Sproutful AI & Data Usage Policy

Last updated 23 September 2026

AI writes the draft. Your team makes the call.

This policy describes how Sproutful's AI features handle information, for anyone assessing them as part of a privacy review, security questionnaire or audit. It covers what leaves Sproutful when a summary is drafted, who processes it and where, how it is protected and retained, and what you can switch off.

It forms part of the Sproutful Privacy Policy and should be read with it.

1. Scope

This policy covers the AI features in Sproutful:

Everything else about how Sproutful handles information is in our Privacy Policy.

2. Principles

3. How data flows

When summaries are enabled for a participant, the notes recorded for that participant are sent to Google Cloud's Vertex AI service, hosted in Australia (Sydney), which drafts the summary and returns it to Sproutful. The draft appears in Sproutful, marked as AI-generated, for a person to review.

3.1 What is sent

3.2 What is not sent

Summaries are drafted with placeholders where names would sit, and those placeholders are filled in only when the summary is displayed in Sproutful. This covers the names Sproutful holds; a name typed into a note is sent as written (section 3.3).

3.3 Names in note text

Before a note leaves Sproutful, the identifiers Sproutful attaches to it (the participant, the worker, the account holder) are replaced with placeholders, which are filled back in only when the summary is displayed.

The text of a note is sent as it was written. Sproutful does not remove names from it, so a name, a nickname, or a description of a person typed into a note is sent as part of that note. If a name should not reach the AI provider, leave it out of the note text, or disable summaries for that participant.

3.4 Daily summaries across organisations

A session summary draws only on notes recorded by that account holder's workers during the session.

A daily summary draws on every note recorded for the participant that day, including notes recorded by other organisations connected to that participant, unless the account holder has limited its own summaries to its own notes. The resulting summary is visible only to the account holder that enabled the feature. It is not shared with the other organisations whose notes contributed to it. Limiting your summaries to your own notes does not stop another connected organisation's summaries from drawing on notes your team recorded; that is governed by their setting, not yours.

4. Sub-processors

One provider is involved in drafting summaries, and it is listed below. Nothing about AI processing goes to anyone else. Our contract with it limits what it may do with your information to providing the service to us, and forbids using it to train models.

ProviderWhat it does for usWhereWhat it receivesWhat it keeps
Google Cloud (Vertex AI)Drafts summaries from note contentAustralia (Sydney, australia-southeast1)Note content as described in section 3, with the names Sproutful holds replaced by placeholders, and no account detailsNothing beyond the request, except content flagged by automated abuse monitoring, which may be held in Australia for up to 90 days for that purpose only

Google does not use this content to train its models.

If we change the provider we use for AI features, we will tell account holders at least 30 days beforehand, unless the law, a security issue, or keeping Sproutful running requires a shorter period. That matches the commitment in our Terms and Conditions.

5. Where AI processing happens

Everything to do with drafting a summary happens inside Google Cloud's Australian region. The notes go to Vertex AI in Sydney, the draft comes back to Sproutful's Australian infrastructure, and it is stored there with the rest of the participant's record. Nothing crosses a border at any step, including the abuse-monitoring exception described above, which is also held in Australia.

The Privacy Act 1988 (Cth) and the Australian Privacy Principles apply to all of it.

6. Security

WhatHowWhere it applies
In transitTLS 1.2 minimum, 1.3 preferredCalls between Sproutful and Vertex AI; all app and browser sessions
At restAES-256Notes, summaries and backups
KeysGoogle-managed and customer-managed keysAll encrypted storage
AccessMulti-factor authentication on administrative accounts; access limited to those who need itThe Google Cloud project and related tooling
InferenceNot retained beyond the request, subject to the abuse-monitoring exceptionVertex AI

7. Retention

A summary is a separate record. Creating one leaves the underlying notes exactly as they were, and the two are kept on their own terms.

RecordKept forDeleted by
The notes, tasks and medication records themselvesAs set out in the Privacy Policy and the account holder's own obligationsThe account holder
SummariesWith the participant's record they belong toThe account holder, or us on request
AI processing records (model, token counts, errors, references to which notes were used)With the summary they belong to. Service logs of the same processing are kept for up to seven yearsUs, on request
Inference data at GoogleNot beyond the request, except abuse-flagged content held in Australia up to 90 daysNot applicable

Where a summary is edited before being marked reviewed, the original draft is kept alongside the edit so the record shows what was generated and what a person changed.

7.1 Asking us to remove a summary

To have summaries removed, email privacy@sproutful.app. The notes they were drafted from stay where they are. We will let you know in writing when the removal is complete.

8. Labelling, review and audit trail

A summary always carries a label saying it was drafted by AI from the notes. There is no way to produce one without the label.

A person is expected to review each summary before it is used in any record. They can approve it, edit it, or discard it. Where they edit it, the original draft is kept alongside the edit.

8.1 If you are audited

If your organisation is audited, you may need to demonstrate that a person, not software, made each decision about a participant's support. Sproutful's design gives you the evidence:

9. Your controls

ControlWhat it doesHow to use it
Disable summaries for a participantStops all AI processing of that participant's notesThe participant's profile settings
Limit your daily summaries to your own notesYour daily summaries for that participant draw only on notes your team recorded. It does not affect what other connected organisations' summaries draw onThe participant's profile settings
See what AI has processedA log of when summaries were drafted for your participants, and by which featureEmail privacy@sproutful.app
Remove summariesTakes down AI drafts; the notes they came from stayEmail privacy@sproutful.app
Export summariesSummaries export with the rest of the participant's recordThe participant's Export page in Sproutful

9.1 If you are a participant, or speak for one

Summaries are enabled and disabled by the organisation supporting you, so ask them first and they can disable it immediately. If that does not resolve it, contact us at privacy@sproutful.app and we will help. You can also ask for access to information held about you, and complain to us, using the routes in the Privacy Policy.

9.2 Model training

Your content is not used to train AI models. There is no setting for this because there is nothing to disable. It is how the service is built and how our agreement with Google works.

10.1 Roles

PartyRoleResponsible for
The account holder, acting through its team and anyone it has delegated toData controllerDeciding what goes into Sproutful and why, the lawful basis for it, notifying participants and obtaining any consent required, and responding to requests from the people it supports
Sproutful Pty LtdData processorKeeping the processing secure, choosing and overseeing the provider, telling you promptly if something goes wrong, and helping you answer requests from the people you support
Google CloudSub-processorProcessing on Sproutful's instructions, within Australia

10.2 Lawful basis

Summaries are drafted to deliver a feature the account holder has chosen to enable, as part of the service contracted for. Because the notes involved are usually health information, the account holder is responsible for the consent required to collect and use them.

10.3 Data Processing Agreement

Where the law requires it, or where we and an account holder agree to one in writing, a Data Processing Agreement may govern how we process personal information and health information on the account holder's behalf. If one applies, it prevails over this policy on matters of data processing.

10.4 Breach notification

Where a breach involves information processed by an AI feature, we will tell the affected account holders promptly, explain what happened and what information was involved, and notify individuals and the Office of the Australian Information Commissioner where the Notifiable Data Breaches scheme requires it.

10.5 Governing law and contact

This policy is governed by the laws of Western Australia.

Sproutful Pty Ltd
ABN 87 687 351 604
35 Caledonian Ave, Maylands WA, 6051
Email: privacy@sproutful.app
Expect a reply to privacy enquiries within 5 business days.