Skip to main content
Back to home
PRIVACY POLICY · v2.2

Privacy Policy

Version 2.2. Effective 28 July 2026.

1. Introduction

AfterService.ai ("we", "us", "our") is committed to protecting your privacy and being transparent about how we handle your information. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our platform.

We are bound by the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). This Privacy Policy is a notice given under APP 1 and APP 5. It does not form part of the contract between you and us; the contractual terms are set out in our Terms and Conditions, which you should read alongside this policy.

2. Who We Are

AfterService is operated by AfterService Pty Ltd (ABN 21 687 135 048), trading as AfterService.ai. AfterService Pty Ltd is an Australian-owned company that uses artificial intelligence to help Australian Defence Force veterans, serving members, and their families navigate Department of Veterans' Affairs (DVA) entitlements, claims, appeals, and support services.

We are not affiliated with, endorsed by, or operated on behalf of the Department of Veterans' Affairs or any other Australian Government agency.

3. Information We Collect

We collect the following categories of information.

3.1 Information you provide directly

  • Account identifiers: email address and password.
  • Identity and contact information: name, date of birth, phone, postal address, emergency contact.
  • Service record: branch, rank, dates of service, postings, deployments, decorations, discharge type.
  • Health information: medical conditions, symptoms, disabilities, DVA claim statuses (sensitive information under the Privacy Act).
  • Entitlement information: DVA card type, service numbers, compensation details.
  • Content you provide to the AI Assistant: chat messages, questions, uploaded documents, generated appeal narratives, and bio text.
  • Consent records: whether you have accepted each version of this Privacy Policy, our Terms and Conditions, and the AI data-use addendum. Each consent record includes a timestamp, the exact version of the document you accepted, and a cryptographic hash of the text shown at acceptance.

3.2 Information we collect automatically

  • Usage data: pages viewed, features used, time spent, referring pages.
  • Technical data: IP address, browser type, device identifiers, session duration.
  • Diagnostic data: error reports, performance metrics.

3.3 Information from third parties

Documents you authorise an organisation (such as an Ex-Service Organisation or healthcare provider) to share with us via the Connect consent framework (see Section 6).

3.4 Sensitive information consent (APP 3.3)

Conversations with the AI Assistant may include "sensitive information" as defined in section 6 of the Privacy Act 1988 (Cth), including health information (including mental-health information), information about your military service, and information about your family. By creating an account and submitting conversation content, you consent to our collection, storage, and processing of any sensitive information you choose to provide, for the purpose of providing the platform. You can withdraw this consent under Section 10. We do not collect sensitive information by any means other than your voluntary submission.

4. How We Use Your Information, Including AI

We use your information to:

4.1 Operate the platform

Provide the AI Assistant, maintain your profile, process claims and entitlements assistance, deliver transition support, and facilitate community features.

4.2 Personalise your experience

Tailor guidance to your service history, conditions, and stated goals.

4.3 Improve the service

Analyse aggregate usage patterns to improve usability, accuracy, and performance.

4.4 Artificial intelligence and your content (IMPORTANT)

We do not use your content to train or improve AI models. Your chat messages, uploaded documents, and generated narratives are processed by AI only to provide the service to you at the time you use it. Specifically:

  • (a) We do not train, fine-tune, or otherwise improve any AI model on your content, whether identified or de-identified.
  • (b) The foundation models we use (currently Anthropic Claude via Amazon Bedrock, hosted in AWS ap-southeast-2 Sydney) do not retain or train on customer inputs, based on Anthropic's published Bedrock service terms in force from time to time.
  • (c) We do not sell your content to third parties.
  • (d) We do not send your content to third-party AI providers for their own model training.
  • (e) Limited quality-assurance review of your content in its original form may be performed by AfterService employees bound by confidentiality. Quality assurance means checking the service worked correctly for you; it is not model training.
  • (f) If we ever propose to use content for model training in the future, we will update this policy, explain exactly what would change, and ask for your explicit consent first. Continued use of the service will not be treated as consent to training.

4.5 Communicate with you

About your account, security, service changes, and (with separate opt-in) platform news. You may opt out of marketing communications at any time (APP 7).

4.6 Comply with legal obligations

Including retention of consent records for Privacy Act audit purposes.

4.7 Safety and crisis support

Where content you share indicates a serious threat to your life, health or safety, or that of another person, we may surface crisis resources within the platform. Where we reasonably believe it is necessary to lessen or prevent that threat and it is unreasonable or impracticable to obtain your consent first, we may disclose the minimum necessary information to emergency services under Item 1 of the table in section 16A(1) of the Privacy Act.

AfterService is not a crisis service and does not monitor your account in real time. If you are in immediate danger, call Triple Zero.

We do not routinely disclose your identity to Open Arms, Lifeline, or other support services without your consent.

4.8 Automated decision-making

Some parts of the platform use your information in substantially automated ways to produce guidance that could affect what you decide to claim or pursue. We disclose this now, ahead of the automated-decision requirements commencing 10 December 2026, because you should know how the tools work before you rely on them.

