Privacy policy
What we collect, and what we do with it.
Last updated 26 July 2026. Written to the Privacy Act 1988 and the Australian Privacy Principles.
What we collect
- Account data: your name, work email, job title and role within your firm.
- Firm data: your practice details, rate card, scope library, letter templates and branding.
- Proposal content: client and project names, addresses, contacts, scope and fee data you enter.
- Usage telemetry: sign-in times, feature usage and error reports, used to operate and improve the service.
Why we collect it
- To provide the service you have subscribed to — producing, storing and retrieving your fee letters.
- To secure the service, including the audit log needed to investigate misuse.
- To support you when you ask us to.
- We do not sell personal information, and we do not use your proposal content to train models.
Where it is stored
- Australia. All data resides in AWS ap-southeast-2 (Sydney), including document processing and any AI-assisted drafting. There is no cross-region replication.
Disclosure and subprocessors
- We disclose personal information only to the subprocessors listed on our security page, and only to the extent needed to run the service.
- We do not disclose your fee data to other customers, and our own staff cannot access it without an audited impersonation session that notifies your firm owner.
Retention
- Proposals and firm data are retained for the life of your subscription plus 90 days after cancellation, then purged.
- Audit records are retained for seven years, because their value is being able to reconstruct what happened long after the fact.
Access and correction (APP 12 and 13)
- Firm owners can export all firm data — structured JSON plus a document archive — self-serve, at any time.
- You can correct account and firm details in the application. If something cannot be corrected there, email us and we will fix it.
Destruction (APP 11)
- Firm owners can request deletion self-serve. We apply a 30-day soft delete with an emailed confirmation and an audit trail, then a scheduled hard delete.
- The delay is deliberate: it is the difference between a mistake and a catastrophe.
Cookies
- Essential cookies only — the session cookie that keeps you signed in. We do not use advertising or analytics cookies, so there is no consent banner to dismiss.
Data breaches
- We operate under the Notifiable Data Breaches scheme. If a breach is likely to result in serious harm we will notify affected firms and the OAIC as required, following a documented runbook.
Complaints
- Email privacy@feeletter.com and we will respond within 30 days.
- If you are not satisfied with our response you may complain to the Office of the Australian Information Commissioner at oaic.gov.au.
Privacy officer: privacy@feeletter.com · Red Yellow Blue Pty Ltd, Melbourne, Victoria.