PRIVACY POLICY
Qyrotec Pty Ltd
Version: V1.0 Effective date: 27 August 2026 Last updated: 27 August 2026
Introduction
Qyrotec Pty Ltd ACN 696 749 505 (Qyrotec, we, us or our) respects your privacy. This Privacy Policy explains how we collect, hold, use and disclose your Personal Information in connection with the Pantha software product and our related services (the Service) and our website at www.qyrotec.com (the Website).
This Privacy Policy is governed by the Privacy Act 1988 (Cth) (the Privacy Act) and the Australian Privacy Principles set out in the Privacy Act (the APPs). In this Privacy Policy, Personal Information has the meaning given to it in the Privacy Act.
This Privacy Policy should be read together with our Pantha Terms of Use and EULA (the Terms) and our Cookie Policy. In this Privacy Policy, unless the context requires otherwise, the terms Your Content, Outputs, Organisation and Organisation Customer have the meanings given to them in the Terms, and references to "content" and "outputs" in lowercase have the same meanings as Your Content and Outputs, respectively. Terms defined in this Privacy Policy (including Personal Information, Service and Website) have the meanings given here.
By accepting this Privacy Policy (including when you accept it on installation or when you create an account) and by using the Service or the Website, you acknowledge that you have read this Privacy Policy and, to the extent your consent is required under the Privacy Act, you consent to the collection, holding, use and disclosure of your Personal Information in the manner described in this Privacy Policy, including the overseas disclosures described in clause 9. If we later wish to handle your Personal Information for a purpose that is not described in this Privacy Policy and for which your consent is required, we will seek your consent at that time.
Privacy at a Glance
This section provides a brief overview of how Pantha handles your information. It is not a substitute for the full Privacy Policy below, which governs if there is any inconsistency.
- Who we are and what we collect. Qyrotec is the maker of Pantha, a desktop AI agent. We mainly collect your email address and optional profile information, an identifier linking your Organisation to our payment provider, your communications with us, and information generated through your use of the Service.
- Where your information goes. Pantha executes tasks and code locally on your device, but your prompts, content and related information may be transmitted to the AI models and tools you select and stored in our cloud. See clauses 2 and 8.
- Our core commitments. We do not sell your Personal Information, use your content to train our own AI models, or use your content or Personal Information for behavioural advertising. Our Privacy Commitments are set out in clause 1.
- Storage, deletion and your rights. Your chat history and content are stored in our cloud so that you can access them across sessions and devices. You may ask us to access, correct or delete your information, subject to the requirements described in clauses 11 and 12. Certain restricted operational records may be retained for up to seven years for security, regulatory, dispute and legal-claim purposes, as explained in clause 11.
- Contact us. You can contact our Privacy Officer at support@qyrotec.com. Further contact information is provided in clause 15.
1. Our Privacy Commitments
We aim to be respectful and transparent about how we handle your information. We make the following commitments, which are given contractually in clauses 8.6 to 8.8 of the Terms. Those Terms are the binding source of these commitments. This clause restates them in plain English, and the two should be read consistently.
- No training on your content. We do not use Your Content or the Outputs generated for you to train, fine-tune or otherwise develop or improve our own machine-learning models or artificial intelligence algorithms.
- No sale of your data. We do not sell your Personal Information or your content.
- No behavioural advertising. We do not use your content or your Personal Information for marketing, behavioural targeting or advertising personalisation. This does not prevent us from sending you our own communications about our products, services and updates, which you can opt out of at any time using the unsubscribe mechanism in those communications.
- No third-party analytics on your content. We do not transmit your content to third-party analytics platforms, other than standard web analytics used on our public-facing Website pages.
- Telemetry. Where we collect telemetry (such as crash diagnostics, performance metrics, error rates, security indicators and information about how features are used), we use it to keep the Service reliable and secure, prevent fraud and abuse, diagnose errors, measure performance and improve the product. Telemetry is based on your use of the Service and is not designed to collect the content of your prompts (although limited content associated with an error may be included in crash or diagnostic records, as described in clause 3.2(e)), may use a persistent identifier to associate related events for these purposes, and does not include advertising identifiers, session replay or screen capture. We do not use it for behavioural advertising or to track you across other websites or services.
