Last updated: 18 August 2026
Your SupportFlow records stay on your device by default. There is no SupportFlow user account and no central database operated by the developer that stores your participant records, shift notes, invoices or other work records.
SupportFlow™ is hosted using Netlify. When you access the app, Netlify may process ordinary technical information required to deliver and secure the app, such as your IP address, browser or device information and web requests. Your participant records are not intentionally sent to Netlify as part of storing or managing them in SupportFlow.
One optional feature, Claimable, sends the question you type to Anthropic's API when you use the deduction checker. Claimable is separate from the app's locally stored participant records and is designed not to access or construct questions from those records. Do not enter participant names, NDIS numbers, health information or other personal information into Claimable.
Other optional actions, such as creating a backup, sharing a shift note or contacting support, can also cause information to leave your device. These are explained below and occur when you choose to use them.
This short version is an overview. The full policy below explains how information is handled.
This policy covers SupportFlow™ (the app), provided by its developer, contactable at globalappsai@gmail.com.
It applies whether you use the app on a phone, tablet or desktop browser, and whether you are using a production release or authorised testing build.
SupportFlow™ is designed for support workers, including sole traders, who may record information about NDIS participants.
As the support worker entering information into the app, you remain responsible for ensuring that you are authorised to collect, store, use and disclose the participant information you enter into SupportFlow, including under any applicable consent, service agreement or other authority.
This policy explains how SupportFlow handles information. It does not establish or replace your own authority or legal obligations concerning participant information.
Because SupportFlow may be used to record sensitive and health-related information, the app has been designed with the standards of the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth) in mind.
The privacy obligations applying to an individual support worker or business depend on their particular circumstances.
Information you enter about yourself may include:
Information you enter about participants may include:
Shift notes and other records may contain sensitive or health-related information concerning a participant's disability, circumstances or support needs.
Information may include:
SupportFlow may store records including:
Your SupportFlow records are stored locally on your device using the app's local data storage.
There is:
Under normal operation, the developer cannot view your locally stored participant records, shifts, invoices, expenses or notes.
This local-first design is intentional and is intended to reduce unnecessary central collection of participant information.
SupportFlow does not operate a central participant-record database or account synchronisation service. During onboarding, the user connects their own Google Drive for encrypted backups. SupportFlow encrypts the backup on the device before upload. Google stores the encrypted backup file in the user’s Drive; the SupportFlow backup password is not sent with the file. If SupportFlow later introduces central storage or account synchronisation, this privacy policy will be updated before that feature is introduced.
When you connect Google Drive, SupportFlow requests access for the backup files the app creates or uses. This access is used only to create, find, update and restore SupportFlow backup files in your Google Drive. SupportFlow does not request unrestricted access to browse or manage unrelated files in your Drive.
Before upload, the backup is encrypted on your device. Google receives and stores the encrypted backup file in your Google Drive. Your SupportFlow backup password is not included in the backup file or sent to Google. When you restore a backup, the encrypted file is retrieved from your Drive and decrypted on your device after you enter the correct backup password.
You can disconnect SupportFlow from Google through your Google Account permissions. Disconnecting stops future Drive access but does not automatically delete backup files already stored in your Drive.
SupportFlow™ is hosted using Netlify, a third-party web hosting and application delivery provider.
When you open or use SupportFlow, your device must communicate with Netlify's infrastructure so that the application can be delivered to your device.
As part of operating its hosting infrastructure, Netlify may process technical information associated with web requests, such as:
This technical hosting information is separate from the participant and business records you store inside SupportFlow.
SupportFlow does not intentionally transmit participant names, NDIS numbers, shift notes, invoices or other locally stored participant records to Netlify merely because the app is hosted there.
Netlify handles information processed through its infrastructure in accordance with its own applicable privacy, security and data-processing terms.
Although your SupportFlow records are stored locally by default, certain actions can cause information to leave your device.
Claimable is an optional deduction-checking feature.
When you submit a question through Claimable, the text you type is sent to Anthropic PBC through Anthropic's API so that the feature can generate a response.
This runtime API use is separate from Anthropic's earlier role as a development tool used to help build SupportFlow.
What Claimable sends:
What Claimable is designed not to send:
Claimable is designed not to read participant records or automatically construct questions from those records.
Do not enter participant names, NDIS numbers, health information or other personal information into Claimable. Ask the deduction question in general terms.
Anthropic is a United States company and API requests may be processed outside Australia. Anthropic handles API data under its own applicable privacy, security and commercial API terms.
The developer does not intentionally authorise participant records to be sent to Anthropic through Claimable.
If Claimable is unavailable or disabled in a particular build, no Claimable API request is sent.
When you create a SupportFlow backup, the backup file is encrypted on your device using AES-256 and a passphrase you choose before the encrypted backup file is exported.
You decide what happens to that file. For example, you may:
The developer does not receive a copy of your backup as part of this process.
Your backup passphrase is not transmitted to or stored by the developer.
If you lose your backup passphrase, the developer cannot recover or decrypt the backup for you.
If you choose to send or store the encrypted backup using another service, that provider's own privacy and data-handling terms apply.
If you choose to share or send a shift note or other record, SupportFlow uses the sharing or communication options available on your device.
You choose what information is shared and who receives it.
Where the app provides a choice between identifying and less-identifying information, you should select the minimum amount of participant information reasonably necessary for the purpose.
The developer does not automatically receive a copy of information you share with another person.
If you choose to contact the developer using a feedback or support feature, the information you decide to include in that communication will be sent to the developer.
Where the app opens your own email application, nothing is sent until you choose to send the message.
