Privacy Policy
Public-facing Privacy and Terms are available, with formal legal review continuing as the platform moves toward wider access.
1. Who we are
Odasiti is a registered business name operated by Tesaroche Pty Ltd, an Australian company. In this policy, “Odasiti”, “we”, “us”, and “our” refer to Tesaroche Pty Ltd in its capacity as the operator of the platform.
- Legal entity: Tesaroche Pty Ltd
- ABN: 26 651 683 859
- Registered office: 59/118 Mounts Bay Road, Perth WA 6000, Australia
- Privacy contact: privacy@odasiti.com
2. What this policy covers
This policy explains how we handle personal information we collect when you visit odasiti.com, preview.odasiti.com,dev.odasiti.com, and when you use the Odasiti mobile application.
Effective date: 15 July 2026.
This policy is governed by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) that sit beneath it. We will update this policy before any material new data category is collected.
3. What information we collect
We split the information we hold into two tiers, based on whether it ever crosses a user-visible boundary. This is a deliberate engineering discipline; it is not legal language.
3.1 Information visible to other users (Tier 1)
This is information that may be shown to you or to the person you are matched with. We deliberately keep this list short:
- Your profile name — a nature-themed pseudonym we help you choose. Your real name is never shown to other users.
- Your country queue and approximate position in it.
- The city your browser reports, banded to within 5 km or 10 km. We never display an exact address or coordinate.
- Your chat-game responses, shown only as shared compatibility dimensions with your match (Level 2 · Exchange). The individual answers themselves are never disclosed.
- Compatibility dimension scores and, on the dedicated Compatibility Dashboard, an overall compatibility index shown only to you and your match. We do not show this index to anyone else or rank users against each other.
- Your age band (a five-year range derived from your date of birth). We never show your exact age or date of birth to other users.
- Voice notes you choose to send to a specific match (Level 2 · Exchange · voice notes).
- Meetup proposals you send to your match (Level 3 · Spark).
- Shared Scrapbook milestone cards visible to both match participants (Commit feature, available through all Levels). Private reflections you add to Scrapbook are visible only to you.
3.2 Server-only information (Tier 2)
This is information we hold for the platform to function, but which we deliberately never return to any user-visible API or display. It is accessible only to our Trust & Safety team under defined circumstances.
- Your email address.
- Your date of birth (used for age eligibility and age-band display; never shown as an exact age to other users).
- Your gender and discovery preferences (used for matching; not shown on your public profile).
- Emergency contact details you provide (name and phone number) and records of SMS notifications sent to that contact when you enable the feature. You confirm you have that person’s permission to share their number with us.
- The latitude and longitude your browser supplies, used only to derive your country and city band. We never display the raw coordinate.
- A salted hash of your email address, used to detect duplicate signups without exposing the email itself.
- Your IP address, held in server logs only and deleted automatically after 90 days.
- Your marketing-communications preference.
- The referral code you signed up under, if any.
- Your government-issued identity document and the verification payload returned by our identity-verification provider (Level 4 · Reveal). This is required before a match can progress to in-person meetups.
- Voice call audio. Voice calls are not recorded by default. Audio is retained only when a safety incident triggers retention, and is held only for the purpose of that investigation.
- Your individual chat-game answer values. Only the resulting compatibility dimension scores cross into Tier 1.
- Your post-meetup Scrapbook event metadata.
We do not collect photos. We do not display your real name to other users. We do not allow chat export.
3.3 Platform in active development
The categories above describe what we collect today. The platform is in active development; specific data fields may evolve before public launch and as we add features. We will amend this policy before any material new data category is collected.
4. Why we collect it
- Country assignment and queue. We are launching country-by-country and need to know which queue to place you in, and to give you a rough sense of where you sit.
- Running the match journey. Game responses, voice notes, meetup proposals, and scrapbook items are the substance of the Odasiti experience. We hold them so the platform functions.
- Identity verification. Level 4 · Reveal requires government-identity verification to protect every user before any in-person contact.
- Email contact. So we can reach you when we open in your country, and — only if you opt in — for product updates.
- Duplicate prevention. So we can detect when the same email signs up twice.
- Service operation and safety. Server logs help us detect abuse, debug failures, and meet our obligations under Australian law.
