Privacy policy

Last updated: 22 September 2026. Effective: 22 September 2026.

This privacy policy explains how Present ("we", "us" or "our") collects, uses, discloses and stores personal information in connection with the Present mobile application, the website at presentsocial.au, and the public record pages at prsnt.au (together, the "Services").

Present is operated by Brian Christopher Kay, a sole trader (ABN 61 260 636 132), of PO Box 8090, Flynns Beach LPO, Port Macquarie NSW 2444, Australia. He is responsible for your personal information, and is the controller of it for the purposes of the General Data Protection Regulation.

We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles.

We apply one standard everywhere. The Services have been built to the requirements of the General Data Protection Regulation (EU) 2016/679, and we extend those protections to every user wherever they live, rather than only to those whose own law requires it. The legal bases in section 3 and the rights in section 10 are therefore available to all users, and not only to users in Europe.

The Services are available internationally and other data protection laws may also apply to you. Section 11 sets out further rights that apply in certain jurisdictions. Where the law of your country gives you rights greater than those described in this policy, those rights prevail.

By creating an account or otherwise using the Services, you acknowledge that you have read this policy.

1. Information we collect

1.1 Account information. To create an account you must join through a valid invitation link. Invitation links are currently personal to one person, and we may add links that can be shared with a group. Registration is available only through Sign in with Apple, and there is no password-based alternative. We collect your display name, your username, the account identifier provided by Sign in with Apple, and an age range, established as described in section 12, which indicates only whether you are under 16, aged 16 to 17, or 18 or over, together with whether that bracket came from Apple or from a date of birth you entered on your device. We do not collect or store your date of birth, and we do not require your legal name.

1.2 Photographs, videos and capture records. Photographs and videos can only be created using the camera within the application. Posts cannot be imported or uploaded: the application does not take a photograph or video from your device photo library, and there is no file picker for posting. The application opens your photo library in one place only, when you choose to attach a screenshot to a bug report or to feedback, as described in clause 1.7. In this policy a post means a photograph or a video created in that way. At the moment of capture, your device produces a cryptographic signature over the post using hardware held on the device, and we record a timestamp issued by our servers rather than by your device clock. We store the post, that signature, the server timestamp, the device model, any caption you write, and a record of whether the post has been altered since capture.

1.3 Capture assessment information. At the time of capture your device records a limited quantity of technical information about the capture itself, which is sealed together with the post. This information is used only to assess whether a capture is consistent, is not published, and is not used to identify the subject matter of a post. Posts are not disclosed to any third-party artificial intelligence service for the purpose of determining their content.

1.4 Location information. Location is collected only at the moment you press the shutter, and is not collected while the application is closed or running in the background. For each post you select one of three options:

(a) Approximate. Your device determines the name of the town, city, suburb or local area you are in, and transmits only that name, the country, the map position of the centre of that area, and how wide that area is in metres. Your device coordinates are not transmitted and are not stored by us.

(b) Precise, which is the default. Your device coordinates at the moment of capture are transmitted and stored, together with the street name supplied by Apple's geocoding service. Before a post with a precise location is posted, the application shows you the exact spot on a map and asks you to confirm it, with the option to share the local area instead. A precise location is visible to everyone who can see the post, and appears on the post's public record page where one exists.

(c) No location. No information about your location is transmitted or stored for that post.

1.4a Locations on a video. A photograph has one location. A video is recorded across several, so a video is recorded as a single place covering all of them. A precise video is placed at the middle of the points it was recorded at, with its stated accuracy widened far enough to cover them all. An approximate video is recorded as an area large enough to contain the whole recording, named by the smallest place the whole of it falls within, which may be a suburb, a county or a state.

1.5 Social information. We collect and store the connections you form, which are mutual and require acceptance by both parties; tags identifying you in posts taken by others, which appear on your profile only after you accept them; replies you write; and shared albums ("moments") that you have agreed to join. We record which invitation link each account joined through, and we do not otherwise track invitations.

1.6 Device and technical information. We collect the device model, operating system version, application version, an attestation produced by Apple's App Attest service confirming that the application is a genuine and unmodified installation, push notification tokens where you enable notifications, and internet protocol addresses and server log information generated when your device or browser connects to our servers.

1.7 Feedback and reports. Where you send a bug report or feedback from within the application, we collect the description you write, any screenshots you choose to attach, up to five, and technical information about your device, being the application version, the iOS version, the device model, the screen configuration and the network type. Where you report content or another user, we collect the reason you select and up to 280 characters of explanation, together with any response given by the person reported.

