Privacy Policy

Last updated 29 July 2026

SwimPilot holds information about children, their families and the people who teach them. This policy explains what we collect, why, who it is shared with, how long it is kept, and how to get a copy of it or have it deleted.

1. Who we are, and whose data this covers

SwimPilot is swim school management software operated by Studio Parallel ("we", "us"). Swim schools use it to run enrolments, classes, attendance, billing and family communications.

Two different relationships are described in this policy, and it matters which one you are in.

  • If you are a swim school — an owner, administrator or teacher with a SwimPilot login — we handle your account information directly, and this policy describes what we do with it.
  • If you are a parent, guardian or student — your relationship is with the swim school, not with us. The school decides what information to collect about your family and why; we hold and process it on the school’s behalf and under its instructions. Ask your swim school first if you want to see, correct or delete family records. We help the school action those requests, and you can always contact us directly if you cannot reach them.

This policy is written to the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth).

2. What information we collect

We collect only what the software needs to run a swim school. We do not buy personal information from data brokers, and we do not collect information for advertising.

CategoryWhat it includes
School staff accountsName, email address, assigned role, multi-factor authentication enrolment, and sign-in and security events.
Families and guardiansFamily or guardian name, contact email address, contact phone number, account balance, and any medical or care notes recorded against the family.
Students (children)Name, date of birth, swimming level and progression history, safety alerts and medical notes, media consent status, attendance records, absences, make-up credits and skill assessments.
Billing and paymentsCharges, credits, adjustments, lesson block purchases and account balances. Card details are entered directly with our payment provider and are never stored by SwimPilot.
CommunicationsMessages exchanged between a school and a family through the SwimPilot inbox, the conversation they belong to, and the sender identifiers (such as an email address, phone number or messaging account ID) used to match an incoming message to the right family.
Photos and videoImages and video of students, captured or uploaded by school staff, and only where the family’s media consent has been recorded.
Technical and security dataIP address, browser and device information, application error diagnostics, and an append-only audit record of who changed what and when.

3. Information about children

Swim schools are, by their nature, records about children. We treat that information as sensitive and build specific protections around it.

  • We collect information about a child from the parent or guardian who enrols them, or from school staff — never directly from the child, and children do not have SwimPilot logins.
  • Medical notes and safety alerts are encrypted by the application itself using a key unique to each school, so they are protected beyond ordinary disk encryption.
  • Access is separated by role: teachers see the safety alerts they need to keep a child safe in the water, while full medical notes are restricted to school owners and administrators.
  • Photos and video may only be viewed where the family has given media consent. Consent is checked every time the media is read, not just when it is captured, so withdrawing consent takes effect immediately.
  • Each school can only ever see its own families and students. Separation between schools is enforced by the database itself, not only by application code.

4. How we use information

  • To run the service: enrolments, class scheduling, rolls and attendance, absences, make-up bookings and progression tracking.
  • To bill accurately: calculating charges and credits, processing payments, and maintaining a correct account balance and financial history.
  • To let schools and families communicate, and to route an incoming message to the right family.
  • To keep children safe: surfacing the medical and safety information a teacher needs at the poolside.
  • To secure the service: authentication, multi-factor authentication, fraud and abuse prevention, and an audit trail of changes.
  • To support and improve the product: diagnosing faults, monitoring errors, and responding to support requests.
  • To meet legal and record-keeping obligations, including financial record retention.

We do not sell personal information, we do not share it with advertising networks, and we do not use family or student information to train third-party AI models.

5. AI-assisted features

SwimPilot includes an assistant that helps school administrators with everyday tasks. It is constrained by design: it can only do what the signed-in administrator could already do, and it reaches data through the same permission-checked paths as the rest of the application rather than querying the database directly.

Where the assistant needs a language model, the request is processed by Anthropic. Content sent for this purpose is not used to train models.

Administrators can also teach the assistant facts about how their school operates — terminology, preferences and workflows. These notes are school-level and administrators are instructed not to record family or student personal information in them. A school’s taught facts are deleted when the school leaves SwimPilot.

