Privacy Policy
Last updated 7 September 2026
This policy describes how Wenara handles personal information, including health information. It is written to meet Australian Privacy Principle (APP) 1.4 under the Privacy Act 1988 (Cth). Health information is sensitive information. There is no small-business exemption for health service providers, so these rules apply from the first real patient record.
This policy is a public APP privacy policy. It is not a substitute for the notice we give you at collection (APP 5).
1. Who we are
Wenara is operated by Deerly Pty Ltd (Australia), trading as Wenara. Contact: privacy@wenara.health. Postal address will be published here when the registered office is confirmed.
Your psychologist is the health practitioner responsible for your care and for the clinical record of that care. In APP terms they determine what goes in that record. We provide the software and store and process that information on their instructions. For account data we collect ourselves (sign-up, billing later, support tickets, security logs), Wenara is the APP entity.
If you want a clinical note changed or deleted, ask your psychologist first. We do not alter a practitioner's clinical record on our own initiative.
2. Kinds of personal information we collect and hold
| Category | Examples | Whose |
|---|---|---|
| Account | Name, email, password hash, MFA factors, practice name, AHPRA / registration details | Practitioners; patients who create an app account |
| Health information | Session notes, transcripts, check-ins, questionnaire scores (for example PHQ-9, GAD-7, K10), safety plans, week plans, referral and MHCP details, GP letters | Patients, entered by them or by their practitioner |
| Messages | Optional practitioner–patient messages (off by default per practice); companion chat if enabled later | Patients and practitioners |
| Practice operations | Appointments, invoices, audit logs of who viewed, approved, signed, exported or deleted a record | Practitioners / practice |
| Pilot applications | Name, work email, practice name, and any note you send on the request form | Prospective practitioners |
| Technical | IP address, device/browser, log timestamps, crash reports if Sentry is enabled | Anyone using the site or apps |
We collect health information only with consent (yours, or your practitioner collecting it as part of care) and only to support that care and run the service.
3. How we collect it
- Directly from you: sign-up, check-ins, safety plans, messages, support email.
- From your treating practitioner: notes, appointments, referral and Medicare/MHCP details, letters they draft in Wenara.
- Automatically: security and diagnostic logs when you use the product.
- We do not buy marketing lists. We do not scrape public profiles to build records.
4. Why we collect, hold, use and disclose it
Primary purposes:
- Provide the clinical workspace and patient app you asked for.
- Generate AI drafts (notes, letters, week plans, briefs) for a registered practitioner to review. A draft is not a record until a human approves it.
- Surface safety concerns to the treating practitioner (see section 8).
- Authenticate users, send transactional email, keep the service secure, and give support.
- During pilot: decide whether to offer a seat, and contact you about that request.
We do not sell personal information. We do not share it with advertisers. We do not use health information to train foundation models (ours or a vendor's). We do not grant a perpetual licence to use identifiable clinical content for marketing.
5. What your psychologist can see
Structured check-in fields (for example mood, sleep, energy, tags, scores) are clinical signal. Your psychologist sees them so they can prepare for the next session.
Free-text reflections can be marked private per check-in. If you mark a reflection private, we do not show that text to them, except where the check-in indicates a risk of harm to you or someone else. In that case we show enough for a human to respond, and we tell you that this exception exists rather than hiding it.
6. Who we disclose it to (subprocessors)
We use a small set of processors, each contracted to use the information only to provide their service to us.
| Provider | Role | Where |
|---|---|---|
| Supabase | Database, file storage, authentication | Australia (Sydney) |
| Vercel | Application hosting | Australia (Sydney) region for this product |
| Anthropic | AI drafting and summarising. Direct identifiers are stripped before send; we request zero data retention. | United States |
| Deepgram | Speech-to-text when a session is recorded with consent | United States |
| Resend | Transactional email (invites, confirmation, reminders) | United States |
We may also disclose information if the law requires it, or to lessen or prevent a serious threat to life, health or safety.
7. Overseas disclosure (APP 8)
Some processing happens outside Australia: Anthropic, Deepgram and Resend in the United States. United States law can compel a US provider to produce data they hold.
Before text is sent for AI processing we run an automated strip of direct identifiers (names, contact details, dates of birth, Medicare numbers, addresses). That reduces, and does not eliminate, the chance that identifying detail remains in free text.