- Cloud storage and deletion on request. We store your content (including chat history) in our cloud so that you can access it across sessions and devices, and on a verified request we will delete it from our active systems within 30 days, except to the extent we are required or entitled to retain it, as described in clause 11.
2. Where Your Data Goes (Data Flows)
Pantha has an unusually rich data path, so this clause explains, in plain terms, where your data can go. The detail of what is transmitted to third-party AI model providers is set out in clause 8.4 of the Terms.
- On your device (local execution). Pantha is installed and runs on your computer, and code and tasks are executed locally on your device. However, most of the information you use with the Service (such as your prompts, attachments, tool results and chat history) is transmitted to the third-party AI models and tools you select, and/or to our cloud, as described in the rest of this clause. Our differentiator is responsible handling of the information that passes through our systems, not a claim that most of your data remains only on your device.
- To third-party AI model providers you select. To generate outputs, the Service transmits data and content from your active chat to the AI model provider you choose. Depending on the provider and the relevant feature, the provider may handle that information on our behalf under its applicable terms, or independently under its own privacy policy and terms (see clause 8).
- To third-party tools and integrations you enable. When you enable tools or integrations (for example, web search or voice transcription), relevant data is sent to those providers so they can perform the action you requested.
- To our cloud. Your account information, chat history, prompts, outputs, tool results and any telemetry we collect are stored on cloud infrastructure operated by us or our hosting and service providers.
- Overseas. Some of these recipients are located outside Australia. See clause 9 (Overseas Disclosure).
3. Information We Collect
3.1 Personal Information You Provide
We collect the following Personal Information that you provide to us:
(a) Account information: your email address, and any profile information you choose to provide. Your password is handled by our authentication provider and is stored only as a salted cryptographic hash;
(b) Payment information: when you create an account or an Organisation, we create a customer identifier with our payment services provider (Stripe) that links your Organisation to that provider. Payment card details, billing address and payment processing are handled by our payment services provider; we do not collect or store full payment card details on our own servers;
(c) Communications: the contents of any communications you send to us through the contact forms or email addresses published on our Website, including support requests, feedback and survey responses;
(d) Identity verification: as part of sign-up, we verify that you control your email address (for example, using a one-time code). We may introduce additional verification (such as SMS codes or other multi-factor authentication) in the future. We do not collect government identity documents such as driver licences or passports;
(e) Organisation and invited-member information: where you create or join an Organisation, the Organisation name and the email addresses (and any role or label) of members you invite. If you invite another person, you confirm you are entitled to provide their details to us for this purpose; and
(f) Other information: any other information you choose to provide, and information we may collect through new features as the Service evolves, in which case we will update this Privacy Policy where appropriate.
3.2 Information Generated through Your Use of the Service
When you use the Service, we may collect:
(a) Usage data: information about your interactions with the Service, including features used, tokens or units consumed, error logs, performance metrics, device information and configuration choices;
(b) Prompts and content: the prompts, instructions, files, attachments and other content you provide to the Service (the prompts may be processed locally on your device, transmitted to third-party AI model providers selected by you, or processed on our servers, depending on the feature being used);
(c) Outputs: the responses, tool calls, code execution results and other outputs generated by the Service in response to your prompts;
(d) Technical information: IP address, device type, operating system, application version, language preference, and similar technical information; and
(e) Crash and diagnostic data: if the Service crashes or encounters an error, we may collect diagnostic data, which may include partial logs or content involved in the error.
3.3 Voice and Audio Data
If you use the voice transcription feature, audio captured from your microphone is transmitted to a third-party transcription provider selected by us. Only the resulting transcript (not the raw audio) is retained by us as part of the content you provide to the Service. This is also described in the Terms.
3.4 Information from Cookies and Similar Technologies
(a) Our Website. We do not set any first-party cookies on the Website, and we do not use advertising or cross-site tracking technologies. The Website uses a cookie-less performance and analytics script (Vercel Speed Insights) that measures Website performance (such as page-load metrics, route, and general browser, device and country information) without setting cookies or persistent identifiers and without cross-site tracking, and may include embedded third-party content (such as YouTube videos), where the third party may receive technical information and may set or access its own cookies when the embedded content loads or when you interact with it. Our Website's theming framework may store a light or dark theme preference in your browser's local storage; this is not a cookie and is not used for tracking.