6. Facebook Messenger and WhatsApp (not yet available)

These channels are not available yet. No school can connect a Facebook Page to SwimPilot today, and no information about you or your family is exchanged with Meta. We are publishing this section ahead of the feature so that the handling is written down before the first message could ever arrive: everything in this section describes how the integration will work once we switch it on, not something happening now.

When it is available, a swim school will be able to connect its Facebook Page so that messages families send to the Page arrive in the same inbox as the school’s other messages. It will always be the school’s choice. If your school does not connect the channel, nothing in this section will apply to you and no information about you will be exchanged with Meta.

The connection will be set up by a school administrator using Facebook Login for Business. The administrator will select the Page they manage and grant SwimPilot access to it. The Page access token that results will be stored encrypted, and will be used only to send and receive that school’s Page messages. To be plain about today: no such token is held anywhere in SwimPilot, because there is no way for a school to create one.

SwimPilot will request only the permissions it needs to run a two-way inbox: pages_messaging, to receive messages sent to the Page and reply to them, and the human agent capability, so a member of staff can answer a family outside the standard messaging window. It will subscribe to the messages and messaging_postbacks webhook fields on the connected Page, and nothing else. We will not request access to Instagram messaging.

Detail
What we will receive from MetaThe content of messages a person sends to the connected Page; the sender’s Page-Scoped ID (a per-Page identifier that cannot be used to identify the person on any other Page or app); the Meta message identifier; and message timestamps.
What we will do with itShow the message to the school’s staff in the SwimPilot inbox, thread it into a conversation, match the sender to an existing family record in that school so staff have context, and let staff reply.
What we will send to MetaThe reply the school’s staff write, and the Page-Scoped ID of the person it should be delivered to, so that Meta can deliver it.
What we never doWe do not use this data for advertising, ad targeting, audience building, or any pixel or conversions integration; we do not sell it or pass it to data brokers; and we do not use it to build a profile of anyone beyond matching a sender to a family in the school that received the message. Message content and sender identifiers are excluded from our error-monitoring and logs.
How long we will keep itMessages will be retained for two years from the last message in the conversation, for operational and dispute-resolution purposes. Learned sender identifiers are deleted when the family record is erased, and will also be deleted when a school disconnects the channel.
How to disconnectA school administrator will be able to disconnect the channel in SwimPilot at any time. You will also be able to remove SwimPilot from your Facebook Page settings or Meta Business settings, which stops any further exchange of data.

WhatsApp will be handled differently, and it is not available yet either. Where a school enables WhatsApp, messages will be brokered by Twilio using the school’s own WhatsApp Business account, and Twilio — not SwimPilot — will be the party that connects to Meta. The information we would hold about a WhatsApp conversation is the same as for any other channel: the message content, the sender’s phone number, and the conversation it belongs to. To have data received through either channel deleted, follow the instructions in section 7.

7. How to request deletion of your data

This section is the data deletion instruction for SwimPilot, including for information received through connected Meta channels. To request deletion, email team@studioparallel.com.au from the address or number you contacted the school on, or ask your swim school to raise the request for you. Tell us the swim school involved and which records you want removed. We will confirm receipt and action the request within 30 days.

When we action a deletion request we permanently remove identifying details: names are erased, contact email addresses and phone numbers are removed, dates of birth are cleared, encrypted medical notes are destroyed rather than merely hidden, and the learned messaging identifiers that link a Messenger or WhatsApp sender to a family are purged.

Two categories are deliberately kept, and cannot be deleted on request. Financial records — charges, credits, payments and adjustments — are retained for seven years to meet Australian financial record-keeping obligations. The audit trail of who changed what is retained for the life of the school account; it holds no readable personal information, because encrypted fields are recorded as redacted. After a deletion, the remaining records no longer identify anyone.

8. Who we share information with

We use a small number of service providers to run SwimPilot. They may only process information to provide their service to us, and never for their own purposes. Some are located outside Australia, so this is a cross-border disclosure under APP 8; we rely on their contractual and security commitments.

