Privacy Policy
Last updated: 16 July 2026
1. About this Policy
Thoroughbreds AI Pty Ltd (“Thoroughbreds.AI”, “we”, “us” or “our”) provides software and analytical services for the thoroughbred breeding, racing and bloodstock industries.
This Privacy Policy explains how we collect, hold, use, disclose and protect information when you use our websites, applications, sale catalogue tools, stable management tools, analytical services and related support services (collectively, the “Service”).
The Service may hold commercially sensitive information that is not Personal Information, including notes, scores, shortlists, purchasing strategies and investment criteria. This Policy also explains how we handle that information as Customer Content.
2. Definitions
In this Policy:
- “Authorised User” means a person whom a Customer has authorised to access its account or workspace.
- “Customer” means the individual or organisation that subscribes to, registers for or is authorised to use the Service.
- “Customer Content” means information submitted to the Service by or for a Customer, including notes, scores, shortlists, comments, purchasing criteria, maximum bids, stable records, contacts, documents, photographs and other account data.
- “Customer-Specific Outputs” means recommendations, rankings, reports, summaries and similar outputs generated for a Customer using that Customer’s Customer Content.
- “Free Plan” means access to some or all of the Service without payment of a subscription fee.
- “Free Plan Improvement Data” means eligible structured information generated through use of a Free Plan, as described in section 7.
- “Personal Information” means information or an opinion about an identified individual, or an individual who is reasonably identifiable.
- “Premium Plan” means a paid, professional or enterprise subscription, regardless of the marketing name given to that plan.
- “Usage Data” means technical, operational and interaction information generated through use of the Service.
If you use the Service for an organisation, that organisation may control the Customer Content and Personal Information held within its account.
3. Information We Collect
3.1 Account and contact information
We may collect:
- name, email address and telephone number;
- company, organisation and role information;
- account settings and preferences;
- billing and subscription information;
- communications, support requests and feedback; and
- information required to authenticate and secure an account.
Payment card information is processed by our payment providers where applicable. We do not require payment or external checkout functionality within the iOS application.
3.2 Customer Content
Depending on the features used, Customer Content may include:
- sale catalogue annotations and markups;
- lot scores, assessments, comments, pass decisions and shortlists;
- purchasing criteria, maximum bids and assessment information;
- horse, ownership, stable, breeding, racing and training records;
- notes, documents, photographs and uploaded files;
- veterinary information relating to horses;
- contact and relationship records;
- reports and comparison results; and
- information entered into support or feedback workflows.
Some Customer Content may contain Personal Information about owners, employees, advisers, veterinarians, trainers, agents or other industry participants.
Customers are responsible for ensuring they are authorised to provide that information to us.
3.3 Information collected automatically
We may collect limited technical and operational information, including:
- device type, browser, operating system and application version;
- IP address and approximate location inferred from IP address;
- login, access and security events;
- error, diagnostic and performance information;
- pseudonymous product usage events; and
- cookies or session information required to provide and secure the Service.
We do not require precise GPS location for the Service’s core workflows.
3.4 Mobile device permissions
Where requested and authorised, our mobile applications may access:
- the camera, to attach photographs to records;
- the photo library, to select existing photographs; and
- add-only photo access, to save images at the user’s request.
These permissions can be managed through the device’s settings.
3.5 Information from other sources
We may receive information from:
- an organisation that creates or administers an account for an Authorised User;
- authentication, billing or integration providers;
- public and licensed thoroughbred industry sources;
- sale companies, racing bodies and other data licensors; and
- business partners where the individual or Customer has authorised the disclosure.
4. Ownership and Confidentiality of Customer Content
As between the Customer and Thoroughbreds.AI, the Customer or relevant rights holder retains ownership of Customer Content submitted to the Service.
We do not claim ownership of Customer Content merely because it is uploaded to or processed by the Service.
We process Customer Content only as reasonably necessary to:
- provide, maintain, secure and support the Service;
- provide Customer-Specific Outputs;
- comply with the Customer’s instructions;
- comply with law;
- exercise our rights under our Terms of Service; and
- use eligible Free Plan Improvement Data as described in this Policy.
We treat Customer Content and Customer-Specific Outputs as confidential. We do not make them available to unrelated customers or competitors unless:
- the Customer chooses to share them;
- access is granted to an Authorised User or team member;
- disclosure is necessary to a service provider acting on our instructions;
- disclosure is required by law; or
- the Customer otherwise authorises the disclosure.
Customer Content does not include Thoroughbreds.AI’s software, generic algorithms, analytical methods, platform designs or public, licensed or independently developed equine data. We retain our rights in those materials.
