Updated 21 September 2026
Introduction
Our social media mobile application (Amicitia App) and our website (www.amicitia.com.au) are created and controlled by Veil Solutions Pty Ltd (ACN 694 188 200) (Amicitia, we, us or our).
Amicitia is committed to ensuring your Personal Information is protected. Amicitia manages your Personal Information in accordance with the Australian Privacy Principles set out in the Privacy Act 1988 (Cth) (Privacy Act).
By accessing and using the Amicitia App, our website and any products and services made available through the Amicitia App you agree to this Privacy Policy.
This Privacy Policy outlines how Amicitia collects, stores, processes, shares, uses and discloses your Personal Information, and how you may access your Personal Information kept by us or how you may make a privacy complaint.
As the Amicitia App uses end-to-end encryption to safeguard your Personal Information and your content (such your posts, messages, captions, images, videos and comments, your profile and biographical information, your private messages and anything you receive from other users on, or via, the Amicitia App) content is encrypted on your device before it reaches us and cannot be read by us.
The information Amicitia collects about you
Personal Information
Personal information has the same meaning that it has under the Privacy Act, namely, information means information or an opinion about an identified individual or an individual who is reasonably identifiable, whether the information or opinion is true or not and recorded in a material form or not.
Amicitia will only collect and hold Personal Information about you that is reasonably necessary to undertake our business activities and functions, make the Amicitia App and website available to you and deliver our products and services to you, or as otherwise permitted by law.
Information you provide to us. The type of Personal Information and Non-Personal Information that Amicitia collects and uses depends on the type of dealings that you have with Amicitia and includes the following:
user profile and registration information (for example, full name, email address, date of birth and profile picture/image) and account credentials (such as your username and password);
data and information relating to your dealings, or enquiries you have made, with us;
your connections and social graph information, for example your friends list, friend requests you send or receive, and the status of those connections;
device tokens used to deliver push notifications to your device. Push notifications are generic and do not contain the content of the post or message;
reports you submit to us about other users or content, including any screenshot you choose to attach to a report was assessed and actioned; and
other information that you provide to us or that we may collect in the course of our relationship with you.
Encrypted content (we cannot read this)
When you create posts, write comments, or send chat messages, the content is encrypted on your device before it is transmitted to our servers. This includes:
post captions and images;
comment text;
chat messages and images;
your full name and bio as stored on your profile
Our servers receive and store this encrypted data, but we do not hold the keys to decrypt it. We cannot read, access, or analyse this content at any time.
Automatically collected data
Device information which is automatically collected from you when you visit and navigate through the Amicitia App and our website. Such information may include, but is not limited to, your device type, your device’s network connections, unique device identifier, your device’s name, your device IP address, screen size and calibration, information about your device’s web browser and internet connection you use to access the Amicitia App and our website, crash, error and performance diagnostic information generated when the Amicitia App encounters a problem, collected using Firebase Crashlytics (provided by Google) and Sentry. This information is technical in nature, relates to the device and the error encountered, and does not include the content of your posts, messages or other material you create in the Amicitia App, browser characteristics, device characteristics, operating system and language preferences, dates and times of visits to the Amicitia App, our website and other usage statistics; and
We collect and hold certain information about you in an unencrypted form as it is necessary for the performance and function of the Amicitia App (such as your email address, your username, your first and last name, your profile picture, your date of birth, your friends list and connection status, timestamps and counts such as the number of likes on a post, device tokens used for push notifications, and any report you submit to us).
Sensitive Information
We also do not intentionally collect your Sensitive Information (as defined by the Privacy Act). However, you or another user of Amicitia App may (intentionally or inadvertently) send us Sensitive Information about an individual as part of a complaint which we receive in unencrypted form. Access to reports is restricted to authorised personnel for the purpose of assessing and actioning the complaint, and complaints are retained and destroyed in accordance with this Privacy Policy.
If you have accidentally sent us Sensitive Information, please contact us to remove, delete or block the Sensitive Information using the details below.
As you must be over 18 years of age to access and use the Amicitia App, we do not collect Personal Information from children (persons under the age of 18 years).
Information from Camera and Photo Library
To allow you to share photos and images in posts and chat, the Amicitia App will request permission to access your device's camera and photo library. When you select an image:
the image is encrypted on your device before it is uploaded to our servers;
we never receive or store an unencrypted version of your photo (except for profile pictures); and
you can revoke camera and photo library permissions at any time in your device settings.
