Effective date: 26 July 2026
## 1. About This Policy
This Privacy Policy explains how TechKangaroos (“we”, “us”, or “our”) handles information when you use the AU Students iOS application (“the App”) and its connected WordPress community service.
AU Students is an independent, unofficial application. It is not affiliated with or endorsed by the Australian Government, the Department of Home Affairs, ImmiAccount, VEVO, any education provider, or any migration agent.
## 2. Information We Handle
### Guest Mode
You may use Guest Mode without creating an account. Guest Mode provides access to official links, sample analytics, legal information, and settings. Guest Mode does not provide access to the Community and does not create a WordPress profile.
### Sign in with Apple and Account Information
If you create an account using Sign in with Apple, we receive and process:
– your Apple account identifier for the App;
– your name, when Apple makes it available;
– your verified email address or Apple private relay email address;
– the public username used in the Community;
– a WordPress user identifier; and
– authentication and session information required to keep you signed in.
The App sends the Apple identity token and a security nonce directly to our WordPress service. The service verifies the token using Apple’s public keys before creating a session. The App stores its WordPress session token in the iOS Keychain. WordPress stores only a cryptographic hash of that session token.
### Community Content
When you use Community, we process:
– messages you submit;
– your public Community username;
– message timestamps;
– moderation status; and
– account identifiers needed to associate messages with your account.
Community messages are visible to other authorised Community users and may also be visible through a connected, authenticated WordPress community page. Do not include passport numbers, transaction reference numbers, ImmiAccount credentials, identity documents, financial records, home addresses, or other sensitive personal information in Community messages.
Community content may be reviewed, restricted, or removed to enforce our community standards and legal obligations.
### Visa Tracker and Checklist Information
The current version processes visa tracker entries, checklist selections, notes, dates, filters, and reminder preferences on your device. These tracker and checklist details are not uploaded to the WordPress Community service unless a future feature clearly tells you otherwise and this policy is updated.
You should not enter passport numbers, transaction reference numbers, visa grant numbers, account passwords, full dates of birth, financial documents, identity documents, or other highly sensitive information into the App.
### Notifications
If you grant notification permission, the App may schedule local notifications for checklist items, course dates, OSHC dates, and other enabled reminders. These notifications are scheduled and delivered by your device. You can change notification permission in iOS Settings.
### Technical and Server Information
Our WordPress hosting provider may process standard server information when the App connects to the Community, such as IP address, request time, requested endpoint, response status, and basic device or network information supplied with the request. This information is used for security, abuse prevention, service reliability, and troubleshooting.
## 3. How We Use Information
We use information to:
– create and manage your WordPress-connected App account;
– authenticate you securely;
– synchronise your name, username, and verified email with WordPress;
– provide and moderate Community chat;
– maintain security and prevent abuse;
– respond to support, privacy, and deletion requests;
– provide local reminders and App functionality; and
– comply with legal obligations.
We do not use personal information for third-party advertising or cross-app tracking.
## 4. How We Share Information
We may share or make information available:
– to other authorised Community users, when you post a Community message;
– to Apple, as required to operate Sign in with Apple and iOS services;
– to our WordPress hosting and technical service providers, solely to operate and secure the service;
– when required by law, regulation, legal process, or a valid government request; or
– when reasonably necessary to protect users, enforce our terms, investigate abuse, or protect our rights.
We do not sell personal information.
Official links in the App open external websites, including government and Study Australia services. Those services operate under their own privacy policies, and we do not control their data practices.
## 5. Data Retention
Account information is generally retained while your account remains active.
Community messages are retained while needed to operate the Community, enforce community standards, resolve disputes, and meet legal obligations. Messages may be removed by moderators. When the in-app account deletion process completes successfully, the connected WordPress subscriber account and messages associated with that account are deleted, except where retention is legally required.
Local App information remains on your device until it is removed by the App, you delete the App, or you reset the relevant device data. Standard server logs may be retained according to our hosting provider’s security and backup schedules.
## 6. Your Choices and Rights
Depending on your location, you may have rights to request access to, correction of, or deletion of your personal information, or to object to or restrict certain processing.
Within the App, you can:
– use Guest Mode without creating an account;
– edit your public username;
– control notification preferences;
– sign out; and
– request account deletion from Settings.
You may also contact us using the address below for privacy questions or requests. We may need to verify your identity before completing a request.
## 7. Account Deletion
You can initiate account deletion from Settings in the App. A successful deletion request removes the connected WordPress subscriber account and its associated Community messages. Deleting the App from your device does not by itself delete an online account.
If an account deletion request fails because the service is unavailable, contact us so we can complete the request.
## 8. Security
We use reasonable administrative and technical safeguards designed to protect information. These include HTTPS connections, server-side verification of Apple identity tokens, nonce validation, hashed server-side session tokens, iOS Keychain storage, access controls, and moderation tools.
No electronic transmission or storage system is completely secure. We cannot guarantee absolute security.
## 9. Children
The App is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided personal information, contact us so we can investigate and take appropriate action.
Parents and guardians should supervise minors who use Community features.
## 10. International Processing
Our service providers may process information in countries other than the country where you live. Where required, we take reasonable steps to ensure information receives appropriate protection.
## 11. Changes to This Policy
We may update this Privacy Policy when the App, connected services, or legal requirements change. We will publish the revised policy with a new effective date. Material changes may also be communicated through the App or App Store listing where appropriate.
## 12. Contact Us
For privacy questions, support, content concerns, or account deletion assistance, contact:
TechKangaroos
Email: techkangaroos.au@gmail.com
—
# Recommended App Store Privacy Answers
Confirm these answers against the production WordPress host and any additional SDKs before publishing.
## Data Used for App Functionality, Linked to the User, Not Used for Tracking
– Contact Info — Name
– Contact Info — Email Address
– Identifiers — User ID
– User Content — Other User Content
## Possible Additional Server Data
If production server logs are retained and associated with a user, review whether “Other Data” or relevant diagnostics categories must also be declared.
## Tracking
– Data used for tracking: No