YourCSM ("we", "us") is a browser-based document classification tool operated by Yoursoftware Pty Ltd. Contact: privacy@yoursoftware.com.au.
YourCSM helps mortgage brokers classify, rename, and organise client documents (PDFs, images) using AI. Classification happens in the broker's browser using AI provider APIs the broker themselves authorises.
| Data type | Where it's stored | Who can see it |
|---|---|---|
| Client document files (the PDF / image bytes) | Your browser only — IndexedDB (database ycsm_files_v1). Stored unencrypted. See Section 8. | Only you, and anyone with access to your device or browser profile. |
| Extracted fields, applications, clients, settings, API keys | Your browser only — localStorage (key ycsm). Encrypted with AES-256-GCM if — and only if — you set an Access passphrase in Settings. Unencrypted otherwise. | Only you, and anyone with access to your device or browser profile. |
| Document text sent to AI for classification and extraction | Transmitted to the AI provider configured in Settings — Google (Gemini) by default, or Anthropic (Claude) or Groq if you select them. See Section 4 for regions. | The AI provider, to generate the classification. We do not see it — except on an internal Yoursoftware account, where Claude traffic is relayed by us (Section 4). |
| Account email, password hash, role (if you create a YourCSM sign-in) | Yoursoftware-operated backend (Microsoft Azure, Australia East) | You and Yoursoftware. No document content is stored there. |
| Drive OAuth token (if used) | Your browser session only | Only you. Token is per-broker. |
| Files imported from Drive | Your browser only (after download) | Only you. |
| Files exported to Drive | Your own Drive account | You + anyone you share the Drive folder with. |
When you classify a document, the document text is transmitted to whichever AI provider is configured in Settings. The default provider is Google (Gemini, model gemini-2.0-flash). If you have not changed the provider in Settings, your client document text is sent to Google. These are the supported providers and the recipients involved:
| Recipient | Used for | Where they process it | Privacy policy |
|---|---|---|---|
| Google (Gemini) — default provider | AI document classification + field extraction. Receives your client document text. | Overseas (United States, and other Google regions) | policies.google.com/privacy |
| Anthropic (Claude) | AI document classification + field extraction, where you select it. Receives your client document text. | Overseas (United States) | anthropic.com/privacy |
| Groq | AI document classification, where you select it. Receives your client document text. | Overseas (United States) | groq.com/privacy-policy |
| Yoursoftware Pty Ltd (our own backend, hosted on Microsoft Azure) | Account sign-in for all users. Additionally, for users signed in on an internal Yoursoftware account, Claude requests are relayed through our endpoint (/api/ai) so the organisation's API key stays server-side — meaning your document text passes through our infrastructure in transit before reaching Anthropic. This does not apply to brokers using their own API key. | Australia East (Azure), then onward to Anthropic (United States) | This policy |
| Google (Drive) | Optional Drive import / export, using your own Google account | Your own Drive tenancy | policies.google.com/privacy |
| Australian Business Register (ABR) | ABN lookups against the public register only — no client personal information is sent | Australia | abr.business.gov.au |
| Microsoft Azure | Hosting of the YourCSM application files and the sign-in backend | Australia East | privacy.microsoft.com |
You can switch AI providers at any time via Settings. Except for the internal-account Claude relay described above, we do not proxy or relay provider traffic — your browser talks to the provider directly, and we do not store the document text in either case.
If you are a broker using YourCSM to process documents your clients have provided, you have your own privacy obligations under the Privacy Act 1988 (Cth). At a minimum, your client engagement letter should disclose that:
YourCSM data lives in your browser's local storage while you are working a file — it is a working copy, not a long-term store. Your durable 7-year record for AML/CTF and NCCP record-keeping is the copy you push to MyCRM (your system of record); set and hold your retention policy there. In YourCSM, periodically purge clients you no longer need via Settings once they have been handed off to MyCRM.
We hold no central store of your clients' documents or extracted data, so requests from clients to access, correct, or delete their personal information must be actioned by you (the broker) using your local copy. We cannot fulfil those requests on your behalf because we do not hold that data. Where we do hold personal information — your own YourCSM account record (email, password hash, role) — you may request access, correction or deletion at privacy@yoursoftware.com.au.
localStorage. It does not protect the original document files, which are held unencrypted in your browser's IndexedDB store. Anyone with access to your device, your operating-system account, or your browser profile can read those files. This is a known limitation and we are stating it plainly rather than leaving you to assume otherwise. Compensating control: use full-disk encryption (BitLocker / FileVault), a locked OS account, and purge clients from YourCSM once they are handed off to your system of record.
localStorage state blob with AES-256-GCM, and wraps that data key under two independently derived keys (your passphrase and a recovery key) using PBKDF2-SHA-256 at 150,000 iterations. Neither the passphrase nor the recovery key is stored. Scope: the state blob only. Document files in IndexedDB are not encrypted by this control.YourCSM is a B2B tool for mortgage brokers. We do not knowingly collect information from children under 18. If a broker uploads a document containing a minor's information (e.g. parent applying for a loan with a dependant listed), the same browser-local storage rules apply.
We will publish updated versions at this URL with a revised "Effective" date. Substantial changes will be announced in-app via the Help modal.
Email: privacy@yoursoftware.com.au.
We will acknowledge a privacy complaint within 5 business days and respond substantively within 30 days. If your complaint concerns documents held by your broker rather than by us, we will tell you and direct you to them.