CoeusX
CoeusX
  • Home
  • About
  • FAQ
  • Ask Lawg
CoeusX
CoeusX
open menu
Privacy Policy
Your privacy is important to us. This policy explains how we collect, use, and protect your information.
Last updated: 16 August 2026

1. Introduction and Scope

1.1 About Us

CoeusX Pty Ltd (ABN 19 689 184 361) (“we”, “us”, “our”) operates the Lawg AI-powered tax research and legal information service (the “Service”). This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information (“Personal Data”) when you access or use the Service.

1.2 Scope

This Policy applies to:

  • Our website at lawg.ai
  • The Lawg AI tax research and information service
  • The Lawg Chrome Extension
  • Our communications with you
  • Any other interactions with our business

This Policy does not apply to third-party websites or services linked from our Service.

1.3 Legal Framework

We are bound by the Australian Privacy Principles (APPs) in the Privacy Act 1988 (Cth). If you are located outside Australia, additional rights may apply (see Section 14).

1.4 Purpose of this Policy

This Policy is a notice about our information-handling practices. It does not, by itself, mean that you have consented to every practice described in it. Where consent is required, we will request it separately.

2. Information We Collect

2.1 Information You Provide to Us

  • Account Information: Name, email address, and authentication credentials when you register
  • User Content: Queries, inputs, documents, and other data you submit to the Service
  • Team Workspace Information: Organisation name, membership, invitations, assigned role, active workspace, and content created or published within a team workspace
  • Consultation Information: Audio you intentionally capture, transcripts, consent confirmation, live guidance, session settings, and requested post-meeting drafts
  • Subscription and Billing Information: Plan, billing interval, seat quantity, subscription status, transaction references, and limited payment metadata. Payment-card details are collected by Stripe and are not stored by Lawg.
  • Feedback: Survey responses, support requests, and user feedback
  • Third-Party Integration Data: Data you authorise from connected services

2.2 Information We Generate and Collect Automatically

  • AI-Generated Content: Responses generated by the Service’s artificial intelligence systems in response to your queries
  • Session Data: Session identifiers, timestamps, and interaction data
  • Technical Data: IP address, browser type, device information, operating system
  • Usage Data: Features used, pages viewed, time spent on the Service
  • Location Data: Approximate location derived from your IP address
  • Team Access Audit Data: For authorised private-team-chat review, the organisation, reviewer, chat owner, operation, chat identifier, and time of access. The audit record does not copy chat titles, prompts, answers, or source references.

2.3 Information We Receive from Other Sources

  • OAuth Providers: When you authenticate via Google or Microsoft, we receive your name, email, and profile picture
  • Authentication Provider (Clerk): Verification and session management data
  • Connected Services: Data from services you authorise
  • Payment Provider (Stripe): Subscription, invoice, payment-status, and customer reference information

2.4 Chrome Extension Data

When using the Lawg Chrome Extension, we collect:

  • Selected Text: When you highlight text and use “Ask Lawg”, the selected text is sent to our servers for analysis
  • Questions: The suggested question you select or the question you enter is sent to our servers to generate a response
  • Authentication: Sign-in and session management are handled by Clerk through its Chrome Extension SDK and Sync Host. Lawg does not store Clerk access tokens in its own Chrome storage keys.
  • Request Metadata: Our API receives your IP address, request time, and the Lawg API operation used for quota enforcement, security, and service reliability.
  • Page Context: When you activate “Ask Lawg”, the current page URL and title are transmitted with the selected-text request. The current API does not use or persist those fields as part of the answer or chat record.
  • Local Storage: Lawg temporarily stores only the identifiers of the sign-in tab and the tab to return to after sign-in. These identifiers are removed when the sign-in flow completes, is cancelled, or you sign out.

We do NOT collect through the Extension:

  • A list of pages you visit or browsing activity when you do not activate “Ask Lawg”
  • Activity tracking across websites
  • Any data for advertising purposes

2.5 Chrome Web Store Limited Use

Notwithstanding any broader disclosure elsewhere in this Policy, our use and transfer of information received through the Chrome Extension adheres to the Chrome Web Store User Data Policy, including its Limited Use requirements.

