Last updated: May 2026
1. Introduction
Littlebird Australia Pty Ltd ABN 83 111 099 775 (trading as "Doclio") ("Company", "we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the DOCLIO construction management platform ("Service").
Please read this Privacy Policy carefully. If you do not agree with our policies and practices, please do not use our Service.
2. Information We Collect
2.1 Account Information
When you register an account, we collect information such as your name, email address, phone number (optional), company name, job title, and billing address.
2.2 Project Data
We collect all data you upload to or create within the Service, including project files, drawings, documents, annotations, comments, approvals, reports, and project metadata (dates, statuses, assignees, etc.).
2.3 Usage Data
We automatically collect information about your interactions with the Service, including:
- Log data (IP address, browser type, pages accessed, timestamps)
- Device information (operating system, device type, unique identifiers)
- Feature usage and engagement metrics
- Error reports and performance data
- AI query logs (prompt, model used, token counts, credit cost β used for billing, analytics, and abuse prevention). Where a question was dictated we record that it was, but never any audio β see section 12
2.4 Cookies and Tracking
We use cookies, web beacons, and similar tracking technologies to enhance your experience, remember preferences, and gather analytics. You can manage cookie preferences through our cookie consent banner.
2.5 Communication Data
If you contact us for support or other enquiries, we collect the content of your messages, contact information, and any supporting documentation you provide.
3. Legal Basis for Processing
Our handling of personal information is governed by the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). For individuals in the EU/UK, we also rely on the following legal bases under GDPR Article 6:
| Processing Activity | Legal Basis |
|---|---|
| Account creation and service provision | Contract (Article 6(1)(b)) |
| Billing, payment, and AI credit management | Contract (Article 6(1)(b)) |
| Legal compliance and fraud prevention | Legal obligation (Article 6(1)(c)) |
| Analytics and service improvement | Legitimate interests (Article 6(1)(f)) |
| Marketing communications | Consent (Article 6(1)(a)) |
4. How We Use Your Information
We use collected information to:
- Provide and maintain the Service
- Process billing, subscriptions, and AI credit top-ups
- Answer your AI queries and comparison requests
- Send important account notifications and support communications
- Improve and personalise the Service
- Detect, prevent, and address fraud or security issues
- Comply with legal and regulatory obligations
- Analyse trends and user engagement (with consent where required)
- Send marketing communications (with consent)
5. Data Sharing & Third-Party Sub-Processors
5.1 Sub-Processors
We share your data with the following trusted third-party service providers who process it on our behalf under contractual data-protection obligations:
- Supabase (United States): cloud database, authentication, and edge function hosting. Processes account data, project data, and AI query logs. Encrypted in transit and at rest.
- Cloudflare R2 (Global): object storage for uploaded drawings, documents, and attachments. Access is restricted by signed URLs and server-side authorisation.
- Stripe (Ireland/United States): payment processing for subscriptions and AI credit top-ups. Stripe handles billing information and payment details directly; we do not store full card numbers.
- Anthropic (United States): provides the Claude AI models that power the AI Personal Assistant. Your prompts, attached drawing images, and selected project context are sent to Anthropic to generate responses. Anthropic does not train models on your data (per their API terms).
- Tavily (United States): optional AI web-search fallback. Only triggered when you explicitly request a web search from the AI assistant. Your search query is sent to Tavily.
- Resend (Global): transactional email delivery (share invitations, notifications, approval requests, support replies sent from the app).
- Migadu (Switzerland): hosted mailbox provider for our inbound and outbound business email on the
@docl.iodomain (e.g.hello@docl.io,privacy@docl.io). Migadu handles messages you send us directly to those addresses; it does not process in-app share invitations or notifications (those go via Resend). - Sentry (EU): error tracking and performance monitoring. Collects anonymised error logs and session metadata to help us diagnose issues. Text content is masked.
- Google (United States): analytics and tag management. We use Google Analytics 4 to understand how visitors interact with our websites (aggregated page views, session duration, referrer, device class) and Google Tag Manager to load analytics tags. IP addresses are truncated by Google before storage. Analytics cookies only fire after you consent via our cookie banner. We also load Google Fonts from Google's CDN, which may record the IP address of your browser during font fetches.
