Tero
How we collect, use and protect your personal information.
Tero Studio Pty Ltd (“Tero”, “we”, “us”) is an Australian company based in Melbourne. This policy explains how we handle personal information across everything we run: the Tero mobile application (the “App”), our websites at tero.au and join.tero.au (the “Sites”), and our email correspondence.
It is written to comply with the Australian Privacy Principles under the Privacy Act 1988 (Cth), and with the Spam Act 2003 (Cth) for our email.
When you join at join.tero.au. Joining is a short walk of four questions followed by your name and email. We collect:
When you use the App.
When you visit our Sites. IP address, browser type, pages visited, referring website, and cookie identifiers set by the services listed in section 5.
What we never collect. We do not collect health information, location data, contacts, photographs, microphone audio or biometric information. We do not ask what you are treating, managing or recovering from, and we do not want to know.
We advertise on Meta’s platforms (Facebook and Instagram). To measure whether that advertising works, we share limited information with Meta:
This lets us count how many people joined, and understand which of our films and photographs brought them here. We do not sell your personal information, we do not share your email address in a readable form with any advertiser, and we do not buy information about you from anyone.
You can limit this at any time through your device and browser settings, and through your Meta ad preferences. Doing so does not affect your membership or the releases you receive.
We use a small number of established services to run Tero, and we share only what each one needs to work.
| Service | What it does | Where |
|---|---|---|
| Supabase | Accounts, database, content storage | Australia and United States |
| Klaviyo | Our letters and membership emails | United States |
| Meta | Advertising measurement (section 4) | United States |
| Netlify | Website hosting | United States |
| Cloudflare | Bot protection on the join form | United States |
| Resend | Sign-in and transactional email | United States |
| RevenueCat | Membership management | United States |
| Apple | App distribution, payments, Sign in with Apple | United States |
| Sign in with Google | United States | |
| Stripe | Payment processing on the web | United States |
| Shopify | Our shop, when it opens | Canada and United States |
Each holds your information under its own privacy terms. We do not authorise any of them to use it for their own purposes beyond providing the service to us.
Several of the services above store information on servers outside Australia, principally in the United States. By using the App or the Sites you consent to your information being transferred to and held in those countries.
We take reasonable steps to satisfy ourselves that these providers handle personal information in a way consistent with the Australian Privacy Principles, but once information is held overseas it may be subject to the laws of that country.
We protect your information with encryption in transit, encryption at rest, role-based access controls, and row-level security on our database. Passwords are never stored in a readable form, and sign-in is handled by established providers rather than by us.
No system is perfectly secure. We work hard at this and we will not pretend it is absolute.
We keep your information for as long as you are with us. If you delete your account, we remove your personal information from our active systems within 30 days, except where we are required to keep records by law, such as transaction records for tax. Backup copies may persist for up to 90 days before they are permanently deleted.
If you joined at the door but never opened an account, you can ask us to remove you at any time and we will.
Under the Australian Privacy Principles you may:
If you signed in with Apple, deleting your account in the App also revokes your Apple sign-in tokens for Tero.
To exercise any of these, write to keelan@tero.au. We will respond within 30 days.
Our advertising runs in Australia, but our Sites can be reached from anywhere.
If you are in the European Union or the United Kingdom, we handle your information in accordance with the General Data Protection Regulation. Our lawful bases are consent for marketing, contractual necessity to provide what you signed up for, and legitimate interests to improve the work and prevent abuse. You also have the right to data portability and the right to object to processing.
If you are in California, you have rights under the California Consumer Privacy Act, including the right to know what we collect and the right to request deletion. We do not sell personal information as that term is defined under the CCPA.
Tero is not made for anyone under 16, and we do not knowingly collect information from anyone under 16. If you believe a child has given us their information, write to keelan@tero.au and we will delete it.
The App does not use cookies. It stores a sign-in token on your device using secure system storage so you stay signed in.
Our Sites use cookies for essential functionality, for bot protection on the join form, and for the advertising measurement described in section 4. You can disable cookies in your browser, though parts of the Sites may then not work.
We may revise this policy as the work changes or the law does. Where a change is material we will tell you inside the App or by email at least 30 days before it takes effect. The date at the top shows when it was last revised.
Tero Studio Pty Ltd
keelan@tero.au
tero.au
If our response does not satisfy you, you may complain to the Office of the Australian Information Commissioner, GPO Box 5288, Sydney NSW 2001, on 1300 363 992, or at oaic.gov.au.