Privacy Policy
Last Updated: 11 September 2026
1. Data Controller
Daniel Busch Dental Care Pty Ltd (ABN 71 616 422 229), Queensland, Australia, operating as G6Solver (“G6”, “we”, “us”), is the data controller for personal data collected through the G6Solver platform and website. For data you pass to G6 tools via the MCP protocol, G6 acts as a data processor on your behalf.
Contact: [email protected]
2. Information We Collect
- Account Information — name, email address, username, password (hashed and salted).
- Payment Information — processed via Stripe. We store your Stripe customer ID and subscription status. We do not store full card details.
- Usage Data — IP address, browser type, device information, session logs, tool invocation counts.
- Hardware Fingerprint — a SHA-256 hash derived from device characteristics (CPU core count, screen resolution, timezone, browser identity) used solely for single-device license enforcement. Only the irreversible hash is stored; raw device characteristics are not retained.
- API Key Metadata — API key ID, tier, creation date, last-used timestamp.
- MCP Tool Data — the request text and any context you send to solver tools are retained as part of your run history, along with run status, timing, token counts and cost. The separate cross-session learning record keeps only a one-way digest of your request rather than its text. See Sections 7 and 10.
- Cookies — authentication tokens and session continuity (see Section 13).
Important: We do not track or store session content from our reliability infrastructure unless you explicitly share it with us for support.
3. Special Category Data
We do not collect health data from you. G6Solver includes a duty_of_care component, which is a building block for developers who need one inside their own AI application. It is not part of any G6Solver plan and is not available on our hosted service, so there is no route by which health data reaches us through it.
If you build duty_of_care into your own application, you are the controller for any health data your own users provide, and obtaining consent and handling that data lawfully is your responsibility. That data does not come to us.
Correction, 13 September 2026: an earlier version of this policy said G6 may process special category health data, including responses to mental health screening instruments, if you used that component. That was wrong. The component is in no plan and on no server of ours, and this section previously disclosed processing that could not occur.
4. Lawful Bases for Processing
Which law applies. G6Solver is an Australian business, and the law governing how we handle your personal information is the Privacy Act 1988 (Cth) and the Australian Privacy Principles. We do not currently offer this service to customers in the EU, the EEA or the UK. We still set out our lawful bases in the GDPR’s terms below, and hold ourselves to the GDPR’s standard throughout this policy, for two reasons: our legal advice is that meeting the GDPR meets the Australian requirements, and we may offer the service in those markets in future. If we do, the GDPR will apply to us directly rather than by choice.
On that basis, we process personal data under the following lawful bases (GDPR Article 6):
- Contract (Art. 6(1)(b)) — account management, service delivery, payment processing, API key provisioning.
- Consent (Art. 6(1)(a)) — optional marketing communications.
- Legitimate Interests (Art. 6(1)(f)) — security monitoring, fraud prevention, service improvement, analytics. Our legitimate interests are: maintaining platform security, preventing abuse, and improving service reliability.
- Legal Obligation (Art. 6(1)(c)) — tax records, regulatory compliance, responding to lawful data requests.
5. How We Use Your Information
- Provide and operate services.
- Manage accounts and authentication.
- Process payments and licensing.
- Improve performance and security.
- Respond to support requests.
- Comply with legal obligations.
6. Storage and Security
Account data and billing information are stored on our servers using industry-standard encryption (Fernet-based at rest, TLS in transit). Database backups are encrypted at rest. Running a solver task writes durable records — see Sections 7 and 10 for what those contain and how long they are kept; that write happens on every run and is not optional.
7. MCP Data Processing
When you use G6Solver via the MCP protocol (e.g. through Claude Code), the following data is processed:
- Tool inputs — parameters you send to MCP tools are processed server-side. For solver runs, your request text and any context you supply are stored as part of your run history (run record, project state, event log and the case bank used to recognise similar problems later), and persist across sessions. The separate cross-session learning record stores a one-way digest of your request rather than its text.
- Reuse of stored requests — a stored request may be matched against a later run of yours to reuse a prior approach, which can include sending the earlier request text to the model provider named in Section 9.
- API key metadata — your API key ID, tier, and last-used timestamp are logged for rate limiting and billing.
- Usage metrics — tool invocation counts and billing-relevant usage records are stored for account and license purposes.
- Security audit logging — we do not log the content of your tool inputs or outputs for marketing or analytics purposes. Minimal metadata (tool name, timestamp, API key ID, success/failure status) is logged for security auditing and rate limiting. The durable record of this is your tool-call log, which we delete after 365 days on a daily job. The security gateway also keeps an in-memory audit log for the life of a server process; it is not written to disk and does not survive a restart.
Onward transfer: When a G6 tool invokes an LLM, your tool inputs may be forwarded to the LLM provider’s API (see Section 8). Your source code files remain local — only data you explicitly pass to tools leaves your machine.
8. International Transfers & Third-Party Services
G6 shares data with the recipients below. Several of them are located outside Australia, including in the United States.
- LLM providers — Anthropic, OpenAI, OpenRouter (tool inputs forwarded for AI processing).
- Payment processing — Stripe (billing and subscription data).
- Hosting — Google Cloud (our servers and databases, in the United States), Cloudflare (DDoS mitigation, CDN).
- Email delivery — Zoho (account emails such as address verification and password resets, sent through Zoho’s Australian service).
- Error monitoring — Sentry (error reports from our servers).
- Sign-in providers — Google and GitHub, only if you choose to sign in with them (see below).
- Source hosting — GitHub/Microsoft (code repository).