5. How We Use Information
We use Personal Information, Customer Content and Usage Data to:
- provide, operate and secure the Service;
- create, authenticate and administer accounts;
- support catalogue review, scoring, shortlisting and comparison workflows;
- provide stable, horse, contact and document-management features;
- generate Customer-Specific Outputs;
- provide customer support and respond to enquiries;
- process subscriptions and billing;
- send operational and security communications;
- detect fraud, abuse and unauthorised access;
- diagnose faults and maintain service reliability;
- comply with legal obligations;
- enforce our agreements;
- understand how the Service is used;
- develop, test and improve the Service; and
- use eligible Free Plan Improvement Data as described in section 7.
We may use aggregated or appropriately de-identified information to understand industry patterns, measure service performance and improve the Service, provided that the information does not identify a Customer or reasonably reveal its confidential information.
We do not sell Customer Content or Personal Information to data brokers.
We do not use Customer Content for third-party behavioural advertising.
6. Premium Plan Information
Customer Content submitted under a Premium Plan is not used to train or improve a model shared across unrelated customers unless:
- the Customer expressly agrees;
- the information has been appropriately aggregated or de-identified so that it no longer identifies the Customer or reasonably reveals its Customer Content; or
- the use is governed by a separate written agreement with the Customer.
Premium Plan Customer Content may be used to provide customer-specific functionality, including recommendations, rankings, reports, summaries and analytical outputs for the relevant Customer account.
Where Customer Content is used to personalise recommendations:
- the information is used only for the relevant Customer or authorised team;
- training data and model artefacts are scoped to that Customer;
- information from unrelated Premium Plan Customers is not pooled into the Customer’s model;
- the Customer’s model is not used to provide another Customer’s recommendations; and
- Customer-Specific Outputs are treated as confidential.
An organisation-wide model may only be used where authorised for the relevant organisation account.
7. Information Generated Through Free Plans
As part of the basis on which we make a Free Plan available, we may use limited structured information generated through use of that plan to develop, train, test, validate and improve:
- the Service;
- analytical and statistical methods;
- models and algorithms;
- recommendations and rankings;
- industry benchmarks; and
- other features that may benefit multiple users.
Free Plan Improvement Data may include structured inputs and interactions such as:
- numerical scores and ratings;
- classifications and structured assessment choices;
- feature interactions and usage patterns;
- public catalogue references; and
- relevant outcomes.
Unless we provide additional notice and obtain any authorisation required by law, Free Plan Improvement Data does not include:
- free-form notes or private messages;
- photographs, documents or attachments;
- catalogue markups;
- shortlists or pass decisions;
- maximum bids, purchasing criteria or investment strategies;
- contact or stable records;
- payment information; or
- information submitted under a Premium Plan.
Where reasonably practicable, we aggregate Free Plan Improvement Data or separate it from direct user and account identifiers before using it for these purposes.
Eligibility is determined by the plan under which the information was generated:
- information generated under a Premium Plan is not converted into Free Plan Improvement Data merely because an account is later downgraded;
- information generated after an account moves to a Free Plan may be eligible for use under this section;
- information generated after an account upgrades to a Premium Plan will be treated as Premium Plan information; and
- eligible information generated while an account was on a Free Plan may continue to be used after an upgrade, subject to this Policy and applicable law.
Aggregated statistics, benchmarks and model artefacts created from eligible Free Plan Improvement Data may continue to be used after an account is upgraded, cancelled or deleted, provided that they no longer identify the Customer or reasonably permit reconstruction of its Customer Content.
Information generated before this section became applicable to an account will be used only where we have provided appropriate notice and satisfied applicable legal requirements.
We do not sell Free Plan Improvement Data or provide it to third parties for advertising or training their general-purpose models.
We may provide additional notices or controls before introducing a materially different use of Free Plan Improvement Data.
8. Artificial Intelligence and Automated Processing
The Service may use deterministic software, statistical methods, machine-learning systems and AI-assisted features.
We do not authorise third-party AI providers to use Customer Content submitted through our business or API integrations to train their general-purpose models. We do not opt Customer Content into voluntary provider model-improvement programs.
Some selected features may use an approved third-party AI service acting as a processor on our behalf. Where this occurs:
- we send only the information reasonably necessary to provide the requested feature;
- the provider processes the information through an appropriate business or API service;
- the information is subject to applicable confidentiality, security and data-use restrictions;
- we do not authorise the provider to use it for general model training; and
- processing may occur outside Australia as described in section 13.