Photographs usually contain embedded metadata, which can include the date and time the photograph was taken, the device model, camera settings and, where location tagging is enabled on your device, the GPS coordinates of where the photograph was taken. Amicitia does not read this metadata and our servers cannot access it, because the image is encrypted on your device before it is uploaded. The metadata does, however, remain part of the image file, which means it is available to the people you choose to share the image with once the image is decrypted on their device. If you do not wish to share location metadata, you can disable location tagging in your device camera settings. We are developing automatic removal of this metadata before encryption for a future release.
How Amicitia collects Personal Information
Direct collection from you. We will collect Personal Information and Non-Personal Information about you in a number of different ways. We may collect Personal Information and Non-Personal Information directly from you or in the course of our dealings with you. For example:
when you setup and create an account on the Amicitia App and when access and use the Amicitia App or purchase our products and services;
when you visit our website or contact or correspond with us online (for example, when you complete online forms, or subscribe to our publications, alerts and newsletters), lodge a complaint about another user, request customer support services, contact us via email or telephone with a query or request or make a comment on our social media sites or you participate in a promotion, competition or survey; or
from publicly available sources of information.
Collection from third parties
We may also collect Personal Information about you from publicly available sources and third parties, including:
when you provide your Personal Information to third parties (including to our related bodies corporate, business partners, service providers and third party contractors);
if you use:
our social media sites or applications; or
other third party products and services that interact with, or connect with, the Amicitia App;
If you provide us with Personal Information about another individual (as their authorised representative), we rely on you to:
inform them that you are providing their Personal Information to us; and
advise them that they can contact us for further information.
You must take reasonable steps to ensure the individual is aware of, and consents to, the matters outlined in this Privacy Policy, including that their Personal Information is being collected, the purposes for which that information is being collected, the intended recipients of that information, the individual’s right to access that information, and who we are and how to contact us.
How Amicitia uses your Personal Information
Purposes of use and disclosure
Amicitia respects your privacy and we will not sell your Personal Information. Amicitia only uses, processes and discloses your Personal Information and Non-Personal Information for the purposes for which it is collected. In particular, Amicitia uses, processes and discloses your Personal Information for the following purposes:
provide you with access to, and use of, the Amicitia App and to provide the means through you can access and use our products and services and website (including, but not limited to, creating an account, delivering OTP verification codes, account recovery, displaying your profile to friends, birthday reminders and sending push notifications);
manage, operate, maintain, test, develop, improve and upgrade the Amicitia App, systems and products and services offered by us from time to time, informing you about scheduled maintenance or outages and managing our relationship with you, content moderation, investigating complaints about the Amicitia App and other users, responding to customer support requests, investigating app crashes and debugging;
notify you of opportunities we think you might be interested in, including new products or services offerings, information about the Amicitia App, products and services, offers, competitions, promotions, events and surveys;
to customise our advertising and content on our Amicitia App;
to verify your identity;
to perform research and analysis about the Amicitia App and for data analytics purposes, including usage patterns, trends, benchmarking and other statistical or behavioural data. Before we use your Personal Information for this purpose, we ensure Personal Information is made anonymous by removing data that can identify you;
for direct marketing purposes (see section 6 below);
to comply with regulatory or other legal requirements,
for any purpose to which you have consented; and
for any other purpose notified to you at the time of collection.
In the event of a merger, acquisition or sale of the whole or part of our business or assets, we reserve the right to transfer your Personal Information as part of the transaction, without your consent or notice to you.
We do not use your Personal Information for advertising, sell your data to third parties, or share your information with business partners for marketing purposes.
Disclosure to third parties
With your consent, we may provide your Personal Information and Non-Personal Information to the following recipients:
our employees, related entities, business partners, third party contractors, suppliers and agents from time to time for the purpose of delivering, providing and administering the Amicitia App (including customer support services), our products and services, our promotions, deals and competitions;
external business advisors, such as auditors, lawyers, insurers and financiers;
third party service providers who process or use your Personal Information and Non-Personal Information for the purpose of performing functions on our behalf, but may not process or use such information for any other purpose. Our current third party service providers (Authorised Affiliates) are in figure 1 (see end of page).
When we disclose your Personal Information to any of our Authorised Affiliates, we will ensure that they undertake to protect your privacy. Authorised Affiliates are not permitted to use the information for any purpose other than the purpose for which they have been given access.
