Ask Dan Privacy Policy
Last Updated: 17 May 2026
Effective Date: February 12, 2026
1. Introduction
This Privacy Policy explains how Ask Dan, operated by Dan Murtagh ABN 48 815 594 360 ("we," "us," "our," or "Ask Dan"), collects, uses, stores, and protects your personal information when you use the Ask Dan application ("App").
We are committed to protecting your privacy and handling your personal information in accordance with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Where our users are located in the European Economic Area (EEA), we also design our data handling practices to be compatible with the General Data Protection Regulation (GDPR).
By using the App, you consent to the collection and use of your information as described in this Privacy Policy. If you do not agree with this Privacy Policy, please do not use the App.
This Privacy Policy should be read together with our Terms of Service and AI Disclosure.
2. Information We Collect
2.1 Account Information
When you create an account using Apple Sign In, we receive:
- Apple ID identifier: A unique, app-specific identifier provided by Apple (not your actual Apple ID)
- Email address: Your email address, or a private relay email address if you choose to hide your email via Apple's privacy feature
- Display name: Your name as provided through Apple Sign In (you may choose to share or withhold this)
We do not receive or store your Apple ID password. Authentication is handled entirely by Apple.
2.2 Subscription Information
When you subscribe to Ask Dan, we receive subscription status information from Apple, including:
- Subscription plan (monthly or annual)
- Subscription status (active, expired, cancelled)
- Renewal date
We do not receive or store your payment card details, billing address, or any other financial information. All payment processing is handled by Apple through the App Store.
2.3 App Usage Data
We collect information about how you use the App, including:
- Exercise completion records and scores
- Progress tracking data (levels completed, accuracy rates)
- Feature usage patterns (which sections of the App you access)
- Session duration and frequency
2.4 Ask Dan Interaction Data
When you use the Ask Dan AI tutor, we collect:
- The questions you submit to Ask Dan
- The AI-generated responses provided to you
- Timestamps of interactions
- Conversation session identifiers
2.5 Technical Data
We may collect basic technical information to maintain and improve the App, including:
- Device model and operating system version
- App version
- Crash reports and error logs
- General geographic region (country level, derived from IP address during API calls)
2.6 Information We Do NOT Collect
We want to be clear about what we do not collect:
- Payment card details or banking information
- Precise geolocation or GPS data
- Contacts, calendar, or address book data
- Photos, camera, or microphone data
- Health, fitness, or biometric data
- Data from other apps on your device
- Browsing history
- Advertising identifiers (we do not use advertising SDKs)
3. How We Use Your Information
We use the information we collect for the following purposes:
3.1 Providing the Service
- Authenticating your account and managing your subscription
- Delivering ear training exercises and tracking your progress
- Processing your questions through the Ask Dan AI tutor and generating responses
- Syncing your data across sessions
3.2 Improving the Service
- Analysing usage patterns to improve exercises and app features
- Reviewing Ask Dan interactions to improve response quality and the knowledge base
- Identifying and fixing bugs and technical issues
- Understanding which features are most valuable to users
3.3 Communication
- Sending service-related notifications (subscription status, important updates)
- Responding to support inquiries
- Notifying you of material changes to these policies
3.4 Legal and Safety
- Complying with legal obligations
- Enforcing our Terms of Service
- Protecting the rights, safety, and property of Ask Dan and our users
- Detecting and preventing fraud or abuse
4. AI Data Processing
4.1 How Ask Dan Works
Ask Dan uses the Claude API, provided by Anthropic, to generate responses to your questions. When you submit a question:
- Your question text is sent to our server
- Relevant knowledge base entries are retrieved based on your question
- Your question and the relevant knowledge base context are sent to Anthropic's Claude API
- Claude generates a response based on the question and context
- The response is returned to you through the App
4.2 What Is Sent to Anthropic
When processing your question, the following data is transmitted to Anthropic:
- Your question text (the exact words you type)
- Knowledge base context (relevant entries from our proprietary knowledge base, selected by our retrieval system)
- System prompt instructions (our instructions to the AI about how to respond)
4.3 What Is NOT Sent to Anthropic
We do not send the following to Anthropic:
- Your email address or Apple ID
- Your name or account information
- Your subscription status
- Your exercise scores or progress data
- Your device information
- Any other personally identifiable information
4.4 Anthropic's Data Handling
Anthropic processes your question data in accordance with their own privacy policy and terms of service. As of the date of this Privacy Policy:
- Anthropic's API is hosted on servers in the United States
- Anthropic's commercial API terms generally provide that customer data is not used to train their models
- We recommend reviewing Anthropic's current privacy policy at anthropic.com/privacy for the most up-to-date information
We will update this Privacy Policy if there are material changes to how Anthropic handles data that affect your privacy.
