Privacy Policy

Last updated: 17 August 2026

1. Overview

Out West AI Pty Ltd (ABN 84 695 421 615) ("AgDiary", "we", "us", "our") operates the AgDiary farm management platform. This policy explains what we collect, what we do with it, who else sees it, and how long we keep it. It is written to match what the software actually does.

It covers agdiary.ai and the AgDiary apps for iPhone, iPad, Android phones and tablets, Mac and Windows.

We handle personal information under the Privacy Act 1988 (Cth) and the Australian Privacy Principles.

The short version: we collect the account details and farm records you give us so we can run the service and sync it across your devices. We do not sell your data, we do not use it for advertising, and we do not track you across other apps or websites. Some of what AgDiary records is genuinely sensitive — injuries and treatment, licence numbers, where people are — so the sections below spell that out rather than gloss it.

2. What We Collect

Your account

  • Name, email address, and password (stored only as a bcrypt hash — we never see it)
  • Enterprise/organisation name, your role, and your subscription status
  • Sign-in records: date and time, IP address, browser and device type

Farm and business records you enter

  • Diary entries, tasks, calendar and reminders
  • Properties, paddocks and boundaries; livestock, crops, soil and pasture records
  • Chemical, spray, fertiliser, seed and fodder records, including PICs, NVD numbers and agent names
  • Rainfall, weather and environmental observations
  • Machinery, stores, grain, wool and horse records
  • Infrastructure, documents, contacts and supplier details

These are your records. See section 4.

Work health & safety records — including health information

The WHS and compliance modules record information about people, and some of it is health information, which the Privacy Act treats as sensitive. If you use these modules you are recording it about your workers, and you are responsible for telling them so.

  • Incidents and injuries: who was hurt, what happened, a free-text injury description, the part of the body affected, whether treatment was given and what kind (none, first aid on site, doctor/GP, hospital/emergency), treatment details and where treatment happened, whether the incident is notifiable, any regulator reference, and the investigation notes, root cause and corrective actions
  • Licences and competencies: licence type and class, licence number, issuing authority, issue and expiry dates, who verified it, and competency assessment outcomes
  • Hours worked: dates, start and finish times, breaks and total hours, recorded against a named worker (who may not have an AgDiary account)
  • Inductions, toolbox talks and permits: attendance, quiz scores, and for toolbox talks a captured handwritten signature. Hot-work, confined-space and working-at-height permits record worker and standby/spotter names, their company, and whether they are a third party
  • Lone-worker check-ins: expected return time and actual check-in time for solo jobs

People who never used AgDiary

Some of what AgDiary stores is about people who have no account and never agreed to anything with us. If you collect it, you are the one who needs to tell them.

  • Visitor sign-in: the biosecurity visitor register — often a public QR code at the gate — records visitor name, company, phone, email, vehicle registration, purpose of visit, times in and out, whether they have had recent livestock contact and the details of that contact, and whether they accepted the declaration
  • Contractors and attendees named on permits, toolbox talks and inductions, including their signature
  • Your contacts directory: names, companies, phone, mobile, email and addresses of suppliers, agents and contractors you add

Location

AgDiary uses precise (GPS) location, not an approximate area. Location is only read when a feature needs it — there is no background or continuous tracking, and the app does not follow you around.

  • Paddock and property boundaries — captured by walking the boundary or drawing on the map, and stored as coordinates
  • Hazards — you can attach your current position to a hazard with a "Use my location" button, and remove it again
  • Toolbox talks — a new toolbox talk records where it was held automatically, without asking, and there is currently no button to remove that position. We think you should know that rather than discover it
  • Messages — a message can carry a position if you attach one
  • Sharing your position with your team — see below

Teammate location sharing. A manager or teammate can ask where you are. This sends you a notification; nothing is sent back automatically. Tapping it opens a screen that says "Share your location? Your current position will be shared once — this is not continuous tracking," and you choose Share or Decline. If you share, your latitude, longitude and accuracy are sent once and shown as a pin on the person who asked. If you decline, no coordinates leave your phone. You can also share your position with the farm team yourself from the map menu — that one sends straight away, without a confirmation step. There is no in-app switch that turns location sharing off permanently; your controls are declining each request and revoking location permission in your device settings.

