Scope and responsibility
BLOOMFORGE PTY LTD operates Axiom. In this policy, “Axiom”, “we”, “us”, and “our” refer to BLOOMFORGE PTY LTD, and “Service” means the Axiom website, application, and related support services.
We use the Australian Privacy Principles as the baseline for the practices described in this policy. Where the Privacy Act 1988 (Cth) applies to us, those principles are legal obligations. If a statutory small-business exemption applies, we follow the commitments in this published policy as our voluntary privacy standard.
Information we collect
Account and authentication information
- Email address, display name, account identifier, role, and account timestamps.
- The policy version, server timestamp, and signup method associated with your Terms, Privacy Policy, age, and guardian-permission acknowledgements.
- Authentication method and basic profile information received from Google or Microsoft if you choose their sign-in option.
- Passwords are handled by Supabase Auth. Axiom does not receive or store readable passwords.
- Profile image, selected subjects, preferences, and onboarding choices.
Learning and submission information
- Questions viewed or attempted, selected answers, typed working, marks, timing, feedback, and worked-attempt history.
- Photographs of handwritten work, writing-canvas strokes, graph sketches, graph coordinates, and typed asymptotes when you use those answer modes.
- Ratings, rating history, topic progress, XP, streaks, achievements, and daily activity.
- Saved (bookmarked) questions, timed-set and mock-paper sessions and results, and your in-app rewards, including in-app currency balance and transaction history.
- Unsubmitted work-in-progress saved locally in your browser so it can be restored after navigation or a refresh.
Classroom and school information
- If you join a class: the class, the name you enter when joining, the date you joined or left, your consent record, targets your teacher sets, task assignments, task answers and marks, teacher mark changes and comments, and re-mark requests.
- If you are a teacher or school administrator: your school and role, the classes you run, questions you write, import or share, documents you upload for import, AI marking-scheme and import usage, and a log of when you viewed student work or exported data.
Profile, social, and support information
- Display name, avatar, public ratings, friend count, and profile statistics.
- Friend requests, friendships, presence information, and direct-message content.
- Question reports, feedback, support emails, and related correspondence.
Subscription and payment information
- Plan, billing interval, subscription status, renewal or cancellation dates, and Stripe customer, subscription, and price identifiers.
- Stripe collects payment-card and payment-method details through Stripe Checkout. Axiom does not collect or store full card numbers or security codes.
Technical and security information
- IP address, browser user-agent, request route, timestamps, security and rate-limit events, and anonymous-session identifiers.
- Authentication cookies, an anonymous-session cookie or local token, and browser storage described in our Cookie Policy.
- Anonymous page-view and performance measurements from Vercel Analytics and Speed Insights. These tools are configured without account IDs, answers, messages, or email addresses.
- Usage information collected by Google Analytics, such as pages viewed, session and device information, approximate location, and referring site, linked to a pseudonymous cookie identifier rather than your Axiom account.
We do not intentionally collect health information, racial or ethnic origin, political opinions, religious beliefs, sexual orientation, or other sensitive information. Do not include unnecessary personal or sensitive information in answers, images, messages, or support requests.
How we collect information
We collect information:
- directly from you when you register, practise, upload work, communicate, or pay;
- automatically when your browser or device interacts with the Service;
- from Google or Microsoft when you use their authentication service;
- from Stripe about subscription and transaction status;
- from other users through friend requests, messages, reports, and shared interactions;
- from our service providers when they return authentication, delivery, or security results.
We do not obtain marketing profiles about users from data brokers, affiliate programmes, public databases, Facebook, or X.
How we use information
We use personal information where reasonably necessary to:
- create, authenticate, secure, and administer accounts;
- provide questions, marking, feedback, history, ratings, and adaptive difficulty;
- save preferences and restore unsubmitted work on the same browser;
- operate profiles, leaderboards, friendships, messaging, and presence features;
- operate progress rewards such as XP, streaks, and in-app currency;
- process subscriptions, confirm payments, and manage cancellations;
- send confirmation, password-reset, support, billing, security, and legal notices;
- respond to support, feedback, copyright, and privacy requests;
- enforce quotas and fair-use controls, investigate abuse, and protect users;
- diagnose faults, measure performance, and improve the Service using aggregated analysis;
- operate school accounts and classes, including class membership, targets, tasks, marking, gradebooks and exports;
- show teachers and school administrators the student information described in “Classroom and school accounts”;
- send classroom notices such as invitations, join decisions and contract reminders;
- comply with law and establish, exercise, or defend legal claims.