Feedback or support communications may contain basic technical information such as app version, device type, browser information or screen information where this is included to assist with troubleshooting.
Do not include participant names, NDIS numbers, health information or other unnecessary participant information in feedback or support messages.
Support and feedback emails may be retained for as long as reasonably necessary to investigate the issue, respond to you and improve the app.
Claude, an AI system made by Anthropic, was used by the developer as a coding and writing tool during development of SupportFlow, including assistance with code, app copy, legal documents and design assets.
This development-time use is separate from Claimable's runtime use of Anthropic's API.
No real participant records, real support-worker business records or production user information were intentionally provided to Claude or Anthropic during development. Development and testing used fictional or example information created for that purpose.
Claude does not have ongoing access to the deployed app, its users or the locally stored records held on their devices.
Under the current version described by this policy, SupportFlow does not:
Claimable does send the question entered by the user to Anthropic's API when that optional feature is used, as described in section 5.1.
SupportFlow will only request device permissions where they are necessary for a feature you choose to use.
Because your SupportFlow records are stored locally, the security of your information depends partly on the security of your device.
Where enabled, SupportFlow's optional PIN or biometric lock controls access to the app.
A 4 or 6 digit PIN is hashed using PBKDF2 before storage and is not stored or recoverable by the developer in plain text.
Where supported by the device and app configuration, fingerprint or facial authentication may also be used.
The PIN or biometric lock protects access to the app. It should not be interpreted as encryption of the underlying locally stored records.
SupportFlow's locally stored records are not independently encrypted at rest by the app in the current version.
SupportFlow therefore relies partly on the security protections provided by your phone, tablet or computer.
You should protect your device using appropriate measures such as:
Backup files created using SupportFlow's encrypted backup feature are encrypted using AES-256 before export, as described in section 5.2.
The developer does not operate a central database containing SupportFlow participant records. This reduces the amount of participant information held centrally by the developer.
Because participant records are stored locally, the developer cannot detect whether your device has been lost, stolen or accessed without your permission.
If a device containing participant information is lost, stolen or compromised, you should promptly:
The Notifiable Data Breaches scheme under the Privacy Act 1988 imposes notification requirements in certain circumstances where an entity covered by the Act experiences an eligible data breach likely to result in serious harm.
Whether those requirements apply depends on the circumstances and the legal obligations applying to the relevant person or organisation.
If the developer experiences a breach involving information actually held by the developer, such as support correspondence, the developer will assess and respond to the incident and make any notifications required by applicable law.
Because your operational records are stored locally on your device, you have direct access to those records through SupportFlow.
You can correct or delete records using the functions provided by the app.
Where export functionality is available, you may also export your records.
The developer generally cannot retrieve, correct or delete your locally stored participant records because the developer does not possess them.
If you have sent the developer a support or feedback email containing personal information, you may request deletion of information held by the developer by contacting:
globalappsai@gmail.com
Information sent through Claimable is handled by Anthropic under its applicable API data-handling terms.
The two main circumstances in which overseas processing may occur are:
1. Netlify hosting: Netlify operates international infrastructure and may process technical hosting information outside Australia as part of delivering and securing the application. 2. Claimable: When you choose to use Claimable, the question you type is sent to Anthropic's API. Anthropic is a United States company and the request may be processed outside Australia.
This does not mean your locally stored participant database is uploaded to either provider.
You may also choose to use third-party services to store or transmit information exported from SupportFlow, such as your own cloud-storage, email, file-sharing or device-backup service.
Those services operate under their own privacy and data-handling terms.
SupportFlow is intended for adult support workers and is not directed at children as users of the app.
A support worker may, however, provide services to an NDIS participant who is under 18 and may enter information relating to that participant.
Information concerning a participant under 18 should be handled with the same care as other participant information and in accordance with the support worker's applicable legal, consent, service-agreement and NDIS obligations.
Because your SupportFlow records are stored locally on your device, you control their retention.
SupportFlow does not automatically delete your records merely because a particular period has passed.
You are responsible for retaining records for any period required by taxation, NDIS, business, contractual or other applicable requirements.
The Australian Taxation Office generally requires most business records to be retained for five years, although different or longer retention periods can apply to particular records or circumstances.
Information actually received by the developer, such as feedback or support correspondence, will be retained only for as long as reasonably necessary for the purpose for which it was received or as otherwise required by law.
If you believe your privacy, or a participant's privacy, has not been handled properly in connection with SupportFlow, contact the developer:
Email: globalappsai@gmail.com Subject: Privacy complaint
The developer will investigate and respond within a reasonable period.
Depending on the circumstances and applicable law, you may also have the right to make a complaint to the Office of the Australian Information Commissioner (OAIC).
OAIC website: oaic.gov.au Phone: 1300 363 992
NDIS-related privacy or information-handling concerns may also involve obligations administered by the NDIS Quality and Safeguards Commission, depending on the circumstances.
SupportFlow may change over time.
If a future change materially affects how personal information is collected, stored, transmitted or disclosed, this privacy policy will be updated accordingly.
The updated policy will display a revised date.
Where appropriate, a notice will also be displayed within the app.
If a new optional feature involves external storage, synchronisation, artificial intelligence processing or another third-party service, the relevant information handling will be explained before or when that feature is introduced.
Developer: SupportFlow™ Email: globalappsai@gmail.com
This policy describes SupportFlow™'s data-handling practices as accurately as possible. It does not constitute legal advice to support workers about their individual privacy, NDIS, taxation, record-keeping or service-provider obligations. Those obligations may vary according to individual circumstances, applicable legislation, NDIS requirements and agreements with participants.