Signing in with Google or GitHub: If you sign in with Google, Google gives us your name, email address, profile picture and Google account ID; we ask Google for nothing else. If you sign in with GitHub, GitHub gives us your email address and public profile. We use this to create your account and sign you in, and your email address becomes your account email. We store it with your account, do not sell it, and share it only as described in this policy. We do not keep a Google or GitHub access token after you sign in.
Safeguards: Several of the recipients above are outside Australia, including in the United States. Australian Privacy Principle 8 requires us to take reasonable steps before personal information is disclosed overseas. The steps we take are: using established providers who publish their own privacy and security commitments and are bound by them; sending each recipient only the data that part of the service needs; and naming each recipient and its location here, so you can read their policies and decide for yourself.
Correction, 13 September 2026: this section previously said international transfers were “protected by Standard Contractual Clauses (SCCs) as approved by the European Commission”, and that they “comply with Australian Privacy Principle 8”. Both statements have been removed. We hold no record of an executed SCC, and SCCs are in any event a European mechanism governing transfers out of the EEA rather than the rule that applies to an Australian business sending data to the United States. Whether a particular transfer meets APP 8 is a judgement for a regulator and not a claim we should assert about ourselves, so this section now sets out the steps we actually take.
We do not control data processed by third-party providers — please review their privacy policies.
9. Data Sharing
We do not sell, rent, or trade personal information. We disclose data only when required by law, to protect vital interests, or with your consent.
10. Data Retention
- Account data — retained for the duration of your account. You can delete your account yourself from your profile page. Your API keys stop working immediately; the data we store about you is erased after a 30-day recovery period, during which you can undo the request, except the minimal personal records listed below. (Until 13 September 2026 this said “delete your account and uninstall the program” — there is no program to uninstall, and there was no self-service deletion.)
- Personal records retained after deletion — we keep only (a) your sign-up details and the date you signed up, (b) payment records, and (c) the date you deactivated your account. These are retained as business and financial records (e.g. tax-law obligations) and are the documented exception to full erasure, consistent with Australian Privacy Principle 11.2 — destruction or de-identification is required only once personal information is no longer needed and is not required by law to be kept.
- Tool-call audit records — the durable record of which tool ran and when (not its content) is kept for 365 days and then deleted by a daily job. Until 13 September 2026 this said “security audit logs”, which named an in-memory log that never persisted at all — so the retention period described a record that did not exist. Rows that carry money (payments, credit purchases, settled model calls) are excluded from that deletion and kept as financial records, as described above.
- MCP tool data — solver run history (your request text and any context you supplied, run status, timing, token counts, cost) and the cross-session learning record (a one-way digest of your request, plus success or failure, token count and strategy) both persist across sessions. No automatic expiry is currently applied to either.
- Billing records — we keep our own payment and usage records for as long as Australian tax law requires. Stripe separately keeps its own records under its policy; ours are not deleted when theirs are.
11. Your Rights
Australian Privacy Principles 12 and 13 give you the right to access and to correct the personal information we hold about you. We extend the fuller set of GDPR rights (Articles 15–22) to every customer as a matter of policy, whether or not the GDPR applies to them, for the reason given in Section 4:
- Access — request a copy of the personal data we hold about you (GDPR Art. 15).
- Rectification — correct inaccurate or incomplete data (GDPR Art. 16).
- Erasure — request deletion of your data, subject to legal retention requirements (GDPR Art. 17). You can erase your data yourself from your profile page, or email [email protected] for manual deletion. In both cases we retain only the minimal personal records described in Section 10.
- Restriction — request that we limit processing of your data in certain circumstances (GDPR Art. 18).
- Data portability — receive your data in a structured, machine-readable format (GDPR Art. 20).
- Objection — object to processing based on legitimate interests (GDPR Art. 21).
- Withdraw consent — where processing is based on consent, you may withdraw consent at any time by emailing [email protected]. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
To exercise any of these rights, email [email protected]. We aim to respond within 30 days.
12. Automated Decision-Making
G6 tools do not make automated decisions that produce legal effects concerning you or similarly significantly affect you. Should that ever change, we will say so here first, and you would have the right to request human review of any such decision (GDPR Art. 22).
13. Cookies
Used for secure sessions and usability. Disabling cookies may affect functionality.
14. Provision of Data
Providing your name, email, and payment information is a contractual requirement for account creation and service delivery. You are not obligated to provide this data, but we cannot provide the service without it.
15. Jurisdiction & Supervisory Authorities
This Privacy Policy is governed by the Australian Privacy Act 1988 and the Australian Privacy Principles (APPs). You may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
The OAIC is the supervisory authority for this service. We do not currently offer G6Solver to customers in the EU, the EEA or the UK; if we begin to, the GDPR would apply to us directly, and you would also have the right to lodge a complaint with your local supervisory authority under GDPR Article 77.
Correction, 13 September 2026: this policy previously presented GDPR Article 6 as the source of our lawful bases, and said flatly that GDPR rights “apply” to EU/EEA users, without stating anywhere that Australian law is what governs us or that the service is not currently offered in those markets. What we actually do is unchanged — we hold ourselves to the GDPR standard either way — but which law compels it, and where, is now stated rather than implied.
16. Changes to This Policy
Updates will be posted with the “Last Updated” date revised, and material changes will be emailed to you where possible. We record which version of this policy and of the Terms you accepted when you created your account; we do not treat continued use as acceptance of a later version.
17. Contact Us
For privacy enquiries or data requests: [email protected]