Privacy Policy — YourCSM

Effective 19 August 2026 (supersedes 7 August 2026) · Operated by Yoursoftware Pty Ltd · Next review: 19 November 2026, and on any change to storage, provider default, or data flow

The short version: YourCSM is local-first. Your client documents are stored in your own browser and are not uploaded to a YourCSM document store. Document text is sent to an AI provider to be classified and extracted — by default that provider is Google (Gemini), and you can switch to Anthropic (Claude) or Groq in Settings. If you sign in with a Yoursoftware-issued internal account, your Claude requests are relayed through a Yoursoftware-operated endpoint rather than going to Anthropic direct. Section 3 and Section 4 set out exactly what goes where.

1. Who we are

YourCSM ("we", "us") is a browser-based document classification tool operated by Yoursoftware Pty Ltd. Contact: privacy@yoursoftware.com.au.

2. What this tool does

YourCSM helps mortgage brokers classify, rename, and organise client documents (PDFs, images) using AI. Classification happens in the broker's browser using AI provider APIs the broker themselves authorises.

3. What information is collected and where it goes

Data typeWhere it's storedWho can see it
Client document files (the PDF / image bytes)Your browser only — IndexedDB (database ycsm_files_v1). Stored unencrypted. See Section 8.Only you, and anyone with access to your device or browser profile.
Extracted fields, applications, clients, settings, API keysYour browser only — localStorage (key ycsm). Encrypted with AES-256-GCM if — and only if — you set an Access passphrase in Settings. Unencrypted otherwise.Only you, and anyone with access to your device or browser profile.
Document text sent to AI for classification and extractionTransmitted to the AI provider configured in Settings — Google (Gemini) by default, or Anthropic (Claude) or Groq if you select them. See Section 4 for regions.The AI provider, to generate the classification. We do not see it — except on an internal Yoursoftware account, where Claude traffic is relayed by us (Section 4).
Account email, password hash, role (if you create a YourCSM sign-in)Yoursoftware-operated backend (Microsoft Azure, Australia East)You and Yoursoftware. No document content is stored there.
Drive OAuth token (if used)Your browser session onlyOnly you. Token is per-broker.
Files imported from DriveYour browser only (after download)Only you.
Files exported to DriveYour own Drive accountYou + anyone you share the Drive folder with.
Important: We hold no server-side database of your clients, your documents, or your settings — those live in your browser, and if you clear your browser data they are gone. We do operate a small backend for account sign-in and, on internal accounts, for relaying AI requests; it is described in Section 4. Because your documents are held on your device, protecting that device is part of your APP 11 obligation, not ours — see Section 8.

4. Sub-processors

When you classify a document, the document text is transmitted to whichever AI provider is configured in Settings. The default provider is Google (Gemini, model gemini-2.0-flash). If you have not changed the provider in Settings, your client document text is sent to Google. These are the supported providers and the recipients involved:

RecipientUsed forWhere they process itPrivacy policy
Google (Gemini)default providerAI document classification + field extraction. Receives your client document text.Overseas (United States, and other Google regions)policies.google.com/privacy
Anthropic (Claude)AI document classification + field extraction, where you select it. Receives your client document text.Overseas (United States)anthropic.com/privacy
GroqAI document classification, where you select it. Receives your client document text.Overseas (United States)groq.com/privacy-policy
Yoursoftware Pty Ltd (our own backend, hosted on Microsoft Azure)Account sign-in for all users. Additionally, for users signed in on an internal Yoursoftware account, Claude requests are relayed through our endpoint (/api/ai) so the organisation's API key stays server-side — meaning your document text passes through our infrastructure in transit before reaching Anthropic. This does not apply to brokers using their own API key.Australia East (Azure), then onward to Anthropic (United States)This policy
Google (Drive)Optional Drive import / export, using your own Google accountYour own Drive tenancypolicies.google.com/privacy
Australian Business Register (ABR)ABN lookups against the public register only — no client personal information is sentAustraliaabr.business.gov.au
Microsoft AzureHosting of the YourCSM application files and the sign-in backendAustralia Eastprivacy.microsoft.com

You can switch AI providers at any time via Settings. Except for the internal-account Claude relay described above, we do not proxy or relay provider traffic — your browser talks to the provider directly, and we do not store the document text in either case.

Cross-border disclosure (APP 8): every AI provider above is an overseas recipient. Sending a client's document text to them is a cross-border disclosure of that client's personal information. Under APP 5 you must tell your clients that this happens and, where practicable, which countries are involved — see Section 5.

Sub-processor detail, including regions and DPA status, is maintained at /sub-processors.html.

5. Disclosure to clients

If you are a broker using YourCSM to process documents your clients have provided, you have your own privacy obligations under the Privacy Act 1988 (Cth). At a minimum, your client engagement letter should disclose that:

This section is general information about your own obligations, not legal advice. Your licensee's privacy and AI-use policies prevail; obtain your own advice if you are unsure.

6. How long is data kept?

YourCSM data lives in your browser's local storage while you are working a file — it is a working copy, not a long-term store. Your durable 7-year record for AML/CTF and NCCP record-keeping is the copy you push to MyCRM (your system of record); set and hold your retention policy there. In YourCSM, periodically purge clients you no longer need via Settings once they have been handed off to MyCRM.

7. Your rights under Australian privacy law

We hold no central store of your clients' documents or extracted data, so requests from clients to access, correct, or delete their personal information must be actioned by you (the broker) using your local copy. We cannot fulfil those requests on your behalf because we do not hold that data. Where we do hold personal information — your own YourCSM account record (email, password hash, role) — you may request access, correction or deletion at privacy@yoursoftware.com.au.

8. Security measures

Read this before you rely on encryption-at-rest. YourCSM's optional encryption protects the state blob (extracted fields, applications, clients, settings, API keys) held in localStorage. It does not protect the original document files, which are held unencrypted in your browser's IndexedDB store. Anyone with access to your device, your operating-system account, or your browser profile can read those files. This is a known limitation and we are stating it plainly rather than leaving you to assume otherwise. Compensating control: use full-disk encryption (BitLocker / FileVault), a locked OS account, and purge clients from YourCSM once they are handed off to your system of record.

9. Children's data

YourCSM is a B2B tool for mortgage brokers. We do not knowingly collect information from children under 18. If a broker uploads a document containing a minor's information (e.g. parent applying for a loan with a dependant listed), the same browser-local storage rules apply.

10. Changes to this policy

We will publish updated versions at this URL with a revised "Effective" date. Substantial changes will be announced in-app via the Help modal.

11. Contact & complaints

Email: privacy@yoursoftware.com.au.
We will acknowledge a privacy complaint within 5 business days and respond substantively within 30 days. If your complaint concerns documents held by your broker rather than by us, we will tell you and direct you to them.