1.8 Website information. The website at presentsocial.au records the date and time of certain page events together with the name of the event and an identifier for the page or record concerned. This event log does not record internet protocol addresses, browser identifiers or cookies, and does not identify individual visitors. Where you submit an email address through a form on the website, we store that address together with the date of submission and the source of the referral.

1.9 Usage information. We record the days on which you opened Present, which we keep for 90 days. We also count how many times public record pages and invitation pages are opened, without recording anything about the visitor. We use both to understand how Present is used.

2. How we use information

We use personal information to provide, maintain and secure the Services; to verify that a post was captured live by a genuine installation of the application on genuine hardware and has not been altered since capture; to display posts, records, profiles and moments to those permitted to see them; to operate the invitation system; to send notifications you have enabled; to detect, investigate and prevent misuse, fraud and breaches of our terms; to comply with our legal obligations; and to understand aggregate usage of the Services in order to improve them.

We do not ask for, or store, a country or region when you register. For moderation and administration, our systems may indicate the country you are most likely in, based only on the locations you have chosen to share on your posts. We do not scan the content of posts on our servers, and we will update this policy before that changes.

We do not use personal information to rank, recommend or algorithmically order the content you see. We do not display advertising. We do not sell personal information, and we do not disclose personal information to third parties for their own marketing purposes.

3. Legal bases for processing

We process personal information on the following legal bases, and we apply them to every user regardless of where they live: performance of a contract with you, for the provision of the Services; our legitimate interests, in securing the Services, verifying captures, preventing misuse and improving the Services; your consent, for optional processing such as precise location and push notifications, which you may withdraw at any time; and compliance with legal obligations to which we are subject. Where the GDPR or UK GDPR applies to you, these are the bases on which we rely for the purposes of that Regulation.

4. Information that is visible to others

4.1 Within the application. Posts are visible to the people you are connected to, and to their connections where a person you are connected to appears in or created the post. All accounts are private on creation. Accounts belonging to users under 18 years of age remain private and cannot be made public. A user aged 18 or over may make their account public, and may change that setting at any time in the application.

A private account limits who can see your profile and the posts you post within the application and on prsnt.au. You may create a public link for one of your own posts, after confirming, and that post then becomes readable by any person holding the link, whether or not your account is private.

Where you are aged 18 or over and your account is private, a person tagged in one of your posts may also create a public link for that post. You are told when this happens, and you may remove the link. This does not apply to posts by users under 18: only the person who took such a post may create a public link for it.

A private account does not govern every post in which you appear. A post taken by another person is subject to that person's settings and location choice rather than yours. You may accept or decline any tag identifying you in it. Where you accept, the post appears on your profile. Where you decline, it does not appear on your profile. Section 4.4 explains how the photo and video files themselves are delivered.

4.2 Public record pages. Each post may have a public record page hosted at prsnt.au, which can be opened by any person holding the link, without an account. Where a record page exists, it displays the post, the capture time, the device model, the location information according to the option you selected or, where the person creating the link chose to hide the exact location, the local area only, and the caption. Replies are not shown on record pages and remain within the application. A private account is never named on a record page. A person tagged in the post is named only where that person's own account is public; tagged people with private accounts are shown only as a number. Creating a public link makes that post accessible to any person holding the link.

4.3 Moments. A moment has no public page and no public link, and is visible to the people in it and their connections. A post placed in a moment becomes visible to that same wider group, which may be a wider audience than the post reached before. This is described to each person in words before anything is created, and a moment exists only where every person it concerns has agreed to it. A moment lasts 48 hours, after which it is permanently deleted, unless it is the subject of an open report or moderation, in which case it is kept until that is resolved. Deleting a moment does not delete the posts in it.

4.4 How photos and videos are delivered. The photo or video file of every post is stored with Cloudflare and delivered from a permanent web address that contains a long, randomly generated sequence. That address is not published or listed anywhere, it cannot practically be guessed, and the application shows it only to people who are allowed to see the post. It is not protected by a login, however. Anyone who obtains the address of a file, for example because a person who could see the post copied it and passed it on, can open that file, whether or not the account that posted it is private.

Turning off a public link, or making an account private, stops the post's record page at prsnt.au working immediately, but does not change the address of the file itself. Deleting a post deletes the file and removes every cached copy, after which the address no longer works. We plan to replace these permanent addresses with ones that check permission before a file is opened, and will update this policy when we do.

