Legal

Home · Privacy Policy

Privacy Policy — Fraud Finder

Operator: Saviora Technologies Pty Ltd (ABN 55 701 573 855) trading as Fraud Finder ("we", "us", "our").
Contact: info@fraudfinder.com.au
Post: PO Box 649, Caringbah NSW 1495
Last updated: 25 August 2026 · Version: 1.2


At a glance

The rest of this policy is the detail behind those statements.


1. Who we are

Fraud Finder (fraudfinder.com.au) is a document-forensics tool for Australian brokers, lenders and their staff. It helps a human reviewer assess whether a document (for example a payslip or bank statement) shows signs of editing, by reporting observable facts about the file — its saved-state history, internal arithmetic, and metadata. It does not determine intent, and it does not make decisions.

We are committed to handling personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

2. The two kinds of data — and which one we never touch

This policy distinguishes two categories, and the distinction is the design of the product, not a promise layered on top of it:

3. Document Data — processed in your browser, never collected by us

When you analyse a document, the analysis runs inside your browser, on your own device, using your own hardware. The document's bytes are never transmitted to our servers or to anyone else's. Reading the figures and names on the document also happens in your browser, from the document's own text. The evidence report is generated in your browser for you to save or print; we never receive a copy.

Because your device does the work, we do not collect, hold, or have any means of accessing the document or its contents. Our usage records deliberately contain no fields capable of storing document content — not a filename, not a value read from a page, not a document hash, not an image.

The complete list of what your browser transmits when you use Fraud Finder:

  1. Requests to load the application itself — served by Cloudflare, like any website (section 6). For subscribers, the request that fetches the analysis software carries your sign-in session, so we can confirm your subscription before delivering it. It carries nothing else — no document ever accompanies it — and we store nothing from it.
  2. Sign-in traffic to Clerk, our authentication provider (section 6).
  3. A usage record after each analysis — containing only: that an analysis ran, the document type you selected, the number of pages, the number of checks run, the number of findings, which of our checks raised a finding, and timestamps. The check names come from our own fixed list — for example "figures do not reconcile" or "identity differs across saved states" — and record that a check found something, never what it found. Counts and our own labels only; nothing read from the document. When a report prints a verification QR code, the same counts — plus the verdict band and a fingerprint of the document, from which the document cannot be reconstructed — are also sent once to be signed for that code; we sign and return it and store nothing from it.
  4. The ABN check (optional): when ABN verification runs, the 11-digit ABN string — and nothing else — is sent to the Australian Business Register (ABR), an Australian government register, to confirm the ABN's existence and status. No other document content accompanies it. An ABN is generally business information; where the entity is a sole trader it can be personal information, which is why we send it only to the government register that publishes it.
  5. Billing traffic to Stripe, only if and when you subscribe (section 6).

Nothing else is transmitted. There is no sixth channel. Checking a report's verification code happens entirely on the checker's own device — the verify page transmits nothing, to us or anyone.

Individuals named in analysed documents

A document you analyse will usually contain personal information about someone else — an employee named on a payslip, a borrower on a statement. Because the document never leaves your browser, we do not collect or hold that person's personal information at all. Under the Privacy Act, the broker or lender who holds and analyses the document remains responsible for it, including having collected it lawfully and given any required privacy notices.

If you are named in a document that was analysed with Fraud Finder and you want to access, correct or ask questions about that information, please contact the broker or lender you dealt with — they hold the document; we do not.

Employer corroboration — not yet active

This subsection describes a feature that is built but switched off. It takes effect only if and when the feature is enabled, and this policy will be updated at that time. When active, an optional employer-corroboration check would send the employer's name, ABN, website hostname and (where present on the document) a work-email domain — extracted in your browser — to public-record services (DNS, domain registration data, certificate-transparency logs, the Internet Archive) and would request the employer's own public website. Document bytes would still never leave your browser. The same sole-trader nuance applies as for the ABN.

