Sproutful AI & Data Usage Policy
Last updated 23 September 2026
AI writes the draft. Your team makes the call.
This policy describes how Sproutful's AI features handle information, for anyone assessing them as part of a privacy review, security questionnaire or audit. It covers what leaves Sproutful when a summary is drafted, who processes it and where, how it is protected and retained, and what you can switch off.
It forms part of the Sproutful Privacy Policy and should be read with it.
1. Scope
This policy covers the AI features in Sproutful:
- Session summaries — a short written summary drafted from the notes recorded during a session
- Daily summaries — a summary drafted from the notes recorded for a participant across a day
Everything else about how Sproutful handles information is in our Privacy Policy.
2. Principles
- Nothing is sent to an AI model unless a feature has been enabled for that participant
- The output is always a draft. A person reads it and decides whether to keep it, change it or discard it
- Drafts are marked as AI-generated and kept apart from the notes they came from
- Your content never trains a model, ours or anyone else's
- For Australian accounts, the processing stays in Australia
- Any feature can be disabled at any time, per participant
3. How data flows
When summaries are enabled for a participant, the notes recorded for that participant are sent to Google Cloud's Vertex AI service, hosted in Australia (Sydney), which drafts the summary and returns it to Sproutful. The draft appears in Sproutful, marked as AI-generated, for a person to review.
3.1 What is sent
- the note template and field names your account uses
- the values entered into those fields
- the record of tasks and medications marked completed or refused
- when each note was recorded and when each session ran
- the number of photos attached to a note
3.2 What is not sent
- the participant's name or account details
- the names or account details of workers, or of the account holder
- photos themselves — only the count is sent
Summaries are drafted with placeholders where names would sit, and those placeholders are filled in only when the summary is displayed in Sproutful. This covers the names Sproutful holds; a name typed into a note is sent as written (section 3.3).
3.3 Names in note text
Before a note leaves Sproutful, the identifiers Sproutful attaches to it (the participant, the worker, the account holder) are replaced with placeholders, which are filled back in only when the summary is displayed.
The text of a note is sent as it was written. Sproutful does not remove names from it, so a name, a nickname, or a description of a person typed into a note is sent as part of that note. If a name should not reach the AI provider, leave it out of the note text, or disable summaries for that participant.
3.4 Daily summaries across organisations
A session summary draws only on notes recorded by that account holder's workers during the session.
A daily summary draws on every note recorded for the participant that day, including notes recorded by other organisations connected to that participant, unless the account holder has limited its own summaries to its own notes. The resulting summary is visible only to the account holder that enabled the feature. It is not shared with the other organisations whose notes contributed to it. Limiting your summaries to your own notes does not stop another connected organisation's summaries from drawing on notes your team recorded; that is governed by their setting, not yours.
4. Sub-processors
One provider is involved in drafting summaries, and it is listed below. Nothing about AI processing goes to anyone else. Our contract with it limits what it may do with your information to providing the service to us, and forbids using it to train models.
| Provider | What it does for us | Where | What it receives | What it keeps |
|---|---|---|---|---|
| Google Cloud (Vertex AI) | Drafts summaries from note content | Australia (Sydney, australia-southeast1) | Note content as described in section 3, with the names Sproutful holds replaced by placeholders, and no account details | Nothing beyond the request, except content flagged by automated abuse monitoring, which may be held in Australia for up to 90 days for that purpose only |
Google does not use this content to train its models.
If we change the provider we use for AI features, we will tell account holders at least 30 days beforehand, unless the law, a security issue, or keeping Sproutful running requires a shorter period. That matches the commitment in our Terms and Conditions.
5. Where AI processing happens
Everything to do with drafting a summary happens inside Google Cloud's Australian region. The notes go to Vertex AI in Sydney, the draft comes back to Sproutful's Australian infrastructure, and it is stored there with the rest of the participant's record. Nothing crosses a border at any step, including the abuse-monitoring exception described above, which is also held in Australia.
The Privacy Act 1988 (Cth) and the Australian Privacy Principles apply to all of it.
