Legal

Privacy policy

Last updated 7 October 2026.

1. Who we are

Koalaris is run by Mohammed Ahmed, trading as Koalaris, based in Brisbane, Queensland (“we”, “us”). This policy explains how we handle personal information when you use this website, the Koalaris app, the field app and the client portal. We handle personal information in line with the Australian Privacy Principles in the Privacy Act 1988 (Cth).

2. Two kinds of information

Information about you. When you visit the site, contact us, start a trial or subscribe, we collect information about you and your business. We decide how this is used.

Information you put into Koalaris. Businesses use Koalaris to record their clients, sites, equipment, tests, photos, visits and invoices. That information belongs to the business that entered it. We store and process it only to run the service for that business, and we follow its instructions. If you are a client of a business that uses Koalaris, contact that business first about your information.

3. What we collect

  • Contact and account details: name, email, phone, business name, role, and your login details.
  • Enquiries: what you send through our forms, email or phone.
  • Service data: client and site names and addresses, contact people, equipment records, test results, readings, photos, notes, service reports, certificates and invoices.
  • Billing details: your plan and payment history. Card details are entered directly with Stripe. We never see or store full card numbers.
  • Technical data: device and browser type, IP address, pages visited, and app logs used to keep the service secure and working.

We don’t ask for sensitive information (such as health information) and we ask businesses not to enter it. If service data does include it, it is handled only to provide the service.

4. How we use it

  • To provide, secure and support Koalaris, including syncing results from the field app.
  • To set up trials and subscriptions, bill you, and send service emails such as reminders, receipts and trial notices.
  • To answer enquiries and demo requests.
  • To improve the service, using usage information that does not identify you where we can.
  • To send our newsletter or product updates, only if you sign up or are a customer. Every email has an unsubscribe link.
  • To meet our legal obligations.

We do not sell personal information, and we do not use service data to train AI models.

5. Lyra AI

When you use a Lyra AI feature, only the text, photo or file needed for that task is sent to our AI provider, Anthropic, to process. Personal details are removed from notes before they are sent where we can do so. Under its commercial terms, our AI provider does not use this data to train its models. Lyra AI never decides a test result.

6. Who we share it with

We use trusted providers to run Koalaris. They only get what they need to do their job:

  • Supabase: database, file storage and logins. Service data is hosted in Sydney, Australia.
  • Vercel: hosting for the website and app.
  • Resend: sending emails.
  • Anthropic: Lyra AI features.
  • Stripe: subscription payments, and card payments your clients make on your invoices.
  • Xero: only if you connect it, to sync your invoices and payments.

Some of these providers may process data outside Australia, including in the United States. We choose providers with strong security and privacy commitments and take reasonable steps to make sure they protect your information. We may also disclose information if the law requires it, or with your consent.

In the client portal, a client can see only their own equipment, history and documents. They never see your prices, invoices or other clients.

7. Cookies and analytics

We use cookies needed to keep you signed in and the service working. We may also use analytics and advertising tools (such as Google and Meta) to understand how people find and use the website and to measure our ads. You can block or delete cookies in your browser settings. Essential cookies are needed for the app to work.

8. Security

We protect information with encrypted connections, separated data for each business, role-based access, and private storage for photos (with location data removed). No system is perfectly secure. If a data breach is likely to cause serious harm, we will notify the people affected and the OAIC as the law requires.

9. How long we keep it

We keep account and service data while your account is active. When an account closes, the business can export its data, and we then delete or de-identify it within a reasonable time, unless we must keep some records by law (such as billing records for tax).

10. Access, correction and complaints

You can ask to see or correct the personal information we hold about you, or make a privacy complaint, by emailing hello@koalaris.com. We will reply within 30 days. If you are not happy with our response, you can contact the Office of the Australian Information Commissioner at oaic.gov.au.

11. Changes

We may update this policy from time to time. The latest version is always on this page, and we will tell customers by email about important changes.

12. Contact

Privacy questions: hello@koalaris.com.