Privacy policy
First Six is a mobile and web app that helps a university student through their first six weeks: what matters each week, their timetable and events, a weekly wellbeing check-in, and a way to ask a real person for help. This policy explains what we collect, how it is used, and the control you have over it. It is written to be read, not to be survived.
Effective date: 12 July 2026
Who we are, and who this policy is for
The app is operated by First Six Technologies Pty Ltd (ACN 699 938 817, ABN 19 699 938 817), trading as First Six ("First Six", "we", "us"), registered in Queensland, Australia. You can reach us at privacy@firstsix.com.au.
Your university is the data controllerThe organisation that decides why and how personal data is handled, and is legally accountable for it.; First Six is its processorThe organisation that handles data on the controller's instructions and on its behalf.. Your university decides to offer the app, provides the support behind it, and is the legal custodian of your records. First Six operates the app and handles your data on your university's instructions, under a data-processing agreement. Where this policy says "your university's support team", it means staff your institution has authorised, not First Six staff.
This policy covers the First Six mobile app (iOS and Android) and the First Six web apps for students and staff. It does not cover the separate systems your university runs, such as your single sign-on or your student records system.
The short version
- We collect the enrolment details your university provides, the wellbeing check-ins and help requests you choose to make, your timetable and event activity, and your private workspace. We hold as little as we need.
- Your primary data is stored in Australia.
- By default, staff see the whole-group picture. But the support staff who cover your cohort can open your individual weekly check-in responses, so someone can reach out if you are struggling, and every such access is logged.
- We never hold your password, we take no payment data from you, and the mobile app has no analytics or tracking in it at all.
- You can see your own data in the app, and you can ask to have it deleted.
- If you are ever at immediate risk, the app shows you support resources and alerts your university's team. First Six is not a medical service.
Information we collect
From your university (your enrolment record). Your name, your institutional email address, and your program and campus. We do not receive or store your university's directory or your password.
Things you tell the app about yourself. A preferred name, the groups or situations you identify with (for example first-in-family, commuter, working student), and onboarding answers you choose to give. You can change these.
Your weekly wellbeing check-in. Each week you can say how the week is landing by choosing from a short set of options. If you indicate you are struggling, we may ask one optional follow-up: what is weighing on you most, from a fixed list. You can skip the check-in and you can change your answer.
Help and crisis requests. When you ask for help, we collect the type of help, any note you choose to write, how urgent it looks, and the conversation between you and your university's support team.
Your timetable and events. Classes and items you add or edit (including any title, location, or note you type), and which events you save or RSVP to.
Your private workspace. Your tasks, notes, and focus-timer sessions. These are private to you.
Push notification token, if you turn notifications on. If you opt in, your device gives us a push token so we can send you reminders and let you know when someone replies. You can turn this off at any time.
Limited technical data. On the web apps, we keep short-lived, personal-data- minimised diagnostic logs and error reports to keep the service working (personal details are scrubbed before they leave the app). The mobile app itself contains no analytics, no tracking, and no advertising identifiers, and does not collect your device model, location, or contacts.
We deliberately do not hold some things, because the strongest protection for a piece of data is not having it. We take no passwords (your university signs you in), no payment data (billing is with your university), and no health records beyond the wellbeing you choose to self-report. We do not sell your data and we do not use it for advertising.
What the mobile app stores on your device
The mobile app keeps three things in your device's secure storage (the operating system keychain, hardware-backed where your device supports it), never in plain storage: your session token (which keeps you signed in), a short-lived sign-in verifier (deleted as soon as sign-in completes), and your push token if you have turned notifications on. Your session token only ever travels in a secure request to our servers, never in a web address. Signing out deletes it from your device and ends the session on our servers.
Who can see your wellbeing and help data
Your check-in is not anonymous to your support team, and we want to be plain about that, because the point of a check-in is that someone can notice and reach out.
- The cohort picture (the default staff view). When staff open the wellbeing dashboard, they see the whole group: the share of students thriving or struggling this week, not a list of names. On these aggregate views, small groups are protected: a breakdown stays hidden until at least five students sit behind it, so a percentage can never be pointed at one person.
