Privacy Policy
Last updated 28 September 2026
Draft — under legal review. This policy has not yet been reviewed by a lawyer and will change before Anvox is generally available.
About this policy
Anvox provides software that Australian law firms use to record client consultations, organise client files and prepare case files. This policy explains how we handle personal information under the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
Two kinds of information
Information we hold for law firms. When a firm uses Anvox, we store recordings, transcripts, files, case files, client details and consent records on the firm's behalf. The firm decides what is collected and why, and its own privacy policy applies to its clients. We use this information only to provide Anvox to that firm. If you are a client of a firm that uses Anvox, please contact the firm first about your information; we will help the firm respond.
Information about our own users and contacts. This covers the people who have Anvox accounts, people who email us, and visitors to this website. The rest of this policy is mainly about this information.
What we collect
- Account details: name, email address, firm and role. Passwords are stored only as a one-way hash by our authentication provider. We also keep the setup of your authenticator app and a hashed copy of your recovery codes.
- Activity records: sign-ins and the changes made in Anvox, kept in the firm's audit log.
- Consent records: for each recorded consultation, the version of the consent script read, who read it, when, and the outcome.
- Correspondence: what you send us by email.
This website
This website sets no cookies and uses no analytics, advertising or tracking. It loads nothing from other websites; its fonts are served from this site. Our host, Vercel, processes the technical details your browser sends with each request, such as your IP address and browser type, to deliver pages and protect against abuse. We do not use them to identify you. Pages may be delivered from Vercel servers near you, which may be outside Australia.
How we use information
- To provide Anvox to your firm, including sign-in, two-step verification and security notices.
- To send service emails, such as account verification and password resets.
- To answer your questions and support your firm.
- To meet our legal obligations.
We do not sell personal information, use it for advertising, or use client content to train models.
Where information is stored and processed
Recordings, transcripts, files, case files and account data are stored in Sydney, Australia (AWS ap-southeast-2), including backups. The services that process client content are pinned to Australian regions:
- Supabase (database and authentication) and Amazon S3 (file storage): Sydney.
- Vercel (the application): Sydney functions.
- Deepgram (transcription), through its Australian endpoint. It keeps no audio or transcripts beyond processing and does not train on them.
- Anthropic's Claude on Amazon Bedrock (drafting), through the Australia-only profile, which runs only in Sydney and Melbourne. Nothing is kept beyond the request or used to train models.
- Amazon SES (email): Sydney.
Some limited operational information, such as website request logs and error reports that contain no client content, may be processed by our providers outside Australia, including in the United States.
We tell firms about any change to these providers 30 days in advance.
How long we keep it
- Consultation audio: 30 days after the session by default. A firm can choose deletion straight after processing, or 90 days.
- Transcripts, files and case files: for the life of the matter, under the firm's policy. Deleting a matter removes it from Anvox at once, from our main storage within 7 days and from backups within 30 days.
- Consent records and audit logs: 7 years.
- Backups: 30 days, rolling.
- Accounts are disabled rather than deleted, so that names stay on the audit log.
If a client withdraws consent, the audio for that consultation is deleted straight away. The firm's transcript and case file are kept and marked as consent withdrawn, unless the firm's policy is to delete them too.
How we protect it
Information is encrypted in transit and at rest. Each firm's data is isolated by the database itself. Every account needs two-step sign-in. Anvox staff have no standing access to firm data. Read the security summary, or ask us for our full security document.
Data breaches
We follow the Notifiable Data Breaches scheme. If a breach affects a firm's information, we notify the firm within 72 hours of confirming it, notify the Office of the Australian Information Commissioner where required, and help the firm tell its clients.
Access, correction and complaints
You can ask for access to, or correction of, the personal information we hold about you by emailing hello@anvox.ai. We will respond within 30 days. Clients of a firm should contact the firm first.
If you have a complaint about how we have handled your information, email us and we will respond within 30 days. If you are not satisfied, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au.
Contact
Privacy questions: hello@anvox.ai. Security questions and incident reports: security@anvox.ai.