(b) Our Service (the Pantha desktop application). The Service is a desktop application and does not use cookies to track you, and does not use advertising or cross-site tracking technologies. When you sign in, the AWS Cognito hosted sign-in screen (the only third-party web page shown within the Service) sets authentication and security cookies on the AWS Cognito domain (not on our own domain), which are set and managed by AWS. Payments are completed by opening our payment services provider (Stripe) in your device's default external browser, so no Stripe cookies are set within the Service. The Service also stores certain data locally on your device in application files (rather than cookies), including an encrypted sign-in token, your settings and preferences (including your theme), and operational data used by the local sandbox. This on-device data is not used for advertising or tracking.
(c) The term "cookies" is used broadly in our Cookie Policy to include related technologies such as local storage, session storage, web beacons, pixels, scripts and software development kit (SDK) tools. For more information, including how to manage these technologies, please refer to our Cookie Policy.
3.5 Sensitive Information and Unsolicited Personal Information
The Service is not designed or intended for use cases involving the submission or processing of sensitive information (as defined in the Privacy Act). We do not ask you to provide that information, and you must not knowingly include it in any prompt, file or other content you submit to the Service.
When you submit content to the Service, you request and instruct us to process that content as necessary to perform your request. This processing may include transmitting the content to the third-party AI model providers and tools you select and storing it in our cloud so that we can provide the Service and maintain your chat history, as described in this Privacy Policy.
We do not routinely inspect, monitor or classify your content for the purpose of determining whether it contains sensitive information. If such information is nevertheless included in your content, it may therefore be processed automatically as part of your request without being identified or classified by us as sensitive information. This does not mean that we have reviewed or approved the information or that the Service supports its intentional processing.
The prohibition in this clause applies whether the information relates to you or another person. In particular, you must not knowingly submit sensitive information about another person. Your submission of information about another person does not constitute consent by that person or, by itself, establish that you are authorised to provide it.
If we become aware that content contains sensitive information, we may restrict, remove or delete that content where reasonably necessary for privacy, security or legal compliance.
Where we receive unsolicited Personal Information (including sensitive information), we will assess whether we could have collected it under the Privacy Act. If we could not have collected it, we will, where lawful and reasonable, destroy or irreversibly de-identify it as soon as practicable. Because we do not routinely inspect or classify content submitted through the Service, we may not identify unsolicited Personal Information at the time it is received. The obligations in this paragraph are subject to any circumstance in which destruction or de-identification would be unlawful or unreasonable, including where the information is subject to an applicable legal hold. Any retention under clause 11 remains subject to the Privacy Act.
3.6 What We Do Not Collect
Consistent with our privacy-respecting approach, we do not require or collect, as mandatory account fields, your full legal name, your telephone number, or your residential or physical address (any billing address is handled by our payment services provider and is not stored on our own servers). We do not collect government identity documents. We do not seek to collect sensitive information (see clause 3.5). Some information, such as your theme preference, is stored only locally on your device and is not collected by us.
4. Organisations and Multi-User Accounts
(a) When you create an account, we create an Organisation for you and make you its owner. Your Organisation is the account workspace to which your Plan, Credits, billing and data are attached.
(b) An owner may invite other people to join the Organisation as members. When you invite a member, we collect that person's email address and any role or label you assign to them.
(c) Activity and usage by members is attributed to the Organisation. The Organisation's owner and administrators may be able to view members' activity and usage within the Organisation, and may access, use, manage and delete content within it.
(d) As between the members and the Organisation, content created, submitted or generated within an Organisation is owned and controlled by the individual or legal entity that owns or controls the Organisation account (the Organisation Customer), as set out in the Terms. If you use the Service as a member of an Organisation (for example, as an employee), the Organisation Customer determines how that content is handled, and you should direct any privacy request relating to that content to the Organisation Customer in the first instance. This does not limit Qyrotec's obligations in relation to Personal Information that Qyrotec collects, holds, uses or discloses in its own capacity (including for authentication, billing, security, telemetry and direct communications with you).
