Alice Booking Diary

Privacy Policy

Effective date: 17 June 2026 · Last updated: 18 June 2026

This Privacy Policy is published at https://alicefamily.app/privacy and is free to read, always available, and does not require you to log in or pay. It is the same policy linked from our homepage, our Google sign-in / consent screen, the in-app Settings, and (when our mobile apps launch) the Apple App Store and Google Play store listings. This is the single, canonical Alice privacy policy; it is not a supplement to, and does not defer to, any separate FreshTech policy.

1. Who we are

Alice (also called "Alice Booking Diary") is an AI receptionist and booking assistant for trades and small businesses. Alice answers inbound phone calls with an AI voice, runs a website chat widget, qualifies enquiries, and books jobs into the business owner's diary.

Alice is provided by FreshTech-Community Pty Ltd — a proprietary company registered in Victoria, Australia — ACN 699 190 513. We operate the public-facing brands "FreshTech Community", "Alice", and "Alice Booking Diary". (FreshTech Community was previously operated by Tien Thanh Tran as a sole trader; the business was incorporated as FreshTech-Community Pty Ltd on 18 June 2026, which is now the provider and data controller. This is the change of controller anticipated in our earlier policy — your rights, and the way we handle your information, are unchanged.)

In this policy, "we", "us", "our", "FreshTech" and "FreshTech Community" mean FreshTech-Community Pty Ltd (ACN 699 190 513). "You" means the person reading this — most often a business owner who uses Alice, or a customer of one of those businesses whose details pass through Alice.

We handle personal information in line with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Where the law of another place applies to you (for example, the EU/UK GDPR or California's CCPA/CPRA), the relevant section below also applies.

Our two roles. Alice is used by business owners, and their customers' personal information flows through Alice:

Privacy contact

2. The personal information we collect

We only collect what Alice needs to do its job. Below is every category of personal information Alice handles — we do not collect data for undisclosed purposes.

A. Information about a business's customers (end-customers) — supplied by the owner or captured by Alice when it answers a call or chat:

B. Call audio recordings and call transcripts (a distinct, sensitive category we call out separately) — when a customer calls a business's Alice voice line, Alice may record the call audio and create a written transcript of the conversation. These recordings and transcripts can contain anything the caller says (name, contact details, address, the nature of the job, and any other personal information they choose to share). Because this is voice and conversation data, we treat it with particular care (see Sections 5 and 6).

C. Business owner account information:

D. Google Calendar data (only if you connect your Google Calendar):

E. Technical and usage information needed to run the app, keep it secure, prevent abuse, and debug errors (for example, log and device/connection information).

We do not store card numbers

Card and bank payments are processed by Stripe. When Alice creates or sends a payment request, the customer enters their card details directly with Stripe. FreshTech does not see, collect, or store full card numbers. Stripe handles card data under its own terms and security standards.

We also do not intentionally collect sensitive information beyond what is described above. Please don't volunteer health, biometric, or other sensitive information to Alice unless it's genuinely needed for the booking.

3. How we collect your information

We collect personal information in these ways, and this section also serves as our APP 5 collection notice (the things we must tell you at or before we collect your information):

What we must tell you at collection (APP 5): our identity and contact details are in Section 1; the purposes of collection are in Sections 4–6; the parties we usually disclose information to are in Sections 8–10; the fact that your information is likely to be disclosed to recipients overseas (and which countries) is in Section 9; and the main consequence if information is not provided is that Alice may not be able to take or complete a booking, answer the call properly, or run the relevant feature. This policy also explains how you can access and correct your information and how to complain (Sections 13–14).

4. How we use your information, and why

We use personal information only for the purposes described in this policy. We do not use it for undisclosed secondary purposes.

What we useWhy we use it (purpose)
Account + business profileTo create and secure your account, run the app, and support you.
Customer name, phone, email, address, job/booking detailsTo answer enquiries, qualify the job, prepare and (where you've enabled it) make bookings, contact the customer about their booking, and keep your booking history.
Call recordings + transcriptsTo handle the call, capture booking details accurately, let the owner review what was said, and improve reliability and quality (Section 6).
Google Calendar busy/free + eventsSo Alice doesn't double-book you, and to add/update the bookings Alice itself makes (Section 10).
Conversation + booking data sent to our AI "brain"So Alice can understand the caller/chatter and respond (see the AI note below).
SMS sending (Twilio)To send booking confirmations and, where the owner has set them up, permitted messages to customers.
Payment requests (Stripe)To create and send invoices/payment links at the owner's direction.
Technical/log dataTo keep the service secure, prevent abuse, and fix faults.