AI-assisted results are provided as analytical tools. They do not replace professional judgement and do not make legally binding or similarly significant decisions about individuals.
Our use of eligible Free Plan Improvement Data to improve our own Service is separate from permitting a third-party provider to train its general-purpose models.
9. Product Analytics, Diagnostics and Cookies
We use limited analytics and diagnostic information to understand feature adoption, identify errors, maintain security and improve reliability.
Within the authenticated Service:
- automatic capture of confidential page content and user interactions is disabled;
- session replay is disabled;
- direct identifiers such as names and email addresses are not intentionally included in product analytics;
- account identifiers used for analytics are pseudonymous;
- analytics events and properties are restricted; and
- notes, scores, shortlists, uploaded documents and other confidential screen content are not intentionally captured.
We do not use product analytics for third-party advertising, cross-app tracking or behavioural advertising.
Our public website may use cookies or similar technologies for essential functionality, preferences and limited website analytics.
Users can control non-essential cookies through their browser or available cookie controls. Disabling essential cookies may prevent parts of the Service from functioning.
10. Offline Device Storage
Some Service features support offline use at sales or other locations with limited connectivity.
When offline functionality is enabled:
- selected Customer Content may be stored locally on the user’s device;
- locally stored information is partitioned by account and authorised team;
- changing accounts or teams does not make another account’s offline data available;
- offline information expires under configured retention settings;
- users can clear Service data stored on the device; and
- some deployments may disable persistent offline storage.
The default offline retention period may vary by deployment and configuration.
Signing out does not necessarily delete offline data from the device. Users should use the device-data removal control when returning, transferring or disposing of a device.
Customers remain responsible for securing devices used to access the Service, including by using device passcodes, encryption and remote device-management controls where appropriate.
11. When We Disclose Information
11.1 Service providers and subprocessors
We use service providers for functions such as:
- cloud infrastructure and hosting;
- databases and file storage;
- authentication and account security;
- email and service communications;
- customer support and CRM;
- payment processing;
- limited product analytics and diagnostics;
- monitoring and error management; and
- approved AI processing where applicable.
These providers may access information only to perform services for us and are subject to applicable confidentiality, security and data-use obligations.
A current list of material subprocessors and their processing locations is available on request by contacting support@thoroughbreds.ai.
11.2 Teams and administered accounts
Customer Content may be accessible to Authorised Users, team members and administrators according to the permissions configured for the Customer’s account.
An organisation administrator may be able to access, manage, export or delete information held within an organisation-controlled account.
We do not disclose private Customer Content to another Customer unless the Customer has authorised that sharing.
11.3 Customer-authorised integrations
Where a Customer enables an integration or directs us to send information to another service, we may disclose the information required to operate that integration.
The third party’s terms and privacy policy may apply once information is placed under that party’s control.
11.4 Legal and safety requirements
We may disclose information where reasonably necessary to:
- comply with an applicable law, court order or lawful government request;
- protect the rights, safety or property of Thoroughbreds.AI, our Customers or others;
- investigate fraud, abuse or a security incident; or
- establish, exercise or defend legal claims.
Where lawful and practicable, we will notify the affected Customer of a request for its Customer Content.
11.5 Business transactions
Information may be transferred in connection with a financing, merger, acquisition, restructure or sale of all or part of our business.
Any recipient will be required to respect applicable confidentiality and privacy obligations relating to the transferred information.
11.6 No sale of information
We do not sell Customer Content or Personal Information.
12. Marketing Communications
We may send product updates, industry information or promotional communications where permitted by law.
Recipients can opt out of marketing communications using the unsubscribe link or by contacting support@thoroughbreds.ai.
Opting out of marketing does not prevent us from sending security, account, billing or other operational messages.
We do not use confidential Customer Content to target third-party advertising.
13. Overseas Processing and Disclosure
We are an Australian company, but some service providers operate infrastructure or support services outside Australia.
Overseas processing locations may include:
- the United States;
- the United Kingdom;
- member states of the European Economic Area;
- Singapore; and
- other countries identified in our current subprocessor information.
Before disclosing Personal Information to an overseas service provider, we take reasonable steps appropriate to the circumstances to require that the provider protects the information consistently with applicable privacy obligations.
The location in which information is stored may differ from the location from which a provider supplies support, security or operational services.
Enterprise Customers may contact us for information about available regional hosting or processing configurations.
Unless expressly agreed in writing, use of the Service does not guarantee that all processing will occur exclusively within Australia.
14. Security
We take reasonable technical and organisational steps designed to protect Personal Information and Customer Content against misuse, interference, loss and unauthorised access, modification or disclosure.
These measures may include:
- encryption in transit and at rest where supported by the relevant system;
- authentication and access controls;
- account and tenant isolation;
- scoped access to customer-specific data and model artefacts;
- restrictions on analytics and diagnostic collection;
- logging and monitoring designed to avoid confidential payloads;
- controlled access for personnel and service providers;
- secure development and change-review practices;
- backups and recovery controls; and
- incident-response procedures.
Access to Customer Content is limited to personnel and providers who require it for an authorised purpose.
No method of storage or transmission is completely secure.
If we become aware of an eligible data breach, we will assess and provide notifications in accordance with applicable law, including the Notifiable Data Breaches scheme where it applies.
15. Retention and Deletion
We retain Personal Information and Customer Content only for as long as reasonably necessary to:
- provide the Service;
- maintain account continuity and customer-requested backups;
- meet contractual and legal obligations;
- resolve disputes;
- prevent fraud or abuse; and
- maintain appropriate security and audit records.
Retention periods vary according to the type of information and the purpose for which it is held.
When information is no longer required for an authorised purpose, we take reasonable steps to delete it, de-identify it or place it beyond use.
A valid account-deletion request may cover:
- account and profile information;
- Customer Content held in active systems;
- customer-specific recommendations and model artefacts;
- cached results;
- files and attachments; and
- locally stored offline data, which must also be removed from relevant devices.
Information may remain temporarily in encrypted backups until those backups expire under their ordinary lifecycle.
We may retain billing, security, transaction and legal records for longer where required or permitted by law.
Deletion of underlying source information does not necessarily require deletion of aggregated statistics or model artefacts that no longer identify the Customer or reasonably permit reconstruction of its Customer Content.
16. Access, Correction and Privacy Rights
Subject to applicable law, an individual may request that we:
- provide access to Personal Information we hold about them;
- correct inaccurate or incomplete Personal Information;
- explain how their Personal Information has been used or disclosed;
- delete or de-identify information that is no longer required;
- restrict or object to certain processing; or
- provide information in a portable form where required by law or agreed as part of the Service.
Where information is held in an organisation-controlled account, we may refer the request to the relevant Customer or account administrator.
We may need to verify the requester’s identity and authority before processing a request.
If we cannot fulfil a request, we will explain the reason where required by law.
People in the European Economic Area or United Kingdom may have additional rights under applicable data-protection law.
Requests can be made to support@thoroughbreds.ai.
17. Privacy Complaints
A privacy complaint can be made by emailing support@thoroughbreds.ai with:
- contact details;
- a description of the concern;
- relevant dates and supporting information; and
- the outcome being sought.
We will acknowledge the complaint, investigate it and aim to provide a substantive response within 30 days.
If we require more time, we will explain why and provide an updated timeframe.
If the complainant is not satisfied with our response, they may contact the Office of the Australian Information Commissioner:
Website: https://www.oaic.gov.au
Telephone: 1300 363 992
18. Children
The Service is designed for professional and adult participants in the thoroughbred industry and is not directed to people under 18 years of age.
We do not knowingly permit children to create Service accounts.
If we learn that Personal Information has been collected from a child without appropriate authority, we will take reasonable steps to delete it.
19. Changes to this Policy
We may update this Privacy Policy as our Service, providers or legal obligations change.
We will publish the updated Policy and revise the “Last updated” date.
Where a change materially affects how we use or disclose Personal Information or Customer Content, we will provide additional notice and obtain any authorisation required by law or contract.
20. Contact Us
Questions, privacy requests and complaints can be directed to:
Thoroughbreds AI Pty Ltd
Email: support@thoroughbreds.ai
Website: https://www.thoroughbreds.ai
For questions about this policy, contact us at support@thoroughbreds.ai
Freshworks CRM and Web Chat
We use Freshworks CRM and Web Chat to understand public website visits, provide website chat and customer support, and manage information that people choose to submit through website forms, account signup, and profile settings. This may include your name, email address, organisation, optional mobile number, and communication consent choices. Freshworks processes this information on our behalf.
Thoroughbreds remains the source of truth for consent choices made in the app. You can update your mobile number or withdraw phone-call permission in Settings. We do not infer marketing-email consent from operational account or notification preferences.
Freshworks may use cookies or similar technologies to provide these services. For more information, see the Freshworks Privacy Notice.
%2520(2000%2520x%2520500%2520px).png&w=640&q=75&dpl=dpl_2ppTudPQfS9WGJhWNaZbr2buXvye)