Privacy Policy
Last updated: April 2026
Collection Notice (APP 5)
LegalHub collects personal information directly from you when you register an account or use this service. The types of information collected, the purposes of collection, and your rights are set out in this policy. You may access or correct your personal information at any time by contacting privacy@legalhub.au.
1. About this policy
This Privacy Policy explains how LegalHub (ABN to be registered), operated by a sole trader in Queensland, Australia, collects, holds, uses, and discloses personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
By using this website at legalhub.au you acknowledge that you have read and understood this policy. If you do not agree with any part of this policy, please do not use the service.
2. Entity details
| Entity name | LegalHub |
| Structure | Sole trader, Queensland |
| Privacy contact | privacy@legalhub.au |
2A. Anonymity and pseudonymity (APP 2)
You may use a pseudonym when interacting with LegalHub, including when choosing a display name. We do not require you to identify yourself by your real name unless it is impracticable or required by law. You may search case law without creating an account or providing any personal information.
3. What personal information we collect
We may collect the following types of personal information:
- Account information — email address and display name, provided when you register.
- Usage data — pages visited, features used, and timestamps of activity. Search queries are processed in real time to return results but are not permanently stored or linked to your account.
- Technical data — IP address, browser type, operating system, and referring URL, collected automatically by our server logs.
- User-generated content — any text you submit through the community experience-sharing features.
We do not collect sensitive information as defined in the Privacy Act (such as health information, political opinions, or criminal records).
4. How we collect personal information
Personal information is collected through:
- Registration forms — when you create an account.
- Service use — when you search, contribute content, or interact with the platform.
- Server logs — automatically recorded by our web server when you access any page.
- Session cookies — small files stored in your browser to maintain your login session (see Section 11).
We collect personal information directly from you. We do not collect personal information from third parties.
5. Purposes of collection, use, and disclosure
We collect and use personal information for the following purposes:
- Creating and managing your account.
- Providing the legal information search service.
- Operating community features, including displaying your contributions under your chosen display name.
- Administering the credit system.
- Monitoring and improving the performance, security, and reliability of the service.
- Responding to your enquiries or requests.
- Complying with legal obligations.
We will not use or disclose your personal information for a purpose other than those set out above, unless we obtain your consent or are required or authorised by law to do so.
5A. Automated processing
LegalHub uses automated processing to operate the search service. This includes:
- Search ranking — search results are ranked by algorithmic relevance scoring based on text matching.
- Content de-identification — community contributions are processed to extract the legal situation type and outcome while removing personal details. You review and approve the result before it is published.
No automated decision with a significant effect on your rights or interests is made without human oversight.
6. Storage and security
Personal information is stored in an encrypted SQLite database on a secure server. We take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification, or disclosure. These steps include:
- Encryption of data at rest and in transit (TLS/HTTPS).
- Access controls limiting database access to the service operator.
- Regular security reviews of the application code.
- Passwords stored using industry-standard hashing algorithms (never in plain text).
We will retain your personal information only for as long as necessary to fulfil the purposes set out in this policy, or as required by law. When personal information is no longer needed, it will be securely destroyed or de-identified.
7. Disclosure to third parties
We do not sell, rent, or share your personal information with any third party. We do not use third-party analytics, tracking, or advertising services. Search queries are processed through third-party services solely for the purpose of returning relevant results (see below).
When you perform a search, your search query is transmitted to the following third-party services for the sole purpose of returning relevant results:
- Voyage AI (United States) — converts search queries into numerical representations for similarity matching. Voyage AI does not store queries beyond the time needed to process them.
- Isaacus / Kanon 2 (Australia) — re-ranks search results for legal relevance. Queries are not stored.
No other personal information is disclosed to these services. Only the text of your search query is transmitted.
We may disclose personal information if required or authorised by law (for example, in response to a court order or lawful request by a government agency).
8. Overseas disclosure (APP 8)
Our server infrastructure is hosted by Hetzner Online GmbH in Finland. Your personal information may be stored and processed in Finland as a result. Finland is a member of the European Union and is subject to the General Data Protection Regulation (GDPR), which provides a comparable standard of data protection.
Additionally, search queries are transmitted to Voyage AI in the United States for processing as described in Section 7. The United States does not have a comparable federal data protection framework to the Privacy Act, but Voyage AI processes queries transiently without permanent storage.
We do not otherwise disclose personal information to overseas recipients.
9. Access and correction (APPs 12 & 13)
You have the right to request access to the personal information we hold about you and to request correction of any information that is inaccurate, out of date, incomplete, irrelevant, or misleading.
To make an access or correction request, email privacy@legalhub.au. We will respond within 30 days. There is no fee for making a request or for correcting information.
You may also update your display name and email address directly through your account profile page at any time.
10. Data breach notification
In the event of an eligible data breach (as defined in the Privacy Act 1988), we will comply with the Notifiable Data Breaches (NDB) scheme. This means we will:
- Take reasonable steps to contain the breach and assess whether it is likely to result in serious harm.
- Notify affected individuals and the Office of the Australian Information Commissioner (OAIC) if the breach is likely to result in serious harm.
- Include in the notification a description of the breach, the kinds of information involved, and recommended steps for affected individuals.
11. Cookies
LegalHub uses only essential session cookies to maintain your login session while you use the site. These cookies are strictly necessary for the operation of the service.
We do not use:
- Tracking cookies.
- Third-party cookies.
- Analytics cookies.
- Advertising or marketing cookies.
Session cookies are automatically deleted when you close your browser or when your session expires.
12. Complaints
If you believe we have breached the Australian Privacy Principles, you may lodge a complaint by emailing privacy@legalhub.au. We will acknowledge your complaint within 7 days and provide a written response within 30 days.
If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC):
- Website: www.oaic.gov.au
- Phone: 1300 363 992
- Post: GPO Box 5218, Sydney NSW 2001
13. Changes to this policy
We may update this Privacy Policy from time to time. Any changes will be published on this page with an updated "Last updated" date. We encourage you to review this policy periodically. Continued use of the service after changes are published constitutes acceptance of the updated policy.
14. Contact
For any questions about this Privacy Policy or our handling of your personal information, please contact:
LegalHub Privacy Officer
Email: privacy@legalhub.au