  • We use Extension data only to provide or improve the Extension’s disclosed purpose and related security, reliability, and abuse-prevention operations.
  • We transfer Extension data only when necessary to provide or improve that purpose, comply with applicable law, protect against security threats or abuse, or complete a merger, acquisition, or asset sale after obtaining the user’s explicit prior consent.
  • We do not use or transfer Extension data for personalised, retargeted, or interest-based advertising.
  • We do not allow humans to read Extension data unless the user has explicitly consented to access specific data, access is necessary for security or legal compliance, or the data is aggregated and anonymised for internal operations.

2.6 Consultation Data

Consultation starts only after you confirm the in-product notice and grant browser access to your microphone and a selected meeting tab. Your microphone audio is sent to Microsoft Azure Speech for transcription. Client meeting-tab audio is streamed through Lawg to OpenAI Realtime for transcription and live guidance. Audio is processed as a live stream; Lawg does not create a persistent audio recording in its application database or object storage.

Final transcripts are held temporarily while the live session is active and may be processed by OpenAI to generate live guidance and the post-meeting drafts you request. The resulting consultation session record, prompts, summaries, and drafts are stored in the workspace in which the session was created. You are responsible for informing participants and obtaining any authority or consent required by applicable law and your firm's policies before capture begins.

3. How We Use Your Information

3.1 Providing the Service

We use your Personal Data and User Content to:

  • process queries and generate AI-Generated Content;
  • maintain chat history and session continuity; and
  • authenticate users and manage Accounts;
  • administer subscriptions, team seats, invitations, roles, and workspaces; and
  • transcribe authorised consultation audio and generate live guidance and post-meeting materials.

3.2 Improving the Service

  • Analysing usage patterns to improve functionality
  • Debugging technical issues
  • Developing new features based on user feedback

3.3 Safety and Security

We use your information to:

  • enforce our Terms of Service;
  • detect and prevent fraud, abuse, or unauthorised access; and
  • apply automated safeguards, including filtering of prohibited or non-compliant queries.

3.4 Communications

  • Responding to support requests
  • Sending service-related notifications
  • Marketing communications (with your consent)

3.5 Legal Compliance

  • Complying with applicable laws and regulations
  • Responding to legal requests and court orders
  • Protecting our legal rights

3.6 Team Workspaces and Authorised Review

When a team workspace is active, chats, consultations, and uploaded documents created there are scoped to that organisation rather than your Personal workspace. All paid team members receive the product features included in the team's plan; the Member, Super Member, Manager, and Admin roles control collaboration and administration permissions, not product-feature entitlement.

  • Member: Uses the team workspace and sees their own content.
  • Super Member: Has Member access and may publish their own chats to the shared team library.
  • Manager: Has Super Member access and, where the organisation has granted the relevant permission, may list and open private chats created by other members in that team workspace for oversight.
  • Admin: Has Manager access and may manage members, invitations, roles, and team settings.

Manager and Admin private-chat review is read-only and recorded in a metadata-only audit trail. Personal workspace chats are not included. Managers and Admins are users authorised by the organisation, not CoeusX personnel. The organisation is responsible for assigning roles appropriately and giving its personnel any workplace, client, or privacy notice required by law. Lawg also displays this review notice in team member settings.

4. AI Features and Third-Party Data Processing

4.1 How We Use AI

The Service uses artificial intelligence to analyse User Content and generate AI-Generated Content for general information only. This includes:

  • transforming queries into structured representations (embeddings);
  • retrieving relevant Australian legal and tax materials; and
  • generating natural language outputs.

AI-Generated Content may contain errors or inaccuracies and should not be relied upon as professional advice.