- Payments. If you subscribe to a paid tier, we share necessary billing information with our payment processor.
5. How we use it
We use the information we collect for the purposes set out above and for related operational purposes (such as security, fraud prevention, and compliance with our legal obligations).
What we do not do:
- We do not sell your personal information to third parties.
- We do not share your personal information with third parties for advertising purposes.
- We do not enrich your record with data purchased from data brokers.
- We do not use your location data for anything other than country and city assignment.
- We do not display your real name to other users, ever. The identity we collect at Level 4 · Reveal is Tier 2 data, accessible only to our Trust & Safety team under defined circumstances.
6. Where it lives
Your data is primarily stored in Australia, on infrastructure operated by a major commercial cloud provider with data centres in Australia. This covers our databases, server logs, file storage, and the services that power the platform.
Some of the service providers listed in §8 operate internationally, and data shared with them may be transferred to and processed in the United States and other countries where our service providers operate. We rely on the contractual protections each provider offers, and on the protections of the Australian Privacy Principles where they continue to apply.
7. How long we keep it
We retain personal information for as long as is necessary for the purposes for which it was collected and to comply with our legal obligations. Specifically:
- Server logs containing IP addresses are deleted automatically after 90 days.
- Account-level records are retained until you request deletion under §10, or until we are required by Australian law to delete them. Private Scrapbook reflections are deleted when your account is closed.
- Payment records may be retained for up to 7 years as required by financial record-keeping obligations under the Corporations Act 2001 (Cth).
- Voice call audio retained for safety investigations is held only for the duration of the investigation and then deleted.
We aim to delete data that is no longer necessary. If you believe we are holding data longer than we should, contact us at privacy@odasiti.com.
9. Your rights
9.1 Under Australian law (Privacy Act 1988)
The Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth) give you the right to:
- Request access to the personal information we hold about you.
- Request correction of personal information that is inaccurate, out of date, incomplete, irrelevant, or misleading.
- Request deletion of your personal information where we no longer have a lawful reason to hold it.
- Make a complaint about how we have handled your personal information. If you are not satisfied with our response, you can lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
9.2 Where the GDPR applies
Where the EU General Data Protection Regulation applies to our processing of your information, you also have the rights to erasure, portability, restriction of processing, objection to processing, and withdrawal of consent at any time without affecting prior lawful processing. We are an Australian company; we do not currently claim that the GDPR applies to our processing, but we will honour these rights to the extent we are obliged.
9.3 California residents (CPRA)
If you are a California resident, you may have additional rights under the California Privacy Rights Act (CPRA), including the right to know what personal information we collect, the right to delete personal information (subject to exceptions), the right to correct inaccurate personal information, and the right to opt out of the sale or sharing of personal information.
We do not sell your personal information. We do not share your personal information for cross-context behavioural advertising.
US entity: Tesaroche Pty Ltd (Australia) is the data controller for Odasiti today. Formal legal review is continuing on whether a US-resident entity or representative is required for CPRA compliance before wider US access. Contact privacy@odasiti.com to exercise CPRA rights.
10. How to exercise your rights
To exercise any of the rights listed above, contact us at privacy@odasiti.com. We aim to respond within 30 days. If your request is complex, we may take longer and will let you know when to expect a response.
If you are not satisfied with our response, the appropriate escalation paths are:
- For Australian residents: the Office of the Australian Information Commissioner (OAIC), oaic.gov.au.
- For EU residents: your local data protection authority.
12. Children
Odasiti is for adults 18 years and older. We do not knowingly collect personal information from anyone under 18. If you believe we have collected information about a child, contact us at privacy@odasiti.com and we will take prompt steps to delete it.
13. Changes to this policy
We may update this policy from time to time. When we make material changes — to what we collect, how we use it, who we share it with, or your rights — we will:
- Update the “Last updated” date at the top of this document.
- Re-show the cookie banner so you can review the new version and re-consent.
- Email subscribers who opted in to marketing communications where the change is significant.
14. Contact
For questions, requests, or complaints about this policy or how we handle your personal information:
- Email: privacy@odasiti.com
- Postal address: Tesaroche Pty Ltd, 59/118 Mounts Bay Road, Perth WA 6000, Australia.
