Privacy policy
Draft, pending legal reviewLast updated 24 September 2026
This policy explains how Keen Shift Pty Ltd (“we”, “us”) handles personal information in Portalsweep: the website, the web app and the browser extension. We follow the Australian Privacy Principles in the Privacy Act 1988 (Cth). This is a plain-English draft and may change after legal review.
The short version
- We collect what we need to fetch and forward your clients’ supplier bills, and to run your account.
- We store it with Amazon Web Services in Sydney.
- AI providers in the US and China get a masked record when you teach a supplier or a portal moves a button.
What we collect
About you
- Your email address. Your name and practice name too, if you give them to us.
- Your plan and billing history. Stripe handles card details, and the card number stays with Stripe.
- Basic technical records needed to run and secure the service, such as sign-in times. Our servers’ access logs record the IP address of each request made to them and keep it for 30 days. We also use a scrambled (hashed) form of it to limit sign-in attempts.
About your clients (on your behalf)
- Client business names, ABNs if you add them, and the email-in address their bills are forwarded to. Unless that address is a Hubdoc, Dext or Xero Files address, we email it a link to confirm that bills may be sent there, and record when it was confirmed.
- Which suppliers each client uses.
- For each bill fetched: the supplier, invoice number, issue date, amount, a fingerprint of the file, and when it was forwarded.
- The bill PDF itself, held only long enough to forward it.
For client information you enter, you are generally the one responsible for it under privacy law, and we handle it on your behalf to provide Portalsweep. You need to have your client’s permission to access their supplier accounts and to send their bills to us for forwarding.
What we don’t collect
- Passwords for supplier portals. You or your client sign in each time a portal asks.
- Security codes (MFA or one-time codes), or anything typed into a card field. The extension spots these fields and leaves them unread.
- Your browsing outside the supplier websites you’ve added.
Early access and supplier requests
If you join early access or request a supplier, we keep your email address and what you tell us, to contact you about Portalsweep. Ask us to delete it at any time.
How we use it
- To fetch and forward bills and show the completeness board.
- To sign you in and keep your account safe from misuse.
- To bill you and to contact you about your account.
- To fix problems and improve Portalsweep.
We use your information and your clients’ information only for the purposes above. We don’t sell it or use it for advertising.
Where it’s stored
We store Portalsweep data with Amazon Web Services in the Sydney region. The copy of a bill that arrives in the client’s bookkeeping inbox is then held by that service under your agreement with it.
The extension also saves a copy of each bill it fetches in a Portalsweep folder inside your computer’s Downloads folder. Each file’s name gives the supplier, the month and the invoice number. That copy stays on your computer, where you can delete it whenever you like.
Sending information overseas
We disclose some information to service providers outside Australia:
- AI providers in the United States and China. They write the steps from your recording and help find a button again when a portal moves it, and more than one provider may be used for each job. They get the masked record described below, and never a bill PDF.
- A teaching record has the supplier’s name and the pages you opened on its website. Ids and search values in each web address are replaced. Each thing you clicked or chose is listed in order with its timing. The record gives the control’s label and the heading and page section it sat under. For a table it has the column names and the number of rows. For a row you used, each cell becomes a scrambled code (plus the date format where a cell holds a date). For a field you typed in, it has only how many characters you typed, or just the word “date” or “secret” for a date, or for a password, code or card number.
- When a page has changed during a run, they get the step’s description and the label and heading of the button or link it used before. They also get up to 40 buttons and links on the page that might be it. Each comes with its label and the heading and page section it sits under. No web address or table contents are sent.
- Before a record leaves your browser, table contents and anything you type are removed, and numbers, amounts, addresses, email addresses and your clients’ names are masked. Our servers check it again before any AI service sees it.
- Stripe processes payments and may process your billing details in the United States and other countries.
Cookies and local storage
The website doesn’t use advertising or analytics cookies. When you sign in to the web app, your browser stores a sign-in token so you stay signed in. Signing out removes it.
The browser extension keeps its own storage in your browser, which only the extension can read. It holds a short-lived sign-in token that is cleared when the browser closes, and a longer-lived one with your email address, which signing out removes. It also keeps your practice id and panel settings, the supplier steps you’ve accepted, and the progress of a run, so a run that’s interrupted can carry on. Removing the extension deletes all of it.
How long we keep it
- Bill PDFs are deleted from our servers as soon as they’re forwarded. One that can’t be forwarded is deleted automatically within two days.
- Access logs, including IP addresses: 30 days.
- Bill details and client records: while your account is open. When you delete a client, we delete their records: their bill details, run history, forwarding address and pending invites, and any client users of that business lose access.
- Security records: who changed a forwarding address or someone’s access, and when (addresses partly hidden), for 400 days.
- Backups: our database keeps rolling backups for 35 days, so deleted records are gone from backups within 35 days of being deleted.
- Account and billing records: while your account is open, and afterwards for as long as tax law requires.
Your rights to your information
You can see and correct most of your information in the web app. Email support@keenshift.ai to ask for a copy of what we hold or to have it corrected or deleted. We’ll respond within 30 days.
Security
We protect information with encryption in transit and at rest and with short-lived sign-in tokens. Access is limited to the people who need it. The security page has more detail. We will tell you and the Office of the Australian Information Commissioner about any data breach likely to cause serious harm, as the law requires.
Complaints
If you’re unhappy with how we’ve handled your information, email support@keenshift.ai and we’ll try to sort it out within 30 days. If you’re still unhappy, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au.
Changes
If we change this policy in a way that matters, we’ll email account holders before the change takes effect.