Legal

Privacy policy.

This policy explains how CIMP Pty Ltd, the Australian company behind Rusty, handles personal information under the Privacy Act 1988 (Cth) and the Australian Privacy Principles. It is written to be read, not to be survived.

CIMP Pty Ltd  ·  10 Mount View Terrace, Mount Pleasant, Perth WA 6153, Australia

Last updated 30 July 2026. If we change anything material we will change the date and say what moved.

The short version.

The long version is below and does not contradict this. If it ever appears to, the long version governs and we have written it badly.

  • We do not ask a worker who they are. No name, email, phone number, username or employee number — at any point, for any reason
  • Conversations are stored encrypted on the worker’s own device. We do not keep a copy and cannot read them
  • Our safety records hold a risk tier and what the app put on screen. There is no free-text column in that table, so no message content can be written into it
  • This website sets no cookies, runs no analytics and loads nothing from third parties
  • We do not sell personal information, and no provider in our chain trains on your conversations

What we collect.

Split by who you are, because a worker using the app and a customer buying it are in completely different positions.

From a worker using the app

The site code their employer issued, and a random identifier the app generates on the handset. That identifier is not derived from the device hardware, a phone number, or anything the employer issues, and we hold nothing that would let us connect it back to a person. We also record the risk tier of a conversation, the category, which companion was involved, what support options were shown, and whether they were tapped. Not the words.

From a customer or a prospect

If you email us, we hold your email address, your name if you sign it, your organisation and whatever you chose to write. If you become a customer we hold normal business contact details and the site information pack you load into the console. This is ordinary business correspondence and we treat it as such.

From a visitor to this website

Nothing. There is no analytics package, no tag manager, no advertising pixel, no embedded video, no third-party fonts and no cookie banner, because there are no cookies to consent to. Our host keeps standard server logs, including IP addresses, for security and troubleshooting.

Sensitive information

A conversation about someone’s mental health is sensitive information in the ordinary sense of the phrase. Our answer is architectural rather than procedural: we do not receive a copy to hold, so the question of how we secure it does not arise in the usual way.

The mobile app

What the app does
on the handset.

Every permission the app asks for, why it asks, and what leaves the device. If a permission isn’t listed here, the app doesn’t request it.

Microphone

Requested only when someone starts a spoken conversation, and used only for the duration of that conversation. The audio goes to the speech provider that generates the reply. We do not record it, we do not keep it, and an employer never hears it. Voice can be switched off for an entire company, in which case the permission is never requested.

Local network and Bluetooth

Used to find the most direct route for a live call so it doesn’t drop out on camp wi-fi, and to let someone pick a headset or car audio. Nothing is sent to anyone else on the network, and we do not scan for or record nearby devices.

Conversations stay on the handset

Messages are written to a database on the device, encrypted with SQLCipher under a key held in the operating system’s keystore. We hold no copy and cannot read them. To answer a message it passes through our gateway to the model provider; it is not stored at either end.

Crash and diagnostic reporting

The app uses Sentry to report crashes and performance problems, because an app that fails silently at 2am is worse than one that tells us. Personal-data collection is explicitly disabled in our configuration, screenshots are never attached, and no message content is included. What a report contains is the error, the device model, the OS version and the app version.

No advertising, no tracking, no profiles

There is no advertising identifier, no ad network, no analytics or attribution SDK, and no social-media SDK in the app. Nothing is sold or shared for advertising, and nothing is used to build a profile. Fonts are bundled with the app rather than fetched, so opening it does not call a font provider.

Who processes data for us

Supabase (database and storage), LiveKit and WebRTC (carrying live voice), our speech and language model providers (generating replies and scoring risk), Sentry (crash reporting), and Vercel (hosting). Each is bound by contract, and no provider in our chain trains on your conversations.

Deleting your data

Deleting the app destroys the conversation database with it — there is no server copy to request, and no account to close. The anonymous safety records described above cannot be traced back to a person by us or anyone else, so there is nothing in them to identify and remove.

Children

Rusty is provided to adults through their employer as a workplace support tool. It is not directed at children, is not offered to the general public, and we do not knowingly collect information from anyone under 16 — nor could we identify their age, since we collect no identity at all.

Why we hold it,
and who else sees it.

We use what we hold to run the service, to keep it safe, and to show an employer that the support pathway is working. Nothing else.

Your employer

Sees counts and trends by site and by swing, and never an individual. There is no view, no export and no support request that produces one worker’s activity, because the data to build it is not collected. If a manager asks us for it, the answer is that it does not exist.

Our suppliers

A message passes through our gateway to a model provider to be answered, and is not stored at either end. We use infrastructure and model providers under contract, no provider in our chain trains on your conversations, and where a provider offers a formal zero-retention agreement we hold one or are securing it. We will tell you the current status per provider rather than give you a blanket claim.

Nobody else

We do not sell personal information, do not disclose it for advertising, and do not trade it. If we were ever compelled to disclose something by law, what we could produce is bounded by what we hold — which for conversations is nothing.

Where it is,
and where it’s going.

Asked properly this is two questions — where data is stored and where it is processed. Both answers, as they stand today.

Storage — Singapore

Safety records, your content and your site information pack are held in ap-southeast-1. Not Australia, today. Worker conversations are not among them: those stay encrypted on the handset.

Processing — United States

Our safety layer currently executes on US infrastructure by platform default, and the models that write a reply and score risk run there too.

Moving onshore

The database will move to Sydney, ap-southeast-2, and the gateway will pin to Sydney with it. Models will move to AWS Bedrock’s au.* geographic profiles. We will change the tense on this page the day each one completes and not before — ask us where it is up to and we will tell you precisely.

Access, correction
and complaints.

APP 12 and 13 give you the right to ask for what we hold about you and to have it corrected. Here is what that means in practice.

If you are a worker

Your conversations are already in your hands — they are on your phone and nowhere else, and deleting the app destroys them. We cannot retrieve them for you, and cannot identify you in order to try. That is the trade anonymity makes, and it runs in your favour.

If you have written to us

Email hello@askrusty.com.au and we will tell you what correspondence we hold, correct it, or delete it. We aim to respond within 30 days, and normally much sooner.

If you want to complain

Write to us first at the address above and we will take it seriously. If you are not satisfied with how we handle it, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au, and you do not need our permission to do so.

Data breaches

We are subject to the Notifiable Data Breaches scheme and will notify affected people and the Commissioner where a breach is likely to cause serious harm. The honest note here is that the material most people worry about — what someone actually said — is not in our systems to be breached.

Questions about this policy go to hello@askrusty.com.au. A person reads that address.

The data controller is CIMP Pty Ltd, 10 Mount View Terrace, Mount Pleasant, Perth WA 6153, Australia. Written privacy correspondence can be sent to that address or to the email above.