Privacy policy
How SwitchReport handles personal information in the SwitchReport website, camera app and reporting service. Version 2.4 — effective 8 September 2026; replaces the version dated 5 September 2026.
Who we are
SwitchReport is a trading name. The operating entity, its ABN and address will be shown here on finalised registration. Contact us about privacy at support@switchreport.app or on 0457 447 236.
We are bound by the Privacy Act 1988 (Cth) and handle personal information in accordance with the 13 Australian Privacy Principles (APPs); "personal information" has the meaning given in that Act. This policy explains what we collect and why, who else handles it, and how you can access it, correct it or complain. It is provided free of charge — ask us if you need it in another form.
What this covers
All parts of SwitchReport: the website at switchreport.app including the signed-in web app, the SwitchReport app that runs on your FLIR i34 / i64 thermal camera, and the report-generation service behind them. They share one account and one database, so they are described together. It applies to visitors to this website, to account holders and their team members, and to the individuals whose details appear in the records account holders keep. Accounts are opened by the SwitchReport team, see "Availability" below.
What we collect
Your account. Your name and email address; your password (stored only in hashed form by our authentication provider — we can never see it); your business details, including any logo or branding files you upload for your reports; and the professional details you choose to record — thermography certifications, electrical licence details, and the name and qualification of any assistant you record on an inspection. Qualification details are collected because Australian reporting standards require a report to identify the thermographer and their qualification; if you do not provide them, your reports cannot carry them.
Team members. If additional seats are added to your account, we collect each team member's name and email address to invite them and operate their sign-in. Their work is stored under your business account.
Billing. If your account is on a paid plan, we collect billing details — your plan, billing contact and billing address. Payment cards are handled by our payment provider, Stripe: your card details go to Stripe and payments are processed by them, and we do not store your full card number on our own systems. We keep the billing records we need for accounting and tax purposes.
Records you enter about your customers. When you set up a customer and site, you enter business names, billing and site addresses, and contact names, email addresses and phone numbers. This is personal information about other people, and you remain responsible for having a proper basis to collect it. We hold it on your behalf and do not use it for anything except providing SwitchReport to you — see "Your customers' information" below.
Inspection data. Thermal (radiometric) and visual images of the equipment you scan; the temperature readings and priority / criticality codes derived from them; the location structure you build (building, level, room) and equipment identifiers; your condition, repair and non-thermal notes; inspection and recommended re-scan dates; and the reports generated from all of it.
Images are of equipment, not people. Thermal scans assess switchboards and electrical equipment. Please frame captures so that people are not in shot. If a bystander is incidentally captured in a visual photo, we treat that as unsolicited personal information: tell us and we will crop, blur or delete it as soon as practicable.
Technical records. Authentication and sync events — sign-ins, password changes and similar — including the time and originating IP address. We keep these so that we can investigate if an account is misused.
Problem reports and diagnostics. If you choose to send us a problem report or suggestion (from the app or the website), we collect the description you type together with basic technical context (app version, device model or browser type, and the screen you were on). A manually submitted report is emailed to our support mailbox, together with your name, email address and browser type, so we can reply. That email is sent through Google (see "Who else handles it"). Automatic crash diagnostics (a technical stack trace, device model, app version and a short breadcrumb trail of recent screens) are collected only if you have expressly opted in when asked; until you answer, nothing is sent. Breadcrumbs are designed to reference records by internal ID, not by your customers' names. Diagnostics are used solely to support and debug the product — never for marketing or profiling.
What we do not collect. We do not request your device's location — location details exist only as the addresses you type in, and the app requests no location permission. We do not use advertising trackers or analytics cookies, and we do not sell or rent personal information to anyone. We do not ask for "sensitive information" as defined by the Privacy Act (such as health, biometric or racial information) — please do not put it in notes or images. And we do not use government identifiers as our identifiers: our internal record IDs are system-generated, and an electrical licence number you record as a credential is stored only to appear on your reports, as the standards require.
Dealing with us anonymously. You can browse this website, and make a general enquiry, without identifying yourself. The reporting service itself cannot be used anonymously: a thermography report must identify the site, the recipient and the thermographer on its title page, so we need those details to provide it.
How we collect it
Directly from you — accounts are currently set up by us rather than by public sign-up, and you enter details in the app or website and sync the inspections you capture on the camera. Automatically — the technical records described above, generated as you sign in and sync. This policy is always available from this page; where a category of data has its own switch (such as crash diagnostics), we ask you separately before collecting it.
Your customers' information — our role
SwitchReport exists so you can produce inspection reports for your customers. The customer and site records you enter, and the images you capture at their premises, are held on your behalf:
- we use them only to provide SwitchReport to you (and as required by law);
- we never use your customers' contact details for our own marketing, and we never sell them;
- you are responsible for collecting those details lawfully and for telling your customer how they will be used;
- if an individual contacts us directly about information you entered, we will refer them to you and help you respond;
- your reports are delivered to you — we do not send them to your customers or their insurers unless you direct us to.