Photos and files

  • Photos you take or attach, documents you upload, and barcodes you scan
  • Photos from a phone camera often carry hidden metadata, including the GPS position where the photo was taken, the time, and the camera model. We strip that metadata from images when they reach our servers (we keep only the orientation flag, so portrait photos are not shown sideways). The copy on your own device keeps whatever your camera recorded
  • We do not have a table of "photos of people", but people appear in farm and incident photos. Assume they do

Voice input

If you talk to the assistant instead of typing, the app uses your device's own speech recogniser — Apple's on iPhone, iPad and Mac, Google's on Android — to turn speech into text. AgDiary never receives your audio; only the text comes to us. Be aware that depending on your device, language and OS settings, Apple or Google may send the audio to their own servers to transcribe it. That part is between you and them, and it is governed by their privacy policies, not ours.

Biometric unlock

You can lock the app with Face ID, Touch ID or your Android fingerprint/face unlock. Your device tells the app only whether the check passed or failed. No biometric data ever leaves your device, and we never see it or store it. The lock is a screen in front of the app — it does not encrypt or decrypt anything on its own.

Device and technical information

  • A push notification token, so we can send you alerts and reminders
  • The device name, which on most phones is something the owner typed and often contains their name (for example "Bill's iPhone"), plus the app version and platform
  • IP address, browser and user agent, for security and rate limiting
  • Error logs, which can include your email, IP, the page you were on and the data you submitted when something broke
  • Audit logs, which record who changed a record and the before-and-after values. Because of this, a copy of anything you enter — including injury and treatment text — also exists in the audit log
  • Feedback you send us, with your email, the page you were on and your browser details

Assistant conversations

Your conversations with Jack, including any photo you attach, are stored in your workspace. See section 5.

Payment information

Card details are entered directly into Stripe's payment form and never reach our servers. We store only the card brand, last four digits and expiry, so you can tell your cards apart.

What we do not collect

There is no date of birth, tax file number, bank account number, Medicare number or next-of-kin record anywhere in AgDiary. User accounts do not have a phone number field (phone numbers appear only in the visitor register and your contacts).

3. How We Use It

  • To run the platform and sync your records across your devices and your team
  • To sign you in and keep your account secure
  • To show your farm data to the people in your workspace, according to their role
  • To power the features you use — maps and satellite imagery, weather and rainfall, safety and compliance, and the assistant
  • To send notifications you have turned on, and account emails such as verification, password resets and invoices
  • To generate the reports you ask for
  • To bill you, support you, and keep the service reliable

We do not sell your personal information or farm data, and we do not use it for advertising.

4. Your Data, and AI Training

You own your data. Your farm records, paddock boundaries, livestock, diary entries, photos and documents remain yours. We hold them on your behalf and claim no ownership.

  • We do not use your data to train, fine-tune or develop AI or machine-learning models, our own or anyone else's.
  • We do not sell, licence or hand your data to AI vendors, model providers or data brokers for training.
  • Anthropic, who run the model behind the assistant, do not use what we send them to train their models. That is a contractual commitment under our commercial API agreement with them.

5. The AI Assistant ("Jack")

AgDiary includes an assistant called Jack the Jackaroo, built on Anthropic's Claude models. Anthropic process this data for us in the United States. Jack sends Anthropic considerably more than the sentence you type, so here is the whole picture.

Sent every time you talk to Jack

  • Your enterprise name and your first name
  • Every active property: its name, locality and PIC
  • Your livestock head totals by species
  • The names of your rain gauges
  • Your message, the recent history of that conversation, and any photo you attach

Sent when Jack looks something up

Jack answers questions by calling internal tools that read your workspace, and what those tools return goes to Anthropic as part of working out the answer. That includes:

  • Property, paddock and livestock detail, including whole livestock records
  • Diary entries, including free-text notes, NVD numbers, PICs and agent names
  • Hours worked per worker, with the worker's email address
  • Notification titles and message bodies, and task names and due dates
  • Infrastructure, tank and water-monitor detail, and horse records
  • If you ask Jack to log an incident, the injury description for a named person

Jack is blocked from the Finance module and cannot read your financial records.

Photos sent to Anthropic

Several features send an image to Anthropic to read it. Each one only runs when you start it:

  • Photos you attach to a Jack conversation — the assistant actively invites photos of chemical and fertiliser labels, invoices, NVDs and sale dockets, and handwritten horse books, wool books and shearer tally books
  • Chemical label scanning
  • Livestock stock-take photos, such as a whiteboard or tally sheet, sent along with your paddock names and livestock classes
  • Property maps and georeferenced plans you upload, so paddock names, boundaries and infrastructure can be traced off them

Other things sent to Anthropic

  • Toolbox talk voice transcripts, sent together with the names and email addresses of your active team members so speakers can be matched to people
  • Chemical name matching during imports, and the fencing calculator

How long conversations are kept

Conversations are stored in your workspace so you can look back at them. Be aware that "delete conversation" currently archives it rather than erasing it — it disappears from your list, but the messages remain in the database. We are changing this so that delete means delete. Until then we would rather say so than let you believe otherwise. If you need a conversation genuinely erased now, email us and we will do it by hand.

