Skip to content
morefold
Menu
Knowledge Your documents, organised and searchable Ask Cited answers from your own files Compare Differences flagged side by side Approvals & Audit A person approves every action Automations Follow-ups that run on schedule Integrations Connects the tools you already use
Explore the full platform
Insurance brokers Built with Australian brokerages
Trust
Request a demo

Legal

Privacy Policy

Last updated 15 July 2026

This policy explains how Morefold Pty Ltd (ACN 699 686 149) ("Morefold", "we", "us") handles personal information. It covers this website, morefold.ai, and the Morefold platform at app.morefold.ai. We are an Australian company and we handle personal information under the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). If your organisation has a signed agreement with us, that agreement may add to what is here, but this policy is the shared statement of how we handle personal information.

The short version

Morefold is software for insurance brokerages. Brokers connect the places their documents already live, the platform reads them, flags missing or expiring information, and drafts follow-up actions that a person approves before anything is sent. To provide that service we hold business documents that contain personal information about our customers' clients. Our database lives in Sydney. Document content is processed by AI providers in the United States, with tax file numbers, Medicare numbers, and payment card numbers masked first. We do not sell personal information, we do not use it for advertising, and we do not use it to train AI models.

Who this policy covers

  • Visitors to this website. People who browse morefold.ai or contact us.
  • Platform users. People at our customer organisations who hold a Morefold account.
  • People whose information appears in customer content. Our customers are businesses, and the documents and records they bring into the platform can describe their clients and other third parties. We handle that information on the customer's behalf and at its direction to provide the service. The customer remains responsible for its relationship with its own clients, and its own privacy policy governs how it collects and uses their information. If your broker or adviser uses Morefold, you can contact them about your information, or contact us using the details below.

What we collect

  • Website enquiries. If you email us or request access, we receive your name, your email address, and anything else you choose to include. The website itself uses no tracking cookies and no third-party analytics.
  • Account information. Name, work email address, profile details and preferences, and sign-in records such as session details, IP address, and browser type.
  • Customer content. The documents your organisation uploads or connects, the text and search indexes derived from them, and the client records your organisation keeps in the platform. These can contain personal information, and sometimes sensitive information, about people who are not Morefold users.
  • Connected accounts. If your organisation connects a supported service, such as Google Drive, Microsoft OneDrive or SharePoint, or an email account, we store the connection credentials securely and the material the connection is authorised to provide.
  • Service records. Records of activity in your organisation's workspace, records of AI requests and their outputs, and technical logs used to operate and secure the service.

How we collect it

Directly from you, when you contact us, accept an invitation, sign in, or upload something. From your organisation, when it sets up your account or adds records that mention you. Through connections you authorise. And automatically, as ordinary technical records created by using the service. Access is by invitation; we do not buy personal information or collect it from data brokers. If you choose not to provide information we ask for, we may not be able to provide the service or respond fully to your enquiry.

Why we use it

  • To provide the platform: reading and organising documents, flagging missing or expiring information, drafting actions for your team to review, and sending the communications your team approves.
  • To run accounts: invitations, sign-in, support, and notices about things that need your attention.
  • To keep the service secure and reliable.
  • To meet legal obligations and, where necessary, to establish or defend legal claims.

We do not sell personal information. We do not use it for advertising. We do not use your content to train AI models, and the AI providers we use process it under commercial terms that do not permit them to train on it either.

AI processing

The platform's core feature is AI that reads your documents, so document content is sent to our AI providers, Anthropic and OpenAI, which process it in the United States. Before any content is sent, Australian tax file numbers, Medicare numbers, and payment card numbers are automatically detected and masked; the original values never leave our systems. This masking covers those identifiers only. The rest of a document, including names and contact details, is processed as written, because the AI needs it to be useful. AI-drafted actions are drafts only: anything outbound, such as an email to a client, requires approval by a person in your organisation before it is sent.

