Privacy policy
First Six is a mobile and web app that helps a university student through their first six weeks: what matters each week, their timetable and events, a weekly wellbeing check-in, and a way to ask a real person for help. This policy explains what we collect, how it is used, and the control you have over it. It is written to be read, not to be survived.
Effective date: 27 July 2026
Two additions to the subprocessor table below, both disclosed rather than folded in quietly. GitHub now holds a daily encrypted off-site backup of the database, so losing our main cloud provider would not lose your data with it; it is encrypted with a key we hold offline, so GitHub stores bytes it cannot read. And SendGrid now receives mail as well as sending it, so that replying to an email about a help request puts your reply in the request itself instead of in a private mailbox nobody can see.
Who we are, and who this policy is for
The app is operated by First Six Technologies Pty Ltd (ACN 699 938 817, ABN 19 699 938 817), trading as First Six ("First Six", "we", "us"), registered in Queensland, Australia. You can reach us at privacy@firstsix.com.au.
Your university is the data controllerThe organisation that decides why and how personal data is handled, and is legally accountable for it.; First Six is its processorThe organisation that handles data on the controller's instructions and on its behalf.. Your university decides to offer the app, provides the support behind it, and is the legal custodian of your records. First Six operates the app and handles your data on your university's instructions, under a data-processing agreement. Where this policy says "your university's support team", it means staff your institution has authorised, not First Six staff.
This policy covers the First Six mobile app (iOS and Android) and the First Six web apps for students and staff. It does not cover the separate systems your university runs, such as your single sign-on or your student records system.
The short version
- We collect the enrolment details your university provides, the wellbeing check-ins and help requests you choose to make, your timetable and event activity, and your private workspace. We hold as little as we need.
- Your primary data is stored in Australia, and since 25 August 2026 so is our daily backup of it. We keep a second copy of that backup with GitHub, outside Australia, so that a single provider's bad day cannot lose your data. Both copies are encrypted with a key we keep offline, so nothing readable about you is stored anywhere outside Australia.
- By default, staff see the whole-group picture. But the support staff who cover your cohort can open your individual weekly check-in responses, including your answer about what is weighing on you, so someone can reach out if you are struggling, and every such access is logged. The one exception is the optional private note on a daily wellbeing entry, which only you can read.
- We never hold your password, we take no payment data from you, and the mobile app has no analytics or tracking in it at all.
- You can see your own data in the app, and you can ask to have it deleted.
- If you are ever at immediate risk, the app shows you support resources and alerts your university's team. First Six is not a medical service.
Information we collect
From your university (your enrolment record). Your name, your institutional email address, and your program and campus. We do not receive or store your university's directory or your password.
Things you tell the app about yourself. A preferred name, the groups or situations you identify with (for example first-in-family, commuter, working student), and onboarding answers you choose to give. You can change these.
Groups your university has already recorded, if it sends them. Your university may already hold that you are, for example, first-in-family, a commuter, or a mature-age student, and it can choose to send those to First Six with your enrolment record so you do not have to enter them again. Two things about this:
- Your university decides this group by group. Nothing is sent unless it has been switched on for that particular group.
- You can always take yourself out, on the People page. Once you do, no later update from your university puts you back in. Your choice is final and we remember it.
If a group would reveal sensitive informationA category the Australian Privacy Act protects more strictly. It includes health information, racial or ethnic origin, and sexual orientation. about you (for example a group about being LGBTQIA+, Aboriginal or Torres Strait Islander, or neurodivergent), your university must additionally confirm that it holds your consent to share it with us before it can be sent at all. We record who confirmed that and when. If you would rather it had not been shared, you can remove yourself here and raise it with your university, which is the source.
Your weekly wellbeing check-in. Each week you can say how the week is landing by choosing from a short set of options. If you indicate you are struggling, we may ask one optional follow-up: what is weighing on you most, from a fixed list. You can skip the check-in and you can change your answer.
Help and crisis requests. When you ask for help, we collect the type of help, any note you choose to write, how urgent it looks, and the conversation between you and your university's support team.
Your timetable and events. Classes and items you add or edit (including any title, location, or note you type), and which events you save or RSVP to.
Your private workspace. Your tasks, notes, and focus-timer sessions. These are private to you.
Push notification token, if you turn notifications on. If you opt in, your device gives us a push token so we can send you reminders and let you know when someone replies. You can turn this off at any time.
