Privacy

What we collect, where it is held, and what you can ask for.

This policy covers AssetDNA: the vault, the property record, and this site. It is written from what the software does. It follows the Australian Privacy Principles in the Privacy Act 1988, and the UK GDPR where we serve a client in the United Kingdom. If a sentence here and the software ever disagree, the sentence is the error: tell us.

Last updated 29 September 2026

Who we are

AssetDNA is operated by Stratagem Tools Pty Ltd, trading as AssetDNA. Questions about this policy, and every request under it, go through the contact page with the topic “A privacy request”.

When a property business or a company puts other people's details into its own account, for example its residents' names, that business decides what is collected and why; we hold the information for it. Ask that business first about what it holds; we will help it answer. Everything else on this page is information we decide about.

What we collect, door by door

A vault account (/vault/start)

Your name, your email address, your password stored only as a scrypt hash, and a business vault's name. Your keys are made in your browser: we hold your public keys and their fingerprint, and your private keys only sealed under a key we never receive.

What you keep in a vault

Sealed on your device before it is uploaded. We hold the ciphertext, the size band it was padded to, and a commitment, a fingerprint that proves the exact bytes existed without revealing them. We never receive the contents, their titles, your passphrase, your Secret Key or your recovery kit.

What you choose to show from a vault

Held in plain text because you chose to show it to someone: a proof page's label, a gift's label, a note to a guardian, a beneficiary's display name, a note with an item you send, a name for a passkey, and, if you ask to be emailed a reminder, one date per item.

Guardians and beneficiaries

A person you name holds a vault identity of their own. We link their account, public key and fingerprint to your vault, and compose the notices the vault sends them.

A property account (/signup, and staff invitations)

Your organisation's name, your name, work email, password hash and role, and what you do in the account. Each entry in a building's record notes the email address of the staff account that made it.

Residents (/occupant/join)

Your name, email address and, if you give it, your mobile number, and what your building's operator records about the tenancy: the unit, dates, rent and bond. Your building's operator can see these. When you claim a tenancy, or your operator links you to one, your email address is written into that building's record.

Trial requests and messages (/property, /contact)

What you type: your name and email address, and your company, role, note or message.

Endorsements and channel partners

If you are invited to endorse a record or to act as a channel partner: your name, firm, role, email address and what you submit.

Crash reports

When a page fails in your browser it reports what broke and where: the page's path, the error and its stack, and your browser's description of itself. No account, organisation or session is attached.

Visits to a data room or shared record

The time, which kind of page was read, and your browser's description of itself, counted for the owner. Not who you are.

Limiting repeated attempts

Some doors count attempts per email address or per network (IP) address, to slow down password guessing and floods. A count is deleted within two days of its last use.

Why we use it

To run the account you opened and the service you asked for; to sign you in and keep the account secure; to answer your messages and requests; to send the notices the service needs, such as invitations, reminders, recovery and release notices, once email is switched on; to find and fix faults; and to meet our legal obligations.

We do not sell personal information, we do not use it for advertising, and this site runs no analytics, advertising or tracking script of any kind.

Where it is held

Production runs in the United States: Vercel functions in iad1 (Washington, D.C.) over a Neon Postgres database in us-east-1 (North Virginia). So what you give us is stored with those providers outside Australia, and, if you are in the United Kingdom, outside the UK. An Australian region is planned; this sentence will change when it has happened, not before.

We keep backup copies to recover from a failure: a daily copy on our own equipment, kept for two weeks and then one a week for eight weeks, and a copy of each in Apple's iCloud Drive, encrypted before it leaves our machine and kept by the same rule when we run the backup by hand, so an off-site copy can be older. Something deleted from the service stays in a backup until that copy is deleted.

Who else receives it

Each of these acts on our instructions; none receives your information for its own purposes.

  • Vercel, which hosts this site and runs its code, and keeps short-lived request logs.
  • Neon, which hosts the database.
  • Independent timestamp authorities and the Sigstore Rekor public transparency log, which receive hashes only: fingerprints of the record that reveal nothing about what is in it. The transparency log is public and permanent.
  • An email provider, when email is switched on, which receives each message's address, subject and text in order to deliver it. Email is not switched on today: messages the service composes are held for us to relay, and deleted after 30 days.
  • Anthropic, when the property analyst's language model is switched on, which receives the question a staff member types, to route it. No vault content reaches it.
  • A payment provider, when paid plans are switched on, for billing an organisation.

Inside the service, what you put in is seen by the people it is meant for: your organisation's administrators, a resident's building operator, and anyone you give a data room, a shared record, a gift link or a proof page. We disclose personal information to an authority only where the law requires it.

How long we keep it

  • A sign-in lasts at most 30 days, and ends when you sign out.
  • Crash reports: 30 days, then deleted.
  • Messages the service composes: 30 days, then deleted.
  • Counts of repeated attempts: within two days of last use.
  • Accounts, vaults and property records: while the account is open. Closing a vault deletes everything sealed in it at once; the record keeps that it was closed, with counts and no contents.
  • Trial requests and messages: until we delete them. Nothing deletes them automatically yet, so ask and we will.

One part cannot be edited. Each account's record is a chain: every entry carries the hash of the one before it, and the chain is timestamped by independent authorities. That is what lets anyone check that nothing was changed, and it is why an entry cannot be edited or deleted: changing one would break every entry after it, and the proof with them. So we keep people out of it where we can. Vault entries name a person by an internal id, never by email, and residents' names are kept outside it so that they stay erasable. Two kinds of entry do carry an email address: the staff account that made an entry in a building's record, and a resident's address when they are linked to a tenancy.

What you can ask for

You can ask for a copy of what we hold about you, for a correction, or for erasure. Erasure deletes or blanks what can change, such as your name, email address, phone number, notes and labels, and ends your sign-ins. Entries in the chained record stay; we tell you which ones hold anything about you, and why. Your vault and your property record can also be exported whole, in an open format, from inside the account.

If you are in the United Kingdom you can also ask us to restrict or stop using your information, and to receive it in a portable form. Make any request through the contact page. We may ask you to confirm it from the email address on the account, so that nobody else can make it for you. We answer within 30 days and do not charge for it.

If our answer does not resolve it, you can complain to the Office of the Australian Information Commissioner (oaic.gov.au) or, in the United Kingdom, the Information Commissioner's Office (ico.org.uk).

Cookies and your device

We set cookies only to keep you signed in: one for vault and property accounts, one for residents and one for channel partners, each unreadable by the page's scripts and gone when you sign out or after 30 days. While a staff member connects Xero, one more lasts ten minutes. There are no analytics, advertising or tracking cookies, which is why there is no cookie banner.

Your browser also keeps a few things that never reach us: your vault's Secret Key on a device you choose to remember (forget it from the vault's settings), your auto-lock preference, a gift you are keeping while you create a vault (in that tab only), and small preferences such as recent searches.

Keeping it safe

Passwords are stored only as scrypt hashes, every connection is encrypted, and vault contents are sealed on your device before they are uploaded. No system is perfectly secure. If a breach is likely to cause you serious harm, we will tell you and the regulator, as the law requires.

Changes

When this policy changes we publish the new version here and change the date at the top.