Trust and transparency

Security and Data

Plain answers about where your data goes, how it is handled, and how access is controlled. Your account data and saved documents are stored in Australia.

Where your data is stored

User accounts and session data
Stored in a PostgreSQL database hosted on Supabase in the ap-southeast-2 (Sydney, Australia) region — your account data stays in Australia.
Uploaded documents
Documents you upload for analysis are processed to extract their text and are not added to your library unless you choose to save them. Documents you save are held in a private storage bucket (Supabase, Sydney), reachable only by you through short-lived signed links, and you can delete them at any time.
Generated documents
Documents generated by the tools are returned directly to your browser as file downloads. References (tool used, unit code, timestamp) are stored in your activity history log.

AI providers

Which AI providers are used
RTOAiVoX uses Google Gemini (primary) and OpenAI (fallback). Requests are sent to the respective provider APIs over HTTPS.
Is your content used to train AI models
RTOAiVoX uses these providers' standard APIs. Under Google's and OpenAI's API data-processing terms, content submitted through their APIs is not used to train their models, and we grant no additional rights to use your content for training.
Where AI requests are processed
Requests are processed on Google's and OpenAI's infrastructure; the processing region is determined by each provider under their API terms. Your stored data (accounts and saved documents) remains in Australia.
Redaction and data minimisation
RTOAiVoX does not apply an automated redaction layer between your input and the AI provider. Include only what is needed to generate the resource — avoid pasting identifiable learner or staff personal information into prompts.

Access control

Authentication
RTOAiVoX uses passwordless (magic link) authentication. A time-limited login link is sent to your email address. There are no passwords to compromise.
Sessions
Sessions are managed server-side using signed, encrypted, HTTP-only cookies. Member sessions expire after 24 hours and admin sessions after 1 hour. Magic-link login tokens are single-use and expire 30 minutes after they are issued.
Data isolation between accounts
All user data queries are scoped to the authenticated user ID. Users cannot access each other's records.

Infrastructure and encryption

Transport encryption
All traffic between your browser and RTOAiVoX is encrypted in transit using TLS.
Encryption at rest
Data stored in the Supabase PostgreSQL database and storage buckets is encrypted at rest (AES-256), managed by Supabase.
Hosting
The application runs on Replit's managed cloud infrastructure. Your durable data — accounts, saved documents and the VET catalogue — is stored in the Supabase database in Sydney, Australia.

Your responsibilities

RTOAiVoX generates AI-assisted drafts. Your RTO remains responsible for:

  • +Reviewing, validating, and approving all AI-generated content before use
  • +Ensuring generated documents are contextualised to your specific learners and delivery context
  • +Meeting all obligations under the Standards for RTOs 2025
  • +Complying with the Privacy Act 1988 (Cth) in relation to any learner or staff data you enter
  • +Maintaining appropriate controls over who accesses your RTOAiVoX account

Questions or concerns

Contact us at info@rtoaivox.com.au for any security or data enquiries.

This page is reviewed periodically. For specific data-processing or compliance questions, contact us at the address above.