Privacy notice — CaseOnMe

CaseOnMe is a review of public information you own, or that an adult who has agreed has asked us to include. This page explains what the service does, what you are confirming when you use it, where your data lives, and how long we keep it.

Please read this before you send anything

These terms and the privacy notice govern the service as it works today. They are not legal advice.

What you confirm

  • This is your own footprint, or you have permission from the adult it is about.
  • The profiles and email addresses you give us are yours, or you are allowed to include them.
  • You will not use the report to harass, stalk, intimidate, dox, discriminate against, screen or keep watch on anyone.

What we look at

  • Public profile pages, public links, public usernames and what a public page shows about itself, inside the scope you gave us.
  • We never log in, get past a privacy setting, open a paywall, work around a “prove you’re human” check, or retrieve deleted content.
  • Anything uncertain is for you to look at and decide. It is not proof that an account belongs to you.

What we record

  • What you submit, what the review found, when your report was opened, and limited security information such as your IP address and browser.
  • We keep those so we can deliver the report, keep the service safe, answer a privacy request, and show what we did and why.
  • Your report avoids showing raw contact details unless they are a genuine public finding inside the scope you gave us.

How long we keep it

  • What you submit, what we collect, the working files and your report are deleted within seven days after report completion.
  • We hold them longer only where there is a documented security or legal reason, and we would tell you.
  • A small record that you consented, paid, and what we decided is kept separately for up to 12 months. To ask for access, a copy, a correction or deletion, email [email protected].

The full text

CaseOnMe by S6 Security Labs Privacy Notice

Approved by S6 Security Labs. It has not been reviewed by an external lawyer and is not legal advice.

This notice covers the automated safety checks we run and how to contest one, the service providers we use, where your information is stored, the data we collect, how long we keep it, and your rights.

Last updated: 2026-07-25. Data controller: S6 Security Labs. Contact: [email protected].

Our privacy posture

We handle personal information consistently with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth), and apply those principles as our baseline regardless of whether S6 currently meets the Act's small-business turnover threshold. We collect only what is needed for a consent-led, one-off public-footprint review.

Data we collect

Why we use it

To validate consent/scope, run the authorised review, generate the private report, deliver it, prevent abuse and fraud, troubleshoot, and satisfy privacy requests. We do not sell personal information and do not use it for advertising.

Automated safety checks, and how to contest one

Before we run a review, and again before we release a report, we run an automated safety check. These checks exist to stop the service being used against someone who has not authorised it, and to stop fraud. They are profiling in the privacy sense, and we record them as such.

Your contestability route. If a check holds or refuses your request, you may ask for a human review of that decision. Email [email protected] with your request ID and anything you want us to consider. A person — not the automated check — will review it and tell you the outcome. If we still cannot deliver a report, you are refunded in full under our refunds and review-timing policy. You may also complain to us or to the OAIC (see "Complaints").

Sensitive boundaries

CaseOnMe must not intentionally collect private/access-controlled content, passwords, secret tokens, or credential material. Public demos use synthetic or consented data only.

Children and minors

CaseOnMe does not offer dedicated child/minor scanning. Do not submit a minor's accounts for a child-targeted scan, even if you are a parent or guardian. Guardian/family authority is for authorised adult household, family, client, or representative scopes, and may only include minor-related public information when it is incidental to an authorised adult/family review. These cases receive additional safety review and are not run as child-targeted scans.

Service providers (sub-processors)

We use a small number of providers to host and operate the service. They process personal information only to provide their service to us:

We will update this notice if our provider arrangements materially change.

Where your data is stored — please read this

Your personal information is stored outside Australia, in the European Union.

CaseOnMe's production service is hosted in the EU. That means everything you submit and everything we generate about you — your requester details, the profiles and contact points you supply, the public-source findings, the report itself, and our records of the safety checks and review decisions — is stored and processed on servers in the EU, not in Australia.

We are telling you this plainly because it matters. Sending your personal information overseas is a cross-border disclosure under Australian Privacy Principle 8 of the Privacy Act 1988 (Cth), and you are entitled to know it before you decide to use the service.

What that means for your rights. Under APP 8.1 and section 16C of the Privacy Act, we remain accountable to you for how your information is handled overseas. If the overseas handling of your information would have breached the Australian Privacy Principles had we done it ourselves in Australia, we are treated as having breached them. You complain to us, and to the Australian Information Commissioner, exactly as you would if the data had never left the country. We do not ask you to consent away that protection, and we do not rely on the APP 8.2(a) exception for recipients subject to a substantially similar law. We have not obtained external legal advice on that question, and we would rather remain accountable than claim an exception we have not tested.

A practical consequence to be aware of. Information stored in another country can be subject to that country's laws, including lawful access by its authorities. We cannot promise otherwise, and we will not pretend the risk is zero.

Other overseas processing. Separately from our hosting, some service providers also process limited data outside Australia — payment processing, site delivery and security, email delivery, and administrator sign-in. The categories involved are your name, email address, billing country, payment metadata and request metadata.

Data region. We assign each case a data region based on where you ordinarily live, where the person the report is about is, the authority basis you declared, and corroborating signals such as billing country. It is a handling decision, not a statement about your nationality or citizenship, and we never present it as one. If the signals conflict, or we are uncertain, the case goes to review rather than being quietly moved.

Our customers and our servers are in different places, deliberately. We serve customers in Australia; we host in the EU. Those are two separate facts and we do not want you to confuse them: being an Australian customer does not mean your data stays in Australia. It does not.

If you are not comfortable with your information being stored in the EU, do not submit a request — and if you have already paid and have not yet received a report, contact us and we will refund you.

Retention and deletion

Submitted data, collected results, working artifacts, and retained report copies are deleted as soon as delivery and required validation, debugging, or security review are complete, and by default within seven days after report completion. A documented manual security or legal hold may extend this period only while necessary. Minimal consent, transaction, security-decision, and audit records may be kept for up to 12 months. Case-content backups follow the same seven-day disposal period or exclude case content. Service and access logs — request timestamps, IP address, user agent and route, not case content — are kept for 90 days. Payload-free receipts proving a deletion happened are kept provisionally for 1 year pending a records-schedule review. Full detail is in our retention and deletion policy, which we will provide on request.

Refunds

If we cannot deliver a report, we refund you in full. Our refunds and review-timing policy has the detail, and we will provide it on request. Nothing in it excludes your non-excludable Australian Consumer Law consumer guarantees.

Your rights

You may request access to, correction of, export of, or deletion of your personal information, and may complain about how we handle it. We verify your identity and authority before disclosing, exporting, correcting, or deleting. Contact [email protected]; target response time is 30 days.

Data breach

If a data breach likely to cause serious harm occurs, we will assess and respond consistently with the Notifiable Data Breaches scheme, including notifying affected individuals and the OAIC where required.

Complaints

Contact [email protected] first. If you are not satisfied with our response, you may escalate to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.