4.5 Your Control
You can use Ask Dan without using Ask Dan. If you choose not to use Ask Dan, no question data will be sent to Anthropic.
5. Data Storage and Security
5.1 Where Your Data Is Stored
Your data is stored using Supabase, a cloud-hosted PostgreSQL database service. The hosting region for our Supabase project is Northeast Asia (Tokyo, ap-northeast-1). This means your personal data may be transferred to and stored in Japan.
5.2 Security Measures
We implement reasonable security measures to protect your personal information, including:
- Encryption of data in transit (TLS/SSL)
- Encryption of data at rest (via Supabase's infrastructure)
- Authentication via Apple Sign In (industry-standard OAuth)
- Row-level security policies in the database
- Regular review of access controls
- Secure API key management
5.3 No Guarantee
While we take reasonable steps to protect your information, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security of your data.
6. Data Sharing
6.1 Third-Party Service Providers
We share your information with the following third-party service providers who process data on our behalf:
| Provider | Data Shared | Purpose | Location |
|---|---|---|---|
| Apple | Apple ID, subscription status | Authentication, payment processing | USA |
| Supabase | Account data, usage data, AI interactions | Database hosting and storage | Northeast Asia (Tokyo) |
| Anthropic | Question text, knowledge base context | AI response generation | USA |
| Aggregated website usage data (via Google Analytics cookies) | Website analytics | USA |
6.2 We Do NOT
- Sell your personal information to third parties
- Share your personal information with advertisers
- Use your data for targeted advertising
- Share your data with data brokers
- Make your personal information available to other users
6.3 Legal Requirements
We may disclose your information if required to do so by law, regulation, legal process, or governmental request, or if we believe disclosure is necessary to protect the rights, safety, or property of Ask Dan or others.
7. Data Retention
7.1 How Long We Keep Your Data
| Data Type | Retention Period |
|---|---|
| Account information | While your account is active, plus 30 days after deletion |
| Subscription information | While active, plus as required by Apple's terms and Australian tax obligations (up to 5 years) |
| App usage data | While your account is active, plus 30 days after deletion |
| AI interaction data | While your account is active, plus 30 days after deletion |
| Technical/crash data | Up to 12 months |
7.2 Account Deletion
You can request deletion of your account and all associated personal data by contacting us at info@danmurtagh.com. Upon receiving a valid deletion request:
- We will verify your identity
- We will delete or anonymise your personal data within 30 days
- We will confirm deletion to you
- Some data may be retained where required by law (e.g., financial records for tax purposes)
Note: Deleting your Ask Dan account does not cancel your Apple subscription. You must cancel your subscription separately through Apple ID settings.
8. Your Rights
8.1 Rights Under Australian Privacy Law
Under the Australian Privacy Principles, you have the right to:
- Access your personal information that we hold
- Correct any personal information that is inaccurate, out of date, or incomplete
- Complain to the Office of the Australian Information Commissioner (OAIC) if you believe we have breached the APPs
8.2 Additional Rights for EEA Users
If you are located in the European Economic Area, you may also have the right to:
- Erasure: Request deletion of your personal data
- Restriction: Request restriction of processing of your personal data
- Portability: Receive your personal data in a structured, commonly used, machine-readable format
- Object: Object to the processing of your personal data
- Withdraw consent: Withdraw consent at any time where processing is based on consent
- Lodge a complaint with your local data protection supervisory authority
8.3 Exercising Your Rights
To exercise any of these rights, please contact us at info@danmurtagh.com. We will respond to your request within 30 days.