- Microsoft (United States): Microsoft Clarity β session replay and heatmaps used to improve the product's usability. Clarity records aggregated interactions (mouse movement, clicks, scroll depth) and a masked visual replay of the page. Form input text and annotation content are masked at capture (Strict masking mode) so sensitive project data never leaves your browser. Only fires after you consent via our cookie banner.
A current list of sub-processors is maintained on this page; we will update it when sub-processors change and, where required, provide reasonable advance notice.
5.2 Legal Requirements
We may disclose your information when required by law, court order, or lawful government request, or to protect our rights, privacy, safety, or property.
5.3 Business Transfers
If we are involved in a merger, acquisition, bankruptcy, or sale of assets, your information may be transferred as part of that transaction. We will provide notice before your data becomes subject to a different privacy policy.
5.4 No Sale of Data
We do not sell, trade, or rent your personal information to third parties for marketing purposes.
6. International Data Transfers
Your data may be stored and processed in countries outside the EU/UK, including the United States. Where data is transferred internationally, we rely on appropriate safeguards such as the EU Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum, or equivalent mechanisms to ensure your data receives protection comparable to EU/UK standards.
7. Data Retention
We retain your personal data for as long as necessary to provide the Service and fulfil the purposes outlined in this Privacy Policy. Typical retention periods:
- Account data: retained while your account is active; deleted within 30 days of account termination (subject to backup retention below).
- Project data: retained for the duration of your subscription. You may request export or deletion at any time.
- Billing records: retained for up to 7 years for legal and tax compliance.
- AI query logs: retained for up to 12 months for usage analytics, abuse detection, and billing disputes; then aggregated or deleted.
- Usage / analytics data: retained for up to 12 months before anonymisation.
- Backup copies: retained for up to 90 days after deletion from primary storage.
8. Your Rights
Australian users have rights under the Australian Privacy Principles (APPs), including the right to access and correct your personal information, and to complain about how we handle it. You can exercise these rights by contacting us via our Help Centre or privacy@docl.io. We will respond to requests within a reasonable period (typically 30 days).
EU/UK users have the following additional rights under the GDPR/UK GDPR:
8.1 Right of Access
You have the right to request a copy of the personal data we hold about you in a structured, commonly used, and machine-readable format. You can trigger a self-service data export from your account settings.
8.2 Right to Rectification
You have the right to correct inaccurate or incomplete personal data. You can update most account information directly in your profile settings.
8.3 Right to Erasure ("Right to be Forgotten")
You have the right to request deletion of your personal data, subject to legal retention obligations. Deletion requests are processed within 30 days.
8.4 Right to Restrict Processing
You have the right to restrict or block our processing of your data in specific situations, such as when the accuracy of the data is contested.
8.5 Right to Data Portability
You have the right to receive your personal data in a structured, commonly used format and to transmit it to another controller.
8.6 Right to Object
You have the right to object to processing of your personal data for legitimate interests, including marketing communications. You can manage email preferences in your account settings.
8.7 Right to Withdraw Consent
Where processing is based on consent, you have the right to withdraw that consent at any time without affecting the lawfulness of processing before withdrawal.
To exercise these rights, submit a request via our Help Centre or email privacy@docl.io.
9. Cookie Policy
We use cookies and similar technologies to enhance your experience. Our cookie consent banner allows you to manage your preferences for:
- Essential cookies: required for login, security, and core functionality (always enabled).
- Analytics cookies: track usage patterns and help improve the Service (optional).
- Functional cookies: remember preferences and customisations (optional).
You can change your cookie preferences at any time through our cookie settings or by clearing your browser cookies.
10. Children's Privacy
The Service is not intended for individuals under 18 years of age. We do not knowingly collect personal information from children. If we become aware that a child has provided us with personal information, we will take steps to delete that information and terminate the account.
11. Email-Based Session Continuity (Magic Links)
When the Service sends you an email notification β such as a share invitation, an action thread you have been added to, an approval request, or a catch-up email forwarding an existing thread β that email may contain a single-use sign-in link ("magic link") alongside an alternative anonymous reply link.
11.1 How magic links work
If you click a magic link and an account already exists for the email address it was sent to, you are automatically signed in to that account in your current browser, in the same way that requesting a sign-in link from the login page signs you in. The link is single-use and time-limited (typically 1 hour); it cannot be reused once clicked and expires whether clicked or not.