Our AI "brain" and third-party AI

Alice's voice and chat responses are generated by artificial intelligence. To do this, conversation content and relevant booking data are sent to OpenAI, whose large-language-model API (by default, the gpt-5 model) powers Alice's "brain". This is a core part of how Alice works.

We do not sell your personal information, and we do not use it for third-party advertising.

5. Limiting use and disclosure (APP 6)

We use and disclose end-customer personal information for the primary purpose we collected it (running the booking) and for closely related purposes you would reasonably expect — and not for unrelated purposes without a lawful basis or your consent. In particular:

6. Call recording and transcription

Alice records and transcribes inbound phone calls to a business's Alice voice line. This section explains how that works and your rights.

A spoken announcement at the start of the call. Alice speaks a disclosure at the start of every inbound call. When you call an Alice line you are speaking with an automated AI assistant, not a live human: Alice's spoken opening tells you that you are speaking with Alice, an AI assistant, and that the call is recorded for training and quality purposes. Because Alice answers callers anywhere in Australia, and because New South Wales, Western Australia, South Australia, Tasmania and the ACT require the consent of all parties to record a private conversation (one-party consent in VIC/QLD/NT is not enough for callers from those states), the recording is disclosed up front: if you continue with the call after the announcement, that establishes your consent to the recording. If you do not consent, you can hang up and contact the business another way. Recording is of a call answered by Alice — we do not intercept calls in transit, consistent with the Telecommunications (Interception and Access) Act 1979 (Cth).

Purpose. We use recordings and transcripts to handle and complete the call, capture booking details accurately, let the business owner review what was discussed, resolve disputes, and improve reliability and quality.

Who can access them. The relevant business owner (and their authorised staff) can access the recordings/transcripts for their own customers. Our service providers (telephony, speech-to-text, hosting, and the AI brain — see Section 8) process them only to deliver the feature. FreshTech staff access them only where necessary for support, security, legal compliance, or to fix faults.

Retention. Call audio recordings and transcripts are kept while the owner's account is active, and are deleted on account closure (within approximately 30 days of closure), except where we must keep specific records longer to comply with the law (see Section 12). Transcript retention is also controlled by the business owner in Alice's Settings, and an owner can request earlier deletion of specific customer records. See Section 12.

7. Automated decision-making and AI (transparency)

Alice is an automated system, so we explain here how it makes or contributes to decisions. (Australia's Privacy Act will require this kind of transparency from 10 December 2026 under the Privacy and Other Legislation Amendment Act 2024 / new APP 1.7–1.9. We include it now as a matter of good practice.)

Alice can make mistakes (for example, mishearing a name or time). The business owner remains responsible for reviewing and confirming bookings, availability, prices, and customer communications before relying on them (this responsibility is set out as an enforceable term in our Terms of Service). If a decision made or supported by Alice affects you and you want it reviewed by a person, you can ask for human review: contact the business, or contact us using the details in Section 1, and a person will review the decision.

8. Who we share your information with (our service providers / sub-processors)

To run Alice, we use trusted service providers ("sub-processors"). They process your data only to deliver the Alice features you see, under confidentiality obligations, and never for their own advertising. Using them to run the service is not a sale of your data.

ProviderWhat they do for Alice
CloudflareHosting, app delivery, serverless Workers, and our KV + D1 databases (where booking and account data are stored).
SupabaseAccount authentication (sign-in / login).
VapiVoice telephony — connecting and handling the AI phone calls.
ElevenLabsText-to-speech and speech-to-text (Alice's voice and call transcription).
DeepgramSpeech-to-text transcription for calls.
OpenAIPowers Alice's AI "brain" — generates Alice's voice and chat responses from conversation and booking data (by default the gpt-5 model). Does not train its models on data submitted via its API.
StripePayment processing (invoices and payment links). Stripe handles card data directly.
TwilioSending SMS (e.g. booking confirmations).
GoogleGoogle Calendar API (reading your busy/free times and writing Alice's own bookings) — only if you connect Google. See Section 10.

When our mobile apps launch, this list will be kept consistent with our Google Play Data safety form and our Apple App Privacy label. We will update this policy if our service providers change.

We may also disclose personal information where we are required or permitted by law, to protect our or others' rights and safety, to prevent fraud, or in connection with a sale or restructure of our business (and, for Google-derived data, only with your explicit consent as required by Google's policy).