By creating an account or using the patient app you consent to this overseas disclosure for those purposes. Practitioners must obtain informed consent from patients before recording sessions or inviting them onto the app, including telling them that AI processing may occur overseas.
8. Safety escalation. Wenara is not an emergency service
We are not monitored in real time. If you are in immediate danger, call 000. Lifeline is 24/7 on 13 11 14.
Where the product matches fixed safety phrases (not an AI risk score), it shows crisis support to you — including one-tap emergency and Lifeline contacts — and raises an alert for your psychologist. That clinician review is parallel clinical follow-up in their working hours, not instant emergency dispatch. Wenara does not call Triple Zero for you.
If you use SOS and have nominated trusted contacts, an SMS may be sent to those people only after you confirm send. Phrase matches alone do not automatically message your family or friends. Your safety-plan contacts remain under your control to call or message yourself.
9. Security (APP 11)
- Encryption in transit (TLS) and at rest.
- Row-level access controls so a practitioner reaches only their own patients' records.
- Append-only audit log for clinical view, approve, sign, export and delete actions.
- Human approval before an AI draft becomes part of a record.
- MFA is available and recommended for practitioner accounts.
No system is perfectly secure. We take reasonable steps to protect personal information against misuse, interference, loss, and unauthorised access, modification or disclosure.
10. How long we keep it
Clinical records must be retained under Australian health-records rules. As a working minimum we retain adult clinical records for seven years from the last entry, and records relating to a person who was under 18 until they turn 25, unless a longer state or territory period applies to that practitioner. Your psychologist is the record-keeper; we retain the hosted record so they can meet that duty.
Account profile data that is not part of the clinical record is deleted when you delete the account, subject to backups rotating out and any legal hold.
Pilot request emails are kept only as long as needed to decide the request and follow up, then deleted or minimised.
11. Access, correction and deletion (APP 12 and 13)
Access. Patients can download what they entered in the app (Profile → Download my data, when that control is available). For the clinical record the practitioner holds, ask them. Practitioners can export records from the product; if a control is missing during pilot, email privacy@wenara.health.
Correction. Tell your psychologist if a clinical fact is wrong. Ask us to correct account details we hold.
Deletion. Patients may delete the app account. That removes app-held check-ins, reflections, safety plan and profile, and unlinks the app user from the practitioner. It does not delete the practitioner's clinical record, which they must keep for the retention period above.
12. Complaints
Email privacy@wenara.health. We will acknowledge the complaint and aim to respond within 30 days.
If you are not satisfied, you can complain to the Office of the Australian Information Commissioner: oaic.gov.au, 1300 363 992.
13. Notifiable Data Breaches
If a data breach is likely to result in serious harm, we will assess it under the Notifiable Data Breaches scheme and, where that scheme applies, notify affected individuals and the OAIC.
14. Cookies and analytics
Essential cookies keep you signed in and remember that you completed onboarding. We do not run advertising cookies. If we add product analytics later, this section will name the tool and whether it is first-party only.
15. Automated processing
AI is used to draft notes, letters, week plans and pre-session briefs. Safety language is flagged by fixed phrase match, not by an AI suicide-risk score. Neither diagnoses, prescribes, nor makes a decision that has legal or similarly significant effect without a human. From 10 December 2026, APP entities must say more in this policy about automated decisions that significantly affect individuals. We will update this section if our processing meets that test. Today it does not: a clinician must approve clinical output before it is a record.
16. Children
The patient app is not directed at children under 13. Pilot onboarding assumes adult patients, or adolescents only under a clinician-managed pathway with appropriate consent. We do not knowingly collect personal information from children under 13 online.
17. People outside Australia
Wenara is built for Australian psychologists and their patients. We do not currently offer the product as a US HIPAA covered-entity service or as an EU controller at scale.
If you are in the EEA or UK, additional GDPR / UK GDPR rights may apply (access, rectification, erasure, restriction, portability, objection). Clinical erasure can be limited where retention law requires the practitioner to keep the record. Email privacy@wenara.health.
California: we do not sell personal information and do not share it for cross-context behavioural advertising. Email with the subject "California privacy request" to exercise know / delete / correct rights.
18. Changes
We will change the date at the top when this policy changes. If a change materially affects how health information is handled, we will tell account holders in the product or by email, not only by editing this page.