  • Entitlements guidance. A rules-based wizard uses your service history, dates of service, and recorded conditions to indicate entitlements and health cards you may be eligible for.
  • AI Assistant guidance. The assistant uses your profile, your recorded conditions and claim history, and the documents you have shared with it, to suggest claims you may be able to make, explain decisions, and draft supporting material.
  • Document understanding. Uploaded documents are read automatically to extract structured facts, such as conditions, medications and key dates, which then inform the guidance above.

None of these tools makes a decision about your entitlements. Decisions about liability, compensation and treatment are made by the Department of Veterans' Affairs, not by AfterService. Our output is guidance to help you prepare, and it can be wrong or incomplete, particularly where a document is unclear or your record is incomplete.

You can ask a human to review any guidance the platform has given you, and ask us to correct information the platform has recorded about you, by contacting privacy@afterservice.ai. We respond within 30 days.

5. Data Storage, Inference, and Cross-Border Disclosure

5.1 Australian data sovereignty

All personal information is stored exclusively in Amazon Web Services data centres located in Sydney, Australia (ap-southeast-2). We do not transfer your stored data overseas without your explicit consent.

5.2 AI model location

All AI inference is performed on models hosted in AWS Sydney through the Amazon Bedrock Australia-only inference profile. Prompts and responses do not leave Australian AWS infrastructure during processing.

5.3 Cross-border disclosure (APP 8)

Although your data is stored and processed in Australia, certain of our service providers are incorporated outside Australia:

  • Amazon Web Services Inc. (incorporated in the United States), through which AWS Australia provides hosting in Sydney; and
  • Anthropic PBC (incorporated in the United States), with whom we contract for foundation-model service through AWS Bedrock, delivered within Sydney infrastructure.

Your personal information is stored and processed in Australia. It is not routinely accessed from overseas, and we do not rely on your consent to send it offshore. Where APP 8 applies to our engagement of these providers, we rely on the reasonable steps required by APP 8.1, and we take those steps through binding contractual commitments, including AWS data-residency commitments and the Anthropic Bedrock service terms, together with the technical controls described at 5.1 and 5.2.

We enforce Australian-only inference in our infrastructure, not merely by configuration: every model call uses an Australian inference profile, and our access policies deny non-Australian inference outright, so a misconfiguration cannot send processing offshore.

5.4 Encryption

Your data is encrypted in transit (TLS 1.2+) and at rest (AWS KMS-managed AES-256).

5.5 Access controls

Access to your data is restricted to authorised personnel on a need-to-know basis. All access is logged.

5.6 Retention

  • (a) Account information and profile: retained for the duration of your account, plus up to 30 days after account closure for clean-up, then destroyed or de-identified (APP 11.2).
  • (b) Conversation transcripts and AI artefacts: retained for 12 months from conversation date unless you delete them earlier through your account, or unless retention is required for safety, legal, or regulatory reasons.
  • (c) Consent records: retained for six years (the civil limitation period under the Limitation Act in most Australian states), plus a reasonable audit buffer (Section 7.4), and subject to any longer statutory retention obligation.
  • (d) Diagnostic and security logs: retained for up to 24 months for security investigation, then aggregated or destroyed.

6. Sharing Your Information

6.1 We do not sell, trade, or rent your personal information to any third party for their marketing or commercial use.

6.2 We do not share your information with the Department of Veterans' Affairs, the Australian Defence Force, your employer, or any ex-service organisation without your explicit, case-specific consent, except where disclosure is permitted under Section 4.7 or required by law.

6.3 Trusted service providers. We keep our supply chain deliberately short. The providers that handle your personal information on our behalf are:

  • Amazon Web Services, which hosts all storage, compute and databases in the Sydney region (ap-southeast-2), and through Amazon Bedrock delivers the foundation models that power the AI Assistant within that same Australian infrastructure; and
  • Anthropic, whose Claude models are made available to us through Amazon Bedrock. Anthropic does not receive your content directly from us and, under the Bedrock service terms, does not retain or train on it.

These providers may only use your data to provide their service to us, under confidentiality and data-protection obligations. A standing register of these providers, including the service each provides, the data categories accessed, and the hosting region, is published at our Sub-processor List. If we engage a further provider that handles your personal information, we will update this policy and the Sub-processor List and, where the change is material, prompt you to review it under 7.2.

6.4 Organisation access via Connect. If you choose to connect an Ex-Service Organisation, advocate, or healthcare provider to your AfterService account, you grant that organisation a revocable permission to view parts of your data. You control:

  • which organisation receives access; and
  • revocation at any time via your Organisations page.

We log every grant and revocation, and access is limited to the categories you approve.

Something you should know before you connect an organisation. Many ex-service organisations and advocacy services are small operators. Under section 6D of the Privacy Act, a business with an annual turnover of $3 million or less is generally not covered by the Act. That means once your information reaches such an organisation, the Australian Privacy Principles may not apply to how that organisation handles it, and our controls end at the point of transfer.