Limited technical data. On the web apps, we keep short-lived, personal-data- minimised diagnostic logs and error reports to keep the service working (personal details are scrubbed before they leave the app). The mobile app itself contains no analytics, no tracking, and no advertising identifiers, and does not collect your device model, location, or contacts.
We deliberately do not hold some things, because the strongest protection for a piece of data is not having it. We take no passwords (your university signs you in), no payment data (billing is with your university), and no health records beyond the wellbeing you choose to self-report. We do not sell your data and we do not use it for advertising.
What the mobile app stores on your device
The mobile app keeps three things in your device's secure storage (the operating system keychain, hardware-backed where your device supports it), never in plain storage: your session token (which keeps you signed in), a short-lived sign-in verifier (deleted as soon as sign-in completes), and your push token if you have turned notifications on. Your session token only ever travels in a secure request to our servers, never in a web address. Signing out deletes it from your device and ends the session on our servers.
Who can see your wellbeing and help data
Your check-in is not anonymous to your support team, and we want to be plain about that, because the point of a check-in is that someone can notice and reach out.
- The cohort picture (the default staff view). When staff open the wellbeing dashboard, they see the whole group: the share of students thriving or struggling this week, not a list of names. On these aggregate views, small groups are protected: a breakdown stays hidden until at least five students sit behind it, so a percentage can never be pointed at one person.
- Your individual weekly answer (seen by your support team, and logged). The staff at your university who support your cohort can open a closer view that shows individual check-in responses, including yours, so a week where you say you are struggling can become someone actually reaching out. This is limited to support staff at your university, never other students, never another institution. Every time a staff member opens your record, it is written to a tamper-resistant audit log. It exists to support you, not to grade you.
- The "what's weighing on you" follow-up stays aggregate. If you pick a reason for what is weighing on you, that answer is only ever shown to staff as a group total, with small groups hidden, and is never linked to your name.
- Asking for help directly. When you raise a help request, it goes straight to a staff member to act on, because you have asked someone to. They see what you wrote, the category, and how urgent it looks.
- What stays private, even from staff. Your Workspace (tasks, notes, focus-timer sessions) is visible only to you, and which wellbeing articles you open is not reported to anyone.
The full detail, surface by surface, is in what staff see (and what they don't).
If you might be at immediate risk
If something you write suggests you may be at immediate risk of harm, the app does two things straight away: it shows you immediate-support resources (such as Lifeline 13 11 14, Beyond Blue, and Emergency 000), and it alerts your university's support team so someone can respond.
First Six is a wellbeing companion and a way to reach support. It is not a medical device and does not provide diagnosis, assessment, or treatment. In an emergency, always call 000.
How we share your information
We do not sell your data. We share it only with the service providers that help us run First Six (our subprocessorsA third party that processes data on our behalf as part of running First Six.), and only as needed to deliver the app. Your primary data is stored in Australia; some providers are located overseas, and we name them rather than bury them.
| Provider | What it does | Where | What it can see |
|---|---|---|---|
| Supabase (on AWS, Sydney) | Database, sign-in, file storage: the system of record | Australia | Application data, isolated to your university |
| Vercel | App hosting and content delivery | Sydney compute; global CDN | Requests in transit; no records at rest |
| SendGrid | Sending email (sign-in links and notifications), and receiving your replies: if you reply to an email about a help request, SendGrid receives that reply and passes it to us, and we file it in your request so the conversation stays in one place | United States | Recipient and sender address, and message content in both directions, which can include welfare-relevant wording |
| Slack | Crisis alerts to a channel your university chooses, where it turns it on | Your university's Slack workspace | The crisis alert content |
| Expo | Push notifications and app updates for the mobile app | United States | Your device's push token and a generic notification ("you have a new message"); we deliberately keep welfare detail out of it, so the substance stays behind sign-in |
| Sentry | Error monitoring (web apps) | United States | Diagnostics with personal data scrubbed out before it leaves the app |
| Anthropic | An AI drafting aid used by staff in the admin console | United States | What staff type into it, any file staff attach to it (such as a university handbook or calendar), plus content context such as tags and cohort settings; never student wellbeing records, and never used to train models |
| Anthropic | The "Ask AI" helper on our public help site | United States | The visitor's typed question and the help article's published text; never student wellbeing records, and never used to train models |