We will seek any consent required by law before using information for a materially different purpose. Service and security messages are separate from marketing messages. We do not currently send promotional marketing email.
AI-assisted marking and transcription
For non-multiple-choice marking and handwriting transcription, Axiom sends the relevant question, marking instructions or solution material, your submitted answer, and any answer image or graph evidence to OpenRouter. OpenRouter routes the request to the model selected in Axiom’s marking configuration. Current models may include Google Gemini and OpenAI-family models, including GPT-5.6 Luna.
We do not intentionally include your email address, display name, or account ID in a marking request. Information you write or photograph as part of an answer will, however, be included in that submission.
Our OpenRouter organisation is configured to reject model endpoints that OpenRouter does not designate as zero-data-retention for the enabled model families. This setting is designed to prevent request content being retained or used for model training by eligible endpoints. The request is still processed transiently to produce a result, and routing may use infrastructure operated by an upstream model provider or cloud provider.
AI feedback can be incomplete or wrong. It is used for educational practice and adaptive learning, not to make legal or similarly significant decisions about you. See our Disclaimer for further information.
For teachers, Axiom also uses AI to draft marking schemes and to turn uploaded documents into editable questions. In those requests we send the question content or the uploaded document, not student answers or student details. Uploaded Word documents are first converted to PDF by a converter Axiom runs on its own hosting. Teachers must check AI-drafted schemes and imported questions before using them.
Information visible to other users
Your display name, avatar, join date, friend count, subject ratings, and some profile or leaderboard information may be visible to other users. Additional activity statistics may be limited to you and accepted friends. Presence information is limited to you and your friends.
Direct messages are visible to their participants and may be accessed by authorised administrators when reasonably necessary for safety, moderation, support, or legal compliance. Answer images and detailed attempt history are not public. Avatars are stored as publicly retrievable files, so do not use an avatar you do not want others to see.
Classroom and school accounts
Schools can use Axiom under a School Services Agreement with us. A school’s administrators (shown in Axiom as the school owner) and teachers can create classes, and students join a class with a class code or an email invitation.
What your teacher and school can see. When you join a class, your teacher and your school’s administrators can see your Axiom username and the name you entered when joining; your practice from the time you joined that class, including each question you attempt, your answers, handwriting and the feedback you receive, for as long as Axiom keeps them; your ratings and topic progress; and all work you submit for that class’s tasks, including any marks your teacher changes. They cannot see your email address, your plan, your friends, your presence or your messages. You are asked to agree to this before you join.
Access records. Axiom records each time a teacher or administrator opens a student’s details, an attempt or an answer image, or exports class data. Your school’s administrators can review these records. They are deleted after one year.
Leaving a class. You can leave a class at any time. Your practice stops being visible to that class straight away. Work you submitted for the class’s tasks stays with the class until the task or class is deleted, or the school’s account ends. If you rejoin, visibility starts again from the new joining date.
Teachers. Teachers’ names and usernames are visible to students in their classes, and to other staff at their school. Questions a teacher shares to the school library can be used and copied by other teachers at that school. If a teacher leaves the school, their classes and questions pass to the school’s administrators.
The school’s role. The school decides whether to use Axiom with its students. The school is responsible for any permissions it needs under its own policies, for example parent or guardian permission. We handle classroom information to provide the service to the school, as described in this policy and our School Services Agreement with the school.
Classroom emails. We send classroom notices by email and in the app. Administrative notices, such as invitations and changes to a school’s status, are always sent. You can turn off other classroom emails in Settings.
Overseas processing
Axiom’s primary application services are configured in Australia where our selected plans and providers support that region. Some providers operate global networks or may process limited information outside Australia, particularly OpenRouter and its upstream model infrastructure, Stripe, Google, Microsoft, Resend, Sentry, and Zoho.