How we use it
We use personal information to: provide and operate SwitchReport — including syncing between your camera and the web app, computing temperature readings and priority codes, and generating your reports; create, secure and administer accounts and authenticate sign-ins; process payments for paid plans and keep billing records; respond to support requests and problem reports; maintain and improve SwitchReport and diagnose faults; administer access to the Service; meet our legal obligations; and, with your consent, for any other purpose we describe at the time.
Our automated analysis — hot-spot detection and the priority and criticality codes — assesses equipment readings, and every report is prepared and reviewed by the responsible thermographer. It does not make decisions about individuals.
Our use of AI (Anthropic)
We use Anthropic, our AI provider, in two ways: drafting text for your reports, and helping us triage and reply to support email. Both are described here so it is clear which one applies when.
AI-drafted text (Anthropic). SwitchReport can draft three kinds of text for a capture: the condition observation, the board description, and the wording that accompanies an absolute-maximum reading. Drafting runs in two ways. On the camera, if you turn on AI for an inspection, every capture in that inspection is sent for drafting when the inspection reaches the web. On the web, you can ask for a draft for one capture or for all captures in an inspection at once; when you ask for one, the next captures in your queue may be prepared ahead so they are ready when you reach them. Each request sends that capture's thermal image, the visual photo if there is one, the panel name you typed and the measurement readings to Anthropic, whose service processes it in the United States, and a short draft comes back for you to accept, edit or discard. Only text you approve appears on the report. Nothing is sent for an inspection where AI is off.
We keep a record of each request (who made it, when) to meter usage and prevent abuse, and we record what was drafted and what you did with it, so your reports remain auditable. The request carries the images, the panel name you typed and the readings; it does not include your customer records.
Support email handling (applies automatically to every message). When you email support@switchreport.app, the content of that email — including its full text — is also sent to Anthropic, processed in the United States, to help us classify, triage and prepare a draft reply. Unlike the AI-drafted observation above, this is not something you switch on: it applies to every message sent to that address, because it is part of how we run our support inbox. A person on our team reviews and sends any reply — Anthropic's processing of your message does not by itself result in a reply being sent or a decision being made about you.
For both uses: under Anthropic's API terms, data sent this way is used to provide the response, not to train AI models.
Who else handles it
We use a small number of service providers to run SwitchReport, and we update this list before a new provider takes effect:
- Supabase — database, file storage and authentication, hosted in the Sydney region (ap-southeast-2).
- DigitalOcean — hosting for the website and report engine, in Sydney.
- Zoho Mail — our business email, on Australian servers (if you email us, including to make a privacy request, it is handled there; see also Anthropic below — messages to our support address are also processed for triage).
- Zoho ZeptoMail — automated account emails such as password resets, on Australian servers; this involves handling your email address.
- Google (Google Workspace) — delivers the operator alert emails for problem reports, carrying the submitter's name, email address and description, processed in the United States.
- Anthropic — AI-drafted text (observation, board description, absolute-maximum wording), for every capture when AI is on for an inspection, or on request; and automatic triage/draft-reply processing of every email sent to support@switchreport.app (see above), processed in the United States.
- Microsoft OneDrive — weekly backup copies of thermal and visual images, in Australian-hosted storage, filed under system identifiers; the backup also holds generated report PDFs, which name the site and customer as the report does.
- Stripe — card payment processing for paid plans, as described under "What we collect."
Our web pages do not load fonts, scripts or trackers from third-party servers — everything the pages need is served from our own site.
Beyond these, we disclose personal information only: to our professional advisers where reasonably necessary; where the law requires or authorises it; or, if our business is restructured or sold, to a successor bound by this policy. We do not sell, rent or trade personal information.
Where your data lives
Your account, customer records, inspection data and images are stored in Australia, in a Supabase project hosted in the Sydney region (ap-southeast-2). Data is encrypted in transit between your browser or camera and our servers, and backups are kept in Australian-hosted storage.
The only routine overseas disclosures are to Anthropic in the United States — when AI drafts text for your reports, and (automatically, for every message) when you email our support address — to Google in the United States, when a problem report you submit is emailed to our support mailbox; and to Stripe in the United States, to process payments if your account is on a paid plan. Where we disclose personal information overseas we take reasonable steps to ensure the recipient handles it consistently with the APPs, and we remain accountable for that handling.
Each account can only reach its own records. This is enforced by the database itself rather than only by the application. A small number of our own server-side operations (seat invitations, support alerts, AI usage metering, account deletion) run with elevated access and are the exception; we limit and review them. There is more detail on our Data & security page.
Data on your camera
The SwitchReport app keeps a working copy of your data on the camera itself so you can work without a signal. We want to be specific about what that means, because a camera is a portable object that may be shared, lent, lost or sold.
- Your customer records, sites, inspections and captured images are stored in the app's own private storage on the device.
- Your saved sign-in credentials are held encrypted, using the device's hardware-backed keystore.
- Signing out erases all of that app data from the camera. If you have unsent work, the app warns you and offers to upload it first.
