Nonni Privacy Policy
Effective Date: 10 June 2026
Version: 1.0
Nonni is a product of CarePlans AI Pty Ltd (ABN 92 691 158 237) ("Nonni", "we", "us" or "our") — an artificial-intelligence-powered voice companion service that makes friendly, personalised check-in calls to older adults and others, to support connection and wellbeing. This Privacy Policy describes how we handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
Important warnings
Nonni is a companionship and wellbeing service — it is NOT a medical, emergency or monitoring service, and cannot reliably detect medical emergencies. Nonni may fail to recognise heart attacks, strokes, falls, injuries, medication errors, cognitive decline, suicidal ideation, or any other emergency. Never rely on Nonni for emergency detection or response. In an emergency, always call 000.
Scam warning: Nonni will NEVER ask for passwords, banking details, Medicare numbers, or payment via gift cards or wire transfers during a call. Report suspicious calls to us immediately.
1. Personal information we collect
Information you provide to us
When you or your authorised representative signs up for Nonni and uses the service, we collect:
- Contact information: name, email address, postal address, telephone number(s)
- Demographic information: date of birth, age, gender, city, state, postcode
- Account information: scheduled call times and preferences, conversation topics, language preferences, authentication methods, emergency contact details, consent documentation
- Conversation data: communications with Nonni, topics discussed, stories shared, preferences, interests, memories and reminiscences
- Sensitive information: health information, medications or treatments mentioned, disability status, religious or philosophical beliefs, cultural or ethnic background, and biometric information contained in voice recordings (if disclosed)
- Voice recordings: audio recordings of conversations with Nonni and their transcripts. These may contain voice biometric identifiers, which we treat as sensitive information.
Information from third parties
We may receive information about you from:
- Authorised representatives (family members, guardians, persons with power of attorney)
- Care entities (aged care facilities, home care agencies, healthcare providers), where applicable
- Service providers that help us deliver the service
2. How we use your personal information
Primary purposes
- Service delivery: making scheduled AI voice calls, personalising conversations, remembering previous conversations, and providing companionship and social interaction
- Communication: sending service-related notifications, responding to enquiries, and providing important security and incident updates
- Safety and wellbeing: surfacing signs of distress to your nominated contacts (note: this is not reliable and is not a substitute for human care), meeting mandatory reporting obligations, and helping prevent elder abuse, fraud and scams
Secondary purposes
- Service improvement: improving our own service and analysing usage patterns, using de-identified data where possible. Our AI providers operate under enterprise agreements that, by default, do not use your data to train their models.
- Account management: managing your account and preferences, processing payments and billing, and verifying identity to prevent fraud
- Legal compliance: complying with Australian laws, responding to lawful requests, and protecting rights, safety and property
3. How we share your personal information
We may share your personal information with:
- Authorised individuals: family members or contacts you designate, legal guardians or attorneys (with verification), and emergency contacts in urgent situations
- Care entities: where you are using Nonni through a provider — conversation summaries and wellbeing indicators (not medical assessments)
- Service providers and subprocessors: cloud hosting, AI technology partners (including Anthropic and Hume), transcription, payment processing (Stripe), email and analytics, and security services
- Legal and safety disclosures: to comply with Australian law, protect against fraud or security threats, and meet mandatory reporting obligations regarding abuse, neglect or risk of harm to vulnerable persons
A current list of our subprocessors is available at www.careplans.io/subprocessors.
4. Data retention
We retain personal information for as long as necessary to provide the service, comply with legal obligations, resolve disputes, and support legitimate business purposes. Specifically:
- Active accounts: information retained while the account is active
- Voice recordings: retained for 3 years unless deletion is requested earlier
- Biometric data: subject to enhanced retention controls and deletion rights
- After account closure: personal data deleted within 30 days, except where legal retention is required
- Financial records: 7 years, as required by tax law
- Incident records: 7 years for liability purposes
5. Data storage and security
Where your data is stored and processed
Your personal information is stored in AWS Sydney, Australia. Some AI processing currently occurs in the United States — our language provider (Anthropic) and voice/emotion provider (Hume) operate under enterprise agreements that, by default, prohibit using your data to train their models. We are progressively moving these providers to Zero Data Retention configurations. Other service providers may process limited data overseas where they operate. When we transfer personal information overseas, we take reasonable steps to ensure recipients are subject to protections comparable to the APPs.
Security measures
Technical controls:
- Encryption in transit (TLS 1.2+) and at rest (AES-256)
- Multi-factor authentication for system access
- Network segmentation, firewalls, and intrusion detection
- Regular security patching and secure deletion procedures
Organisational controls:
- Least-privilege access controls and confidentiality agreements
- Staff training on privacy and security
- Regular security assessments and reviews
- Essential Eight Maturity Level 3 controls implemented; our information security management system is aligned to ISO 27001:2022, with certification in progress
6. International data transfers
As described above, some service providers operate outside Australia (including the United States). When we transfer personal information overseas, we take reasonable steps to ensure recipients are bound by laws or agreements that provide protection comparable to the Australian Privacy Principles.
7. Your privacy rights
Under the Privacy Act 1988 and the Australian Privacy Principles, you have the right to:
- Access a copy of the personal information we hold about you (we respond within 30 days)
- Correct inaccurate or incomplete personal information
- Withdraw consent for certain uses of your information
- Data portability — receive your information in a structured, commonly used format
- Object to certain uses, including direct marketing and automated decision-making
- Request deletion, subject to legal retention requirements
- Human review of decisions made solely by automated processing that significantly affect you
Complaints process
Step 1 — Contact us: email privacy@careplans.io (response within 5 business days; resolution target 30 days).
Step 2 — External complaint: if unresolved, contact the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au, phone 1300 363 992, or enquiries@oaic.gov.au.
8. Automated decision-making
Nonni uses automated processing to generate conversational responses, personalise interactions over time, surface keywords that may suggest distress, and schedule calls. You have the right to request human review of automated decisions, to understand the logic involved, and to challenge decisions that significantly affect you.
9. Cookies and tracking technologies
Our website uses essential cookies (session management, security), and — with consent — analytics and functional cookies. You can control cookies through your browser settings.
10. Data breach response
In the event of an eligible data breach, we will notify affected individuals and the OAIC as required under the Notifiable Data Breaches scheme, and provide details of the breach, potential harm, and remediation steps.
11. Changes to this privacy policy
We may update this Privacy Policy from time to time. We will notify registered users of material changes by email and via a prominent website notice before the changes take effect.
12. How to contact us
CarePlans AI Pty Ltd
ABN: 92 691 158 237
- Privacy Officer: privacy@careplans.io
- Security incidents: security@careplans.io
- General enquiries: andrew@careplans.io
Address: 7 York Street, Gladesville, NSW 2111, Australia
Website: www.nonni.ai
Document control
Version: 1.0
Effective Date: 10 June 2026
Next Review Due: 10 December 2026
Complies with the Privacy Act 1988 (Cth), the Australian Privacy Principles, and the Notifiable Data Breaches scheme.