ProviderPurposePrivacy policy
SupabaseDatabase, authentication and file storage. Hosted in the Sydney region.supabase.com/privacy
StripePayment processing. Card details are collected by Stripe directly.stripe.com/privacy
ResendSending transactional email such as invitations and receipts.resend.com/legal/privacy-policy
Meta PlatformsFacebook Messenger conversations, once that channel is available and a school has connected its Page (section 6). No data reaches Meta today.facebook.com/privacy/policy
TwilioSMS delivery, and WhatsApp messaging where a school has enabled it (section 6).twilio.com/legal/privacy
AnthropicThe language model behind AI-assisted features (section 5).anthropic.com/legal/privacy
SentryApplication error monitoring and diagnostics.sentry.io/privacy
InngestRunning scheduled and background jobs such as reminders.inngest.com/privacy
CloudflareBot protection on the sign-up form, where enabled.cloudflare.com/privacypolicy

We may also disclose information where the law requires it, or where it is necessary to prevent a serious threat to a person’s life, health or safety.

9. Where information is stored, and how it is protected

  • Data is stored in Australia. The primary database and file storage are pinned to the Sydney region.
  • Information is encrypted in transit and at rest. Medical notes and safety alerts receive an additional layer of application-level encryption using per-school keys.
  • Photos and video are held in private storage that is never publicly readable. Staff reach them through short-lived links issued by the server only after a consent and permission check.
  • Each school is isolated at the database level, so one school cannot read another school’s records even if application code were at fault.
  • Access within a school is limited by role, so staff see only what their role requires.
  • Administrator accounts can be protected with multi-factor authentication.
  • Every change to family, student, enrolment, billing and settings data is written to an append-only audit log that cannot be altered or deleted. Encrypted fields are recorded as redacted, so the audit trail never stores readable medical information.
  • Diagnostic and error reports are scrubbed of personal information before they leave the application.
  • Backups are taken daily, with point-in-time recovery available.

No system is perfectly secure. If we become aware of a data breach likely to cause serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme.

10. How long we keep information

InformationRetention period
Enrolment records — identity, contact details, medical notes, enrolments, attendance, absences, credits and progressionFor the duration of the relationship, and seven years after a student leaves.
Financial records — charges, credits, adjustments, blocks and balancesSeven years from the entry, in line with Australian financial record-keeping requirements. These records are append-only: a correction is made by adding a reversing entry, never by editing history.
Photos and video of studentsWhile media consent holds. Deleted on withdrawal of consent, or within 12 months of a student leaving.
Messages, including those received through Meta channelsTwo years from the last message in the conversation. Learned sender identifiers are deleted on erasure of the family record or on disconnection of the channel.
Audit records of who changed whatThe life of the school account, and a minimum of seven years. These records contain no readable personal information.

When a swim school leaves SwimPilot, its data is deleted, subject to the financial and audit retention periods above.

11. Your rights

  • Access and a copy — you can ask for a copy of the information held about your family, provided in a portable, machine-readable format (APP 12).
  • Correction — you can ask for inaccurate or out-of-date information to be corrected (APP 13). Every correction is recorded, so there is always a record of what changed and who changed it.
  • Deletion — you can ask for your information to be erased, as described in section 7.
  • Withdraw media consent — you can withdraw consent for photography and video at any time, which immediately prevents further access to that media.
  • Complain — if you are unhappy with how we have handled your information, you can complain to us and, if still unsatisfied, to the Office of the Australian Information Commissioner.

If you are a parent or guardian, please raise these requests with your swim school first, as it holds the relationship with you. We will support the school in actioning them, and you can contact us directly if you cannot reach the school.

12. Cookies

SwimPilot uses only the cookies it needs to work: keeping you signed in, protecting your session, and preventing automated abuse of sign-up forms. We do not use advertising cookies, and we do not track you across other websites.

13. Changes to this policy

We may update this policy as the product changes or the law requires. The current version is always published at this address, with the date it took effect shown at the top. Where a change materially affects how we handle personal information, we will let schools know so they can inform their families.

14. Contact us

For any privacy question, to ask for a copy of your information, or to request deletion, contact Studio Parallel at team@studioparallel.com.au.

If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au or on 1300 363 992.