(e) If you wish to process your own Personal Information separately from an Organisation controlled by another person or entity, you should use a separate Organisation account that you own and control as the Organisation Customer and that is not administered or paid for by another person or entity.
5. How We Collect Your Information
We collect Personal Information directly from you when you:
(a) register for an account or subscribe to the Service;
(b) install, configure or use the Service;
(c) visit or interact with the Website; or
(d) contact us (whether by email, web form or otherwise).
We may also collect Personal Information from third parties (such as identity verification or payment service providers), and from publicly available sources, where it is reasonably necessary for one or more of our functions or activities, or otherwise permitted by law.
Anonymity and pseudonymity. You may generally browse the public Website without creating an account or actively providing identifying account information, although technical information may be collected automatically as described in this Privacy Policy. It is not practicable to provide the Service anonymously or under a pseudonym because we require information such as an email address for account administration, security and billing.
6. Why We Collect, Hold, Use and Disclose Your Information
We collect, hold, use and disclose your Personal Information for the following purposes:
(a) Providing the Service: to set up your account, provide the Service, process your prompts, generate outputs, allow you to access third-party AI models, and otherwise deliver the features you have signed up for;
(b) Billing and payments: to charge you for Plans and purchases of Credits, meter and record Credit consumption, process payments, and manage refunds and billing disputes;
(c) Communications: to communicate with you about your account, the Service, security and privacy notices and technical updates, and, with your consent or where otherwise permitted by applicable law, to send you marketing communications about our products and services;
(d) Support: to provide support for the Service and respond to your enquiries;
(e) Improving the Service: to monitor and analyse use of the Service and the Website, identify defects and improvements, and develop new features. For routine product improvement, we generally rely on aggregated or de-identified information, feedback that you submit, and any telemetry we collect. We do not use Your Content or Outputs to train our own AI models (see clause 1). Limited access to content may still occur where reasonably necessary for support you request, diagnosing a technical problem, security or abuse investigation, legal compliance, or disputes and claims, as described in clause 10;
(f) Safety, security and compliance: to protect the security of the Service and Website, to detect and prevent fraud and abuse, to enforce our terms of service, to comply with our legal obligations, to investigate complaints or potential breaches of law, and to establish, exercise or defend legal claims; and
(g) As otherwise permitted by law: for any other purpose disclosed to you at the time of collection or otherwise permitted under the Privacy Act.
If you do not provide Personal Information that we need to provide the Service (for example, an email address to create an account), we may be unable to provide the Service or otherwise deal with you.
7. Disclosure of Your Information
We may disclose your Personal Information to:
(a) Service providers: our trusted service providers, including cloud hosting providers, infrastructure providers, payment processors, analytics providers, communications and email providers, authentication providers, customer support tools, fraud detection and security providers, and other third parties who assist us in providing the Service and Website (we take reasonable steps to ensure those providers handle your Personal Information appropriately and consistently with applicable laws);
(b) Third-party AI model providers and tools: as described in clause 8;
(c) Professional advisers: our lawyers, accountants, auditors and other professional advisers;
(d) Regulators and authorities: government, law enforcement and regulatory authorities where required by law, court order, or for the protection of our rights or the rights of others;
(e) Corporate transactions: in connection with a sale, merger, acquisition, restructure, reorganisation or financing of our business, in which case your Personal Information may be transferred to the relevant party (subject to appropriate protections); and
(f) With your consent: to any other party where you have given us your consent.
8. Third-Party AI Model Providers and Tools
The Service relies on third-party AI models, APIs and tools that you select. When you use those models, APIs or tools through the Service, the Service may transmit some or all of your prompts and other content to the third-party provider. As described in clause 8.4 of the Terms, the data transmitted associated with an active chat may include, as applicable, system prompts and basic device information, your messages, prior assistant responses, tool results, tool definitions, an account or security identifier, and automated housekeeping data. You should assume that any of your content within an active chat may be transmitted to the provider you select.
We do not intentionally include your email address, your payment information or your precise location in the prompt payload sent to a third-party AI model provider. Network-level metadata (such as IP addresses) may still be processed by providers as part of receiving and responding to requests, which is outside our control.
