Privacy policy

What we collect, and what we do with it.

Last updated 26 July 2026. Written to the Privacy Act 1988 and the Australian Privacy Principles.

What we collect

  • Account data: your name, work email, job title and role within your firm.
  • Firm data: your practice details, rate card, scope library, letter templates and branding.
  • Proposal content: client and project names, addresses, contacts, scope and fee data you enter.
  • Usage telemetry: sign-in times, feature usage and error reports, used to operate and improve the service.

Why we collect it

  • To provide the service you have subscribed to — producing, storing and retrieving your fee letters.
  • To secure the service, including the audit log needed to investigate misuse.
  • To support you when you ask us to.
  • We do not sell personal information, and we do not use your proposal content to train models.

Where it is stored

  • Australia. All data resides in AWS ap-southeast-2 (Sydney), including document processing and any AI-assisted drafting. There is no cross-region replication.

Disclosure and subprocessors

  • We disclose personal information only to the subprocessors listed on our security page, and only to the extent needed to run the service.
  • We do not disclose your fee data to other customers, and our own staff cannot access it without an audited impersonation session that notifies your firm owner.

Retention

  • Proposals and firm data are retained for the life of your subscription plus 90 days after cancellation, then purged.
  • Audit records are retained for seven years, because their value is being able to reconstruct what happened long after the fact.

Access and correction (APP 12 and 13)

  • Firm owners can export all firm data — structured JSON plus a document archive — self-serve, at any time.
  • You can correct account and firm details in the application. If something cannot be corrected there, email us and we will fix it.

Destruction (APP 11)

  • Firm owners can request deletion self-serve. We apply a 30-day soft delete with an emailed confirmation and an audit trail, then a scheduled hard delete.
  • The delay is deliberate: it is the difference between a mistake and a catastrophe.

Cookies

  • Essential cookies only — the session cookie that keeps you signed in. We do not use advertising or analytics cookies, so there is no consent banner to dismiss.

Data breaches

  • We operate under the Notifiable Data Breaches scheme. If a breach is likely to result in serious harm we will notify affected firms and the OAIC as required, following a documented runbook.

Complaints

  • Email privacy@feeletter.com and we will respond within 30 days.
  • If you are not satisfied with our response you may complain to the Office of the Australian Information Commissioner at oaic.gov.au.

Privacy officer: privacy@feeletter.com · Red Yellow Blue Pty Ltd, Melbourne, Victoria.