We ask organisations to commit to handling your information consistently with the APPs before they can receive access. Even so, connecting an organisation is a decision to share your information outside AfterService, and you should be comfortable with that organisation before you grant access. You can revoke access at any time from your Organisations page, which stops future access but cannot recall information already shared.

6.5 Legal compliance. We may disclose your information where required by Australian law (for example, in response to a lawful subpoena).

6.6 Crisis escalation. Where we reasonably believe it is necessary to lessen or prevent a serious threat to your life, health or safety, or that of another person, and it is unreasonable or impracticable to obtain your consent first, we may disclose the minimum necessary information to emergency services or crisis support organisations under Item 1 of the table in section 16A(1) of the Privacy Act. As noted at 4.7, AfterService is not a crisis service and does not monitor your account in real time.

7. Consent Versioning and Re-Acceptance

7.1 We ask you to accept this Privacy Policy when you create your account, and to re-accept it when we make a material update. Each acceptance is recorded with:

  • a timestamp;
  • the version number of the policy you accepted;
  • a cryptographic hash of the exact text shown to you.

7.2 Material updates. If we materially change how we use your data (for example, a new AI training practice, a new category of data collected, a change in sub-processor, or a change in data location), we will prompt you to review and re-accept the updated policy at your next login.

7.3 Non-material updates. We may make minor editorial corrections (typography, link fixes, clarifications) without requiring re-acceptance.

7.4 Historical consent. We retain your consent records for six years, plus a reasonable audit buffer, and subject to any statutory retention obligation. Consent records are retained separately from your personal profile and are not affected by account deletion except at the end of this retention period.

8. Your Rights Under the Privacy Act

Under the Australian Privacy Act 1988, you have the right to:

8.1 Access. Request a copy of the personal information we hold about you, including your consent history.

8.2 Correct. Request correction of information you believe is inaccurate.

8.3 Erase. Request deletion of your account and associated data, subject to any legal retention obligations.

8.4 Withdraw consent. Withdraw consent to any specific data-use activity, including AI processing of your content (see Section 10).

8.5 Anonymity (APP 2). Where lawful and practicable, you may interact with the Platform anonymously or pseudonymously, but doing so will limit functionality (e.g. you cannot use the AI Assistant without identifying information).

8.6 Complain. Lodge a complaint if you believe we have breached the Australian Privacy Principles. You can complain to us at privacy@afterservice.ai. You may also complain at any time to the Office of the Australian Information Commissioner (www.oaic.gov.au or 1300 363 992).

9. Notifiable Data Breaches

If we suffer an "eligible data breach" as defined in Part IIIC of the Privacy Act 1988 (Cth), we will:

  • 9.1 assess the breach as soon as practicable;
  • 9.2 notify affected individuals and the Office of the Australian Information Commissioner in accordance with the Notifiable Data Breaches scheme; and
  • 9.3 co-operate with regulatory authorities and our sub-processors as needed to remediate the breach and prevent recurrence.

10. Withdrawing Consent to AI

You can withdraw consent to AI data-use at any time from your Account Settings page ("Data and AI").

If you withdraw AI consent, the following features will stop working until you re-consent:

  • AI Assistant chat
  • AI-generated appeal letter drafts
  • AI "Expand with AI" for your bio
  • AI-assisted claims narrative generation
  • AI-assisted entitlements guidance
  • AI extraction from uploaded documents

The following features continue to work without AI consent:

  • Document Vault (upload, store, download)
  • Claims list and manual status tracking
  • Entitlements wizard (rule-based)
  • Transition timeline
  • Profile CRUD
  • Community events
  • Crisis resources
  • Find Support directory
  • Organisations (Connect)

Withdrawal is prospective: it stops AI processing of your content from that point on. Because your content is not used to train AI models, there are no model parameters that retain it.

AI-generated outputs you previously created and saved (e.g. in Document Vault) remain yours; we do not purge them on AI consent withdrawal.

11. Children and Vulnerable Users

The platform is intended for adults (18+). If you believe a minor has created an account, please contact privacy@afterservice.ai so we can investigate.

If you have appointed a substitute decision-maker (e.g. enduring power of attorney, guardianship order), they may exercise your rights under this policy on production of valid authority. Contact privacy@afterservice.ai to register.

We recognise that veterans and their families may be experiencing stress, trauma, or mental-health challenges. We design the platform to comply with the Mindframe Australia safe-messaging guidelines and to surface crisis resources prominently.

12. Changes to This Policy

We review this policy periodically. Material changes will trigger a re-acceptance prompt at your next login.

13. Contact Us

Privacy Officer: privacy@afterservice.ai
General enquiries: hello@afterservice.ai
Security: security@afterservice.ai

AfterService Pty Ltd (ABN 21 687 135 048)
Perth, Western Australia

Access, correction and complaint requests should be sent to the Privacy Officer at the address above. We respond within 30 days.

If you are in crisis or need immediate support: