Where your data is stored
- User accounts and session data
- Stored in a PostgreSQL database hosted on Supabase in the ap-southeast-2 (Sydney, Australia) region — your account data stays in Australia.
- Uploaded documents
- Documents you upload for analysis are processed to extract their text and are not added to your library unless you choose to save them. Documents you save are held in a private storage bucket (Supabase, Sydney), reachable only by you through short-lived signed links, and you can delete them at any time.
- Generated documents
- Documents generated by the tools are returned directly to your browser as file downloads. References (tool used, unit code, timestamp) are stored in your activity history log.
AI providers
- Which AI providers are used
- RTOAiVoX uses Google Gemini (primary) and OpenAI (fallback). Requests are sent to the respective provider APIs over HTTPS.
- Is your content used to train AI models
- RTOAiVoX uses these providers' standard APIs. Under Google's and OpenAI's API data-processing terms, content submitted through their APIs is not used to train their models, and we grant no additional rights to use your content for training.
- Where AI requests are processed
- Requests are processed on Google's and OpenAI's infrastructure; the processing region is determined by each provider under their API terms. Your stored data (accounts and saved documents) remains in Australia.
- Redaction and data minimisation
- RTOAiVoX does not apply an automated redaction layer between your input and the AI provider. Include only what is needed to generate the resource — avoid pasting identifiable learner or staff personal information into prompts.
Access control
- Authentication
- RTOAiVoX uses passwordless (magic link) authentication. A time-limited login link is sent to your email address. There are no passwords to compromise.
- Sessions
- Sessions are managed server-side using signed, encrypted, HTTP-only cookies. Member sessions expire after 24 hours and admin sessions after 1 hour. Magic-link login tokens are single-use and expire 30 minutes after they are issued.
- Data isolation between accounts
- All user data queries are scoped to the authenticated user ID. Users cannot access each other's records.
Infrastructure and encryption
- Transport encryption
- All traffic between your browser and RTOAiVoX is encrypted in transit using TLS.
- Encryption at rest
- Data stored in the Supabase PostgreSQL database and storage buckets is encrypted at rest (AES-256), managed by Supabase.
- Hosting
- The application runs on Replit's managed cloud infrastructure. Your durable data — accounts, saved documents and the VET catalogue — is stored in the Supabase database in Sydney, Australia.
Your responsibilities
RTOAiVoX generates AI-assisted drafts. Your RTO remains responsible for:
- +Reviewing, validating, and approving all AI-generated content before use
- +Ensuring generated documents are contextualised to your specific learners and delivery context
- +Meeting all obligations under the Standards for RTOs 2025
- +Complying with the Privacy Act 1988 (Cth) in relation to any learner or staff data you enter
- +Maintaining appropriate controls over who accesses your RTOAiVoX account
Questions or concerns
Contact us at info@rtoaivox.com.au for any security or data enquiries.
This page is reviewed periodically. For specific data-processing or compliance questions, contact us at the address above.