Our Authorised Affiliates may also provide us with Personal Information collected from you. If you disclose Personal Information to an Authorised Affiliate, we rely on you to provide the Authorised Affiliates with consent for us to collect, storage, use, process, alter and disclose your Personal Information.
Amicitia may also disclose any Personal Information we consider necessary to comply with any applicable law, regulation, legal process, governmental request or industry code or standard.
Overseas disclosure
In the course of providing you with access to, and use of, the Amicitia App, our products and services, it may become necessary or desirable to disclose Personal Information to Authorised Affiliates located overseas. The countries in which these overseas recipients may be located will depend upon the individual circumstances. However, in the course of our ordinary business operations we commonly disclose Non-Personal Information to overseas recipients located in:
France/ European Union, being Seald (operated by OVHcloud Labs), which provides encryption and encryption identify management services;
the United Kingdom, being Ably, which provides real-time delivery for encrypted messages; and
the United States, being Apple, Google (including Firebase Cloud Messaging and Firebase Crashlytics) and Sentry, which provide push notification delivery and crash and error reporting services.
Encrypted media files you upload are delivered through a global content delivery network, which may store copies of those files at locations in other countries in order to deliver them efficiently. Those files remain encrypted at all times and cannot be read by the content delivery operator or us.
The laws where these overseas recipients may be located provide various levels of protection for Personal Information which are not always equivalent to the level of protection that may be provided for in Australia. Where we transfer your Personal Information overseas, Amicitia will take reasonable steps to ensure that your Personal Information is treated securely, and the means of transfer provides adequate safeguards.
By accessing or using the Amicitia App, products and services, or providing your Personal Information to us, you explicitly and freely consent to the transfer of your Personal Information to our overseas Authorised Affiliates. If you do not wish to receive information from any of our Authorised Affiliates, please let us know using the details below. However, if you do not provide your Personal Information to us or our Authorised Affiliates, we may not be able to provide you with access to, and use of, the Amicitia App and our products and services.
Reporting and moderation
Because all post, comment, and chat content is end-to-end encrypted, Amicitia's servers cannot read or automatically scan user-generated content. Automated content moderation is not technically possible for encrypted content.
Amicitia relies on user reporting as its primary moderation mechanism. You can report any post, comment, or user account you believe violates our app terms and conditions.
If you submit a report:
you are required to provide an unmodified screenshot of the content you are reporting, taken from your device (where you can see the decrypted content);
the screenshot is uploaded as a plaintext image to a secure, dedicated storage area that is separate from all encrypted content storage;
your report is logged with: the reason you selected, your account identifier, the reported user's account identifier, and the screenshot; and
our moderation team reviews the screenshot and report and takes appropriate action as outlined in our app terms and conditions.
Report records and screenshots are retained for 36 months or longer to support ongoing safety reviews and any resulting legal or law enforcement proceedings.
Children’s privacy and safety
Amicitia is a social media application intended for users aged 18 and over. We do not knowingly collect information about children or permit anyone under the age of 18 to create an account. If you are a parent or guardian and believe your child under 18 has created an Amicitia account, please contact us immediately at admin@amicitia.com.au. We will take steps to remove the account and associated data from our systems.
Amicitia has zero tolerance for child sexual abuse and exploitation. This includes child sexual abuse material, the sexualisation of minors, grooming, sextortion, and the trafficking or solicitation of minors. Any user involved in such activity will have their account terminated immediately and permanently, and Amicitia will report such activities to the relevant law enforcement authorities.
If you encounter any content or conduct you believe involves child sexual abuse or exploitation, report it immediately using the in-app report function, or contact our child safety point of contact at admin@amicitia.com.au, marked for the attention of the Child Safety Point of Contact. Reports indicating possible child sexual abuse or exploitation are prioritised ahead of all other reports. If a child is in immediate danger, contact your local police.
Disclaimer
Amicitia will not disclose your Personal Information to any third party (other than our Authorised Affiliates) without your written consent, unless:
we are otherwise required by the relevant Privacy Act;
we are permitted to under this Privacy Policy; or
we are required by law, regulation, court order, subpoena, warrant, legal proceedings or in response to a law enforcement agency request; and
such disclosure is, in our opinion, reasonably necessary to protect our rights or property, avoid injury to any person or ensure the proper functioning of the Amicitia App.
This Privacy Policy only covers the use and disclosure of information we collect from you. The use of your Personal Information by any third party is governed by their privacy policies and is not within our control.