If no account exists for the recipient's email address, the magic link does not create one. You can still reply to the thread anonymously via the alternative link in the same email, which uses a per-recipient share token (no sign-in required). Anonymous replies attribute the comment to your email address but do not establish a session.
11.2 Why we use them
Magic links remove friction for legitimate recipients (clients, contractors, consultants, certifiers) who need to read a thread or respond without remembering a password. This pattern is widely established for B2B collaboration tools (e.g. Substack, Linear, Notion, Asana, DocuSign). In a construction context, where threads are time-sensitive and recipients are often busy on site, reducing sign-in friction materially improves response rates and audit completeness.
11.3 Audit and security
Every magic-link sign-in event is recorded in the Service's authentication audit log together with the IP address, user agent, and timestamp of the sign-in. This audit trail is available for security investigations and account-takeover review.
Magic links inherit the same protections as any other authentication mechanism: TLS encryption in transit, secure-by-default cookie attributes on the resulting session token, and revocation alongside the account on password reset, account deactivation, or organisation-administrator action.
11.4 Your choices
If you would prefer not to receive magic-link sign-in URLs in outbound notification emails, you can disable email notifications entirely for the affected project under Settings β Notifications. We do not currently offer an option to suppress the magic link while keeping notifications enabled, but the anonymous alternative link is always included alongside the magic link, so you can simply choose to use it instead. Magic-link URLs are never used in marketing communications.
12. Voice Dictation
The AI Assistant offers an optional microphone button so you can speak your question instead of typing it. Dictation is never on by default: it starts only when you press the button, and it stops when you press it again.
12.1 Your browser does the listening, not us
Dictation uses speech recognition built into your web browser. Your browser captures the audio and converts it to text. The audio does not pass through Doclio. We do not receive it, store it, or send it anywhere β we receive only the text your browser produces, at the moment it appears in the message box, exactly as though you had typed it.
Most browsers do not recognise speech on your device. Google Chrome, for example, sends the audio to Google's servers to convert it to text. That transfer is between you and your browser's maker, under their privacy policy and your existing relationship with them β not under this one. We have no contract covering it, no visibility of it, and no ability to control or delete what they receive, which is why your browser's maker is not listed as one of our sub-processors in section 5.1.
If you would rather no audio left your device, do not use the microphone button. Typing the same question sends no audio anywhere.
12.2 What happens to the text
Once dictated words appear in the message box they are ordinary text, and nothing is sent anywhere until you press send. From that point the question is treated exactly like a typed one, including the processing described in section 5.1 for the AI Assistant. You can edit or delete the text before sending it.
We record that a question was asked by voice as part of the AI query logs described in section 2.3, so we can tell how the feature is used. No audio is recorded, because none reaches us.
12.3 Microphone permission
Your browser asks your permission before the microphone is used for the first time, and you can withdraw that permission at any time in your browser's site settings. Withdrawing it disables dictation and affects nothing else in the Service. The microphone is active only while dictation is running, and stops when you press the button again, send your question, or close the assistant.
13. Security Measures
We implement industry-standard security measures to protect your data, including:
- TLS encryption for data in transit
- Encryption at rest for database and object storage
- Secure authentication with per-session tokens
- Row-level security on sensitive tables
- Restricted access to personal data by authorised personnel only
- Regular dependency updates and security reviews
- Data-breach response procedures
Despite our efforts, no security system is impenetrable. Please use a strong, unique password and enable any available additional authentication options to help protect your account.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of material changes by email or prominent notice on the Service. Your continued use constitutes acceptance of the updated policy.
15. Contact Information
For all privacy and data-protection questions, please contact us:
- Help Centre: support.docl.io/kb (preferred β creates a ticket automatically)
- General support: hello@docl.io
- Privacy enquiries: privacy@docl.io
- Legal enquiries: legal@docl.io
- Registered office: Littlebird Australia Pty Ltd (trading as Doclio), Level 3, 1060 Hay Street, West Perth, WA 6005, Australia
- ABN: 83 111 099 775
- Phone: (08) 6311 2841
If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au. EU/UK users may also lodge a complaint with their local supervisory authority (for example, the ICO in the UK).
Disclaimer: This Privacy Policy is provided in good faith as a workable baseline and does not constitute legal advice. Please consult a qualified legal or data-protection professional to ensure compliance with the laws of the jurisdictions where you operate and where your users are located β particularly GDPR, UK GDPR, and local data protection laws such as the Australian Privacy Act.