Privacy Policy
Nexterra Group Pty Ltd, trading as Shastr
Our Privacy Principles
- You own your data. Your organisation retains ownership of its content, documents, and generated artefacts. We process it only for the purposes described in this Privacy Policy.
- AI works for you. Your content is processed only to deliver the specific features and analytics you request. It is not used to train or fine-tune AI models.
- We treat your content with care. We handle documents and organisational information as confidential business information and limit access to what is necessary to operate and support the platform.
- Transparency matters. We clearly identify the third-party providers that help us operate Shastr and explain how they process information.
- Humans stay accountable. AI features surface insights and flag risks to support leadership decision-making. They do not make final strategic, financial, or personnel decisions on your behalf.
Privacy at a glance
- This Privacy Policy applies to the Shastr platform, website, and related services — including account holders, organisations, beta participants, and visitors.
- We collect account data, organisational data, and content you upload or input into the platform.
- We do not use customer content to train or fine-tune AI models.
- We do not sell your personal information to third parties.
- We use a defined set of sub-processors (listed below) to operate the platform.
- You may request access, correction, export, or deletion of your information by emailing privacy@shastr.app.
1. Introduction
Nexterra Group Pty Ltd, trading as Shastr ("Shastr", "we", "our", or "us") respects your privacy and is committed to protecting personal information.
This Privacy Policy explains how we collect, use, store, disclose, and protect information when you use the Shastr platform, website, and related services.
This Privacy Policy applies to all users of the Shastr platform and replaces the previous waitlist and pre-launch Privacy Policy.
By using Shastr, your personal information will be handled in accordance with this Privacy Policy. If you are using Shastr on behalf of an organisation, you should also refer to our Terms of Service and, where applicable, your organisation's Data Processing Agreement with us, which govern the contractual relationship and any specific data handling commitments.
2. Who We Are
Shastr is an Australian technology company providing an AI-native strategic execution platform that helps organisations connect strategy, governance, and execution, generate decision-ready artefacts, and identify strategic drift.
Nexterra Group Pty Ltd, trading as Shastr
ABN: 84 684 815 987
Registered Address: 27 Halley Avenue, Camberwell VIC 3124, Australia
For privacy-related enquiries: privacy@shastr.app
In many cases, when your organisation uses Shastr, your organisation is the controller of personal information about its own people, and Shastr acts as a processor, handling that information on the organisation's instructions, in addition to this Privacy Policy.
3. Information We Collect
3.1 Account and identity information
- Name, work email, authentication credentials (via Clerk)
- SSO identifiers, where applicable
- Job title, role, professional function, organisation details
3.2 Organisational and platform content
- Strategic initiatives, goals, and portfolio data
- Business cases, pitches, governance artefacts, and uploaded documents
- Stakeholder, RAID, and dependency information, which may include personal information about colleagues or third parties who are not Shastr users themselves
If you input personal information about other individuals into the platform, you warrant that you have the appropriate legal basis and authority to do so, consistent with your organisation's own privacy obligations to those individuals.
3.3 AI interaction data
- Text, voice, and other inputs to AI-powered features
- Voice recordings and generated audio (via ElevenLabs), where voice features are used
- AI-generated outputs
3.4 Usage and technical information
- IP address, browser/device information, operating system
- Platform usage data, feature interactions, session data
- Log and diagnostic data for security and reliability
3.5 Billing information
Billing contact and subscription details. Payment card data is processed directly by our payment processor and not stored by Shastr.
3.6 Cookies
See Section 10.
4. Customer Content
You and your organisation retain ownership of all content you upload, create, or generate through the platform, including:
- Uploaded documents and source materials
- Business cases, pitches, initiatives, and portfolio information
- AI-generated artefacts produced from your inputs
Shastr is granted only the limited, non-exclusive right to host, process, transmit, back up, and analyse this content in order to operate the platform and deliver the features, analytics, and outputs you request. We do not use this content for any secondary commercial purpose outside of delivering the Shastr service, except as described in Section 5 (AI Processing) or where you separately agree otherwise.