4.2 Third-Party Service Providers

We share data with trusted third-party providers to deliver the Service:

ProviderPurposeData SharedLocation
OpenAIAI inference, embeddings, consultation transcription and guidanceQueries, selected text, conversation context, client consultation audio and transcriptsUnited States
PineconeVector databaseQuery embeddingsUnited States
CohereSearch optimisationQuery text, document excerptsUnited States/Canada
ClerkAuthentication and Organisation identity managementName, email, OAuth, membership, invitation, role, and session dataUnited States
SupabaseDatabase hostingAccount, workspace, chat, document metadata, consultation, and audit dataAustralia (Sydney)
UpstashShort-term caching, coordination, and live consultation transcriptsCached query-response pairs, service state, temporary transcriptsVarious
Microsoft Azure SpeechConsultant microphone transcriptionConsultant audio and resulting transcriptAustralia (Australia East)
Amazon Web ServicesEncrypted document storage, malware scanning, and service infrastructureUploaded documents, object metadata, and limited operational logsAustralia (Sydney)
StripeSubscription and payment processingContact, customer, subscription, invoice, payment-status, and transaction dataUnited States and other countries where Stripe operates
PostmarkTransactional email deliveryEmail address, message content, and delivery metadataUnited States
CloudflareContent delivery, network security, and abuse preventionIP address, request metadata, and security signalsGlobal network, including the United States

4.3 Data Sharing Principles

  • We share Personal Data only to the extent reasonably necessary to provide the Service.
  • We do not sell Personal Data.
  • We do not use User Content to train AI models without your consent.
  • All Third-Party Providers are contractually required to implement appropriate data protection measures.

5. Data Retention

5.1 Data Retention

  • Active Chat History is retained until you delete the chat or your Account. Deleting a chat removes it from ordinary access and marks its database records as deleted. Those deleted chat and message records are then hard-deleted from the active database within 30 days.
  • Deleting a chat schedules any attachment used only by that chat for deletion from encrypted object storage. Object deletion creates a delete marker and encrypted non-current versions expire within 30 days. Deleted document metadata is hard-deleted from the active database within 30 days once object deletion has been verified.
  • Live consultation transcripts are temporary and expire within two hours, or are deleted earlier after post-meeting generation completes. Stored consultation session records, prompts, summaries, and generated materials are retained while the Account or team workspace remains active, unless deleted earlier.
  • When an Account is deleted, the automated account-deletion process removes its stored chats, documents, document-object versions, Consultation records, and directly identified product-analytics events. It removes the direct user identifier from partner attribution and retains a limited deleted-account tombstone. Team-access audit records are governed by the separate period below because they record actions by and affecting other Organisation members.
  • When a team workspace is deleted, the organisation record is marked deleted and the workspace can no longer be used. Its chats, documents, document-object versions, and Consultation records are hard-deleted within 30 days. A limited Organisation tombstone may be retained for billing, security, deletion-proof, and legal purposes.
  • Private-team-chat access audit records are retained for accountability, security, and dispute handling. The complete audit trail for an Organisation is deleted after 12 consecutive calendar months without another audited access to private team content. A new audited access restarts that 12-month period.
  • Temporary query-processing data may be held in a short-term cache and is automatically purged within 24 hours.
  • Anonymised usage data may be retained for service improvement and analytics.

5.2 Retention Exceptions

We may retain certain data where necessary to:

  • comply with legal obligations;
  • enforce our Terms of Service;
  • resolve disputes; or
  • retain billing, fraud-prevention, security, or transaction records for a period reasonably required for those purposes.

6. Automated Decision-Making

6.1 Content Filtering

We use automated systems (AI-based guardrails) to:

  • Filter queries requesting illegal advice
  • Redirect off-topic queries
  • Detect and prevent misuse

Filtered queries receive an automated response. No human review occurs unless you contact support.

6.2 No Significant Automated Decisions

The Service does not make decisions that have legal or similarly significant effects. It provides general legal information only and does not provide legal, tax, or financial advice.

7. Disclosure of Personal Information

We may disclose Personal Data to:

  • Third-Party Providers: Solely for the purpose of delivering the Service
  • Your Team Workspace: Content you publish to the shared library and team chats reviewed by authorised Managers or Admins as described in Section 3.6
  • Professional Advisers: Including legal and accounting advisers
  • Regulatory Authorities: Where required by law
  • Business Transfers: In connection with mergers, acquisitions, or asset sales
  • With Your Consent: For any other purpose with your explicit consent

8. International Data Transfers

8.1 Primary Storage

Your account data and chat history are primarily stored in Australia (Sydney region).

