TidePlay Back to home

PRIVACY

TidePlay Privacy Policy (Draft)

This policy is a draft and is still being reviewed. It may change before TidePlay launches.

About this policy

TidePlay helps early childhood educators record observations, plan learning and share progress with families, and this policy explains what personal information we handle, why, and what choices you have.

Effective date: 10th October 2026

Operator: Tideplay AI

We handle personal information in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

TidePlay is currently in development. It is an independent product and is not affiliated with ACECQA.

How TidePlay works today. Observations and records are saved in the educator's own browser, on the device they use. TidePlay does not yet keep children's records or photos on its own servers. Where an educator uses an AI feature, the only information that leaves the device is de-identified text sent to our AI provider. Cloud storage, accounts and family access are planned, and we will update this policy and tell services before they launch.

Who this policy covers

This policy applies to three groups, and the education service that uses TidePlay decides what is recorded about children.

  • Educators and service staff who have a TidePlay account.
  • Families and guardians who receive or view documentation about their child.
  • Visitors to this website.

Children do not create accounts or use TidePlay directly, and TidePlay is not directed at children. Each education service decides what it records about the children in its care and is responsible for having the consent it needs from families, including for photos. TidePlay handles that information on the service's behalf and only for the purposes it sets out here.

Information we collect

We collect only what is needed to provide documentation tools to educators and services.

  • Account details: educator name, work email, role, service name and login credentials (stored in protected form). TidePlay does not have accounts yet, so this applies once they are introduced.
  • Children's records entered by educators: a child's name, age or date of birth, room or group, observations, learning notes, attendance, daily records (sleep, meals, toileting and care), incident reports and inclusion or support plans.
  • Health and wellbeing information: allergies, medical needs and additional needs, where a service chooses to record them. This is sensitive information under the Privacy Act, so it is collected only for the child's care and documentation, and only where the service has the consent it needs.
  • Photos and videos that educators attach as evidence of learning. Today these stay on the educator's device.
  • Family communications: messages, summaries and newsletters prepared by educators for families.
  • Technical information: device type, browser, error logs and basic usage data, used to keep TidePlay working and secure.

We do not collect location data from photos, and we do not build advertising profiles. We intend to use Cloudflare Web Analytics on our public website to measure aggregate traffic, as described under "Website analytics" below.

How we use information

We use personal information only to run TidePlay for the services that use it, and never to advertise or to sell.

  • Provide the observation, planning, daily record and family communication features.
  • Help educators draft learning stories and summaries using de-identified text
  • Keep accounts secure, prevent misuse and fix problems.
  • Provide support when a service asks for it.
  • Meet legal obligations.
  • Improve TidePlay using aggregated information that does not identify any child, family or educator.

We do not sell personal information, we do not show advertising, and we do not use children's information to train AI models.

Children's privacy and how AI features work

TidePlay is built so that AI never receives a child's identity or photos.

  • Names are replaced before text leaves the app. A child's name, and the names of other children mentioned, are swapped for random codes on the educator's device.
  • AI receives de-identified text only. It never receives photos, videos, real names, birth dates or contact details.
  • Names are restored only inside the educator's own app, after the AI has responded.
  • Educators stay in control. AI output is a draft, and an educator reviews and approves it before anything is shared with families.
  • No automated decisions about a child, family or educator are made by AI.

Photos and media

Photos and videos of children stay on the educator's own device today, and are never sent to AI.

  • Kept on the device. Photos are shown as previews on the educator's device and are not uploaded to TidePlay or to any third party.
  • Never sent to AI. Photos and videos are not shared with the AI provider.

Planned for cloud storage. Before we introduce cloud storage for photos, we will update this policy and tell services. We plan to:

  • remove location, device and timestamp data from a photo on the device before upload;
  • upload photos directly to private, encrypted storage rather than through our application servers;
  • keep photos private by default, with no public links;
  • show photos through secure links that expire within minutes;
  • store media apart from children's profiles, so each service can reach only its own children's media.

Hosting and service providers

TidePlay uses third-party service providers to support the operation, security and delivery of its website and application.

