Legal
Privacy policy
tibbi collects behavioural data because that is the only way to show whether it works. This page sets out exactly what is collected, why, how long it is kept, and what you can get back.
In short: tibbi handles your data under the Privacy Act 1988 and the Australian Privacy Principles. Data is stored in Australia, and this pilot retention schedule applies in every account state.
What we collect, why, and for how long
| Data | Purpose | Retention |
|---|---|---|
| Account details and sign-in credentials | Signing in, recovery and operating your account | Until an approved deletion request is completed or the service closes. At pilot close you may actively choose to keep the service account; no response means deletion by 31 January 2027. Encrypted backups then expire within 30 days |
| Age-check record | Evidence that the 18+ control was applied; it does not contain your date of birth | Kept separately for 7 years from the date of the check, including after account closure |
| Operational activity: lessons, quizzes, token ledger, simulated bets, runs and cooldown events | Operating your account and showing its history | Kept with the service account until deletion. A separate consented research copy is anonymised at pilot close and retained for 5 years |
| Baseline and endline knowledge answers | Measuring knowledge change with the same instrument at sign-up and two weeks later | Linked by a revocable pilot code until 30 November 2026, so you can withdraw them before pilot close; then irreversibly anonymised and retained for 5 years |
| Real-world betting survey (E-37) | Voluntary, self-reported behaviour change outside tibbi | Separated from the account when saved and retained only as anonymous research data. Once saved, no individual response exists to export or withdraw |
| Support link views and taps | Checking whether help is visible and reachable | Collected as anonymous totals and included in the research dataset kept for 5 years after pilot close |
| Technical security and fault logs: truncated IP, device type, sign-in outcome and errors | Security, fraud prevention and fault investigation | 90 days |
| Privileged access audit trail: authorised staff account, sensitive record, timestamp and reason | Append-only accountability for reads in the restricted admin area; this is separate from technical logs | 12 months |
If you request deletion before pilot close, identifiable research records attached to your account are included in the request. Information already made anonymous cannot be traced back to you or restored to an account. If a retention period changes, this page is updated before the change takes effect.
Your rights
- Access and export — submit a request, re-authenticate and download a machine-readable file from your profile. The secure link expires after 7 days; the file is never sent as an email attachment.
- Delete — submit a request to remove your account and identifiable records. Live data is removed when processing completes and encrypted backups expire within 30 days. A one-way token ledger and append-only safety-control evidence remain without identity; the separate age-check record remains for 7 years from the date of the check.
- Withdraw research consent — baseline/endline answers remain linked and can be removed until pilot close on 30 November 2026. E-37 survey answers are anonymous at save: you can decline or stop before sending, but a saved answer has no identity link to pull back later.
What never happens
- Your data is never sold and never shared with advertising brokers.
- Sponsors never see individual behavioural data — only aggregate figures for their own campaign.
- Your data is never used to personalise odds. The odds are read-only market data.
- No push notification ever leads straight to simulated betting.