- Your individual weekly answer (seen by your support team, and logged). The staff at your university who support your cohort can open a closer view that shows individual check-in responses, including yours, so a week where you say you are struggling can become someone actually reaching out. This is limited to support staff at your university, never other students, never another institution. Every time a staff member opens your record, it is written to a tamper-resistant audit log. It exists to support you, not to grade you.
- The "what's weighing on you" follow-up stays aggregate. If you pick a reason for what is weighing on you, that answer is only ever shown to staff as a group total, with small groups hidden, and is never linked to your name.
- Asking for help directly. When you raise a help request, it goes straight to a staff member to act on, because you have asked someone to. They see what you wrote, the category, and how urgent it looks.
- What stays private, even from staff. Your Workspace (tasks, notes, focus-timer sessions) is visible only to you, and which wellbeing articles you open is not reported to anyone.
The full detail, surface by surface, is in what staff see (and what they don't).
If you might be at immediate risk
If something you write suggests you may be at immediate risk of harm, the app does two things straight away: it shows you immediate-support resources (such as Lifeline 13 11 14, Beyond Blue, and Emergency 000), and it alerts your university's support team so someone can respond.
First Six is a wellbeing companion and a way to reach support. It is not a medical device and does not provide diagnosis, assessment, or treatment. In an emergency, always call 000.
How we share your information
We do not sell your data. We share it only with the service providers that help us run First Six (our subprocessorsA third party that processes data on our behalf as part of running First Six.), and only as needed to deliver the app. Your primary data is stored in Australia; some providers are located overseas, and we name them rather than bury them.
| Provider | What it does | Where | What it can see |
|---|---|---|---|
| Supabase (on AWS, Sydney) | Database, sign-in, file storage: the system of record | Australia | Application data, isolated to your university |
| Vercel | App hosting and content delivery | Sydney compute; global CDN | Requests in transit; no records at rest |
| SendGrid | Sending email (sign-in links and notifications) | United States | Recipient address and message content, which can include welfare-relevant wording |
| Twilio | Crisis SMS, where your university turns it on | United States | Recipient phone number and crisis message content |
| Slack | Crisis alerts to a channel your university chooses, where it turns it on | Your university's Slack workspace | The crisis alert content |
| Expo | Push notifications and app updates for the mobile app | United States | Your device's push token and a generic notification ("you have a new message"); we deliberately keep welfare detail out of it, so the substance stays behind sign-in |
| Sentry | Error monitoring (web apps) | United States | Diagnostics with personal data scrubbed out before it leaves the app |
| Anthropic | An AI drafting aid used by staff in the admin console | United States | What staff type into it, plus content context such as tags and cohort settings; never student wellbeing records, and never used to train models |
| Anthropic | The "Ask AI" helper on our public help site | United States | The visitor's typed question and the help article's published text; never student wellbeing records, and never used to train models |
| Upstash | Anti-abuse rate-limiting | Australia (Sydney) | A visitor IP and route for short-lived counters; no personal records |
| Plausible | Cookieless analytics on the public help site only | European Union | Anonymous page visits. The student and staff apps are not instrumented |
| Google Fonts | Web fonts on page load | Google (US) | Your IP and browser type when a page loads a font |
| BetterStack | Uptime monitoring and the public status page | European Union | No personal data on health probes; standard visitor metadata on the status page |
The always-current list is on the Subprocessors page. Where a provider is overseas, your information may be processed outside Australia; for notifications and alerts that can include some welfare-relevant wording. Your university's own identity provider (its single sign-on) is its system, not ours.
Where your data is stored, and how it is kept safe
Your primary data (the database, sign-in, and file storage) is hosted in Australia, in AWS's Sydney region. Data is encrypted in transit (TLS, with HSTS) and at rest.
One university's data cannot be read by another: isolation is enforced in the database itself (row-level security keyed to your university), not just in app code. First Six's own staff have no standing access to your records; our operator tools show only aggregate health, never names or message content. The single exception is a "break-glass" access that an admin at your university can open for one student, with a reason and an expiry of at most 72 hours, revocable at any time, and even then First Six sees only the technical shape of the records, never the words, your name, or your private workspace, with every look logged in your university's own audit trail. First Six does not yet hold a SOC 2 or ISO 27001 certification, and we say so plainly rather than imply one. Fuller detail is in data residency and tenant isolation.