5. Disclosure of information

We disclose personal information to: service providers who host our infrastructure, store data and deliver notifications on our behalf, and who are permitted to use that information only to provide those services to us; Apple Inc., in connection with authentication, app attestation, push notification delivery, mapping and geocoding; professional advisers; and law enforcement, regulators or other parties where we are required or authorised by law to do so, or where necessary to protect the rights, property or safety of any person.

Where we become aware of material we have reasonable grounds to believe is child abuse material, we will refer details of it to the Australian Federal Police, as section 474.25 of the Criminal Code Act 1995 (Cth) requires of us. Such a referral is made without your consent and without notice to you, and we may preserve the relevant records for that purpose. This applies whatever the account's privacy settings.

6. Overseas disclosure and international transfers

We are based in Australia. Posts are stored with Cloudflare, Inc. using its R2 object storage service, in a storage region in Australia. When a post is viewed, Cloudflare may hold a cached copy at the edge location nearest the viewer, in any country in which Cloudflare operates, for up to one year. When a post is deleted, we delete it from storage and every cached copy is removed from Cloudflare's edge.

Our servers and databases, which hold account information, capture records, location information, connections, tags and replies, together with the website, are hosted by DigitalOcean, LLC on infrastructure located in Sydney, Australia.

Personal information may accordingly be stored on, or accessible from, servers located outside your country of residence, and our service providers may access it from further jurisdictions in order to provide, maintain and secure those services. By using the Services you consent to this disclosure. Australian Privacy Principle 8.1 may not apply to a disclosure made with your consent, and in that case we will not be accountable under the Privacy Act 1988 (Cth) for the handling of your personal information by an overseas recipient. Where we transfer personal information out of the European Economic Area or the United Kingdom, we do so on the basis of an adequacy decision or appropriate safeguards such as standard contractual clauses. The standard contractual clauses we rely on are incorporated in Cloudflare's data processing addendum and DigitalOcean's data processing agreement, each of which can be read in full at those links.

7. Retention

We retain personal information for as long as your account remains open and for so long afterwards as is necessary for the purposes described in this policy, to resolve disputes, and to comply with our legal obligations. You may delete an individual post, which removes it and its record page from the Services, and removes it from our storage and from every copy cached at Cloudflare's edge.

Our database is backed up nightly, and each backup is kept for 90 days, so information deleted from the Services may persist in a backup for up to 90 days before it is gone. Server access logs, which include internet protocol addresses, are kept for one month. Attestation challenges and rate-limiting records are deleted daily.

You may delete your account at any time in the application, under Settings. Deletion takes effect immediately, and your photo and video files are removed from storage within minutes. A ban on an Apple account identifier is handled separately and is not lifted by deleting an account.

The post itself is never altered after capture. Its record may change in one circumstance only: we may remove a note that our automatic checks added in error. Any such change is stamped on the record page itself, which names the change and the date it was made. Making an account private revokes the public links to its posts, other than the profile photo, and does not alter the posts. It does not change the addresses of the underlying files, described in section 4.4.

We also keep, for as long as they are needed for the purposes above: a one-way hash of the Apple account identifier behind an under-16 answer, for one year; the record of the days on which you opened Present, for 90 days; and records of age reviews.

Three things are retained after an account is deleted. Where an Apple account identifier has been banned, a hash of that identifier is kept indefinitely so that the ban remains effective. Our administrative audit log retains its record of moderation actions taken. Your username and email address are retained in a reserved form so that they cannot immediately be registered by another person.

8. Security

We take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification or disclosure. Signing keys are held on your device in hardware that we cannot read. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

Our service providers are responsible for the security of their own systems under their agreements with us, which are described in section 6.

Once a post has been shown to another person, or opened through a public link, we cannot control what that person does with it. They may save it, take a screenshot of it or share it elsewhere, and deleting the post, removing a link or making your account private does not recall those copies. Consider who will be able to see a post before you share it.

9. Your choices

You may choose the location option applied to each post, including no location at all. You may decline any tag, and no tag appears on your profile unless you accept it. You may decline to join any moment. You may control the frequency and categories of notifications in the application, or disable them. You may set your account to private where you are aged 18 or over. You may block another user. You may delete individual posts, or your account.

10. Your rights

These rights are available to all users, wherever they live. You may request access to the personal information we hold about you; correction of information that is inaccurate, out of date or incomplete; deletion of your personal information; restriction of, or objection to, our processing; and a copy of your information in a portable form. You can download that copy at any time in the application, under Settings, then Your data. It is a zip file containing your photos and videos as files, a readable summary, and your information in JSON format. Other people appear in it by username only, and only where you could already see them in the application, and it never identifies anyone who has reported content. It can be downloaded up to five times an hour. You can also delete your account yourself, as described in section 7. Where processing is based on consent, you may withdraw that consent at any time.