Notifiable Data Breaches Laws
In the event of any loss, or unauthorised access or disclosure of your Personal Information that is likely to result in serious harm to you, Amicitia will investigate and notify you and the Australian Information Commissioner as soon as practicable, in accordance with notifiable data breach laws contained in the Privacy Act.
Marketing communications
Direct marketing
Amicitia may use and disclose Personal Information to send you information about the Amicitia App and any other products or services we may offer from time to time, as well as other information that may be of interest to you.
Where we have obtained your prior consent or are otherwise permitted under the Privacy Act, we may, from time to time, use your Personal Information to send you information about the promotions, deals, competitions, the Amicitia App and/or and any other products or services we may offer from time to time, and any other information that we consider may be relevant to you.
These communications may continue, even after you stop using the Amicitia App, products and/or services.
Communication channels
Amicitia may send this information to you via the communication channels specified at the time you provide your consent.
These communication channels may include mail, email, SMS telephone, social media or by customising online content and displaying notices or advertising on the Amicitia App.
Opting-out. You can opt out of receiving these communications by:
contacting us using the details below; or
using the unsubscribe function in the email or SMS.
Storage and security
Protecting your Personal Information
We take reasonable steps in the circumstances to keep your Personal Information and Non-Personal Information safe. We use a combination of technical, administrative, and physical controls to protect and maintain the security of your Personal Information. These measures include:
end-to-end encryption: the content you create in the Amicitia App, including your posts, captions, images, comments, profile bio and private messages, is encrypted on your device before it is transmitted to us. Our servers store that content only in encrypted form and do not decrypt it;
encryption in transit: communications between the Amicitia App and our servers are protected using industry standard Transport Layer Security;
secure cloud infrastructure: our database and encrypted media files are hosted with Amazon Web Services in the Asia Pacific (Sydney) region, and encrypted media is uploaded using time-limited, pre-signed links;
password protection: account passwords are stored in hash form and are not stored or transmitted by us in readable form;
one-time password verification: registration and email verification use one-time passwords delivered by email, and an account is locked after five incorrect attempts;
split-key identity recovery: restoring your encryption identity requires a two-factor process in which the components necessary to restore that identity is held separately by our encryption provider and by us, so that neither party alone can reconstruct your encryption identity; and
access controls: server-side authorisation checks restrict each user to their own content and connections; session tokens are invalidated when you log out or change your password, and encryption keys are cleared from your device’s memory when you log out.
Our officers, employees, agents and third-party contractors are expected to observe the confidentiality of your Personal Information and Non-Personal Information.
Wherever possible, we procure that Authorised Affiliates who have access to your Personal Information and Non-Personal Information take reasonable steps to:
protect and maintain the security of your Personal Information and Non-Personal Information; and
comply with the Australian Privacy Principles when accessing and using your Personal Information.
No guarantee
The transmission of information via the internet is not completely secure. While we do our best to protect your Personal Information and Non-Personal Information, we cannot guarantee the security of any Personal Information and Non-Personal Information transmitted through the Amicitia App.
Because of the way that the Amicitia App is designed, we are not able to read the content you create or share, and we are not able to decrypt it. If our systems were subject to unauthorised access, the content you have posted or messaged would remain encrypted and unreadable. Information that we necessarily hold in unencrypted form, such as your email address, username, display name, date of birth, profile picture and any report you submit to us, do not have the benefit of encryption protection.
You provide your Personal Information and Non-Personal Information to us at your own risk, and we are not responsible for any unauthorised access to, and disclosure of, your Personal Information and Non-Personal Information.
Retention and destruction of Personal Information
We will only retain your Personal Information for as long as necessary for the purposes described in this Privacy Policy, or as required by law. Where your Personal Information is no longer required, we will destroy or de-identify Personal Information.
We will retain Personal Information and Non-Personal Information for the following retention periods that can be seen in figure 2 (see end of page).
When you delete a post, comment, or chat message, or when you delete your account, we remove the encrypted data from our servers. However, because the Amicitia App uses end-to-end encryption technology, we cannot erase content that has already been decrypted and displayed on another user's device.
Accessing and correcting your Personal Information
Amicitia shall use our reasonable endeavours to keep your Personal Information accurate, up-to-date and complete. You have the right to access any Personal Information we hold about you, subject to some exceptions under the Privacy Act.