6. Who Else Receives Your Data

We do not sell your data. We share it only where it is needed to run the service. Everyone listed here is a supplier acting for us or a service you have chosen to connect.

Inside your workspace

Other members of your enterprise see shared farm data according to their role and the diary's visibility settings.

Always in use

  • Anthropic (United States) — the assistant. See section 5 for exactly what goes across.
  • Bush Telegraph (bushtelegraph.ai) — sends our transactional email. It receives the recipient's email address and name, the sender details, the subject, and the full text and HTML body of the message, plus any attachment, which for invoices and reports means the whole document.
  • Stripe (United States) — subscriptions and payments. Receives your enterprise name, the email of the person paying, and your plan. Card details go to Stripe directly and never touch our servers.
  • Google Firebase Cloud Messaging, and Apple's Push Notification service on Apple devices — deliver push notifications. They receive your device push token and the content of the notification, which can include a task name, an alert, or the name of the person asking for your location.
  • Esri (ArcGIS) and OpenStreetMap — map and satellite tiles. Loading a map tells them your IP address and which piece of ground you are looking at, which points at where your property is.
  • Bureau of Meteorology (Australia) — forecasts, observations and warnings, requested by location or station, without your identity.
  • Out West AI website analytics — our own analytics service, at outwest.ai. It records the page address, page title, referring page, screen size and browser language, and keeps a long-lived visitor ID in your browser's local storage. It runs on every page of the website, including pages you see once signed in. It is first-party, it is not shared with advertisers, and it does not follow you to other companies' sites — but it is tracking, so we are not going to call it "essential cookies only". This runs on the website; the mobile and desktop apps contain no analytics at all.
  • Australian and state government mapping services — vegetation and land layers on the map, which receive the map area you are viewing.

Only if you or your administrator turn them on

  • Xero — accounting. We send draft journals (dates, descriptions, amounts, account codes and GST treatment) and read back invoices, bank transactions, contacts and P&L. Worker hours and names are not sent to Xero; the "Xero timesheet export" produces a CSV file that you download and handle yourself.
  • Integrity Systems / NLIS (Australia) — livestock traceability and eNVDs. Receives PICs, species, head counts, movement details and declaration answers.
  • Copernicus Data Space / Sentinel Hub (European Union) — satellite imagery and vegetation index. Your paddock boundary polygons are sent to it to calculate figures for that paddock.
  • OpenWeatherMap, DPIRD Western Australia, Long Paddock (Queensland SILO), WeatherLink (Davis weather stations) — weather and rainfall. These receive your property's coordinates or station identifiers. Long Paddock in particular is sent your exact property coordinates, because its data is interpolated to a point.
  • FarmBot (Australia) — tank and rain sensor data, using the credentials you supply.
  • Keycloak — single sign-on, where your organisation uses it. Your email and name pass through it when you sign in.
  • Meat & Livestock Australia — market price indicators. No farm or personal data is sent.

Embedded content on our website

Some pages embed content from other companies, which lets them see your IP address and set their own cookies: Stripe on billing pages, YouTube and Vimeo for help videos, jsDelivr for a script library, and EmailJS on the "book a demo" page, which sends the name, email and company you type there to us by email.

Other

  • Hosting and infrastructure suppliers, and our backup service, which are bound by confidentiality obligations.
  • Legal — if we are required by law, a court order or a regulator, or where we need to protect people's safety.

7. Where Your Data Is Processed

AgDiary is an Australian service and your data is held in Australia. Some of the suppliers above process data overseas: Anthropic, Stripe, Google and Esri in the United States, Copernicus in the European Union, and OpenWeatherMap and WeatherLink outside Australia. Where they do, we rely on their contractual and legal protections.

