Stripe: we never see or store your card details, and we receive your name, billing address and any tax identifier you give Stripe, for invoicing.
Conversations you save are stored on the practice platform in Sydney, under an organisation record that belongs to your account. When learners use your embed links, their sessions work exactly as described under "Embedded and anonymous use" above, with two differences: your account can see how many rehearsals have been used but never what anyone said, and transcripts and written debriefs are de-identified after 30 days.
6. Sensitive and health information
Sensitive information, which includes health information, is given extra protection under the Privacy Act.
We do not ask for sensitive information, and our scenarios are not designed to elicit it. But practice conversations cover subjects like performance, wellbeing, return to work and complaints, and a learner may volunteer something personal about themselves or another person. That means health or other sensitive information can end up in a transcript.
Where that happens, we treat it as sensitive information: it is stored under the same controls as everything else described in section 11, it is only disclosed as described in this policy, and it is subject to the retention rules in section 10.
Please do not enter real clinical details, real medical records, or identifying information about a third party into a practice conversation. You will get better practice from a realistic composite than from real data, and it protects both of us.
7. Where your information goes
We keep this list current because clients ask for it during procurement. These are the third parties involved in running the website and the platform, what each one does, and where the processing happens.
| Provider | What it does for us | What it can see | Where |
|---|---|---|---|
| Supabase | Database, sign in and file storage for the platform, and sign in for Lazuro Tools accounts | All account details, transcripts and results | Hosted in Sydney (AWS ap-southeast-2). Vendor is US based. |
| Vercel | Hosting and delivery for this website and the platform, and cookie-free visit counts | Request logs; data in transit through the application | Application runs in the Sydney region (syd1). Vendor is US based. |
| Anthropic | Generates the AI character's replies and the written debrief | Scenario text and conversation transcripts | United States |
| ElevenLabs | Converts the character's replies to speech, and your speech to text, on the practice platform and in Conversation Builder tries | Reply text; your microphone audio while you speak | United States |
| Formspree | Delivers contact form submissions to our inbox | Whatever you put in the enquiry form | United States |
| Sentry | Reports application errors so we can fix them | Technical error details, which may incidentally include identifiers | United States |
| Cloudflare | Runs the Lazuro Tools service that connects the builders to sign-in, payments and the AI provider | What you send to an AI feature, and text to be spoken, while it passes through; technical request details | Global network, including Australia. Vendor is US based. |
| Stripe | Takes payment for Lazuro Tools plans and issues invoices | Your name, email, billing address and payment details | Global. Vendor is US based. |
| Google Fonts | Serves the two typefaces used on this website | Your IP address when a page loads | United States |
| jsDelivr | Serves the sign-in library used on the Lazuro Tools account page | Your IP address when that page loads | Global network. Vendor is Poland based. |
We do not sell personal information. We do not disclose it to anyone else except where you have asked us to, where your organisation has instructed us to under our agreement with them, or where we are required to by Australian law.
AI providers and model training
We use the Anthropic API under commercial terms. Under those terms, content sent through the API is not used to train Anthropic's models. Anthropic retains API data for up to 30 days for trust and safety purposes and then deletes it, other than in limited cases such as a legal requirement or a trust and safety flag.
8. Disclosure outside Australia
As the table above shows, some of our providers are based in, or process data in, the United States. This is disclosure of personal information to overseas recipients under APP 8.
Before engaging any of them we take reasonable steps to satisfy ourselves that they handle personal information consistently with the Australian Privacy Principles, including reviewing their published security and privacy commitments and their contractual terms.
We have deliberately kept the data that matters most in Australia. Account records, transcripts and results are stored in Sydney. The overseas processing that occurs is for generating replies, speech and error reports, and is transient rather than a second copy of your record.
You should understand that once information is handled overseas it may be subject to the laws of that country, and that Australian law may not be enforceable against a foreign provider in the same way.
9. AI, scoring and automated decisions
The platform uses a large language model (Claude, from Anthropic) in two ways: to play the character you practise against, and to produce your debrief afterwards.
The debrief is generated automatically. It rates you against behaviours defined for that scenario, states whether you met each objective, and quotes the parts of your conversation it based that on.
We do not make any decision about you. We do not decide anyone's employment, enrolment, progression or standing. We produce practice feedback and give it to you and, subject to section 5, to your organisation.
What your organisation does with that output is their decision and their responsibility. We recommend to every client that AI generated practice scores are used as a development conversation starter and never as the sole basis for a decision about someone's job or studies.
AI systems get things wrong. A rating can be unfair or simply mistaken. If you think your debrief is wrong, you can ask for it to be reviewed by a person: contact us or your administrator, and see section 12.
10. How long we keep things
Each client organisation sets its own retention period for practice records. For rehearsals made through a Conversation Builder link, the period is 30 days. When a session passes that period, the platform automatically strips the transcript and the written debrief and marks the record as de-identified. This runs daily.
What remains afterwards is aggregate information that is no longer about an identifiable person: that a session happened, how long it took, and the counts that feed reporting. We keep that because it is what makes long-run reporting possible, and because it is no longer personal information.
We de-identify rather than delete outright because it preserves the integrity of an organisation's historical reporting. If you need actual deletion of a record, ask us and we will do it.
Enquiry and client records are kept while we are working together and afterwards for as long as we are required to keep business and tax records, which is generally five years.
11. Security
We take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification or disclosure. In practice that includes:
- Encryption in transit for everything, and encryption at rest for the database
- Row level access controls in the database, so an organisation's records are reachable only by that organisation
- Column level restrictions preventing transcripts from being read by roles that do not need them
- Sessions that are validated on our server rather than trusted from the browser
- Embedded scenarios locked to an approved web address, with tokens that expire
- Rate limiting and spending caps to contain abuse
- Restricted administrative access, held by the smallest number of people possible
No system is perfectly secure, and we do not claim otherwise.
12. Access, correction and deletion
Under APP 12 and APP 13 you can ask us for a copy of the personal information we hold about you, and ask us to correct it if it is wrong or out of date. You can also ask us to delete it.
Email jaredfras1@gmail.com. We will respond within 30 days. There is no charge. We may need to verify who you are before we hand anything over, and where the information belongs to a client organisation's account we may need to involve them.
If we refuse a request we will tell you why in writing, and tell you how to complain about it.
13. If something goes wrong
If a data breach occurs that is likely to result in serious harm, we will notify the affected individuals and the Office of the Australian Information Commissioner, as required by the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act.
Where the breach involves a client organisation's data, we will notify that organisation promptly so they can meet their own obligations.
14. Complaints
If you think we have mishandled your personal information, tell us first at jaredfras1@gmail.com. We will acknowledge your complaint within 5 business days and give you a written response within 30 days.
If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner:
- Online at oaic.gov.au/privacy/privacy-complaints
- By phone on 1300 363 992
- By post to GPO Box 5288, Sydney NSW 2001
15. Changes to this policy
We will update this policy when what we do changes, including when we add or remove a provider from the table in section 7. The version number and dates at the top of this page tell you when it last changed.
If a change materially affects how we handle information about platform users, we will tell the client organisations affected rather than relying on you noticing a new date on a web page.
Questions about any of this?
Procurement teams are welcome to ask for detail beyond what is on this page.
Get in touch