Privacy
What 180 Degrees IT Solutions holds about your child in this app, who can see it, how long it is kept, and how to get every bit of it back.
Last updated 20 September 2026.
What we hold
APP 1.4(a)
Everything you put in the app about the child it is for. That means health information: diagnoses, medications and doses, seizures, bowel and sleep records, pressure areas, pain observations, photographs and video, appointments, and what anybody wrote about how a day went.
It also means information about the adults around them: names, email addresses, phone numbers, which house they work in, when they are rostered, what they are qualified to do, and what they recorded.
It includes home addresses, how to get into the house, Medicare and NDIS numbers, and funding amounts, because a support worker arriving at 6am needs the first two and the family needs the rest in one place.
Almost all of that is sensitive information under the Privacy Act, and health information about a child is the most sensitive category there is. We treat every field as if it were.
How we collect it and how we hold it
APP 1.4(b)
We collect it from you. Nobody types anything into this app about a family except that family and the people they have invited into their circle. We do not buy information, we do not import it from anywhere, and we do not receive it from your NDIS plan manager or your hospital.
Every family has their own separate part of the database, not a shared table with a family column. A query for one family physically cannot reach another one.
Every field that says anything about a person is encrypted before it is stored, under a key that belongs to that family alone. That key is itself encrypted under a master key. Photographs and video are encrypted on the phone before they are uploaded, so the unencrypted picture never exists on our servers at all.
The servers are in Australia and the backup copy of the master key is held in Microsoft Azure in the Australia East region.
Traffic between your phone and the app, and between the app and its database, is encrypted.
Why we hold it, and who can see it
APP 1.4(c)
To run the app for you. That is the only purpose. We do not use anything in here to build a product, train a model, generate statistics, or work out anything about your child.
Inside your circle, you decide who sees what. A parent can keep a support worker out of the funding, the house details, or the clinical record, and the app records both the decision and every time somebody was refused.
A parent or guardian always keeps access to the child’s own health record. Nobody in the circle can take that away, because that is a matter for a court, not a setting in an app.
We do not sell anything, we do not share anything with advertisers or analytics companies, and the app runs no third-party scripts at all. That last one is enforced by the browser rather than promised: the app tells your browser to refuse any script that did not come from us.
The uncomfortable part, said plainly: 180 Degrees IT holds the master key to these servers. Technically, we could decrypt what is in here. We do not, we log administrative access, and you should know that rather than find it out.
Whether anything goes overseas
APP 8
No part of the record leaves Australia. The app, the database and the photographs are on Australian servers, and the backup of the master key is in Microsoft Azure’s Australia East region.
If that ever changes, this policy will say so before it happens, and it will name the country.
How long we keep it, and how it is destroyed
APP 11
A health record about a child has to be kept until the later of two dates: seven years after the last thing written in it, and the day the child turns twenty-five. That is the law, not our preference, and the app shows you the exact date on the Settings screen.
Before that date we will refuse a request to delete the record, and we will tell you the date and the reason rather than simply saying no.
When it is destroyed, we destroy the family’s encryption key. That is stronger than deleting rows: it makes every copy unreadable at once, including copies in backups we can no longer reach into. The record that a destruction happened outlives the data, so you can always be told what happened to it.
A support worker’s own private notes are different. They carry no retention obligation and she can have them destroyed on request at any time.
Getting your copy
APP 12
Any time, without asking us. The Take your record screen produces one file with everything in it: the passport, every care log entry, the medication schedule, the emergency page and every photograph.
It is one ordinary web page file. It opens by double-clicking, in any browser, with nothing installed and no internet connection, and it does not need this app to exist.
It comes from the record on our servers, not from the phone you ask on, so it is the same complete file whichever device you use.
The file is not encrypted and it is not protected once it leaves. The app says so twice before it makes one.
Correcting something that is wrong
APP 13
Almost everything in the app can be edited by the people in the circle, without contacting us.
A care log entry that was recorded in error can be removed by a parent or guardian. The entry stops appearing everywhere in the app, and a record that it was removed, by whom and when, stays. A health record that could be silently rewritten would not be worth anything to a hospital.
If something cannot be corrected inside the app, write to us at the address below and we will correct it or tell you why we have not.
Complaining about how we handled your information
APP 1.4(e)
Write to [email protected]. Tell us what happened and what you want done about it.
We will acknowledge it within 5 business days and answer it properly within 30 days. If we need longer we will say so and say why, before the 30 days are up.
If you are not satisfied with our answer, you can take it to the Office of the Australian Information Commissioner at oaic.gov.au or on 1300 363 992. You do not need our permission and you do not have to come to us first.
If something goes wrong
APP 11.1
If information in this app is lost, or accessed by somebody who should not have it, and it is likely to cause serious harm, we have to tell you and the Office of the Australian Information Commissioner. That is the Notifiable Data Breaches scheme and it is not optional.
We will tell you what happened, what was involved, and what you should do, in plain words and without waiting to finish the investigation first.
Contact
180 Degrees IT Solutions, [email protected].