Privacy Policy
MaidOS is software for running a cleaning business. To do that it holds two quite different things: information about you, our member, and information about your business — your staff, your job applicants and your clients.
We treat the second kind as yours, not ours. We do not sell any of it, we do not use it to advertise to anyone, and we do not use it to train AI models. This policy sets out exactly what we hold, who else touches it, and what you can ask us to do about it.
Who we are and what this covers
MaidOS is operated by Jason Shipway, trading as The Self Maid Co (“we”, “us”, “our”). This policy covers the MaidOS web application at selfmaid.ai and every workspace running on it.
We handle personal information in line with the Australian Privacy Principles in the Privacy Act 1988 (Cth). We commit to those standards as a matter of practice, whether or not the Act applies to a business of our size in a given year.
The two kinds of information we hold
Nearly every question about your data has a different answer depending on which of these it falls into, so it is worth being precise up front.
- Your account information — we decide how it is handled.Your name, email, login credentials, subscription status and how you use the product. We collected it, we decide what happens to it, and this policy governs it directly.
- Your business information — you decide how it is handled.Your employees, job applicants, clients, payroll figures, quotes and documents. Your staff and clients never agreed anything with us; they dealt with you. We hold this material on your instructions and act on it only to run the product for you, to keep it secure, or where the law requires. If one of your clients or staff asks us about their information, we will refer them to you.
What we collect
About you
- Your name, email address and password (stored only as a cryptographic hash).
- Your workspace name, subscription tier and billing status.
- Your progress through the training program — videos watched, quiz results, weekly reflections and goals.
- Your conversations with the AI coach, kept so you can scroll back through them.
- Technical records created automatically: IP address, browser type, and timestamped logs of requests and errors.
About your business
- Employee records, pay rates, timesheets and payroll entries.
- Job applicants: their applications, your notes, interview checklists and any documents they submit.
- Clients, quotes, rate cards, jobs and invoices — entered by you or synced from Jobber.
- Your financial figures: weekly profit, margins and pricing scenarios.
- Documents, SOPs and checklists you create or upload.
We do not collect payment card numbers. Card details are entered directly with Stripe and never reach our systems — we receive only confirmation that a subscription started, renewed or ended.
We do not deliberately collect sensitive information (health, racial or ethnic origin, political or religious beliefs, criminal record, or biometric data). Please do not enter it into free-text fields such as recruitment notes.
Where it comes from
Most of it comes from you, typed into the product. The exceptions are:
- Jobber. If you connect your Jobber account, you authorise us through Jobber’s own consent screen to read your jobs, clients and invoices on a nightly schedule. You control this: disconnecting in your settings stops the sync. Your Jobber access tokens are held encrypted (AES-256-GCM) and are never displayed back to you or to anyone else.
- Stripe. Tells us your subscription status when a payment succeeds, fails or is cancelled.
- Your own team. Where you invite staff into your workspace, information about them may be entered by other people in your business rather than by you.
How we use it
We use the information to:
- provide the product — sign you in, show your workspace, run its features;
- bill you and manage your subscription;
- answer your questions through the AI coach and generate the documents you ask for;
- send you service email: sign-in links, receipts and notices about the product;
- keep the service secure and diagnose faults;
- understand which features get used, so we know what to build and what to fix; and
- meet our legal obligations.
We do not sell personal information, and we do not disclose it to anyone for their own marketing.
AI features and your data
The AI coach answers questions using Anthropic’s Claude models, searching a knowledge base built from the program’s own coaching material. Other parts of the product also use Claude to draft documents — SOPs, price-increase letters and day-in-the-life cards.
Your data is not used to train AI models. When you ask the coach a question, that question and the context needed to answer it are sent to Anthropic and Voyage AI for processing, and the answer comes back to you. Under our agreements with those providers, your inputs and outputs are not used to train their models; they are retained only briefly for abuse monitoring and then deleted.
AI answers can be wrong. Section 8 of the Terms of Service explains what the coach is and is not, and why it is not a substitute for professional advice.
Where your data is stored
Your workspace data lives in Australia. The database, file storage and application servers all run in Sydney — Supabase in ap-southeast-2 and Vercel in syd1.
Some providers in the table above operate overseas, mainly in the United States. Where that happens we take reasonable steps to ensure the provider handles your information consistently with the Australian Privacy Principles, including through contractual commitments. By using the AI, email and payment features you consent to that disclosure.
The community leaderboard
Members appear on the leaderboard by default. The community leaderboard ranks workspaces on business metrics and shows your business name alongside your position. If you would rather not be identified, turn on anonymous mode in Settings and your entry appears without your name. Your underlying figures are never published either way — only your ranking.
How long we keep it
- While you are a member: for as long as your account is open.
- After you cancel: we keep your workspace for 90 days so you can return to it or export it, then delete it. Ask us sooner and we will delete it sooner.
- Billing records: kept for seven years, because tax law requires it.
- Backups: deleted data can persist in encrypted backups for up to 30 days before those rotate out.
- Logs: kept for up to 30 days for security and fault diagnosis.
How we protect it
- Everything travels over TLS, and the database is encrypted at rest.
- Workspaces are isolated from each other at the database level by row-level security, so one member’s queries cannot reach another member’s data.
- Passwords are stored as salted hashes and are not recoverable, even by us.
- Jobber access tokens are encrypted with AES-256-GCM before being stored.
- Administrative access is limited to those who need it to operate the service.
No system is perfectly secure. If a data breach occurs that is likely to cause you serious harm, we will notify you and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme.
Your rights
Email privacy@selfmaid.ai and you can:
- ask for a copy of the personal information we hold about you;
- ask us to correct anything that is wrong or out of date;
- ask us to delete your account and its data;
- ask for your workspace data in a portable format;
- withdraw a consent you have given, such as the Jobber connection; or
- complain about how we have handled your information.
We will respond within 30 days. If we refuse access or correction we will tell you why in writing. If you are not satisfied with how we handle a complaint, you can take it to the Office of the Australian Information Commissioner at oaic.gov.au or on 1300 363 992.
Children
MaidOS is a business tool and is not intended for anyone under 18 — the same minimum age the Terms of Service set for holding an account. We do not knowingly collect information from children. If you believe a child has given us information, contact us and we will delete it.
Changes to this policy
We will update this page when our practices change, and change the effective date at the top. If a change materially affects your rights — a new category of data, a new purpose, or a new disclosure — we will tell you by email or in the product before it takes effect.
Contact us
Privacy questions, requests and complaints go to privacy@selfmaid.ai, addressed to the Privacy Officer, Jason Shipway, trading as The Self Maid Co, Western Australia, Australia.
This policy works alongside our Terms of Service, which set out the mutual confidentiality undertaking between us and the rules for using the product.