9. Sending information overseas (cross-border disclosure)

Your personal information is likely to be disclosed to recipients located outside Australia. Several of our service providers store and process data overseas — predominantly in the United States (where, depending on the provider and its configuration, Cloudflare, Stripe, Twilio, Vapi, ElevenLabs, Deepgram, OpenAI, and Google may host or process data), and possibly other countries where those providers operate.

Before disclosing personal information overseas, we take reasonable steps to ensure the overseas recipient handles it consistently with the Australian Privacy Principles — for example, through data-processing terms with our providers that require appropriate protection. No data transfer can be guaranteed perfectly secure.

For individuals protected by the GDPR (EU/UK): where we transfer your personal data outside the EEA/UK, we rely on an appropriate safeguard such as the European Commission / UK Standard Contractual Clauses or an adequacy decision. You can request a copy or further detail using the contact in Section 1.

10. Google Calendar data and Google API "Limited Use"

This section applies only if you connect your Google Calendar to Alice.

Alice's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

What Google data we access:

Why (purpose): Alice reads your busy times so it never double-books you, and writes or updates only the bookings Alice itself makes on your behalf. Google Calendar data is used by Alice's booking code for availability — it is not fed into the AI/LLM brain.

The exact permission (scope) we request: https://www.googleapis.com/auth/calendar.events.

Why we need this scope and not a read-only one. Alice does two things with your calendar: (1) reads your busy/free times so it won't book over an existing commitment, and (2) writes the confirmed bookings Alice makes back into your calendar so your diary stays in one place. A read-only scope (such as calendar.events.readonly or freebusy) would let Alice see your busy times but not write the bookings it creates, which is core to the product — so the read-write calendar.events scope is the minimum scope Alice needs. Alice does not request broader Google scopes than the feature requires.

How we store it. Your Google busy/free times are cached transiently in Cloudflare KV with an approximately 60-minute time-to-live, after which the cache expires. Your access/refresh tokens are stored securely so Alice can keep your calendar in sync.

A clear notice before you connect. When you go to connect Google Calendar inside Alice ("Connect Google Calendar" / Cal-Sync), we show you what Alice will access (your calendar busy/free times) and why (so it won't double-book you), and we ask for this access in context at the point you connect — not bundled into sign-up — so you reach Google's consent screen already knowing what is being requested.

What we will never do with Google data. Consistent with Google's Limited Use requirements, we do not: use Google Calendar data for advertising or retargeting; sell, rent, or transfer it to third parties; use it to develop, train, fine-tune, or improve any AI or machine-learning model beyond serving your own account; or allow anyone to read it except where you've given consent, for security, to comply with law, or in limited aggregated/operational cases permitted by Google's policy. We transfer Google data only to provide the calendar feature to you (with your consent), to comply with law, for security, or as part of a merger with your explicit consent.

Disconnecting and deletion. You can disconnect Alice from Google at any time in your account settings, or by removing Alice at https://myaccount.google.com/permissions. On disconnect, Alice immediately deletes the stored Google access and refresh tokens, purges the cached busy/free data, and stops accessing your Google Calendar. All stored Google data is deleted on account closure (Section 12).

11. How we keep your information secure

We use reasonable technical and organisational measures appropriate to the product to protect personal information:

No internet service can be guaranteed perfectly secure. If a data breach occurs that is likely to cause serious harm, we will respond in line with the Notifiable Data Breaches scheme under the Privacy Act and notify affected individuals and the OAIC where required.

12. How long we keep your information, and deletion

We keep personal information only for as long as we need it for the purposes in this policy, then delete or de-identify it. As a single, consistent rule: call recordings, transcripts, and customer/booking data are kept while the owner's account is active and deleted on account closure (within approximately 30 days), except transaction and financial records, which we keep for approximately 7 years to comply with Australian tax-record law. An owner can request earlier deletion of specific customer records.

InformationHow long we keep it
Account + business profileWhile your account is active; deleted within ~30 days of account closure.
Booking details + booking historyWhile your account is active; deleted within ~30 days of account closure, except transaction/financial records kept ~7 years for Australian tax-record law.
Call audio recordings + transcriptsWhile your account is active; deleted within ~30 days of account closure (transcript retention is also owner-configurable in Settings; owner can request earlier deletion of specific records).
Google Calendar busy/free cacheTransient (≈60-minute expiry); purged immediately on disconnect, and on closure (Section 10).
Google access/refresh tokensUntil you disconnect Google or close your account (deleted immediately on disconnect).
Transaction / financial records (invoices, payment records)Approximately 7 years, to comply with Australian tax-record law.
Technical/log dataA limited period for security and debugging.