Pantha acts as a conduit and toolset for the models and tools you select. When you select a third-party AI model provider or tool, your content is transmitted to that provider at your direction and is handled under its own privacy policy and terms, which we do not control. Other providers we engage to operate the Service (such as our hosting, authentication, payment and transcription providers) handle information on our behalf under their applicable terms (which may include data-processing terms), and we take reasonable steps to ensure they handle your information appropriately.
A third-party provider acting independently under its own privacy policy and terms does not, by itself, remove Qyrotec's obligations under the Privacy Act (including APP 8) where those obligations apply.
We recommend that you review the privacy policy and terms of each third-party provider before using that provider through the Service.
If you activate the voice transcription feature, audio captured from your microphone will be transmitted to a third-party transcription provider selected by us, and only the resulting transcript (not the raw audio) will be retained by us as part of your content.
Use of third-party tools, APIs, websites or integrations is also subject to the terms of those third-party providers.
9. Overseas Disclosure
Some of our service providers and third-party AI model providers are located outside Australia. The countries in which they are likely to be located include the United States, the United Kingdom, member countries of the European Union, and Canada. The actual location may depend on the particular provider you select, the feature you use, and that provider's infrastructure and processing arrangements from time to time.
Because the Service depends on overseas providers (including the third-party AI model providers and tools that you select), we rely on your consent to disclose your Personal Information to recipients located overseas, and you give that consent by accepting this Privacy Policy. You acknowledge and agree that, if you consent to these overseas disclosures, Australian Privacy Principle 8.1 will not apply to them, and that we will not be accountable under the Privacy Act (and you will not be able to seek redress under the Privacy Act against us) for any act or practice of an overseas recipient that would otherwise breach the Australian Privacy Principles. Overseas recipients may handle your Personal Information in accordance with their own privacy policies and terms and the laws of the countries in which they operate, which may differ from Australian law.
Although we rely on your consent for these overseas disclosures, we will still take reasonable practical steps to select reputable providers and, where a provider handles Personal Information on our behalf, to check that the provider's applicable terms (which may include data-protection terms) are appropriate. When you select and use a third-party AI model provider or tool through the Service, your content is disclosed to that provider at your direction and is handled in accordance with that provider's own privacy policy and terms, which we do not control. We recommend that you review those policies and terms before selecting a provider.
10. Data Security
We take reasonable steps to protect your Personal Information from misuse, interference, loss, and unauthorised access, modification or disclosure. Those steps include encryption of data in transit, encryption at rest for customer data stored on our servers, access controls, multi-factor authentication for administrative access, monitoring, and regular security reviews.
Your content may be accessed by authorised personnel only where reasonably necessary to provide support requested by you, investigate security or abuse, diagnose a technical problem, comply with law, resolve a dispute, or establish, exercise or defend legal claims.
Despite these measures, no method of transmission over the internet or method of electronic storage is completely secure, and we cannot guarantee absolute security.
If we become aware of an eligible data breach affecting your Personal Information, we will comply with our obligations under the Notifiable Data Breaches scheme in the Privacy Act.
11. Data Retention
We retain your Personal Information for as long as is necessary to provide the Service to you, comply with our legal obligations, resolve disputes, enforce our agreements, protect the security of the Service, and establish, exercise or defend legal claims.
11.1 Operational lifecycle
(a) Active customer. While your account is active (including where you cancel a paid Plan and drop to a free Plan or remain able to sign in), we retain account information and content so that we can provide the Service.
(b) Dormancy. After 24 consecutive months without a sign-in or other use of the Service, we may attempt to notify you, and may deactivate the account if it remains inactive.
(c) Account closure or deactivation. After account closure or deactivation, we generally retain residual account and content data for a tail of up to 90 days, and then delete or de-identify it except to the extent we are required or entitled to retain it under this clause 11.
(d) Billing, financial and tax records. We retain billing, payment and tax records for approximately 7 years from the date of the relevant transaction or other date required by applicable accounting or tax rules (or longer if required by law).
11.2 Operational defence record
Because Pantha is an agentic product that can act on a user's instructions, a claim or investigation relating to the Service may arise long after the underlying events. An adequate defence may require reconstructing what a user instructed, configured and approved, and what the agent did.
