Legal

Privacy Policy

How Hourglass AI Pty Ltd collects, uses, stores and discloses personal information, in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles.

Effective

31 August 2026

Entity

Hourglass AI Pty Ltd

ABN

32 696 937 372

ACN

696 937 372

Jurisdiction

New South Wales, Australia

1.Who We Are

This Privacy Policy applies to Hourglass AI Pty Ltd (ACN 696 937 372; ABN 32 696 937 372), trading as Hourglass AI, and to this website at thehourglass.ai. We are an Australian AI implementation agency: we build and deploy AI systems inside other companies, which means we handle both our own visitor and customer data and, separately, data belonging to our clients.

We are bound by the Privacy Act 1988 (Cth) and the thirteen Australian Privacy Principles (APPs). This policy explains what we collect, why, who we share it with, how long we keep it, and how you can access, correct or complain about it. It sits alongside our Terms and Conditions, which govern the commercial relationship.

2.What We Collect

We collect only what we need to answer an enquiry, deliver a service, or run our business. In practice that is:

  • Contact details: your name, email address, company name, role, phone number where you give it, and your LinkedIn profile where you supply one.
  • Enquiry content: what you write in a discovery-call, partner, or download form, and the company website URL you submit to the AI roadmap generator.
  • Course and waitlist data: your position, referrals and any deposit or payment status for the AI Pod cohort course.
  • Transaction data: order records for paid products. Card details are entered directly into Stripe and are never seen or stored by us.
  • Files you upload: material you send us during onboarding for a build.
  • Technical data: aggregate page analytics, plus a short-lived record of submissions our bot filter blocks (kept for 30 days so we can spot and fix false positives, then deleted).

We do not seek sensitive information as defined by the Privacy Act (health, biometric, racial or ethnic origin, political or religious beliefs, sexual orientation, criminal record) through this website, and ask that you do not send it to us unsolicited.

3.How We Collect It

Almost all of it comes directly from you: a form on this site, an email, a call, or a document you send us during a project. We also collect information indirectly when you interact with us on a public platform such as LinkedIn, when a partner or client refers you, and through the analytics described in section 10.

You can browse this website without telling us who you are. If you choose not to provide information a form asks for, we may not be able to respond to you or deliver the service.

4.Why We Use It

We use personal information to:

  • respond to enquiries and arrange discovery calls;
  • scope, quote, deliver and support the services you engage us for;
  • process payments, issue invoices, and meet our tax and record-keeping obligations;
  • run the AI Pod cohort course, including the waitlist and referral mechanics;
  • send the updates and newsletters you have asked for, and nothing else;
  • protect our forms from automated abuse; and
  • improve the website and understand which content is useful.

We do not sell personal information. We do not use it for automated decision-making that produces a legal or similarly significant effect on you.

5.Client Data We Process

When we build AI systems inside a client's business, that work necessarily touches the client's own data, which may include emails, documents, CRM records, employee records and customer information. In that context the client is the entity responsible for the personal information, and we act on their instructions under the engagement contract.

Our commitments to clients on that data are set out in section 7 of our Terms and Conditions: we use it only to deliver the agreed services, we do not use it to train third-party AI models, we keep it confidential, and we return or delete it at the end of an engagement on request. If you are an individual whose information a client has given us, please contact that organisation first; we will redirect your request to them and assist them in responding.

6.AI and Third-Party Providers

Our services use third-party AI model providers. Content you or your organisation submit to a system we build may be transmitted to those providers to generate a response. We select providers that offer commercial terms excluding customer content from model training by default, and we configure them that way, but we do not control their infrastructure and cannot guarantee their performance or availability.

AI output can be wrong. Any output produced by a system we build should be reviewed by a person before it is relied on for a decision that matters. This is set out in full in section 9 of our Terms and Conditions.

7.Who We Disclose To

We disclose personal information only to the service providers we need to run the business, and only for that purpose:

  • hosting, database and file storage providers that run this website and our systems;
  • Stripe, for payment processing;
  • email delivery and newsletter platforms, to send what you have asked for;
  • our internal collaboration tools, so the right person picks up your enquiry;
  • professional advisers such as accountants and lawyers, where required; and
  • a government agency or court where we are compelled by law.

We may also disclose information to a purchaser in connection with a sale of our business, subject to that purchaser agreeing to handle it consistently with this policy.

8.Overseas Disclosure

Some of the providers above store or process data outside Australia, principally in the United States and the European Union. Where we disclose personal information to an overseas recipient we take reasonable steps to ensure it is handled consistently with the Australian Privacy Principles, including through the provider's contractual data protection terms. Where a client requires data residency in Australia, we scope the build accordingly.

9.Storage, Security and Retention

Information is held in access-controlled cloud services, encrypted in transit and at rest by those providers. Access inside Hourglass AI is limited to the people who need it to do the work. No method of transmission or storage is completely secure, so we cannot guarantee absolute security, but we take reasonable steps to protect information from misuse, interference, loss, and unauthorised access, modification or disclosure.

We keep personal information only while we have a reason to: for the life of the relationship, plus the period we are required to retain business records (generally seven years for financial records). Bot-filter records are deleted after 30 days. Marketing contacts are removed on unsubscribe. When information is no longer needed and we are not required to keep it, we destroy or de-identify it.

If a data breach occurs that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme.

10.Cookies and Analytics

This site uses Vercel Analytics to count page views and understand which pages are useful. It is privacy-friendly by design: it does not use cross-site tracking cookies and does not build a profile of you across other websites. We do not run advertising trackers or third-party ad pixels on this site.

We set a small number of functional cookies and equivalent browser storage, for example to keep an administrator signed in or to remember a form token that protects our forms from bots. You can block or delete cookies in your browser; parts of the site that depend on them may then not work.

11.Marketing and Opting Out

We send our Monthly Update and occasional product news only to people who asked for them. Every email carries a one-click unsubscribe, and we honour it immediately. You can also email us and ask to be removed. Unsubscribing from marketing does not stop transactional messages about a service you are actively using, such as an invoice or a course logistics email.

12.Access and Correction

You may ask us for a copy of the personal information we hold about you, and ask us to correct anything that is wrong, out of date, incomplete or misleading. Email hello@thehourglass.ai. We will verify your identity and respond within 30 days. There is no charge for making a request; if a request requires substantial work we may charge a reasonable cost-based fee and will tell you before we do.

If we refuse access or correction we will tell you why in writing and how to complain. You may also ask us to delete information we no longer need to keep.

13.Complaints

If you think we have breached the Australian Privacy Principles, email hello@thehourglass.ai with the details. We will acknowledge your complaint within five business days and give you a written response within 30 days.

If you are not satisfied with our response, you can refer the matter to the Office of the Australian Information Commissioner at oaic.gov.au or on 1300 363 992.

14.Changes to This Policy

We review this policy as our services change and will publish any updated version on this page with a new effective date. Material changes affecting how we handle information already collected will be notified to affected individuals where practical. The version on this page is always the current one.

15.Contact Us

For any privacy question, access request or complaint, contact our Privacy Officer at hello@thehourglass.ai, or use the contact form on our home page.

Legal Entity

Hourglass AI Pty Ltd · ABN 32 696 937 372 · ACN 696 937 372 · New South Wales, Australia · hello@thehourglass.ai

This Privacy Policy was last updated on 31 August 2026. It should be read with our Terms and Conditions.