Who we share it with

We do not sell personal information, and we do not share it with advertisers. It is shared only where running the service requires it:

  • Service providers. A small set of providers operate parts of the platform on our behalf: database and application hosting in Sydney, file storage in the Asia-Pacific region, the AI providers described above in the United States, AI observability and background-job tooling in the United States, and delivery of our own system email from Japan. Each receives only what its role requires, and we can provide a current list of these providers on request.
  • Services you connect. If your organisation connects its Google or Microsoft accounts, those providers handle that data under your organisation's own arrangements with them. Microsoft connector processing happens inside your organisation's own Microsoft 365 tenant.
  • Professional advisers and authorities. Our professional advisers where necessary, and regulators, courts, or law enforcement where the law requires it.

Emails to your organisation's clients are sent from the approving broker's own connected mailbox, so they leave through your organisation's existing email provider, not through a Morefold address.

Where your information lives

Our database and application run in Sydney, Australia. Uploaded document files are stored with our storage provider in the Asia-Pacific region, which does not guarantee storage in Australia only. Some processing happens overseas: document content is processed by our AI providers in the United States, some operational tooling runs in the United States, and our own system email is delivered from Japan. Personal information may therefore be disclosed to recipients in the United States and Japan. Whenever personal information goes overseas, we take reasonable steps to ensure the recipient handles it consistently with the Australian Privacy Principles, including choosing Australian regions where our providers offer them and masking the identifiers described above before AI processing.

Google user data

Morefold's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We access Google user data only with your authorisation and only to provide features you ask for: signing you in, importing the Drive files you select, and sending emails you have approved from your own Gmail address. We do not use Google user data for advertising, we do not sell it, and we do not use it to develop, improve, or train generalised AI or machine learning models. Document content from any connected source, including Google Drive, is processed by the AI providers named above solely to provide these features to you.

Sensitive information and government identifiers

Documents processed for your organisation can include sensitive information, such as health information in claims material. We handle it only to provide the service and for no other purpose, and your organisation is responsible for being entitled to share it with us. We never use tax file numbers, Medicare numbers, or other government identifiers to identify anyone, and they are masked before document content is sent to an AI provider.

How we protect it

We take reasonable technical and organisational steps to protect personal information, including encryption in transit and at rest, isolation between customer organisations enforced at the database layer, least-privilege access to connected accounts, sign-in protections and rate limiting, audit logging of workspace activity, restricted and logged staff access, and human approval before the platform sends anything outside your organisation. No system is perfectly secure, and we do not claim ours is.

How long we keep it

We keep personal information only for as long as it is needed. Website enquiries are kept while we deal with them. Customer content and client records are kept for the life of the customer relationship, and afterwards for the period Australian financial-services record-keeping obligations require, typically up to seven years, or longer where the law requires it or a legal claim reasonably needs it. Technical logs are kept for a short operational period. When information is no longer needed, we take reasonable steps to delete or de-identify it; residual copies can persist briefly in backups.

Access and correction

You can ask us for access to the personal information we hold about you, and ask us to correct it, by emailing [email protected]. There is no charge for making a request, and we may need to verify your identity before acting on one. We will respond within the timeframes the Privacy Act requires. If the information sits inside a customer organisation's content, we may need to coordinate with that organisation, and in some cases the law allows or requires us to refuse; if we do, we will tell you why in writing.

Cookies and analytics

This website sets no cookies and uses no third-party analytics or advertising tools. The platform uses only the cookies needed to keep you signed in securely.

Data breaches

We are subject to the Notifiable Data Breaches scheme. If a data breach occurs that is likely to result in serious harm, we will notify the affected individuals and the Office of the Australian Information Commissioner as the Privacy Act requires.

Complaints

If you think we have mishandled your personal information, email [email protected] and tell us what happened. We will acknowledge your complaint, look into it, and reply with what we found and what we will do. If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au.

Changes

We may update this policy as the product and the law change. The current version will always be on this page, with the date shown above. If a change meaningfully reduces your rights or expands what we collect or share, we will give platform customers notice before it takes effect.

Contact

Privacy questions, requests, and complaints: [email protected]. Morefold Pty Ltd (ACN 699 686 149), Australia.

Product

Knowledge Ask Compare Approvals & Audit Automations Integrations

Solutions

Insurance brokers

Company

Trust Request a demo

Legal

Privacy Terms
morefold

Morefold Pty Ltd · Australia.

Get in touch