RoxWhy Privacy Policy for Learning Data

Last updated: August 9, 2026

This Privacy Policy explains how RoxWhy collects, uses, stores, and shares information for its AI learning workspace.

Information We Collect

We may collect:

  • Account information, such as name, email address, authentication identifiers, and profile details.
  • Learning content, such as prompts, messages, uploaded documents, notes, knowledge bases, RoxBot instructions, generated study material, and saved workspace context.
  • AI NAPLAN Insights information, such as the identity-free structured result returned from an in-memory image analysis, test year and year level, the short answers supplied by the user, temporary generated-report data, and delivery records. The source report image may contain identity fields, but the model is required to disregard them and RoxWhy does not save that image in its database, filesystem or object storage.
  • Usage and metering information, such as AI-token usage, plan limits, feature activity, technical logs, and error events.
  • Billing information, such as plan, subscription status, payment provider references, invoices, receipts, and top-up records. Stripe handles full payment card details.
  • Support information, such as category, subject, message, account context, email address, and support history.
  • Device and cookie information, such as browser, IP address, session cookies, security cookies, and analytics or diagnostics where configured.

Parents, Guardians, and Students

RoxWhy is designed for study support used by students, adult learners, parents, and guardians. If a parent or guardian creates or manages an account for a student, we may process information that the account owner or student provides while using the account, contacting support, uploading learning material, or using AI learning features.

Students should use RoxWhy with parent, guardian, school, or account-owner permission where that permission is required. Parents and guardians can contact support for account, deletion, access, or data questions.

For AI NAPLAN Insights, a student who states that they are under 15, or does not provide an age band, cannot start the upload workflow. A parent or guardian aged 18 or over must restart the workflow and act as the submitting adult. These in-product role and age statements are operational safeguards; they do not independently verify age, identity, parental responsibility, or legal authority.

How We Use Information

We use information to:

  • Provide RoxWhy tutoring, writing, knowledge-base, upload, and RoxBot features.
  • Process AI-powered AI workflows and retrieve relevant source context.
  • Read and explain a NAPLAN report image in memory, prepare an identity-free quick analysis, generate an optional detailed report from that structured analysis, and deliver a one-off paid PDF by email.
  • Manage accounts, sign-in, security, support, subscriptions, and AI-token credits.
  • Detect abuse, debug issues, monitor reliability, and improve the product.
  • Send service messages, support replies, receipts, and important account notices.
  • Comply with legal, tax, accounting, and security obligations.

AI Providers and RoxWhy Processing

RoxWhy may send prompts, messages, retrieved source excerpts, uploaded document text, and related workspace context to AI-powered services and AI providers when needed to generate responses or perform learning workflows.

Do not upload content you are not permitted to process with an AI service. For sensitive documents, remove unnecessary personal information before uploading where practical.

AI NAPLAN Insights accepts one JPG, PNG or WebP image rather than a raw PDF. For each free analysis, the image passes through RoxWhy request memory to the configured AI provider once. The model is instructed to disregard identity fields, the structured response has no identity fields, and RoxWhy clears its in-memory image buffers after the request. RoxWhy does not save the source image in its database, filesystem or object storage. The free structured result is held in the browser session. If the user chooses the paid report, RoxWhy temporarily retains the identity-free structured analysis, the short user answers, technical audit metadata, generated report content and delivery records while it prepares and retries delivery. The higher-reasoning paid call uses that identity-free analysis; the source image is not uploaded again. The PDF is rendered for email delivery and is not added to a RoxWhy account, online report library or downloadable report store.

AI-generated explanations, summaries, predictions, and inferences can be inaccurate.

NAPLAN and pathway predictions are educational planning estimates, not official results, admissions advice, diagnoses, or guarantees. RoxWhy records the evidence basis, assumptions, uncertainty, confidence, and methodology status for each prediction or scenario. A footer disclaimer does not replace these limitations beside the relevant result.

Billing Providers

Stripe or another configured payment provider processes payment details for subscriptions and purchases. For an AI NAPLAN Insights order, Stripe also collects the email address used to deliver the report. RoxWhy stores the minimum provider references, delivery address while needed, and billing state required for report delivery, receipts, refunds, disputes, accounting, and support.

Email and Support Providers

RoxWhy may use Resend or another configured email provider to send account, support, and service emails, including an AI NAPLAN Insights PDF attachment. Support messages may be stored in RoxWhy's admin inbox.

Cookies

RoxWhy uses essential cookies for sign-in, sessions, security, and preferences. Analytics, diagnostics, or chat cookies are only used where configured. See the Cookie Policy.

Retention

We keep information for as long as needed to provide RoxWhy, maintain billing records, meet legal obligations, resolve disputes, prevent abuse, and improve reliability. Guest NAPLAN sessions expire after the configured guest period. After paid PDF delivery or expiry, educational inputs and generated report content are removed by the operational cleanup process once active work has cleared; they are not retained as an account report. Minimum payment, refund, dispute, and email-provider audit records may be retained where legally or operationally required. Any private temporary source objects created under an earlier storage design remain subject to background deletion and are not used for new extraction requests. Backup copies may remain until routine encrypted-backup rotation and are not used for ordinary product access. You may request access, correction, or deletion by contacting support, subject to legal, billing, security, dispute, or backup retention requirements.

Security

We use reasonable technical and organisational measures to protect information. No system is perfectly secure, and you are responsible for keeping your sign-in method safe.

Your Choices

You may request access, correction, deletion, or support with account data by emailing support@roxwhy.com.au. We may need to verify your identity before completing account-specific requests.

Contact

For privacy questions, account deletion, or data requests, contact support@roxwhy.com.au.