On account closure / deletion we delete the personal information associated with your account that we hold in our own systems (our Cloudflare KV and D1 storage), except a defined, limited set we may keep where we are required to by law (in particular transaction/financial records kept ~7 years for tax purposes), or to prevent fraud, or to resolve disputes or enforce our agreements — and only for as long as necessary. Any such retained data continues to be protected under this policy.

Data held by our voice/SMS providers. Some call recordings, transcripts and SMS records are also held by our service providers (for example Vapi, ElevenLabs, Deepgram and Twilio). These provider-held copies are deleted on each provider's own retention cycle.

13. Your privacy rights and how to use them

Subject to the role split in Section 1 (we are the processor of end-customer data on the owner's behalf), you have the following rights.

Access and correction. You can ask us for access to the personal information we hold about you, and to correct it if it's wrong. Owners can update much of their business profile directly in the app. To make a request, contact us at [email protected] (Section 1); we aim to respond within 30 days.

Deleting your account and data. You can delete your Alice account and the associated personal information we hold in any of these ways: (a) in the app, at Settings → Account → Delete business; (b) on our public web page at https://alicefamily.app/delete-account (no login required); or (c) by emailing [email protected]. For your security, in-app and web deletion are confirmed with a one-time code sent to your account email. On deletion we purge the personal data we hold in our own systems (Cloudflare KV and D1) and revoke any connected Google access, subject only to the limited legal/fraud/dispute retention described in Section 12 (and the provider-held-data position there). You can also delete or edit individual customer records inside the app.

Withdrawing consent and disconnecting services. You can withdraw consent to optional processing at any time — for example, by disconnecting Google Calendar (Section 10) or, once the Social feature ships, disconnecting Facebook/Instagram (Section 17). Withdrawing consent doesn't affect processing already carried out.

If you are an end-customer of a business that uses Alice: the business is the controller of your details. Please direct access, correction, or deletion requests to that business in the first instance; we will help the business action your request, and you may also contact us.

14. How to make a privacy complaint

If you think we have mishandled your personal information:

  1. Contact us first at [email protected] (the privacy contact in Section 1). Tell us what happened and what you'd like us to do.
  2. We will investigate and aim to respond within a reasonable time (generally within 30 days), explaining our findings and any steps we'll take.
  3. If you're not satisfied, you can escalate to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or 1300 363 992.
  4. GDPR users may also lodge a complaint with their local data-protection supervisory authority.

15. Additional rights for EU / UK individuals (GDPR)

This section applies if and to the extent the EU or UK GDPR applies to you.

16. Additional rights for California residents (CCPA/CPRA)

This section applies if and to the extent the California Consumer Privacy Act (as amended by the CPRA) applies.

17. Facebook / Instagram ("Social" feature)

This section applies once the Social feature (Meta / Facebook / Instagram integration) launches; until then it is forward-looking. If you connect Facebook or Instagram to Alice, we will:

18. Children

Alice is a tool for businesses and is not intended for use by children, and we do not knowingly collect personal information from children. If you believe a child's personal information has been provided to us, contact us (Section 1) and we will delete it.

19. Changes to this policy

We may update this policy from time to time — for example, to reflect new features or legal changes (such as the December 2026 automated-decision-making rules). When we do, we'll update the "Last updated" date at the top and, for material changes, take reasonable steps to let you know. The current version always lives at https://alicefamily.app/privacy.

When our mobile apps launch, our store and platform disclosures — the Google Play Data safety form and the Apple App Privacy label (which will declare "Voice or sound recordings" for Alice's call recordings) — will be kept consistent with this policy and with how Alice actually behaves.

20. Governing law and how to contact us

Governing law. This Privacy Policy and any dispute arising out of or in connection with it are governed by the laws of Victoria, Australia. You and we submit to the non-exclusive jurisdiction of the courts of Victoria, Australia (and the Commonwealth courts that hear appeals from them).

Goods and Services Tax (GST). FreshTech Community is not currently registered for GST. Our subscription prices — a permanent free tier, Alice Chat at AUD $49/month, and Alice Voice+Social at AUD $149/month — therefore carry no GST component. If we become required to register for GST in the future, GST may then apply to these prices, and we will update our billing disclosures accordingly.

Contact us.

To delete your account and data, see Section 13. To complain, see Section 14.

Alice Booking Diary is operated by FreshTech-Community Pty Ltd (ACN 699 190 513), Victoria, Australia. Questions: [email protected] · About · Privacy · Terms · Refunds