We may need to verify your identity before processing your request. We will not charge you a fee for exercising your rights unless your request is manifestly unfounded or excessive.
9. Children's Privacy
Ask Dan is not directed at children under 13 years of age. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at info@danmurtagh.com and we will delete that information.
Users between 13 and 18 may use Ask Dan with the consent of a parent or legal guardian, as described in our Terms of Service.
10. International Data Transfers
Your personal data may be transferred to, stored in, and processed in countries other than Australia, including the United States (where Anthropic, Apple, and Google operate). These countries may have different data protection laws than Australia.
When we transfer your data internationally, we take reasonable steps to ensure that your personal information receives an adequate level of protection, including:
- Ensuring our service providers are bound by contractual obligations to protect your data
- Relying on Apple's and Anthropic's published privacy and data protection commitments
- For EEA users, implementing appropriate transfer mechanisms as required by GDPR (such as Standard Contractual Clauses where applicable)
11. Cookies and Analytics
Ask Dan is a web application hosted at ask.danmurtagh.com. We use Google Analytics 4, a web analytics service provided by Google LLC ("Google"), to understand how visitors find and use the site so that we can improve it.
11.1 What Google Analytics Collects
Google Analytics collects standard, aggregated usage information, including:
- Pages viewed and time spent on the site
- Approximate location at the country/region level (derived from IP address — see 11.3)
- The referring website or search that brought you to the site
- Device type, browser, and operating system
11.2 Cookies We Use
To do this, Google Analytics sets first-party cookies in your browser (typically named _ga and _ga_<id>). These cookies store a randomly generated identifier so that repeat visits can be recognised as the same browser. They do not contain your name, email address, or any directly identifying information, and typically expire up to 24 months after your most recent visit.
11.3 IP Addresses
Google Analytics 4 uses your IP address only transiently to derive approximate geographic location and does not log or store IP addresses in its reports.
11.4 How This Data Is Handled
Analytics data is processed by Google on our behalf and is transferred to and stored on servers in the United States. We do not use Google Analytics data for advertising or to attempt to identify individual visitors, and Ask Dan is not connected to any Google advertising products or audiences. Google's handling of this data is governed by Google's Privacy Policy at policies.google.com/privacy.
11.5 How to Opt Out
You can prevent Google Analytics from collecting your data by:
- Installing the Google Analytics Opt-out Browser Add-on (tools.google.com/dlpage/gaoptout)
- Blocking or clearing analytics cookies in your browser settings
- Using a browser or extension that blocks analytics scripts
Opting out of analytics does not affect your ability to use Ask Dan.
Other than Google Analytics as described above, we do not use advertising trackers, cross-site tracking, or cross-app tracking technologies.
12. Data Breach Notification
In the event of a data breach involving your personal information that is likely to result in serious harm, we will:
- Notify the Office of the Australian Information Commissioner (OAIC) as required under the Notifiable Data Breaches scheme (Part IIIC of the Privacy Act)
- Notify you as soon as practicable, describing the nature of the breach and steps we are taking
- If you are located in the EEA, notify the relevant supervisory authority within 72 hours as required by GDPR
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by:
- Updating the "Last Updated" date at the top of this policy
- Posting a notice within the App
- Where required, sending you direct notification
Your continued use of the App after any changes constitutes your acceptance of the updated Privacy Policy.
14. Contact Us and Complaints
14.1 Contact
If you have any questions about this Privacy Policy or our data handling practices, please contact us at:
Email: info@danmurtagh.com
Website: ask.danmurtagh.com
14.2 Complaints
If you believe we have breached the Australian Privacy Principles or are not satisfied with our response to a privacy concern, you may lodge a complaint with:
Office of the Australian Information Commissioner (OAIC) Website: www.oaic.gov.au Phone: 1300 363 992
If you are located in the EEA, you may also lodge a complaint with your local data protection supervisory authority.
This Privacy Policy is part of the Ask Dan project. Copyright Dan Murtagh. All rights reserved.