| Upstash | Anti-abuse rate-limiting | Australia (Sydney) | A visitor IP and route for short-lived counters; no personal records |
| Plausible | Cookieless analytics on the public help site only | European Union | Anonymous page visits. The student and staff apps are not instrumented |
| Google Fonts | Web fonts on page load | Google (US) | Your IP and browser type when a page loads a font |
| BetterStack | Uptime monitoring and the public status page | European Union | No personal data on health probes; standard visitor metadata on the status page |
| GitHub | Holds our daily off-site backup, so a copy of the database exists somewhere other than our main cloud provider and one provider's bad day cannot lose your data | United States / global | Encrypted data only, which GitHub cannot read. The backup job runs on GitHub's build machines and encrypts the copy in memory before anything is stored, so the only version kept is the encrypted one, and the key that opens it is held offline and never goes to the cloud. Kept 30 days, then deleted automatically |
| Amazon Web Services | Holds the Australian copy of that same daily backup, in a storage bucket we own in Sydney | Australia (Sydney) | Encrypted data only, which AWS cannot read. It is the identical file described in the row above: same job, same encryption, same offline key. The credential our backup job uses can only add files and list their names, not download or delete them. Kept 30 days, then deleted automatically |
The always-current list is on the Subprocessors page. Where a provider is overseas, your information may be processed outside Australia; for notifications and alerts that can include some welfare-relevant wording. Your university's own identity provider (its single sign-on) is its system, not ours.
Where your data is stored, and how it is kept safe
Your primary data (the database, sign-in, and file storage) is hosted in Australia, in AWS's Sydney region. Data is encrypted in transit (TLS, with HSTS) and at rest.
There is one deliberate exception, and we would rather name it than let you find it. Once a day we back the database up, and we keep that backup in two places: one in Australia, in a storage bucket we own in Sydney, and one with GitHub, outside Australia, so that losing any single provider would not take your data with it. The backup job runs on GitHub's build machines and encrypts the copy in memory before anything is stored, so the only version kept is the encrypted one, and the key that opens it is held offline and never goes to the cloud. Both providers store bytes they cannot read. Each copy is deleted automatically after 30 days. So no readable record about you is held outside Australia. The Australian copy was added on 25 August 2026; before that date the overseas copy was the only one.
One university's data cannot be read by another: isolation is enforced in the database itself (row-level security keyed to your university), not just in app code. First Six's own staff have no standing access to your records; our operator tools show only aggregate health, never names or message content. The single exception is a "break-glass" access that an admin at your university can open for one student, with a reason and an expiry of at most 72 hours, revocable at any time, and even then First Six sees only the technical shape of the records, never the words, your name, or your private workspace, with every look logged in your university's own audit trail. First Six does not yet hold a SOC 2 or ISO 27001 certification. Fuller detail is in data residency and tenant isolation.
How long we keep your information
We keep your information for the life of your enrolment and then delete it, in line with the arrangement between First Six and your university. Some records your university is legally required to keep (for example certain help or crisis records, for duty-of-care or reporting reasons) may be held for longer; where that applies, it is generally no more than 12 to 24 months after your enrolment ends. We hold as little as we need, for no longer than we need it.
When your data is deleted it is a hard delete: your check-ins, help requests, saved items, and timetable are removed from the live system, not just hidden. Two bounded things outlive a delete: routine encrypted backups, which age out on a short rolling cycle (within 30 days), and the tamper-resistant log of staff actions, kept for accountability. Group statistics are recalculated without your responses; what remains are anonymous counts that never identified you.
If you send us a feature request
Our roadmap has a box anyone can use to ask for something. You do not need an account and you do not have to identify yourself.
If you choose to leave an email address, we use it for one thing: to reply to you about that request, including telling you if we build it. It is not added to a mailing list, it is not used for marketing, and it is not shared with your university or anyone else. Ask us and we will delete it.
The request itself, without the email, is kept while the idea is live so we can tell whether several people have asked for the same thing. Please do not put anything sensitive in it: it is a suggestion box, not a support channel, and if you need help or want to raise something about your own wellbeing, use the help option inside the app instead, where it reaches the right people.
Your choices and your rights
- See your own data in the app: your check-in history, any help request, and the enrolment details synced from your university.
- Change what you share. The check-in is optional; you can skip it, change your answer, and adjust your profile.
- Turn notifications off in the app or your device settings.