- Photos also saved to the camera's own picture gallery are not erased. SwitchReport saves a copy of each scan into the device gallery, in folders named after the customer and site, so you keep your own copy. Those folders are outside the app and SwitchReport deliberately does not delete them. If a camera is shared or passed on, remove them yourself in the gallery.
- Your camera is FLIR hardware and can connect to FLIR's own cloud, "FLIR Ignite," or to other camera-backup apps. If you turn one on, the photos in your camera gallery — including the inspection images above — may also upload to that service. Those services are run by others, may store data outside Australia, and are outside SwitchReport's control; turning them on is your own choice, and if you do, you are responsible for what it means for your customers' data. SwitchReport's own copy of your data stays in Australia, as described further up this page.
How we protect it
We take reasonable technical and organisational steps to protect personal information from misuse, interference, loss, and unauthorised access, modification or disclosure. In plain terms:
- Encrypted in transit — all traffic uses HTTPS. Plain HTTP requests are redirected, and the .app domain is on browsers' HTTPS-only preload list, so mainstream browsers will not attempt an unencrypted connection.
- One account cannot see another's data — row-level security separates accounts for everything the website and camera read directly. A small number of our own server-side operations (seat invitations, support alerts, AI usage metering, account deletion) run with elevated access and are the exception; we limit and review them.
- Passwords are stored hashed by our authentication provider and are never visible to us; sign-in attempts are rate-limited and authentication events are logged.
- On the camera, working data lives in protected app storage, credentials are encrypted with the hardware keystore, and release builds are hardened so app data cannot be extracted over a USB cable.
- Backups — our database is backed up daily, and thermal and visual images are additionally backed up weekly to Australian-hosted storage, filed under system identifiers; the backup also holds generated report PDFs, which name the site and customer as the report does.
- Access within our team is limited to the people who need it to run and support SwitchReport.
No system is perfectly secure, and we will never claim otherwise. If a data breach occurs that is likely to result in serious harm, we will assess it promptly (within 30 days of suspecting an eligible breach) and notify the Office of the Australian Information Commissioner and affected individuals as soon as practicable, in accordance with the Notifiable Data Breaches scheme. There is more technical detail on our Data & security page.
How long we keep it — and your control over your records
We retain inspection records and their associated images for 7 years from the date of the inspection, unless we are required by law to keep them longer, or they are needed in connection with a legal claim. Thermal reports have long-term value — a fault often has to be shown developing over years, and an insurer or auditor may ask for an earlier baseline scan long after the work was done. That retention is the lawful basis on which we keep report records even after they are no longer needed day-to-day.
Your records are in your control. You can archive records in the product, and you can ask us at any time to delete records earlier than the periods above (unless the law requires us to keep them). Deleting a specific record is immediate and cannot be undone, and we are not responsible for the loss of records deleted by you or at your request. Your delivered reports are yours — if your own compliance obligations require you to keep a report or its images, keep your delivered copy (the camera also files a copy of each scan into its own gallery — see "Data on your camera" above).
If you close your account, closing it starts a 30-day period in which it can be restored; after that everything is permanently removed, including backup copies, within a further 30 days. Other records — such as authentication logs and diagnostics — are kept only as long as needed for the purposes described above, then deleted or de-identified. When personal information is no longer needed for any purpose we are allowed to keep it for, we destroy or de-identify it.
Marketing
We may occasionally email account holders about SwitchReport product updates. Every such email contains a working unsubscribe link; opting out is free and honoured promptly, and we comply with the Spam Act 2003 (Cth). We never use your customers' details for marketing, and you can ask us at any time where we obtained any information we used to contact you.
Access, correction and complaints
The fastest path is in the product — your account, customer and inspection details can be viewed and edited directly, and past reports deliberately preserve what was true at the time they were issued (corrections apply to the live records, not to history).
Access. You can ask us for a copy of the personal information we hold about you. Email support@switchreport.app; we will verify it is you, and respond within 30 days. We do not charge for making a request, and if we ever needed to charge for giving access it would be reasonable and quoted first. We can refuse access only on the limited grounds the Privacy Act allows; if we do, we will tell you why in writing and how to complain.
Correction. If information we hold is inaccurate, out-of-date, incomplete, irrelevant or misleading, we will correct it free of charge. If we refuse, you may ask us to attach a statement of your disagreement to the record, and we will.
Complaints. If you think we have breached the APPs or mishandled your information, tell us first at support@switchreport.app so we can put it right — we will acknowledge your complaint promptly and aim to resolve it within 30 days. If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (OAIC): online at oaic.gov.au, by phone on 1300 363 992, or by post to GPO Box 5218, Sydney NSW 2001.
Availability
Accounts are opened by the SwitchReport team rather than through a public sign-up. Any data shown in a demonstration of the product is fabricated sample data, not the records of any real person or business. Everything in this policy applies in full to every account from the day it opens.
Children
SwitchReport is a professional tool for licensed electrical work. It is not directed at children, and we do not knowingly collect personal information from anyone under 18.
Changes to this policy
If we change how we handle personal information, we will update this page and the date at the top. Where a change is significant — including adding a service provider — we will update this policy before the change takes effect and tell account holders directly.