How long we keep your information
We keep your information for the life of your enrolment and then delete it, in line with the arrangement between First Six and your university. Some records your university is legally required to keep (for example certain help or crisis records, for duty-of-care or reporting reasons) may be held for longer; where that applies, it is generally no more than 12 to 24 months after your enrolment ends. We hold as little as we need, for no longer than we need it.
When your data is deleted it is a hard delete: your check-ins, help requests, saved items, and timetable are removed from the live system, not just hidden. Two bounded things outlive a delete: routine encrypted backups, which age out on a short rolling cycle (within 30 days), and the tamper-resistant log of staff actions, kept for accountability. Group statistics are recalculated without your responses; what remains are anonymous counts that never identified you.
Your choices and your rights
- See your own data in the app: your check-in history, any help request, and the enrolment details synced from your university.
- Change what you share. The check-in is optional; you can skip it, change your answer, and adjust your profile.
- Turn notifications off in the app or your device settings.
- Sign out. Signing out ends the session on that device and revokes it on our servers. Signing out is not the same as deleting.
- Delete your data. Because your university is the data controller, deletion is authorised by your university. You can start a request from the app's settings or through your university's privacy or student-services contact. If you contact us at privacy@firstsix.com.au, we will route your request to your university's privacy contact and confirm back to you. A hard delete cannot be undone.
- Correct your data, or complain. You can ask us or your university to correct information that is wrong. Under the Australian Privacy Act you can also complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
Because wellbeing information is sensitive informationA category the Australian Privacy Act protects more strictly, including health and wellbeing information. under the Privacy Act 1988 (Cth), by using the wellbeing check-in and help features you consent to First Six and your university handling it in the ways described here, including your support team being able to see your individual check-in responses. You can withdraw that consent by not using those features, or by asking to have your data deleted; doing so will not affect the rest of the app.
Children and age
First Six is provided to students by their university and is intended for use by tertiary students. It is not directed at children under 16. Some students may be under 18; where that is the case, your university provides the consent basis for handling their information, as part of its role as the data controller.
Trying the demo
The app offers an anonymous "Explore a demo" option so app-store reviewers and prospective users can look around without a university sign-in. The demo creates a fully synthetic, auto-expiring practice account with made-up data in an isolated demo space. Using the demo does not collect any information about your device, and nothing you do in it reaches or notifies any real university or its staff.
Cookies and similar technologies
- The mobile app uses no cookies. It keeps only the sign-in items described above, in your device's secure storage.
- The web apps use a small number of strictly necessary items to keep you signed in and secure, not for advertising or cross-site tracking.
- The public help site uses cookieless analytics (Plausible) and loads web fonts from Google.
Changes to this policy
If we change this policy, we will update the effective date at the top and, for significant changes, let you know in the app or by email. Continuing to use First Six after a change means the updated policy applies.
Common questions
Can a staff member see my individual check-in answer?
Yes. The support staff who cover your cohort can open your individual weekly check-in responses, so they can follow up if you might need a hand, and every access is logged. The default view they work from is the whole-group picture. The one part that stays anonymous is the short "what's weighing on you" follow-up, which is only ever shown as a group total.
Is any of my data stored outside Australia?
Your primary data (database, sign-in, file storage) is in Australia. Some subprocessors are overseas, mostly for email, notifications, and error monitoring; the full list and what each can see is on the Subprocessors page.
How do I delete my data?
Your university authorises deletion. Start from the app's settings, through your university, or email privacy@firstsix.com.au and we will route it. It is a hard delete and cannot be undone.
Contact
Questions, requests, or concerns about your privacy: privacy@firstsix.com.au. Because your university is the data controller, you can also raise a request through its privacy or student-services contact, and we will work with them to action it.
First Six Technologies Pty Ltd (ACN 699 938 817, ABN 19 699 938 817), registered in Queensland, Australia.
Related
The fastest answer is usually one question away.