4. Account & Usage Data — what we collect and hold

If you hold an account, or an organisation has arranged one for you

Data Why Where it is held
Email address and sign-in identity Creating your account, signing you in, account security Clerk (United States) and our database (Sydney, Australia)
Role and subscription status Knowing what your account is entitled to Our database (Sydney, Australia) and Stripe
If an organisation arranged your access (for example your aggregator): which organisation, your email address, the dates your access started and ended, whether it ended because you released it yourself or because the organisation removed it, and who made each change Giving you access without you paying us directly, and invoicing that organisation for the seats it arranged Our database (Sydney, Australia)
Usage records — that an analysis ran, the document type, page/check/finding counts, which of our checks raised a finding, timestamps Operating the service, usage dashboards, and billing accuracy Our database (Sydney, Australia)
Billing details — your card is handled solely by Stripe; we store only a Stripe customer/subscription identifier and subscription status Payment Stripe (United States)
Support correspondence, if you contact us Answering you Microsoft 365 (our email service)

We collect this information directly from you (when you sign up, sign in, subscribe or contact us) and from the operation of the service (usage records).

One exception, where an organisation arranges your access. If your aggregator or employer arranges Fraud Finder for you, we receive your email address from them, usually before you have had any contact with us, so that we can create your access and invite you to set up your own sign-in. We use it only for that and for invoicing them. If you would rather we did not hold it, tell us or tell them and the access can be withdrawn.

We do not collect sensitive information (as defined in the Privacy Act), and we do not buy, sell or trade personal information.

Note that a usage record is personal information about you, the account holder (it records that your account ran an analysis at a time). It contains nothing about any person named in the document. A check name describes the document, not a person: "figures do not reconcile" says a check did not balance, and nothing about who is named on the page.

If you are named in a document someone analysed

We hold nothing about you. See section 3.

If you visit our website

The app runs no third-party analytics and no advertising trackers. Our marketing website (fraudfinder.com.au) may use advertising and analytics cookies, including retargeting pixels, as described in section 8. Cloudflare, which serves both, generates short-lived technical logs (such as IP addresses) as part of operating and protecting any website on its network.

Anonymity and pseudonymity

You may generally use the website without disclosing your identity to us. However, you cannot access or use the Fraud Finder service without a user account; you are required to be identified for this purpose. We need to verify that you fall within an eligible user category, and because this is a paid service we need to check that the account user is paying for the service.

5. Why we collect, hold, use and disclose it

We use Account & Usage Data to provide and operate the service; authenticate you and secure your account; determine entitlement and process subscription payments; understand aggregate usage of the service; meet our legal obligations; and communicate with you about your account or material changes to the service or this policy.

We may also market Fraud Finder: we may email you about features and offers (every marketing email includes an unsubscribe link, and opting out never affects your service), and we may advertise on third-party platforms, including showing ads to people who have visited our marketing website (section 8). We never use anything from a document for marketing — Document Data never reaches us — and we do not sell personal information. We do not disclose Account & Usage Data to anyone except the providers in section 6 or where the law requires. You can opt out of marketing communications as indicated above.

6. Who we disclose it to

We use a small number of service providers, each receiving only what its function requires:

Provider Function What it receives Where
Clerk Sign-in and authentication Your email address, sign-in identity and authentication events United States
Stripe Subscription payments Your name, email, card details (entered directly with Stripe — we never see the card number) and transaction details United States (Stripe's own providers operate in the EU, US and India)
Cloudflare Hosting the app and website; our database and cache Technical traffic data; our database records (Account & Usage Data only) — the database itself is stored in Sydney, Australia Global network; database in Australia
Australian Business Register (ABR) The optional ABN verification check The 11-digit ABN string only Australia
Microsoft 365 Support and account email Your email address and correspondence Australia / United States (Microsoft's data centres)
Advertising platforms (such as Google, Meta or LinkedIn, when we run ads) Advertising and retargeting for our marketing website A cookie or advertising identifier recording that your browser visited fraudfinder.com.au — never Document Data, and nothing from inside the app United States

No document content is disclosed to any of them. Document Data never reaches us, so there is nothing of it for us to disclose.

We may also disclose Account & Usage Data where required or authorised by law (for example, to a court or regulator), and in the event of a business sale or restructure, to the acquirer — on terms that continue to protect it consistently with this policy.

7. Overseas disclosure

Some of our service providers are located overseas. The countries where your Account & Usage Data is likely to be disclosed are the United States (Clerk — authentication; Stripe — billing; Microsoft — email, which may also be stored in Australia; advertising platforms, when we run ads). Our own database is stored in Sydney, Australia, and Cloudflare serves the application through its global network. The ABR is in Australia.

Before disclosing personal information to an overseas recipient, we take reasonable steps to ensure the recipient handles it consistently with the Australian Privacy Principles, including through the contractual data-protection terms we hold with each provider.