- Sign out. Signing out ends the session on that device and revokes it on our servers. Signing out is not the same as deleting.
- Delete your data. Because your university is the data controller, deletion is authorised by your university. You can start a request from the app's settings or through your university's privacy or student-services contact. If you contact us at privacy@firstsix.com.au, we will route your request to your university's privacy contact and confirm back to you. A hard delete cannot be undone.
- Correct your data, or complain. You can ask us or your university to correct information that is wrong. Under the Australian Privacy Act you can also complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
Because wellbeing information is sensitive informationA category the Australian Privacy Act protects more strictly, including health and wellbeing information. under the Privacy Act 1988 (Cth), by using the wellbeing check-in and help features you consent to First Six and your university handling it in the ways described here, including your support team being able to see your individual check-in responses. You can withdraw that consent by not using those features, or by asking to have your data deleted; doing so will not affect the rest of the app.
Where a group came from your university rather than from you, that consent is not the basis, because you did not do anything. The basis is the consent your university holds and confirms to us before any such group can be sent. This is why a sensitive group cannot be sent automatically until your university has made that confirmation, and why removing yourself is permanent rather than undone by the next update.
Children and age
First Six is provided to students by their university and is intended for use by tertiary students. It is not directed at children under 16. Some students may be under 18; where that is the case, your university provides the consent basis for handling their information, as part of its role as the data controller.
Trying the demo
The app offers an anonymous "Explore a demo" option so app-store reviewers and prospective users can look around without a university sign-in. The demo creates a fully synthetic, auto-expiring practice account with made-up data in an isolated demo space. Using the demo does not collect any information about your device, and nothing you do in it reaches or notifies any real university or its staff.
Cookies and similar technologies
- The mobile app uses no cookies. It keeps only the sign-in items described above, in your device's secure storage.
- The web apps use a small number of strictly necessary items to keep you signed in and secure, not for advertising or cross-site tracking.
- The public help site uses cookieless analytics (Plausible) and loads web fonts from Google.
- The pricing calculator on that site tells us when the page is opened and what was entered into it. See below.
The pricing calculator
The pricing page on our help site is not linked from anywhere: it is shared with a particular institution, by a link we send. So that we know to pick the conversation up, opening it sends us a notification containing the figures you put into the calculator (a student count and two toggles), how long the page was open, and the ordinary details every web request carries: your IP address, browser, language, and the page you arrived from.
There is no account, no cookie and no profile behind it. The numbers you type are not stored against you, are not used for anything but that one notification, and are not shared with anyone. If you would rather look at it without telling us, say so and we will send you the same figures as a PDF.
Changes to this policy
If we change this policy, we will update the effective date at the top and, for significant changes, let you know in the app or by email. Continuing to use First Six after a change means the updated policy applies.
Common questions
Can a staff member see my individual check-in answer?
Yes. The support staff who cover your cohort can open your individual weekly check-in responses, so they can follow up if you might need a hand, and every access is logged. The default view they work from is the whole-group picture. That includes the short "what's weighing on you" follow-up, which they can see against your name on your own profile, so that naming money or your wellbeing as the blocker gets you help rather than a statistic. In the insights reports it stays a group total with small groups suppressed, and there is no way to click from those numbers to a person.
One thing is different: the optional private note you can add to a daily wellbeing entry is yours alone. No staff view contains it. If you want your support team to know what it says, you send it yourself.
Is any of my data stored outside Australia?
Your primary data (database, sign-in, file storage) is in Australia. Some subprocessors are overseas, mostly for email, notifications, and error monitoring; the full list and what each can see is on the Subprocessors page. One more thing sits overseas and is worth naming: a daily backup of the database is kept with GitHub so a single provider's outage cannot lose your data. It is encrypted before it is stored and the key that opens it is held offline, so GitHub keeps bytes it cannot read, and it is deleted after 90 days. Nothing readable about you is stored outside Australia.
How do I delete my data?
Your university authorises deletion. Start from the app's settings, through your university, or email privacy@firstsix.com.au and we will route it. It is a hard delete and cannot be undone.
Contact
Questions, requests, or concerns about your privacy: privacy@firstsix.com.au. Because your university is the data controller, you can also raise a request through its privacy or student-services contact, and we will work with them to action it.
First Six Technologies Pty Ltd (ACN 699 938 817, ABN 19 699 938 817), registered in Queensland, Australia.
Related
The fastest answer is usually one question away.