The short version
- Your holdings and tax documents are stored in Australia and encrypted at rest.
- We do not trade your personal information and we do not share it for advertising.
- You can export everything, or erase everything, from Your data, with no email required.
- Uploaded tax documents are erased on a retention clock once they have been processed.
Underly is an information service, not an adviser. Nothing here changes that. See the Disclaimer.
Who is collecting it
Seraco Pty Ltd (ACN 673 560 757, ABN 36 673 560 757) of Victoria, Australia is the entity responsible for the personal information described here. Privacy enquiries go through Contact.
What we collect, and why (APP 3 and APP 5)
- Identity and contact: your email address, and a display name if you give one. We need it to create your account, send one-time sign-in codes, and contact you about the service. Without it there is no account.
- Authentication: passkey public keys and session records. We never receive or store a password or a biometric; a passkey's private half stays on your device.
- Portfolio holdings: the tickers, units and values you record. This is what the look-through, exposure and income figures are computed from. It is the reason the service exists.
- Tax documents: the AMMA and distribution statements you upload, and the ATO-label components extracted from them. These are sensitive financial records and are treated as such: encrypted, access-logged, and erased on a retention clock.
- Billing: subscription status and the identifiers our payment processor gives us. Card numbers go to the processor and never reach Underly's servers.
- Technical: request logs (IP address, user agent, timestamps) kept for security and fault-finding, and an audit record of access to, export of and erasure of your data.
We collect this from you directly. Where a figure comes from a public source instead, such as issuer holdings files or ASX reference data, it is not personal information and is shown with its source and as-at date.
Purpose limitation
We use your personal information to run the service you asked for: computing your figures, organising your tax labels, authenticating you, billing you, supporting you, and keeping the service secure. We do not use your holdings to build products for third parties, and we do not profile you for advertising. If we ever want to use your information for a new purpose, we will ask first.
Email we send you (APP 7)
Two kinds, and they are governed differently. Account email, meaning sign-in codes, address confirmations and notices about your own data, is how the service works, so it is always sent and there is nothing to opt out of. Product email is everything else: a note if your account has no portfolio saved, a reminder when AMMA statements are issued, and a notice before a paid plan renews.
Every product email has an unsubscribe link that works without signing in, and your mail client's own unsubscribe control works too. Turning it off is honoured from the next send onwards, and the same switch is on Account → Your data if you change your mind. Your address is never traded, and nobody else emails you on our behalf.
Who we disclose it to (APP 6 and APP 8)
- Hosting: our Australian hosting provider, which holds the encrypted database and document storage.
- Email delivery: Resend, which sends sign-in codes and service email. It receives your email address and the message, nothing else, and processes them in the United States.
- Payments: Stripe, which receives your billing details directly and returns a customer identifier. Stripe processes payment information in the United States.
- Statement reading: Anthropic, whose models read the tax statements you upload. It receives the statement file and returns the figures it read from it; nothing else about your account goes with it, and it processes the file in the United States. This is the one disclosure that sends a sensitive financial record rather than a contact detail, which is why it happens only when you upload a statement, and why the extraction can be turned off without stopping the rest of the service.
Those three recipients are outside Australia (APP 8). We send each of them only what it needs to do its job, under terms that require it to protect the information and to use it solely to provide that service to us, and we remain accountable to you for it. Using the part of Underly that depends on one of them, such as signing in, paying, or having a statement read, involves that disclosure; the rest of the service does not.
We disclose personal information beyond that only where the law requires it, and where we are permitted to tell you, we will.
Where it is held, and how it is protected (APP 11)
- Databases and document storage are hosted in Australia.
- Holdings and tax documents are encrypted at rest with per-record authenticated encryption; keys are held separately from the data and rotated.
- Transport is HTTPS throughout. Sessions are cookie-based, HTTP-only and same-site.
- Access to production data is limited to the people who need it, and every access, export and erasure is recorded in an audit log.
- Backups are encrypted and are subject to the same retention clock.
How long we keep it
- Account and holdings: while your account is open, then erased when you close it.
- Uploaded tax documents: kept for the current financial year plus the ATO's five-year record-keeping window, or until you erase them, whichever comes first.
- Sign-in codes and expired sessions: purged automatically once they lapse.
- Audit records: kept for seven years, identified only by account identifier. These survive account closure because they are the record that the closure happened.
- Billing records: your plan, its status and the identifiers linking you to our payment processor are erased when you close your account. The invoices themselves are business records held by Stripe, which keeps them for the period Australian tax law requires.
- Email we have sent you: a record of which product emails have gone to your account and when, kept while your account is open and erased with it. It is what stops the same email reaching you twice, so it is kept for as long as it can still prevent one.
The current schedule and the purge job that enforces it are documented in the repository at docs/compliance.md.
Getting it, correcting it, erasing it (APP 12 and APP 13)
Your data gives you a machine-readable export of everything held about you, and a one-step erasure of your account and its contents. Both are immediate and both are logged. If you would rather ask a human, email Contact and we will respond within 30 days.
If something we hold is wrong, correct it in the app or tell us and we will fix it. If we disagree that it is wrong, we will note your correction request alongside the record.
If something goes wrong
We maintain a data-breach response plan under the Notifiable Data Breaches scheme. If a breach is likely to cause you serious harm, we will notify you and the Office of the Australian Information Commissioner as soon as practicable, and tell you plainly what happened, what was involved and what to do about it.
Complaints
Reach us through Contact and we will acknowledge within five business days and respond within 30 days. If our response does not settle it, you can take the complaint to the Office of the Australian Information Commissioner at oaic.gov.au.
Cookies
Underly sets a session cookie so you stay signed in, and a preference cookie for light/dark mode. There are no advertising or cross-site tracking cookies.
Visit counting
We count visits to our public pages so we know which of them people find useful. The software runs on our own servers alongside the rest of Underly, so no analytics company receives anything about your visit.
- It sets no cookies and assigns you no identifier. Repeat visits are not linked to each other beyond the day they happen, and never to your account.
- What is recorded is the public page address, the site that linked you to it, your browser and screen width, and the country your network resolves to.
- Pages inside your account are not counted at all: not the addresses, not the fact of the visit. Counting stops at the sign-in boundary.
- Campaign parameters in a link are kept, so we can tell an article from a newsletter. Every other query parameter is discarded before the count is recorded.
The counter runs on the same Australian servers as the rest of Underly, so nothing about your visit is disclosed to anyone overseas and the cross-border rules in APP 8 are not engaged by it.
Changes
We will give at least 30 days' notice by email before a material change to this policy takes effect, and keep the effective date above current.