8. Security

What we actually do:

  • Everything travels over HTTPS/TLS. The mobile apps additionally pin our certificate, so they will not talk to anything impersonating us
  • Passwords are stored as bcrypt hashes
  • Each enterprise's data is strictly separated from every other enterprise's
  • Session cookies are httponly, secure and samesite; forms are CSRF-protected; sign-in endpoints are rate limited
  • On your phone or tablet, the local AgDiary database is encrypted with SQLCipher, and your sign-in token is encrypted again before being placed in the device's Keychain or Android Keystore
  • Backups are taken daily, weekly and monthly

Two things we want to be straight about. First, photos and map tiles cached on your device are ordinary files, not inside the encrypted database — they are protected by your device's own passcode and disk encryption, not by ours. Second, our backups are compressed archives transferred over HTTPS to our backup service; we do not currently encrypt the archive itself, so we are not going to claim "encrypted backups" here. Both are on the list to fix.

9. How Long We Keep Things

These are the periods we hold data for:

  • Active accounts — for as long as the account is open.
  • Closed farm accounts — the workspace becomes read-only and everything is kept for 12 months, so you can reopen it and pick up where you left off. After 12 months it is purged, apart from the records listed below that we are required to keep.
  • Location history12 months. This covers position sharing between team members and the positions attached to records.
  • Diagnostic logs — error logs, device logs and sign-in logs: 90 days.
  • Audit logs7 years. This is deliberate. Audit logs are what show who changed a workplace safety record and when, which is the whole point of having them.
  • Work health & safety records — incidents, inductions, competencies and hours worked are kept for as long as work health and safety law requires, which is longer than the account itself. See section 10 for what happens to your name on them.
  • Backups — up to 365 days.

About backups, plainly: backups are kept for up to 365 days, which is longer than several of the periods above. So for up to a year after something is deleted from the live system, a copy can still exist in a backup archive until that archive ages out. A deletion promise that quietly excludes backups is only half true, so we are saying it here rather than in a footnote.

How we are tracking against this. The periods above are our policy and what we are building to. The automated jobs that enforce them are written but not yet running on a schedule, so at the moment removal at the end of a period happens when we do it, not automatically. We would rather tell you that than print a number we are not yet keeping. If you want something removed now, ask us and we will action it.

10. Your Rights

Under the Australian Privacy Principles you can:

  • Access the personal information we hold about you
  • Correct anything wrong or out of date — most records you can edit directly in the app
  • Ask us to delete your account (see below)
  • Withdraw consent for optional processing, and turn notifications off, or revoke camera, photo, location, microphone and biometric permissions in your device settings at any time
  • Complain to us, and if you are not satisfied, to the Office of the Australian Information Commissioner

What deleting your account does

Deleting your account anonymises you rather than erasing the farm's safety records, because a business is legally required to keep those. Specifically:

  • Destroyed: your name, email address, phone number, your location history, your devices and push tokens, and your assistant conversations.
  • Kept, but no longer linked to you: work health and safety records — incidents, inductions, competencies and hours worked — remain as evidence that the work was done, with your identifying details replaced so they can no longer be traced back to you.

We do not currently offer a self-service data export. The Reports section produces farm and finance reports as PDF or spreadsheet, and several lists can be downloaded as CSV, but neither is a personal-data export and we are not going to describe them as one. If you want a copy of the personal information we hold about you, email us and we will put it together.

11. Cookies and Tracking

The website sets these cookies:

  • Session cookie — keeps you signed in. If you tick "keep me signed in" it lasts 30 days
  • CSRF token — protects forms from being submitted by another site

Your light/dark theme choice is stored in your browser's local storage, not in a cookie.

We run no advertising tags and no third-party tracking or advertising cookies. We are not in any advertising network — see ads.txt. A Meta (Facebook) pixel used to run on our sign-in and public pages; it was removed in August 2026.

We do run our own website analytics, described in section 6, which keeps a visitor ID in your browser's local storage. Embedded content from Stripe, YouTube, Vimeo and jsDelivr sets its own cookies on the pages where it appears.

12. Permissions the App Asks For

The apps ask for these only when a feature needs them, and you can change them any time in your device settings:

  • Camera and Photos — to take, attach and scan
  • Location — to map paddocks, stamp records, and share your position with your team when you choose to
  • Microphone and speech recognition — for talking to the assistant
  • Notifications — for alerts, reminders and location requests
  • Face ID / Touch ID / fingerprint — to unlock the app

13. Children

AgDiary is a business tool for farmers and agribusinesses. It is not directed at children and we do not knowingly collect personal information from them.

14. Changes to This Policy

We may update this policy. We will notify you of significant changes by email or a notice in the platform, and the date at the top will change. Continued use after a change means you accept the updated policy.

15. Contact Us

Questions about this policy, requests about your data, or a complaint:

Out West AI Pty Ltd
ABN 84 695 421 615
Email: privacy@agdiary.ai or it@outwest.ai

If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au.