Privacy Policy
Last updated: June 29, 2026
This Privacy Policy explains how Petrus Labs Pty. Ltd., which operates BEHAVIQ, collects, uses, shares, and protects personal information when you use our website and services. It is written against the product as it works today.
Summary
- We collect account data, security/session data, usage data, and billing data.
- We process the prompts, files, and audio you send to run the Service and return responses.
- We use third-party providers for infrastructure, AI, payments, email, login, monitoring, and feedback forms.
- We do not sell your personal information.
- We do not use your prompts, uploads, or chat history to train our own general-purpose models.
Who we are
BEHAVIQ is operated by Petrus Labs Pty. Ltd.. If you have privacy questions, requests, or complaints, contact us at support@behaviq.io.
What we collect
Account and authentication information
- Email address, account ID, name, and basic profile information.
- Password hashes if you use password login. We do not store your plaintext password.
- Authentication and security records such as verification codes, 2FA data, API key metadata, SSO metadata, SCIM metadata, and session records.
- Provider identifiers and related metadata if you use social or enterprise sign-in.
Workspace and usage information
- Workspace settings, member roles, invitations, audit logs, and administrator actions.
- Usage records, model settings, billing events, and credit balances.
- User preferences and organisation instructions, such as response guidance, terminology, and safety policies.
Chat, files, and voice data
- Messages you send, files you upload, and the responses the Service generates.
- Chat metadata such as timestamps, identifiers, and message previews used to display conversation history.
- If you use voice features, audio and transcript data needed to provide speech-to-text or text-to-speech features.
Technical and security information
- IP address, user agent, device/browser details, timestamps, and request metadata.
- Error and performance data used to diagnose reliability or security issues. Browser session replay is disabled in the supplied production and sandbox configurations.
Billing and support information
- Subscription records, invoice data, Stripe customer and payment identifiers, and credit purchase records.
- Messages you send us for support, sales, feedback, or account administration.
Mobile and device information
- If you use a mobile or installed version of the Service, we may use device permissions such as microphone, file picker, downloads, and share features when you choose to use them.
- Some preferences, drafts, session data, and biometric lock settings may be stored locally on your device. Biometric checks are handled by your device where available; we do not receive your fingerprint or face data.
How we use personal information
- To provide the Service and keep it working.
- To authenticate users, administer workspaces, enforce permissions, and secure accounts.
- To process payments, invoices, subscriptions, and credits.
- To investigate abuse, bugs, outages, and security incidents.
- To comply with legal obligations and enforce our Terms.
- To improve reliability, safety, and product operations.
AI and model providers
We use third-party AI providers to run core product features. We do not use your prompts, uploads, or chat history to train our own general-purpose models. Prompts, uploaded files, retrieved knowledge base content, user preferences, organisation instructions, and safety guidance may be sent to those providers where needed to generate a response. Optional web search may send part of a request to a search provider through the AI provider so the feature can work. Other external integrations are disabled unless we explicitly enable them for a workspace.
Model providers may keep limited records for abuse monitoring, security, legal compliance, or service operation under their own enterprise terms and retention settings. Workspace retention controls in BEHAVIQ do not automatically erase every provider-side record.
If an external integration is enabled for your workspace, that integration may be operated by someone other than us and may have its own terms and privacy practices.
Workspace administrators and employer visibility
If you use BEHAVIQ through an organisation, workspace administrators can manage members, roles, invitations, billing, usage limits, API keys, SSO, SCIM, knowledge-base files, workspace settings, and audit logs. They can see usage and administrative records needed to run the workspace.
Ordinary workspace administrator tools are not designed to let an employer read every individual chat. We may access limited content or metadata where needed to provide support, investigate abuse or security issues, comply with law, fix technical problems, or handle a request from the organisation under a written agreement.
Who we share information with
We share personal information with service providers where needed to run the Service. This currently includes:
- Cloudflare for hosting, storage, and application infrastructure.
- OpenAI for AI features, including chat, retrieval, voice, file search, and optional web-connected features.
- Stripe for billing and payments.
- Resend for transactional email delivery.
- Google if you choose Google sign-in.
- Sentry for error and performance monitoring.
- Microsoft Forms for feedback forms.
- External integration providers only where we explicitly enable an integration for your workspace.
We may also disclose information where required by law, to protect rights or safety, or as part of a sale, merger, restructure, or similar transaction.
International transfers
We are based in Australia, but some of our providers operate internationally. Personal information is likely to be processed in Australia and the United States. Depending on the feature you use, it may also be processed in other countries where our infrastructure providers or an explicitly enabled workspace integration operates.
Cookies and similar technologies
We use cookies and similar technologies for session management, login state, security, and basic product preferences.
Retention
We keep personal information for as long as we reasonably need it to provide the Service, protect the platform, meet legal obligations, and resolve disputes.
- Saved conversations do not expire automatically by default.
- For eligible workspaces, administrators can leave conversation retention as indefinite, or choose 30, 90, 180, or 365 days.
- A finite conversation retention setting controls how long inactive conversations remain visible in the product before they become eligible for scheduled deletion from BEHAVIQ application storage, including the app's database records and stored message objects.
- Knowledge-base files stay available until an administrator removes them. Removing a file starts the applicable detach or purge process for the provider file objects used by that feature.
- Audit log views and exports are currently limited to a 365-day window.
- Billing, tax, and accounting records may be retained longer where the law requires it.
Deletion can take additional time to finish in background jobs, backups, logs, and provider systems. Some provider records, audit records, billing records, security records, support records, and legal records may also be kept where needed for security, fraud prevention, legal compliance, dispute handling, backups, or the integrity of the Service.
Enterprise and pilot workspaces
For enterprise or pilot workspaces, a separate written agreement may set stricter rules for participant notice, subprocessor information, support, retention, export, deletion, incident notification, and offboarding. Where that agreement applies, it controls over this public policy to the extent of any inconsistency.
Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, or obtain a copy of your personal information, and to object to or restrict some processing. To make a request, contact support@behaviq.io.
Privacy complaints
If you think we have mishandled your personal information, please email us at support@behaviq.io and describe the issue. We will review the complaint, investigate where appropriate, and respond in writing.
If you are not satisfied with our response, or we do not respond within a reasonable time, you can make a complaint to the Office of the Australian Information Commissioner (OAIC). Details are available at oaic.gov.au.
Data breaches
If we become aware of a data breach that must be notified under applicable law, we will assess it and notify affected people and regulators where required.
Security
We use administrative, technical, and organisational safeguards designed to protect personal information. No system is completely secure, so please use care when deciding what to upload or include in prompts.
Children
The Service is not directed to children under 13. If you believe a child has provided personal information to us, contact us and we will review the issue.
Changes to this policy
We may update this Privacy Policy from time to time. If we do, we will post the updated version here and change the "Last updated" date.
Contact
Questions about privacy? Email support@behaviq.io.