Legal

Privacy Policy

This Policy explains how Ntense.AI handles personal information across our website, AI features, projects, billing, cloud workspaces and connected local devices.

Effective 16 September 2026

Ntense.AI (“Ntense”, “we”, “us” or “our”) is responsible for the personal information described in this Policy. This Policy should be read with our Terms of Use.

1. Information we collect

  • Waitlist and contact information: name, email, persona, enquiry details and communication history.
  • Account information: GitHub identifier, login, name, email, avatar and profile URL.
  • Learning and career information: goals, selected roles, knowledge progress, assessments, interview responses, certifications and learning history.
  • User Work: prompts, code, project submissions, files, messages, feedback, showcases, workspace content and AI-assisted outputs.
  • Billing information: plan, subscription, payment status, transaction and invoice identifiers. Payment processors handle full card details; we generally do not store them.
  • Technical and usage information: IP address, browser/device information, session and authentication events, API-key metadata, model usage, logs, workspace status, security events and approximate location derived from access information.
  • Connected-device and tunnel information: when you enable remote access, device and runtime details, commands and terminal output, files accessed or transferred, browser content and debugging data, and traffic routed through the services you enable. The information involved depends on your configuration, permissions and actions.
  • Preferences: notification, privacy, workspace and marketing choices.

2. How we collect information

We collect information directly from you, automatically when you use the service, from your cloud workspace and API activity, and from providers you connect or transact with. These providers may include GitHub, Stripe, AWS infrastructure and configured AI/model providers.

If you provide information about another person, you must have permission to do so and tell them about this Policy where required.

3. Why we use information

  • provide accounts, role-based learning, assessments, projects, certificates, API access and workspaces;
  • personalise recommendations and evaluate skills and progress;
  • process payments, subscriptions and credits;
  • operate AI features and send prompts, context and outputs to configured model providers;
  • secure the service, prevent abuse, investigate incidents and enforce our Terms;
  • communicate about access, service changes, support, security and transactions;
  • send marketing where you consent or where otherwise permitted, with an opt-out;
  • analyse, research, develop and improve our services and commercial products;
  • comply with legal obligations and protect legal rights.

4. User Work and commercial use

Our Terms of Use give Ntense a broad default licence to use and commercialise User Work, reflecting that many project ideas and instructions originate from Ntense as an AI-native accelerator. If you and Ntense agree in writing to opt an existing or private project out of that default licence (see the Terms, “Opting out for existing or private projects”), we will handle the excluded User Work accordingly, alongside any personal information it contains. Where User Work contains personal information, we handle that personal information under this Policy and applicable privacy law. We may de-identify or aggregate information for analytics, research, product development and commercial purposes.

Do not include passwords, API secrets, regulated information, confidential client/employer data, or unnecessary sensitive information in prompts, assignments, messages or workspaces.

5. AI and automated processing

Ntense uses AI to conduct interviews, generate feedback and content, recommend career roles and learning work, assist work, and analyse knowledge and usage. Inputs may include your messages, goals, selected role, project context and prior answers; outputs and evaluation signals may be stored with your account.

Large language models and other AI systems can generate incorrect or fabricated information (“hallucinations”), including information about individuals. Ntense cannot predict or control every model response or eliminate these errors. Information about an identified or reasonably identifiable person remains personal information even if generated by AI or inaccurate, and we handle it under this Policy and applicable privacy law.

Verify AI output before relying on it or sharing it. Decisions with significant effects should not rely solely on automated output. You may contact us to request access to or correction of personal information, ask how an AI-assisted assessment was used, or request reasonable human review where available. AI limitations do not remove Ntense’s obligations to protect personal information and take reasonable steps concerning its accuracy where required by law.

Local execution and data transfer. Running software on your own device does not mean that all information remains on that device. When you enable an agent, browser connection or tunnel, relevant commands, outputs, selected files, browser data or application traffic may pass between your device and the Workspace. Information used as AI context may also be sent to configured model providers. Automated actions can disclose personal information or credentials available within the access you grant. Do not assume that sensitive content in files, browser sessions or command output will be detected or removed automatically.

6. When we disclose information

  • Service providers: cloud hosting, storage, email, authentication, payments, analytics, support, security and AI/model providers, only as needed for their services.
  • Other users and the public: information you publish in public profiles, showcases, public projects or shared collaboration areas.
  • Legal and safety recipients: regulators, courts, law enforcement or affected parties where reasonably necessary or required by law.
  • Business transactions: advisers and a buyer, investor or successor in a merger, financing, restructure or sale, subject to appropriate safeguards.

We do not sell payment-card details or account credentials. Commercial rights in User Work are governed by the Terms.

7. Overseas handling

Our providers and infrastructure may process information outside Australia, particularly in the United States and other countries where GitHub, Stripe, AWS and AI/model providers operate. Privacy protections in those countries may differ from Australian law. We take reasonable steps appropriate to the service and applicable law when selecting and managing providers.

8. Cookies and similar technologies

We use cookies and similar storage for authentication, security, onboarding intent, internal preview access, preferences and core service operation. Some analytics or third-party integrations may also use these technologies. Blocking essential cookies may prevent login or other features from working.

9. Security and retention

We use administrative, technical and physical safeguards designed to protect information, including hashed credentials, access controls, audit logs and restricted administrative tools. No system is completely secure, and you must protect your GitHub account, sessions and API keys.

We strongly recommend an isolated local sandbox, such as a dedicated virtual machine or a suitably restricted container, for AI-generated code and remote-control tools. Use only the data and permissions needed for the task, keep sensitive information and production credentials outside that environment, maintain backups, and stop connections or revoke access when no longer needed. A tunnel is not itself a sandbox, and isolation does not prevent information you choose to transmit from reaching the Workspace or configured providers.

We retain information for as long as needed to provide the service, maintain security and records, resolve disputes, enforce agreements and meet legal obligations. Retention varies by record type. Account deletion removes access, revokes credentials and anonymises or deletes information as described in the product; limited financial, project, security, backup or legal records may remain where necessary.

The Terms of Use address software supplied “as is”, AI and execution risks, and limitations of liability. Those provisions do not waive your privacy rights or Ntense’s obligations under applicable law.

10. Access, correction, deletion and choices

You can update certain information and preferences in the dashboard. You may request access to or correction of personal information, ask questions, withdraw marketing consent, or request account deletion through Settings or our contact page. We may need to verify your identity and may retain information where permitted or required by law.

Transactional, access and security messages are necessary to provide the service and are not treated as optional marketing.

11. Children

Ntense is not directed to children under 13. Users under 18 require parent or guardian permission and supervision. If you believe a child has provided personal information without appropriate permission, contact us.

12. Questions and complaints

Contact us through our contact page with “Privacy” as the topic. Include enough detail for us to investigate. We aim to acknowledge and respond within a reasonable period.

If you are not satisfied with our response and Australian privacy law applies, you may be able to complain to the Office of the Australian Information Commissioner at oaic.gov.au.

13. Changes to this Policy

We may update this Policy as our service or legal obligations change. We will publish the current version here and take reasonable steps to notify users of material changes where required.