To exercise any of the other rights, contact us at [email protected]. We will respond within the period required by applicable law.

11. Additional rights in certain jurisdictions

11.1 California. Where the California Consumer Privacy Act, as amended by the California Privacy Rights Act, applies to you, you have the right to know the categories and specific pieces of personal information we have collected, the sources of that information, the purposes for collecting it and the categories of third parties to whom it is disclosed; to delete personal information; to correct inaccurate personal information; and not to be discriminated against for exercising any of these rights. The categories we collect are set out in section 1. We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined in that Act, and we have not done so in the preceding twelve months. A precise location, where you choose that option for a post, is sensitive personal information under that Act; we use it only to display and verify the location of that post, and you may decline it for any post or all posts.

11.2 New Zealand. Where the Privacy Act 2020 applies to you, you have the right to access and to request correction of personal information we hold about you, and you may complain to the Office of the Privacy Commissioner.

11.3 Canada. Where the Personal Information Protection and Electronic Documents Act applies to you, you have the right to access personal information we hold about you and to challenge its accuracy, and you may complain to the Office of the Privacy Commissioner of Canada.

11.4 Singapore. Where the Personal Data Protection Act 2012 applies to you, you have the right to request access to, and correction of, personal data we hold about you, and to withdraw consent to its collection, use or disclosure.

11.5 Brazil. Where the Lei Geral de Protecao de Dados applies to you, you have the rights of confirmation, access, correction, anonymisation, portability, deletion, and information as to the entities with which we have shared your data.

11.6 Switzerland. Where the Federal Act on Data Protection applies to you, you have the right to access, correct and delete personal data we hold about you, and you may complain to the Federal Data Protection and Information Commissioner.

11.7 Other jurisdictions. Where any other data protection or privacy law applies to you and confers rights not described in this policy, we will honour those rights to the extent that law requires.

To exercise any of these rights, contact us at [email protected]. We may need to verify your identity before acting on a request. You may use an authorised agent where the applicable law permits.

12. Children

12.1 The Services are not available to persons under 16 years of age, anywhere. Only an age bracket is ever transmitted to us: "16 to 17" or "18 and over". Age is established when you register, and is checked again when a person confirms that they are 18 or over, and during a review under clause 12.4a.

12.2 On iOS 26 and later we ask Apple's Declared Age Range service, which returns a bracket derived from the age held on the person's Apple Account. Where Apple cannot answer, because the operating system is older, the account carries no date of birth, or the person declines to share it, the application asks for a date of birth on the device and converts it to the same bracket on the device. The date of birth itself is never transmitted to us and is not stored on the device or on our servers. We hold no date of birth for any person. We do record whether a bracket came from Apple or from a date of birth entered on the device, so that entered ages can be reviewed.

12.3 Accounts belonging to users aged 16 or 17 are private and cannot be made public. A user aged 16 or 17 may still create a public link for one of their own posts, after confirming, as described in section 4. No other person may create a public link for a post by a user aged 16 or 17. Because we hold no date of birth, the restriction does not lift automatically. The person may confirm at any time that they are 18 or over, at which point the check in clause 12.2 is repeated. The account remains private until they choose otherwise.

12.4 Any person may report an account they believe belongs to someone under 16, in the application or by email. We review such a report within 24 hours. If we become aware that we have collected personal information from a person under 16, we remove the account and delete that information.

12.4a Answers about age. Where Apple answers that you are under 16, that answer is final for us and we do not ask again. We keep a one-way hash of the Apple account identifier for one year, so that the question cannot simply be asked again until Apple gives a different answer. Where you tell us yourself that you are under 16, a person reviews the account.

12.4b While a review is happening the account is paused. Nothing of yours is deleted, you can still download a copy of your data as described in section 10, and you may email [email protected] if you believe we have it wrong.

12.5 Our commitments on child safety, including our obligation to refer child abuse material to the Australian Federal Police, are set out in our child safety policy.

13. Changes to this policy

We may amend this policy from time to time. Where a change is material we will take reasonable steps to notify you, including within the application. The date at the top of this policy indicates when it was last amended.

14. How to contact us, and how to complain

Questions, requests and complaints about privacy may be sent to [email protected]. By post: PO Box 8090, Flynns Beach LPO, Port Macquarie NSW 2444, Australia.

We will acknowledge your complaint and respond within a reasonable period. If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner at oaic.gov.au. If you are in the European Economic Area or the United Kingdom, you may also complain to your local supervisory authority.