Likely overseas recipients or processing locations include the United States and countries in which Google, Microsoft, OpenRouter-approved zero-data-retention model endpoints, and their cloud subprocessors operate. AI routing is dynamic, so it is not practicable to list every possible country in advance. Transactional email may also be processed through provider infrastructure in Japan. We take reasonable steps appropriate to the service and risk, including provider due diligence, access controls, data minimisation, contractual terms, and zero-data-retention routing for AI requests.
Retention and deletion
We keep account and learning records while your account is active and for as long as they are reasonably needed for the purposes described above. Some information follows shorter operational schedules:
- inactive direct-message threads are scheduled for deletion after 7 days;
- detailed attempt replay data and answer-media references are scheduled for removal after 90 days (365 days for Axiom Max subscribers). If a Max subscription ends, replay data older than 90 days becomes inaccessible immediately and is removed after a further 30 days;
- practice, timed-set, and mock-paper session state is deleted 30 days after last activity (marked attempts remain in your history);
- Stripe webhook and rate-limit security events are scheduled for deletion after 90 days;
- anonymous sessions are scheduled for deletion after 30 days of inactivity;
- older rating history is downsampled after 24 months while preserving daily progress points;
- when a school’s School Services Agreement ends, its account becomes read-only for 30 days, and then the school, its classes, questions, tasks and task submissions (including answer images submitted for tasks) are deleted;
- answer images submitted for class tasks are kept with the task until it or the school is deleted, rather than following the replay schedule above;
- documents uploaded for import are deleted 30 days after the import finishes;
- classroom access records are deleted after one year;
- classroom email delivery records are deleted after 30 days, and invitation links are removed from them once the email is sent.
When you complete self-service account deletion, Axiom deletes the authentication account and associated application rows, asks Stripe to delete the customer or cancel the subscription, and attempts to remove answer images and avatars. Deleting a student account also deletes that student’s class memberships, targets and task submissions. A periodic orphan sweep is used if storage deletion is temporarily unavailable. Copies may remain for a limited time in provider backups or logs before their normal expiry.
We may retain the minimum information reasonably required for law, accounting, fraud and abuse prevention, disputes, or enforcement. For example, the email address of a user who deletes an account while actively banned may remain on an abuse-prevention blacklist. Irreversibly de-identified aggregate information is not personal information and may be retained.
Security
We use measures designed to protect information, including encrypted network connections, Supabase row-level security, private storage for answer images, server-side secrets, restricted administrative access, signed anonymous tokens, rate limits, bot protection, security headers, audit records, and restricted Redis credentials.
No online service is completely secure. You are responsible for protecting your account credentials and should tell us promptly if you suspect unauthorised access. If the Notifiable Data Breaches scheme applies and an eligible data breach occurs, we will assess and provide notifications required by law.
Children and young people
Axiom is designed for secondary students. You must be at least 13 to create an account. If you are under 18, you must have permission from a parent or legal guardian to use the Service and enter into our Terms of Service. Signup currently uses a self-attested age and guardian-permission confirmation rather than collecting identity documents. We may seek further confirmation where reasonably necessary and may close an account if we learn that the requirements are not met.
We minimise information used for educational purposes, do not use student data for targeted advertising, and restrict private submissions and messages by access controls. Young users should not share their address, school details, phone number, passwords, or other unnecessary identifying information in answers, profiles, or messages.
If you join a class, your teacher and school administrators can see the information described in “Classroom and school accounts”. Your school may require a parent or guardian’s permission for you to use Axiom in class. You can leave a class at any time.
Access, correction, deletion, and complaints
You can review practice history and profile information in Axiom, update certain profile and preference fields, and delete your account in Settings. You may also contact us to request access to or correction of personal information, ask a privacy question, or make a complaint.
We may need to verify your identity. Rights and exceptions depend on applicable law and we may refuse or limit a request where legally permitted, including to protect another person’s privacy or platform security. We aim to acknowledge and respond to privacy complaints within a reasonable period, ordinarily within 30 days.
If the Privacy Act applies and you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner.
Changes to this policy
We may update this policy as Axiom, our providers, or applicable law changes. We will update the date at the top. For material changes, we will provide reasonable notice by email and, where appropriate, an in-app notice before the change takes effect. Minor or clarifying updates may take effect when published.
Contact us
Email privacy and support enquiries to support@mail.axiomvce.com.
BLOOMFORGE PTY LTD433 Collins Street
Melbourne VIC 3000
Australia