Privacy Policy
Last updated: 13 June 2026
This Privacy Policy explains how we handle your personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). It is written in plain language as general information. It is not legal advice.
1. Who we are
Gambit Tells is a personal strategy coaching service operated in Australia by NUYU Health Technologies Pty Ltd (ABN 35 692 027 937, ACN 692 027 937) of Level 8, 805/220 Collins St, Melbourne VIC 3000. References to "we", "us", or "our" mean NUYU Health Technologies Pty Ltd trading as Gambit Tells. Our contact address is [email protected].
Despite our company name, Gambit Tells is not a health, medical, or therapeutic service. See our Disclaimer for what the service is and is not.
2. What personal information we collect
We collect the following categories of information when you use Gambit Tells:
- Account information: your email address and a hashed version of your password. We never store your password in readable form.
- Coaching content: conversations, target profiles, strategy notes, uploaded files, and other content you create inside the app. This is the core of your coaching experience.
- Billing data: subscription tier and payment status. Payment card details are processed directly by Stripe and are never stored on our servers.
- Usage data: feature usage patterns, session timestamps, and interaction logs used to operate and improve the service.
- Technical data: IP address, browser type, device type, and server-side error logs. We retain logs for a limited period for security and debugging purposes.
Some of the content you choose to provide - for example, notes about your own circumstances or relationships - may be sensitive in nature. You decide what to put into the app. We treat all coaching content as confidential to your account and handle it as described in this policy.
3. How we use your information
We use your personal information to:
- Operate, maintain, and improve the Gambit Tells service.
- Generate coaching responses to the content you provide.
- Process subscriptions and manage your account.
- Send transactional emails (account verification, password reset, billing receipts).
- Detect and prevent fraud, abuse, and security incidents.
- Comply with our legal obligations.
We only collect personal information that is reasonably necessary to provide the service (APP 3), and we use it only for the purposes described in this policy or a directly related purpose you would reasonably expect (APP 6).
4. Automated processing
Gambit Tells uses a third-party artificial intelligence provider to generate coaching responses. When you submit content for coaching, that content is transmitted to Anthropic to generate a response. Anthropic processes this content under its own terms and privacy policy and under our commercial arrangement with it.
We do not use your coaching content to train any artificial intelligence model operated by Gambit Tells, and our arrangement with Anthropic does not permit your content to be used to train its general models.
5. Communications
The emails we send you are transactional - account verification, password resets, and billing receipts - and are necessary to operate your account. If we ever send marketing or promotional messages, they will include an unsubscribe option and we will handle your consent in accordance with the Spam Act 2003 (Cth).
6. Third-party processors and overseas disclosure
We use the following third-party processors to operate the service:
| Processor | Purpose | Data location |
|---|---|---|
| Anthropic | Automated processing - generates coaching responses from your content | United States |
| Stripe | Payment processing and subscription management | United States |
| Resend | Transactional email delivery (verification, password reset, billing) | United States |
| DigitalOcean | Cloud hosting and managed database. Your account and coaching data is stored on DigitalOcean infrastructure. | Australia (Sydney region) |
| Cloudflare | DNS, network routing, and DDoS protection | Global edge network |
Some of these processors are located outside Australia, primarily in the United States. Before disclosing personal information to an overseas recipient, we take reasonable steps to ensure the recipient handles it consistently with the Australian Privacy Principles, as required by APP 8. Under the Privacy Act, in most cases we remain accountable for how these overseas processors handle the personal information we disclose to them. By using the service, you acknowledge that your information is processed by these providers in the locations shown above.
7. What we do not do
- We do not sell your personal information to any third party.
- We do not share your coaching content with other users.
- We do not use your data for advertising or ad targeting.
- We do not run any third-party ad tracking scripts on the service.
8. Retention and deletion
We retain your personal information for as long as your account is active, and for a reasonable period afterwards only where needed to meet legal, accounting, tax, or fraud-prevention obligations (for example, billing records that tax law requires us to keep). When personal information is no longer needed for any purpose permitted by law, we take reasonable steps to delete or de-identify it (APP 11).
You may request deletion of your account and associated data at any time by contacting us at [email protected]. We will action deletion requests within a reasonable time, subject to the limited retention obligations described above.
9. Security and data breaches
We apply reasonable security measures to protect your personal information, including:
- Encryption of data in transit using TLS.
- Hashed storage of passwords using industry-standard algorithms.
- Per-account access controls so your coaching content is isolated to your account.
- Access controls limiting who can reach production systems and data.
- Regular review of our security practices.
No system is completely secure. If a data breach occurs that is likely to result in serious harm to you, we will comply with the Notifiable Data Breaches scheme under Part IIIC of the Privacy Act: we will assess the breach, and where it is an eligible data breach we will notify both you and the Office of the Australian Information Commissioner (OAIC) as required. If you believe your account has been compromised, contact us immediately at [email protected].
10. Your rights
Under the Privacy Act 1988 (Cth) and the Australian Privacy Principles, you have the right to:
- Access the personal information we hold about you (APP 12).
- Request correction of inaccurate, out-of-date, or incomplete personal information (APP 13).
- Request deletion of your personal information, subject to the legal retention obligations described above.
- Complain about a breach of the APPs to us, and if unresolved, to the OAIC.
If you access the service from outside Australia, additional data-protection laws may apply to you. Users in the European Economic Area or the United Kingdom may have further rights under the GDPR or UK GDPR (including access, erasure, portability, objection, and restriction). Contact us and we will deal with your request under the law that applies to you.
To exercise any of these rights, contact us at [email protected]. There is generally no charge to access your own information, and we will respond within a reasonable time.
11. Cookies and local storage
Gambit Tells uses browser localStorage to store your authentication token so you remain logged in between sessions. This is a functional necessity, not a tracking mechanism.
We do not use third-party tracking cookies, advertising cookies, or analytics scripts that profile your behaviour across websites.
12. Children
The Gambit Tells service is intended for users aged 18 and over. We do not knowingly collect personal information from anyone under 18. If you believe a person under 18 has created an account, contact us and we will delete it promptly.
13. Contact and complaints
For privacy-related questions or complaints, contact us at [email protected]. We will acknowledge your complaint and aim to resolve it within a reasonable time.
If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC). A privacy complaint to the OAIC must generally be made within 12 months of when you became aware of the issue.
14. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date at the top of this page. Continued use of the service after an update constitutes acceptance of the revised policy.