8.2 Overseas Processing

Lawg's primary application database and uploaded-document storage are hosted in Australia. Authentication, AI, payment, email, analytics, caching, and network security providers may process Personal Data outside Australia as necessary to provide their services, including in the following jurisdictions:

  • United States: OpenAI, Pinecone, Clerk, Stripe, Postmark, Google, Microsoft Clarity, and Cloudflare
  • United States/Canada: Cohere
  • Other countries: Upstash, Stripe, Cloudflare, and other providers operating distributed infrastructure

8.3 Transfer Safeguards

  • Contractual data protection obligations
  • Selection of providers with recognised security practices
  • Industry-standard encryption in transit and at rest

9. Your Rights

9.1 Rights Under Australian Privacy Law

  • Access: Request a copy of your personal information
  • Correction: Request correction of inaccurate information
  • Deletion: Request deletion (subject to legal requirements)
  • Opt-out: Unsubscribe from marketing
  • Complaint: Lodge a complaint with us or OAIC

9.2 How to Exercise Your Rights

  • Email: privacy@coeusx.ai
  • Response time: Within 30 days
  • Verification: We may verify your identity

9.3 Chrome Extension Users

If you use the Lawg Chrome Extension, you can:

  • Sign out at any time to clear your authentication data
  • Uninstall the extension to remove all locally stored data
  • Contact us to request deletion of any data associated with your account

9.4 Complaints

If you are dissatisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC):

  • Website: www.oaic.gov.au
  • Phone: 1300 363 992

10. Security

10.1 Technical Measures

  • Industry-standard encryption in transit and at rest
  • Access controls and authentication
  • Automated prompt injection detection and content moderation screening on all user inputs
  • Periodic security reviews
  • Automated threat detection

10.2 Organisational Measures

We take reasonable steps to protect Personal Data, including maintaining internal data handling practices, incident response capabilities, and assessing the security posture of our Third-Party Providers.

10.3 Limitations

While we implement industry-standard security measures, no method of transmission or storage is completely secure. We do not guarantee absolute security of your Personal Data.

11. Cookies and Tracking Technologies

11.1 Types of Technologies

  • Authentication Cookies: Set and managed by our authentication provider, Clerk, to maintain your login session
  • Analytics Cookies: Set by Google Analytics and Microsoft Clarity to understand usage patterns and improve our services
  • Local Storage: Used to store your cookie consent preference and UI state; this data remains in your browser and is not transmitted to our servers

11.2 Partner referral attribution

If you arrive at lawg.ai using a link distributed by one of our partners or its sales representatives, the link may contain a referral code. We collect that code from the link and send it to our first-party API at api.lawg.ai to identify the active partner and the specific sales representative or referral source.

We use referral attribution to record the first partner referral for an eligible new account, measure attributed registrations, administer the partner program, protect reporting integrity, and prepare registration performance reports. Referral attribution is not connected to checkout or billing and is not used to measure subscription or payment outcomes. We do not use the referral cookie for cross-site advertising, behavioural profiling, fingerprinting, or remarketing, and we do not use a third-party affiliate pixel for this purpose.

When the referral code is recognised, the Lawg API sets a first-party cookie named __Host-lawg_ref. It is limited to api.lawg.ai, has a maximum lifetime of 90 days, and uses the Secure, HttpOnly, SameSite=Lax, and Path=/ settings without a Domain attribute. The signed cookie token contains only a stable internal sales-representative identifier, an issue timestamp, and an expiry timestamp. Before registration, this is pseudonymous identifier data rather than permanently anonymous data. It does not contain your name, email address, Lawg questions, uploaded documents, payment-card details, or other matter content. Your browser sends the cookie to the Lawg API automatically, and frontend JavaScript cannot read it.

If you later create or sign in to a Lawg account, we check whether the referral was captured before the account was created, subject to a short technical race allowance. For an eligible new registration, we create an immutable first-touch record linking the account, partner, specific sales representative or referral source, and capture and attribution timestamps. A later referral link cannot replace that first attribution.