You can access, or request that we correct, your Personal Information by writing to us using the details below. Amicitia may require proof of identity. If we do not allow you to access any part of your Personal Information, we will tell you why in writing.
We will not charge you for requesting access to your Personal Information but may charge you for our reasonable costs in supplying you with access to this information.
We will endeavour to respond to your request for access or correction within 30 days from your request.
Cookies policy and analytics
Amicitia does not currently use cookies, web beacons, advertising identifiers, or third party analytics or advertising software development kits in the Amicitia App or on our website. We do not track your activity across other applications or websites, and we do not use your information for behavioural advertising.
We use crash and error reporting tools, Firebase Crashlytics and Sentry, which collect technical diagnostic information when the Amicitia App encounters a problem. These tools do not collect the content you create in the Amicitia App and are not used for advertising or profiling.
If we introduce cookies, analytics or similar technologies in the future, we will update this Privacy Policy and, where required by law, obtain your consent before doing so.
Privacy complaints
If you have any issues about this Privacy Policy or the way Amicitia handles your Personal Information, please contact us using the details below and provide full details of your complaint and any supporting documentation.
At all times, privacy complaints:
will be treated seriously;
will be dealt with promptly;
will be dealt with in a confidential manner; and
will not affect your existing obligations or your commercial arrangements with us.
Our Privacy Officer will endeavour to:
respond to you within 10 business days; and
investigate and attempt to resolve your concerns within 30 business days or any longer period necessary and notified to you by our Privacy Officer.
If you are dissatisfied with the outcome of your complaint, you may refer the complaint to the Office of the Australian Information Commissioner.
How to contact us
If you have any complaints or issues you wish to raise with us regarding the way we have handled your Personal Information, or would like to discuss any issues about our Privacy Policy, please contact us directly by:
email at admin@amicitia.com.au; or
via the Contact Us page of our website, https://www.amicitia.com.au/contact, or
using the ‘Report a Problem’ function within the ‘Help Centre’ section of the Amicitia App.
Changes to this Privacy Policy
From time to time, it may be necessary for us to review and revise our Privacy Policy. We may notify you about changes to this Privacy Policy by posting an updated version on the Amicitia App.
We encourage you to check the Amicitia App from time to time to ensure you are familiar with our latest Privacy Policy.
FIGURE 1. Authorised Affiliates
Service Provider | Role and Data Involved |
Seald SDK / OVHcloud Labs (France) | End-to-end encryption and key management. Stores your encrypted identity on its SSKS servers (located in the EU). Cannot read your content — only stores encrypted key material. |
Amazon Web Services — S3 + CloudFront (USA) | Stores encrypted media files (posts, chat images) and delivers them to your device. AWS never receives unencrypted content. |
Amazon Web Services — SES (USA) | Delivers email one-time passwords for account verification and identity recovery. |
Ably (United Kingdom) | Delivers encrypted chat messages in real time between users. Ably only ever receives and transmits ciphertext — it cannot read message content. |
Apple APNs (USA) | Delivers push notifications to iOS devices. Notifications contain generic text only (e.g. 'You have a new message') — no content is transmitted. |
Google FCM (USA) | Delivers push notifications to Android devices. Same as above — generic text only. |
Firebase Crashlytics / Google (USA) | Crash and error reporting. Receives device diagnostics only — not your personal content. See Section 3.3. |
Sentry / Functional Software Inc. (USA) | Error monitoring and performance tracking. Receives technical diagnostic data only. |
FIGURE 2. RETENTION PERIODS
Data Type | Retention Period |
Account information (email, username, profile picture, date of birth) | For the duration of your account. Post-deletion retention periods are subject to legal review and applicable law. |
Soft-deletion grace period | 30 days from account deletion request. Account is deactivated but restorable. After 30 days without re-login, permanent (hard) deletion is triggered. |
Encrypted content (posts, comments, chat messages, images) | Retained for the duration of your account. On account deletion request, retained for a 30-day grace period, then permanently deleted if no re-login occurs. |
Server logs (IP addresses, access timestamps) | Up to 12 months for security monitoring and troubleshooting. |
Crash reports (Firebase Crashlytics, Sentry) | Up to 12 months. Contains device diagnostics only — no personal content. |
Content reports (moderation) | Up to 36 months from the date of report submission, to support legal claims and ongoing safety investigations. |
In-app support correspondence | Retained as required by applicable law and legal counsel guidance. |
Identity recovery data (2MR secret key) | For the duration of your account. Deleted on account deletion. |
