Scope and responsibility
BLOOMFORGE PTY LTD operates Axiom. In this policy, “Axiom”, “we”, “us”, and “our” refer to BLOOMFORGE PTY LTD, and “Service” means the Axiom website, application, and related support services.
We use the Australian Privacy Principles as the baseline for the practices described in this policy. Where the Privacy Act 1988 (Cth) applies to us, those principles are legal obligations. If a statutory small-business exemption applies, we follow the commitments in this published policy as our voluntary privacy standard.
Information we collect
Account and authentication information
- Email address, display name, account identifier, role, and account timestamps.
- The policy version, server timestamp, and signup method associated with your Terms, Privacy Policy, age, and guardian-permission acknowledgements.
- Authentication method and basic profile information received from Google or Microsoft if you choose their sign-in option.
- Passwords are handled by Supabase Auth. Axiom does not receive or store readable passwords.
- Profile image, selected subjects, preferences, and onboarding choices.
Learning and submission information
- Questions viewed or attempted, selected answers, typed working, marks, timing, feedback, and worked-attempt history.
- Photographs of handwritten work, writing-canvas strokes, graph sketches, graph coordinates, and typed asymptotes when you use those answer modes.
- Ratings, rating history, topic progress, XP, streaks, achievements, and daily activity.
- Unsubmitted work-in-progress saved locally in your browser so it can be restored after navigation or a refresh.
Profile, social, and support information
- Display name, avatar, public ratings, friend count, and profile statistics.
- Friend requests, friendships, presence information, and direct-message content.
- Question reports, feedback, support emails, and related correspondence.
Subscription and payment information
- Plan, billing interval, subscription status, renewal or cancellation dates, and Stripe customer, subscription, and price identifiers.
- Stripe collects payment-card and payment-method details through Stripe Checkout. Axiom does not collect or store full card numbers or security codes.
Technical and security information
- IP address, browser user-agent, request route, timestamps, security and rate-limit events, and anonymous-session identifiers.
- Authentication cookies, an anonymous-session cookie or local token, and browser storage described in our Cookie Policy.
- Anonymous page-view and performance measurements from Vercel Analytics and Speed Insights. These tools are configured without account IDs, answers, messages, or email addresses.
We do not intentionally collect health information, racial or ethnic origin, political opinions, religious beliefs, sexual orientation, or other sensitive information. Do not include unnecessary personal or sensitive information in answers, images, messages, or support requests.
How we collect information
We collect information:
- directly from you when you register, practise, upload work, communicate, or pay;
- automatically when your browser or device interacts with the Service;
- from Google or Microsoft when you use their authentication service;
- from Stripe about subscription and transaction status;
- from other users through friend requests, messages, reports, and shared interactions;
- from our service providers when they return authentication, delivery, or security results.
We do not obtain marketing profiles about users from data brokers, affiliate programmes, public databases, Facebook, or X.
How we use information
We use personal information where reasonably necessary to:
- create, authenticate, secure, and administer accounts;
- provide questions, marking, feedback, history, ratings, and adaptive difficulty;
- save preferences and restore unsubmitted work on the same browser;
- operate profiles, leaderboards, friendships, messaging, and presence features;
- process subscriptions, confirm payments, and manage cancellations;
- send confirmation, password-reset, support, billing, security, and legal notices;
- respond to support, feedback, copyright, and privacy requests;
- enforce quotas and fair-use controls, investigate abuse, and protect users;
- diagnose faults, measure performance, and improve the Service using aggregated analysis;
- comply with law and establish, exercise, or defend legal claims.
We will seek any consent required by law before using information for a materially different purpose. Service and security messages are separate from marketing messages. We do not currently send promotional marketing email.
AI-assisted marking and transcription
For non-multiple-choice marking and handwriting transcription, Axiom sends the relevant question, marking instructions or solution material, your submitted answer, and any answer image or graph evidence to OpenRouter. OpenRouter routes the request to the model selected in Axiom’s marking configuration. Current models may include Google Gemini and OpenAI-family models, including GPT-5.6 Luna.
We do not intentionally include your email address, display name, or account ID in a marking request. Information you write or photograph as part of an answer will, however, be included in that submission.
Our OpenRouter organisation is configured to reject model endpoints that OpenRouter does not designate as zero-data-retention for the enabled model families. This setting is designed to prevent request content being retained or used for model training by eligible endpoints. The request is still processed transiently to produce a result, and routing may use infrastructure operated by an upstream model provider or cloud provider.
