Privacy Policy

Effective date: 1 September 2026

1. About this policy

This Privacy Policy explains how Iron Atlas Pty Ltd ACN 699 650 283 ABN 86 699 650 283, trading as Modular MathDesk, collects, uses, holds, and discloses personal information for the website, accounts, billing, licensing, downloads, updates, support, and desktop application. The policy is separate from the Terms of Service and Software Licence. Users acknowledge that they have read it rather than accept it as a second contract.

Modular MathDesk is intended for Australian users at launch. A controlling account holder, purchaser, agreement acceptor, or named beta tester must be at least 18. A person under 18 may use the product only through an adult or organisation-controlled account with appropriate supervision and permissions.

General enquiries: [email protected]. Support: [email protected]. Privacy requests and complaints: [email protected]. Legal notices: Suite 1087, Level 1, 241 Adelaide St, Brisbane City QLD 4000.

2. Information we collect

Account and authentication information includes name, email address, password authentication data, verification status, account identifiers, sessions, IP address, user agent, and security events handled through the application's authentication system.

Early-access information includes email address, optional name, optional role or use case, source information, consent records, IP address, and user agent supplied or recorded when someone requests beta or early access.

Licence and access information includes licence keys, entitlements, validation records, hashed device identifiers, device activations, reset or deactivation records, application version and build, and server-recorded legal-acceptance evidence.

Billing information includes Stripe customer identifiers, plan and subscription status, payment status, invoice and checkout references, and related billing metadata. Stripe processes payment-card details. Modular MathDesk servers do not store those card details.

Email information includes addresses, delivery metadata, and transactional email records used for verification, password reset, billing, licence, account, and service messages through Resend.

Support and bug-report information includes anything you choose to send, such as contact details, product and licence context, screenshots, logs, document or debug snapshots, and correspondence. Review material before sending it because it may contain confidential, personal, or sensitive information.

Update and download information includes requests made to Modular MathDesk services to check the latest version or select a platform-specific installer. The current application does not create a durable account-linked download event. Ordinary server, security, delivery, and provider logs may still contain request information such as IP address, user agent, time, and requested path.

3. Documents, modules, and desktop data

In the current product, calculation documents and modules remain on your device or in storage locations you select. Modular MathDesk servers do not store them. The desktop application does not send product telemetry or crash uploads to Modular MathDesk servers in the current release build.

If you use a cloud-synced folder, network drive, shared folder, source-control repository, backup product, or collaboration service, you choose that provider and control the arrangement. Its terms and privacy practices apply.

The desktop application stores licence information locally, including the licence key and validation cache. You are responsible for securing your device, user profile, backups, and local files.

4. User-selected AI providers

Desktop AI features are bring-your-own-key. The application stores the provider credential locally using operating-system-supported secure storage where available. When you invoke an AI feature, it sends the request directly from your device to the provider you selected. Iron Atlas ordinarily does not proxy, receive, or retain prompts or responses from this direct flow in the current product.

A request may include prompts, worksheet text, calculation context, results, errors, file paths, and optional images. The selected provider and any downstream model provider may process that material overseas and under their own retention and model-training settings. Review their current terms and privacy controls before sending confidential, personal, regulated, or third-party material.

OpenRouter is the current user-facing AI gateway. It and the model provider selected through it are services chosen by the user, not service providers Iron Atlas engages to run the Modular MathDesk website or account service. Iron Atlas does not use locally stored documents or modules to train AI models.

5. GitHub installer delivery and aggregate counts

GitHub and its download infrastructure deliver approved desktop installers. When you request an installer, GitHub and its infrastructure may process ordinary request information such as IP address, user agent, requested asset, time, and delivery or security logs.

GitHub reports an aggregate request count for each release asset. Iron Atlas may inspect the total count for each Windows or macOS installer for release and platform planning. The count does not identify unique users, prove that a transfer completed, or prove that the software was installed or used. Iron Atlas does not add account-linked download tracking merely to obtain this aggregate count.

6. How we use information

We use personal information to create and secure accounts, authenticate users, manage subscriptions and billing, issue and validate licences, manage device activations, record legal acceptance, deliver installers and updates, send service emails, provide support, investigate faults, prevent fraud and abuse, keep required records, and comply with law.