6. Security
| What | How | Where it applies |
|---|---|---|
| In transit | TLS 1.2 minimum, 1.3 preferred | Calls between Sproutful and Vertex AI; all app and browser sessions |
| At rest | AES-256 | Notes, summaries and backups |
| Keys | Google-managed and customer-managed keys | All encrypted storage |
| Access | Multi-factor authentication on administrative accounts; access limited to those who need it | The Google Cloud project and related tooling |
| Inference | Not retained beyond the request, subject to the abuse-monitoring exception | Vertex AI |
7. Retention
A summary is a separate record. Creating one leaves the underlying notes exactly as they were, and the two are kept on their own terms.
| Record | Kept for | Deleted by |
|---|---|---|
| The notes, tasks and medication records themselves | As set out in the Privacy Policy and the account holder's own obligations | The account holder |
| Summaries | With the participant's record they belong to | The account holder, or us on request |
| AI processing records (model, token counts, errors, references to which notes were used) | With the summary they belong to. Service logs of the same processing are kept for up to seven years | Us, on request |
| Inference data at Google | Not beyond the request, except abuse-flagged content held in Australia up to 90 days | Not applicable |
Where a summary is edited before being marked reviewed, the original draft is kept alongside the edit so the record shows what was generated and what a person changed.
7.1 Asking us to remove a summary
To have summaries removed, email privacy@sproutful.app. The notes they were drafted from stay where they are. We will let you know in writing when the removal is complete.
8. Labelling, review and audit trail
A summary always carries a label saying it was drafted by AI from the notes. There is no way to produce one without the label.
A person is expected to review each summary before it is used in any record. They can approve it, edit it, or discard it. Where they edit it, the original draft is kept alongside the edit.
8.1 If you are audited
If your organisation is audited, you may need to demonstrate that a person, not software, made each decision about a participant's support. Sproutful's design gives you the evidence:
- a summary and the notes behind it are separate records, and one never overwrites the other
- who reviewed a summary, and what they did with it, is recorded against their login
- if a reviewer changed the draft, both versions are kept
9. Your controls
| Control | What it does | How to use it |
|---|---|---|
| Disable summaries for a participant | Stops all AI processing of that participant's notes | The participant's profile settings |
| Limit your daily summaries to your own notes | Your daily summaries for that participant draw only on notes your team recorded. It does not affect what other connected organisations' summaries draw on | The participant's profile settings |
| See what AI has processed | A log of when summaries were drafted for your participants, and by which feature | Email privacy@sproutful.app |
| Remove summaries | Takes down AI drafts; the notes they came from stay | Email privacy@sproutful.app |
| Export summaries | Summaries export with the rest of the participant's record | The participant's Export page in Sproutful |
9.1 If you are a participant, or speak for one
Summaries are enabled and disabled by the organisation supporting you, so ask them first and they can disable it immediately. If that does not resolve it, contact us at privacy@sproutful.app and we will help. You can also ask for access to information held about you, and complain to us, using the routes in the Privacy Policy.
9.2 Model training
Your content is not used to train AI models. There is no setting for this because there is nothing to disable. It is how the service is built and how our agreement with Google works.
10. Legal framework
10.1 Roles
| Party | Role | Responsible for |
|---|---|---|
| The account holder, acting through its team and anyone it has delegated to | Data controller | Deciding what goes into Sproutful and why, the lawful basis for it, notifying participants and obtaining any consent required, and responding to requests from the people it supports |
| Sproutful Pty Ltd | Data processor | Keeping the processing secure, choosing and overseeing the provider, telling you promptly if something goes wrong, and helping you answer requests from the people you support |
| Google Cloud | Sub-processor | Processing on Sproutful's instructions, within Australia |
10.2 Lawful basis
Summaries are drafted to deliver a feature the account holder has chosen to enable, as part of the service contracted for. Because the notes involved are usually health information, the account holder is responsible for the consent required to collect and use them.
10.3 Data Processing Agreement
Where the law requires it, or where we and an account holder agree to one in writing, a Data Processing Agreement may govern how we process personal information and health information on the account holder's behalf. If one applies, it prevails over this policy on matters of data processing.
10.4 Breach notification
Where a breach involves information processed by an AI feature, we will tell the affected account holders promptly, explain what happened and what information was involved, and notify individuals and the Office of the Australian Information Commissioner where the Notifiable Data Breaches scheme requires it.
10.5 Governing law and contact
This policy is governed by the laws of Western Australia.
Sproutful Pty Ltd
ABN 87 687 351 604
35 Caledonian Ave, Maylands WA, 6051
Email: privacy@sproutful.app
Expect a reply to privacy enquiries within 5 business days.