Appropriately authorised personnel may access referral records and KPI reports. Reports contain aggregate registration counts only, shown at the partner level and, where appropriate, at the sales-representative level in aggregated form. They do not contain user identifiers, email addresses, Lawg content, registration timestamps, subscription status, payment amounts, invoice identifiers, or payment timestamps. Partners and their sales representatives may receive only appropriately aggregated registration KPI information. We do not disclose your identity, Lawg questions, uploaded documents, matter information, or payment information to them.

We minimise referral data by keeping only the identifiers, relationships, and capture and attribution timestamps needed to assign eligible first registrations and produce aggregate registration totals. The referral cookie is cleared after successful processing, rejection, or a determination that the account is ineligible. If registration does not occur, it expires after no more than 90 days. When a Lawg account is deleted, we remove the direct Clerk user identifier from the attribution record. Historical attribution records may be retained without that identifier so aggregate registration totals remain accurate. We may retain those records to prevent fraud, protect reporting integrity, meet operational needs, or satisfy legal retention requirements. Detaching the direct account identifier does not necessarily make every retained record anonymous; we continue to handle retained personal information under this Policy.

You can block or delete cookies through your browser controls. Doing so may prevent or remove referral attribution but will not prevent normal use of Lawg. To ask about referral information or to request access, correction, or deletion (subject to applicable legal and retention requirements), contact us at privacy@coeusx.ai.

11.3 Analytics Services

We use the following analytics services to understand how visitors interact with our website:

ServicePurposeData CollectedProvider
Google Analytics 4Website analyticsPage views, user interactions, traffic sources, device/browser info (anonymised IP)Google LLC (United States)
Microsoft ClarityUser experience analysisSession recordings, heatmaps, click patterns, scroll behaviourMicrosoft Corporation (United States)

These services help us understand how users navigate our website, identify areas for improvement, and optimise the user experience. We use the data in aggregate form and do not use them to identify individual visitors.

11.4 Your Choices

  • Cookie Consent: When you first visit our site, you can accept or decline non-essential cookies via our cookie banner
  • Browser Settings: Configure your browser to block or delete cookies
  • Opt-Out Tools: Use Google’s opt-out browser add-on or Microsoft Clarity’s opt-out feature
  • Disabling analytics cookies will not affect the core functionality of our website

11.5 Do Not Track

We do not currently respond to Do Not Track browser signals but may update this as standards develop. You can use our cookie consent mechanism to control tracking preferences.

12. Children’s Privacy

The Service is not intended for individuals under 18. We do not knowingly collect information from children. If we learn we have collected data from a child, we will delete it promptly.

13. Changes to This Policy

We may update this Policy from time to time. When we make material changes:

  • We will update the “Last updated” date
  • We will notify you by email or through the Service of significant changes

Continued use after changes constitutes acceptance of the updated Policy.

14. Additional Disclosures for Specific Regions

14.1 European Economic Area, Switzerland, and United Kingdom

If you are located in these regions, you may have additional rights under the General Data Protection Regulation (GDPR) or UK GDPR:

  • Legal Basis: We process data based on the performance of a contract, legitimate interests, legal obligations, or consent
  • Data Portability: Receive your data in a structured, machine-readable format
  • Right to Object: Object to processing based on legitimate interests
  • Supervisory Authority: Lodge a complaint with your local data protection authority

Where applicable, we rely on Standard Contractual Clauses or other approved transfer mechanisms.

14.2 New Zealand

If you are located in New Zealand, you have rights under the Privacy Act 2020 similar to those described in Section 9.

15. Contact Us

For privacy-related enquiries:

CoeusX Pty Ltd (ABN 19 689 184 361)

Privacy Officer

Email: privacy@coeusx.ai

LawgLawg

AI-native tax workflow platform for Australian accountants — research, issue spotting, advice drafting, and consultation support with source-backed outputs.

CoeusXPowered by CoeusX

Product

About LawgLawg AI AssistantMessage from CEONewsFeature Requests

Legal

Privacy PolicyTerms of ServiceFAQContact

Partners

Microsoft Partner

© 2026 Lawg by CoeusX. All rights reserved. v1 Jersey

LinkedInXInstagram

AI-generated content is for general information only and does not constitute legal advice.