AI feedback can be incomplete or wrong. It is used for educational practice and adaptive learning, not to make legal or similarly significant decisions about you. See our Disclaimer for further information.
Information visible to other users
Your display name, avatar, join date, friend count, subject ratings, and some profile or leaderboard information may be visible to other users. Additional activity statistics may be limited to you and accepted friends. Presence information is limited to you and your friends.
Direct messages are visible to their participants and may be accessed by authorised administrators when reasonably necessary for safety, moderation, support, or legal compliance. Answer images and detailed attempt history are not public. Avatars are stored as publicly retrievable files, so do not use an avatar you do not want others to see.
Overseas processing
Axiom’s primary application services are configured in Australia where our selected plans and providers support that region. Some providers operate global networks or may process limited information outside Australia, particularly OpenRouter and its upstream model infrastructure, Stripe, Google, Microsoft, Resend, and Zoho.
Likely overseas recipients or processing locations include the United States and countries in which Google, Microsoft, OpenRouter-approved zero-data-retention model endpoints, and their cloud subprocessors operate. AI routing is dynamic, so it is not practicable to list every possible country in advance. Transactional email may also be processed through provider infrastructure in Japan. We take reasonable steps appropriate to the service and risk, including provider due diligence, access controls, data minimisation, contractual terms, and zero-data-retention routing for AI requests.
Retention and deletion
We keep account and learning records while your account is active and for as long as they are reasonably needed for the purposes described above. Some information follows shorter operational schedules:
- inactive direct-message threads are scheduled for deletion after 7 days;
- detailed attempt replay data and answer-media references are scheduled for removal after 90 days;
- Stripe webhook and rate-limit security events are scheduled for deletion after 90 days;
- anonymous sessions are scheduled for deletion after 30 days of inactivity;
- older rating history is downsampled after 24 months while preserving daily progress points.
When you complete self-service account deletion, Axiom deletes the authentication account and associated application rows, asks Stripe to delete the customer or cancel the subscription, and attempts to remove answer images and avatars. A periodic orphan sweep is used if storage deletion is temporarily unavailable. Copies may remain for a limited time in provider backups or logs before their normal expiry.
We may retain the minimum information reasonably required for law, accounting, fraud and abuse prevention, disputes, or enforcement. For example, the email address of a user who deletes an account while actively banned may remain on an abuse-prevention blacklist. Irreversibly de-identified aggregate information is not personal information and may be retained.
Security
We use measures designed to protect information, including encrypted network connections, Supabase row-level security, private storage for answer images, server-side secrets, restricted administrative access, signed anonymous tokens, rate limits, bot protection, security headers, audit records, and restricted Redis credentials.
No online service is completely secure. You are responsible for protecting your account credentials and should tell us promptly if you suspect unauthorised access. If the Notifiable Data Breaches scheme applies and an eligible data breach occurs, we will assess and provide notifications required by law.
Children and young people
Axiom is designed for secondary students. You must be at least 13 to create an account. If you are under 18, you must have permission from a parent or legal guardian to use the Service and enter into our Terms of Service. Signup currently uses a self-attested age and guardian-permission confirmation rather than collecting identity documents. We may seek further confirmation where reasonably necessary and may close an account if we learn that the requirements are not met.
We minimise information used for educational purposes, do not use student data for targeted advertising, and restrict private submissions and messages by access controls. Young users should not share their address, school details, phone number, passwords, or other unnecessary identifying information in answers, profiles, or messages.
Access, correction, deletion, and complaints
You can review practice history and profile information in Axiom, update certain profile and preference fields, and delete your account in Settings. You may also contact us to request access to or correction of personal information, ask a privacy question, or make a complaint.
We may need to verify your identity. Rights and exceptions depend on applicable law and we may refuse or limit a request where legally permitted, including to protect another person’s privacy or platform security. We aim to acknowledge and respond to privacy complaints within a reasonable period, ordinarily within 30 days.
If the Privacy Act applies and you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner.
Changes to this policy
We may update this policy as Axiom, our providers, or applicable law changes. We will update the date at the top. For material changes, we will provide reasonable notice by email and, where appropriate, an in-app notice before the change takes effect. Minor or clarifying updates may take effect when published.
Contact us
Email privacy and support enquiries to support@mail.axiomvce.com.
BLOOMFORGE PTY LTDUnit 2706, 433 Collins Street
Melbourne VIC 3000
Australia