5. AI Processing
Shastr uses third-party AI service providers — our current AI providers include Anthropic (Claude models) and ElevenLabs (voice generation) — to power capabilities such as pitch generation, business case drafting, drift detection, and voice interactions. We may also use additional AI providers configured for specific features. Where this materially changes how personal information is processed, we will update this Privacy Policy and notify account administrators.
- Purpose: AI processing is used only to deliver the features, analytics, and outputs you request.
- No model training: Your content is not used to train, fine-tune, or otherwise improve underlying AI models, whether ours or our providers', under our commercial arrangements with those providers. We do not claim zero data retention unless a separate zero-retention arrangement applies to a specific provider and feature.
- Processing scope: Inputs are processed only as necessary to generate the requested outputs, in line with our providers' standard data handling terms.
- Human-in-the-loop: AI outputs — including drift and governance risk signals — are designed to inform human decision-making, not replace it. Your organisation remains responsible for decisions made using these outputs.
- Retention: AI interaction data is retained consistent with the retention periods in Section 13.
Automated analysis and decision-making
Shastr's platform uses automated analysis, including AI, to surface insights, risks, and recommendations. The kinds of personal information that may be used in this analysis include account identifiers, role and organisation details, and content you or your organisation input into the platform (for example initiative owners, stakeholder names, or document text).
Shastr does not make final governance, financial, or personnel decisions — these remain the responsibility of you and your organisation. Automation is used to substantially assist human review (for example by drafting artefacts or flagging alignment risks), not to replace human judgement. We will continue to review this disclosure against Australia's automated decision-making transparency requirements under the Privacy Act as they apply from 10 December 2026.
6. Confidential Business Information
We treat all your content as confidential. Access by Shastr personnel is limited to what is necessary to operate, secure, support, or maintain the platform, or where required by law, regulation, or a valid legal process. We do not review, analyse, or use this content for any purpose beyond delivering the service to you, and access is governed by the role-based controls described in Section 11.
7. How We Use Your Information
We use personal information to:
- Create and administer accounts and organisation access
- Provide platform functionality and AI-powered features
- Maintain, secure, and improve the platform
- Communicate about your account, service changes, and support
- Send marketing communications where you have consented (see Section 8)
- Investigate and prevent fraud, misuse, or security incidents
- Comply with legal and regulatory obligations
8. Marketing Communications
Where you have provided consent, we may send product announcements, beta/research invitations, and event communications. You may withdraw consent at any time via the unsubscribe link in our emails or by contacting privacy@shastr.app. This will not affect service-related communications necessary for your account.
We comply with the Spam Act 2003 (Cth) for all commercial electronic messages.
9. Disclosure of Information — Sub-Processors
We do not sell, rent, or trade personal information.
| Provider | Purpose | Data involved | Location |
|---|---|---|---|
| Anthropic | AI processing (Claude models) | AI feature inputs/outputs | United States |
| ElevenLabs | Voice generation | Voice inputs and generated audio | United States |
| Pendo | Product analytics and in-app guidance | Usage events; visitor and account identifiers | European Union (EU hosting) |
| Neon | Primary database / storage | All platform data | Sydney, Australia |
| Clerk | Authentication and identity | Account credentials, SSO identifiers | United States |
| Vercel | Hosting and deployment | Application traffic, technical data | Sydney, Australia |
| Stripe | Billing | Billing/subscription data | United States |
The locations above describe our production customer environment. Non-production environments used for development or testing may use different regions. Some providers (including Clerk, Anthropic, ElevenLabs, and Stripe) process data in the United States even when our application and database run in Australia. Pendo processes analytics data in the European Union.
We may also disclose information where required by law, to protect our legal rights, to investigate fraud or security incidents, or as part of a merger, acquisition, or business restructure, subject to confidentiality obligations.
10. Cookies and Tracking Technologies
We use:
- Essential cookies — required for authentication, security, and core platform functionality (including cookies managed by Clerk); these cannot be disabled if you use the service.
- Functional cookies — remember preferences and settings where used (for example flow or context preferences).