For that reason, we may retain an operational defence record for up to seven years from the date each relevant record is created. That record may include prompts and instructions, configuration and access-control settings, approvals, tool calls, actions, results and Outputs. It is retained only for security and safety investigations, dispute and regulatory response, and establishing, exercising or defending legal claims. Access to, and use of, that archive is restricted to those purposes. It is not used for product improvement or general business analytics.
If we are subject to an actual or reasonably anticipated legal claim, investigation, regulatory enquiry or similar proceeding, we may retain relevant information under a legal hold beyond the ordinary periods in this clause until the matter is finally resolved and any further lawful retention period ends.
11.3 Deletion and de-identification
(a) On a verified deletion request, we will delete or de-identify Personal Information from our active systems within 30 days, except to the extent we are required or entitled to retain it under this Privacy Policy or applicable law. A verified deletion request that removes information from our active systems does not necessarily erase restricted operational defence-archive copies retained under clause 11.2, which may remain for the periods described in that clause. Routine backups are isolated from active use, and residual copies in those backups are overwritten in the ordinary course of our backup rotation cycle.
(b) Where a third party handles your information on our behalf, we will take reasonable steps available to us under applicable law and the provider's applicable terms to request that the provider delete or return Personal Information held on our behalf. Where your content has been transmitted at your direction to a provider acting independently under its own terms, we may not be able to delete that content from the provider's systems, and its retention and deletion are governed by that provider's privacy policy and terms.
(c) When Personal Information is no longer needed for any purpose for which it may be used or disclosed under the APPs, and we are not otherwise required or entitled to retain it, we will take reasonable steps to destroy it or irreversibly de-identify it. Genuinely de-identified information may be retained indefinitely.
12. Your Rights
12.1 Access
Subject to the exceptions in the Privacy Act, you have a right to access Personal Information that we hold about you. To request access, please contact us using the details in clause 15. We may need to verify your identity before providing access, and we may charge a reasonable fee for access in some circumstances (but not for making a request).
12.2 Correction
You have a right to request that we correct Personal Information that we hold about you if it is inaccurate, out-of-date, incomplete, irrelevant or misleading. You may also update certain information directly through your account settings in the Service. If we refuse a correction request, we will tell you why and, if you ask us to, take reasonable steps to associate a statement with the information that you have requested the correction.
12.3 Deletion
You may request that we delete your Personal Information at any time. We will delete or de-identify your Personal Information as described in clause 11.3, except to the extent that we are required or entitled to retain it.
12.4 Marketing
You may opt out of receiving marketing communications from us at any time by following the unsubscribe link in any marketing email or by contacting us using the details in clause 15. Even if you opt out of marketing communications, we may continue to send you non-marketing communications relating to your account and use of the Service (for example, security notices, billing messages and service updates).
12.5 Complaints
If you have any concern or complaint about how we have handled your Personal Information, please contact our Privacy Officer using the details in clause 15. We will:
(a) acknowledge your complaint;
(b) investigate it and, where needed, request further information from you;
(c) provide an outcome within 30 days where practicable, or explain any delay and give you an updated timeframe; and
(d) if you are not satisfied with our response, remind you that you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at https://www.oaic.gov.au.
13. Children
The Service is not directed to individuals under the age of 18. We do not knowingly collect Personal Information from children. If you become aware that a child has provided us with Personal Information, please contact us so that we can take appropriate steps to delete the information. The Terms require users to be at least 18 years old.
14. Changes to this Privacy Policy
We may amend this Privacy Policy from time to time. We will give you reasonable notice of any material change, including by posting the updated Privacy Policy on the Website and updating the "Effective date" and "Last updated" details. The updated Privacy Policy applies from its effective date. Where a change introduces a new handling of your Personal Information for which your consent is required, we will obtain that consent before that handling begins, for example by asking you to accept the updated Privacy Policy.
15. Contact Us
If you have any questions, concerns or requests in relation to this Privacy Policy, or if you wish to make a privacy complaint, please contact our Privacy Officer at:
Privacy Officer - Qyrotec Pty Ltd
Email: support@qyrotec.com