No Document Data crosses any border, because no Document Data leaves your browser. The only document-derived value that leaves your device is the ABN string, and it goes to an Australian government register in Australia.

8. Cookies

The app uses authentication cookies set by Clerk to keep you signed in. These are strictly necessary for the service to function, and the app sets no advertising or analytics cookies.

The marketing website (fraudfinder.com.au) may use advertising and analytics cookies, including retargeting pixels from platforms such as Google, Meta or LinkedIn, so we can measure our advertising and show Fraud Finder ads to people who have visited the site. These record that your browser visited our website and which pages you viewed. They are never connected to any document, to Document Data, or to anything you do inside the app. You can block or delete cookies in your browser settings, and each advertising platform offers its own opt-out.

9. Security and storage

Account & Usage Data is held in our database in Sydney, Australia, and by the providers in section 6, protected by encryption in transit and at rest, secrets management, and access controls. Card data is handled solely by Stripe; we never receive or store card numbers.

The most effective security control in Fraud Finder is architectural: the most sensitive material involved — the documents — is never in our possession, so it cannot be lost, breached or misused by us.

10. Retention

When personal information is no longer needed for any purpose for which it may be used or disclosed, we take reasonable steps to destroy or de-identify it.

11. Data breaches

We maintain a data-breach response process. If a data breach involving personal information we hold is likely to result in serious harm and cannot be remediated, we will notify affected individuals and the Office of the Australian Information Commissioner as soon as practicable, in accordance with the Notifiable Data Breaches scheme.

Because we never hold the documents you analyse, a data breach on our side could not expose them. Our breach surface is limited to the Account & Usage Data described in section 4.

Nevertheless, if you believe that any personal information we hold about you has been impacted by a data breach, you can also contact the Privacy Officer (details in section 17).

12. Access and correction

You may request access to, or correction of, the personal information we hold about you that is inaccurate, incomplete, out-of-date, not relevant or misleading, by contacting the Privacy Officer in writing at info@fraudfinder.com.au, or by post to PO Box 649, Caringbah NSW 1495.

Most of your personal information is visible and editable directly in your account. Nevertheless, we will respond to your request within 30 days. We will not charge you for making a request or for correcting information; if a charge ever applies to giving access, it will not be excessive. If we refuse a request, we will give you written reasons and how to complain.

If your request concerns information in a document analysed by a broker or lender, please contact them — we do not hold the document or its contents (section 3).

We may refuse access to personal information if: (a) we have a lawful right to withhold the information; (b) we believe that giving access may endanger the life, health or safety of any individual, or endanger public health or safety; (c) giving access would have an unreasonable impact on the privacy of other individuals; (d) your request is frivolous or vexatious; or (e) your personal information is part of existing or anticipated legal proceedings between you and us.

There are limited circumstances where you may be allowed to access personal information on behalf of another individual, when you are acting as a personal representative of that person (such as an attorney under a power of attorney, or an executor or administrator of a deceased estate). If this applies, we will require adequate evidence of your authority and your identity before we can supply any information.

13. Complaints

If you believe we have mishandled your personal information, contact info@fraudfinder.com.au and we will acknowledge your complaint within 5 business days and aim to resolve it within 30 days.

If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (OAIC): www.oaic.gov.au · 1300 363 992 · enquiries@oaic.gov.au · GPO Box 5218, Sydney NSW 2001

14. No automated decision-making

Fraud Finder is decision-support, never decision-making. It reports observable facts about a file's structure and history to a human reviewer. It makes no decision about any individual, and no computer program we operate makes — or does anything substantially and directly related to making — a decision that could significantly affect an individual's rights or interests. Any decision about a loan, an application or a document is made by the broker, lender or reviewer using their own judgement.

15. Credit reporting

We are not a credit reporting body and not a credit provider. We do not collect, hold or disclose credit reporting information or credit eligibility information, and Part IIIA of the Privacy Act and the Privacy (Credit Reporting) Code do not apply to us. Our customers' obligations under those laws are their own.

16. Changes to this policy

We will post changes here with an updated date and version, and will notify account holders of material changes. Earlier versions are available on request.

17. Contact

Privacy contact: The Privacy Officer, Saviora Technologies Pty Ltd Email: info@fraudfinder.com.au Post: PO Box 649, Caringbah NSW 1495