We do not sell personal information. We do not use personal information for unrelated direct marketing without the notice or consent required for that use.

7. Providers we engage and other disclosures

Iron Atlas engages providers to operate the service. Current categories include Stripe for billing, Resend for transactional email, Cloudflare for domain, network, and security services, Hetzner for web and database hosting, and GitHub for source, deployment infrastructure, container hosting, and installer delivery. The authentication library runs within the Modular MathDesk web service rather than operating as a separate account provider.

Services that you select independently, such as cloud storage, source control for your own files, OpenRouter, and downstream AI model providers, are not engaged by Iron Atlas for the direct desktop flow. Information goes to them because you choose and invoke that service.

We may disclose information where required by law, to enforce the Terms, protect users or service security, investigate suspected fraud or abuse, obtain professional advice, or complete a business sale, merger, restructure, or asset transfer subject to appropriate confidentiality and legal controls.

8. Overseas handling

Personal information may be processed outside Australia. Likely locations under the current provider arrangements include Germany or Finland for Hetzner's European hosting locations, the United States and Europe for Cloudflare network metadata, the United States for Resend, the United States and other locations used by GitHub and its infrastructure, and Australia, Ireland, the United States, and other locations used by Stripe and payment participants.

A user-selected AI request may be processed in the United States or another country used by OpenRouter, the selected model provider, and their subprocessors. The exact country depends on the provider and model selected at the time of the request.

Provider locations and subprocessors can change. We review practicable provider information and take reasonable steps appropriate to the service and information involved, but we do not claim that all processing remains in Australia.

9. Retention

We retain account, authentication, billing, licence, device, security, support, and email records only for as long as reasonably needed for the purpose collected, service operation, accounting and tax obligations, fraud prevention, security, backups, disputes, legal claims, and other legal requirements. Some deletion and cleanup processes are manual. We do not promise an automatic deletion schedule where one is not implemented.

Legal-acceptance evidence is append-only and may remain after other account information is deleted. We retain the accepted bundle identifier, exact document versions and hashes, server receipt time, account and entitlement links, application version and build, and idempotency evidence for contract administration, disputes, and legal claims, subject to applicable law. The acceptance record does not store the raw licence key or raw device identifier.

Payment, invoice, accounting, fraud, dispute, and security records may remain for the period required by law or reasonably needed to establish, exercise, or defend a legal claim. Backups may retain deleted information until the relevant backup is securely overwritten or expires under the backup process.

If Iron Atlas keeps a small snapshot of GitHub aggregate asset counts for a beta or release decision, it should contain only the date, release tag, asset filename, and aggregate count. The operational plan is to keep such a snapshot for up to 12 months after the relevant decision unless it becomes part of a documented release or dispute record.

10. Security

We use administrative, technical, and organisational safeguards appropriate to the service and information. These include access controls, authentication, encrypted network transport, restricted credentials, and measures intended to prevent unauthorised alteration of legal evidence. No internet service or storage method can be guaranteed secure against every risk or continuously available.

11. Access, correction, and deletion

You may request access to, correction of, or deletion of personal information by emailing [email protected]. We may verify identity before acting and may ask for information needed to locate the relevant records.

We will respond within a reasonable period. We may refuse or limit a request where permitted or required by law, including where information must be retained for billing, tax, security, fraud prevention, backup integrity, contract administration, disputes, legal claims, or another legal obligation. We will explain a refusal where required.

12. Privacy questions and complaints

Send a privacy question or complaint to [email protected] with enough detail for us to investigate. We will assess it and respond within a reasonable period.

If you are not satisfied with the response, you may be able to complain to the Office of the Australian Information Commissioner through oaic.gov.au.

13. Changes to this policy

We will update the effective date when this policy changes. We will give reasonable notice of a material change through an account email, in-product notice, website notice, or another suitable channel.

Where a material change affects collection, disclosure, direct AI handling, or another practice significant to users, we will seek renewed acknowledgement before continued meaningful desktop use where appropriate. A privacy acknowledgement confirms that the user has read the policy. It does not turn the policy into a separate contract.