- Analytics cookies — used on our marketing website (including Google Analytics) and product analytics (including Pendo) to understand usage and improve the product. Google Analytics is limited to the marketing website; Pendo may also run in the authenticated platform for signed-in users.
On first visit to our marketing website, you will be shown a cookie banner allowing granular, opt-in consent for non-essential categories (functional and analytics). Essential cookies remain on. You can manage or withdraw preferences at any time via the Cookie settings link in the marketing site footer. We do not rely on implied consent for non-essential cookies. You can also contact privacy@shastr.app with cookie-related questions.
11. Data Security and Incident Response
We implement technical and organisational measures designed to protect personal information and confidential business content, including:
- Encryption of data in transit (TLS) and encryption at rest provided by our infrastructure providers
- Role-based access controls limiting internal and organisational access to what is necessary for support and operations
- Logical separation of customer data between organisations / workspaces
- Authentication safeguards via our identity provider, including support for multi-factor authentication where enabled for your organisation
- Application monitoring and logging to support reliability and security investigations, and database recovery history configured with our database provider
While no system can guarantee absolute security, we maintain these layered safeguards to protect your information and continue to invest in strengthening them as the platform grows.
If we become aware of a data breach likely to result in serious harm, we will notify the OAIC and affected individuals within the timeframes required under the Australian Notifiable Data Breaches (NDB) scheme, and will separately notify affected organisation administrators promptly under any applicable Data Processing Agreement.
If you believe your personal information has been compromised, contact privacy@shastr.app immediately.
12. International Data Transfers
Some sub-processors operate infrastructure outside Australia, including in the United States (Section 9). Where we transfer personal information overseas, we take reasonable steps to ensure recipients are subject to privacy protections at least as protective as the Australian Privacy Principles, including through contractual safeguards.
13. Data Retention
| Data type | Retention period |
|---|---|
| Active account/organisation data | Retained for the duration of the active subscription or workspace relationship |
| Account/data after termination | We aim to delete or de-identify within 30 days of termination or a verified deletion request, unless a longer period is required by law or agreed in a DPA |
| Database recovery history | Retained according to our production database provider configuration (currently 1 day of point-in-time recovery history) |
| Operational, diagnostic, and AI processing logs | Generally retained for up to 90 days, unless a longer period is needed for security investigation or legal compliance |
Where information is no longer required, we take reasonable steps to securely delete, anonymise, or de-identify it.
14. Your Rights
Subject to applicable law, you may request to:
- Access personal information we hold about you
- Correct inaccurate or out-of-date information
- Export your data, including account information, uploaded documents, generated artefacts, business cases, and initiative data
- Delete your personal information, subject to legal, contractual, or legitimate retention requirements
Requests may be submitted to privacy@shastr.app. We may require identity verification and will generally respond within 30 days. Some requests relating to organisational data may need to be made through, or be subject to, your organisation's administrator and its agreement with us.
15. Age Eligibility
Shastr is intended for use by individuals aged 18 or over, acting in a professional or organisational capacity, and is not directed at or intended for use by children.
16. Complaints
Contact privacy@shastr.app with any concerns; we aim to acknowledge promptly and resolve within 30 days.
If unsatisfied, you may lodge a complaint with the OAIC:
- Website: https://www.oaic.gov.au/
- Phone: 1300 363 992
- Email: enquiries@oaic.gov.au
17. Third-Party Websites and Integrations
Our platform may link to or integrate with third-party services your organisation chooses to use. We are not responsible for their privacy practices.
18. Changes to this Privacy Policy
We may update this Privacy Policy to reflect changes in practices, legal obligations, or service providers. Material changes — particularly those affecting AI processing or sub-processors — will be communicated directly to account administrators in addition to being published here.
19. Contact Us
Nexterra Group Pty Ltd, trading as Shastr
ABN: 84 684 815 987
Registered Address: 27 Halley Avenue, Camberwell VIC 3124, Australia
Email: privacy@shastr.app
© 2026 Nexterra Group Pty Ltd, trading as Shastr. All rights reserved.