Application infrastructure: TidePlay plans to use Supabase for its application backend, which may include database services, user authentication and file storage, depending on the features enabled. Information processed through these services is subject to the relevant service configuration and provider terms.

Public website hosting: The hosting provider for TidePlay’s public website will be identified in this policy once the hosting arrangement has been confirmed.

Data storage and processing locations: Data may be stored or processed in Australia or other countries, depending on the services used and their configuration. We will identify the relevant providers and locations and explain any applicable overseas processing in this policy. We do not claim that all TidePlay data is stored exclusively in Australia unless this has been verified.

Website analytics

TidePlay intends to use Cloudflare Web Analytics to understand aggregate website traffic and performance. Cloudflare describes this service as privacy-focused and designed not to track individual visitors across websites.

Website analytics are used to understand how the public website performs and how visitors interact with it, rather than to build advertising profiles.

Who we share information with

We share information only with the people and providers needed to run TidePlay, and we do not sell it.

  • The education service you or your child belongs to. Families see only their own child's documentation.
  • AI provider: Anthropic, which receives de-identified text only, as described above.
  • Hosting and infrastructure providers, including Supabase once cloud features launch, as described under "Hosting and service providers" above.
  • Website analytics: Cloudflare Web Analytics, once it is enabled.
  • Regulators and authorities where the law requires it, or to protect someone's safety.
  • A successor organisation if TidePlay is sold or restructured, on the condition that this policy continues to apply.

Providers may use information only to deliver their service to us, and are bound by confidentiality and security obligations.

Storage, security, overseas disclosure and retention

Today, information is saved on the educator's own device, and the cloud protections below will apply once cloud storage launches.

Security. Children's names are replaced with random codes on the device before any text is sent to the AI provider, and text is sent over an encrypted connection. Because records are saved on the device, educators should keep it locked and up to date. When cloud storage launches, we plan to encrypt information at rest, separate each service's data from every other service's, limit staff access to what their role needs, and keep access logs.

Where data is held. Records are held on the educator's device. The AI provider is based in the United States, so de-identified text may be processed outside Australia. No names, photos or other identifying information are sent. We take reasonable steps under APP 8 to make sure overseas providers protect information appropriately. When cloud storage launches, we plan to host data in Sydney, Australia.

Retention. Records stay on the device until the educator or service deletes them, and TidePlay does not keep a copy. Text sent to our AI provider is de-identified first. The provider automatically deletes it within 30 days, except in limited cases such as legal requirements or safety review. When cloud storage launches, we will keep personal information only for as long as reasonably necessary for the purposes it was collected, subject to legal obligations and operational requirements, and we will follow the service's instructions about deleting it. Services may have legal duties to keep some records for set periods, and we will not delete those until the period ends. When information is deleted from the active application, copies may remain temporarily in backups or other recovery systems until they expire or are securely removed. How long that takes depends on the provider and its backup configuration.

Your rights and how to complain

You can ask to see, correct or delete the personal information we hold about you or your child.

Because the education service decides what is recorded about a child, requests about a child's information are best made to the service first, and we will help the service respond promptly. You can also contact us directly.

Under the Privacy Act and the Australian Privacy Principles, you can:

  • ask for access to the personal information we hold about you or your child;
  • ask us to correct information that is inaccurate, out of date or incomplete;
  • ask us to delete information we no longer need, which we will do unless the law requires us to keep it;
  • withdraw a consent you have given us, at any time.

If you have a concern about how we have handled personal information, contact us first using the details below and we will respond within a reasonable time. If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or on 1300 363 992.

Data breaches, changes and contact

If a data breach is likely to cause serious harm, we will notify the affected services, individuals and the OAIC as the Notifiable Data Breaches scheme requires.

We may update this policy as TidePlay changes. We will post the new version here with a new effective date and tell services directly about any significant change.

For privacy enquiries, requests to access or correct personal information, or other privacy-related concerns, please contact us using the details below. We will review privacy requests and respond in accordance with applicable privacy obligations.

Privacy contact: Wendy Miranda - Founder & Developer

Email: tideplayadmin@gmail.com