At Throwha, your privacy matters. This Privacy Policy explains what personal information we collect, how we use it, and your rights under the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
We are committed to handling your information with care and transparency. For questions or requests, contact us at enquiries@throwha.com.
SECTION 01Who We Are
Throwha is an AI-assisted digital coaching platform for throws athletes (shot put, discus, javelin, hammer), operated by Lee O'Halloran, based in New South Wales, Australia.
We are subject to the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). This policy explains how we manage personal information in accordance with those obligations.
SECTION 02What Information We Collect
We collect personal information that is necessary to provide our services. The types of information we collect include:
| Category | Examples | Source |
|---|---|---|
| Account information | Name, email address, password (hashed), account type (athlete/coach), country, timezone | You, at registration |
| Classification data | Para athletic classification (e.g., F46), disability information you choose to share | You, optionally |
| Training data | Session logs, performance metrics, distances, throws recorded, training notes | You, during use |
| Video and media | Video footage of training sessions uploaded for technique analysis | You, during use |
| Coaching content | Technique cues, coach notes, AI-generated feedback, messages between coaches and athletes | Platform-generated or user-provided |
| Technical data | IP address, browser type, device information, usage logs, error reports | Automatically collected |
| Payment data (coaches) | Billing name, payment method details (processed by our payment provider — we do not store full card numbers) | You, at checkout |
Sensitive Information
Para athletic classification data (e.g., F46, F40) may constitute sensitive information under the Privacy Act as it may relate to health or disability status. We collect this information only where you provide it voluntarily and only for the purpose of enabling appropriate coaching and performance tracking. We handle this information with additional care and will not use or disclose it for any other purpose without your explicit consent.
Information We Do Not Collect
We do not collect: government identifiers (e.g., Medicare numbers, Tax File Numbers), financial account credentials, or biometric data beyond voluntarily uploaded video footage.
SECTION 03How We Use Your Information
We use your personal information only for the purposes for which it was collected, or purposes that are directly related. Specifically:
- Providing the Platform: To create and manage your account, deliver AI coaching feedback, store training logs, and enable coach–athlete collaboration;
- AI coaching analysis: Your training data and video footage may be processed by Anthropic's Claude AI to generate technique feedback. This processing is subject to Anthropic's applicable data handling commitments;
- Communications: To send service notifications, respond to enquiries, and (with your consent) send product updates or newsletters;
- Security and fraud prevention: To protect the Platform and our users from misuse, unauthorised access, or fraudulent activity;
- Service improvement: To analyse usage patterns and improve the Platform's features and performance — using aggregated, de-identified data where possible;
- Legal compliance: To comply with applicable laws, regulations, court orders, or law enforcement requests;
- Payment processing: To process subscription payments from coach accounts.
We will not use your personal information for direct marketing without your consent. You may withdraw consent for marketing at any time by using the unsubscribe link in our emails or contacting us.
SECTION 04Data Sharing and Disclosure
Athlete-Controlled Sharing with Coaches
Your training data is yours. We share your data with a coach only if you explicitly grant them access through the Platform. You can revoke this access at any time. Coaches are bound by obligations under our Terms of Service not to misuse athlete data.
Third-Party Service Providers
We engage trusted third-party providers who assist us in operating the Platform. These providers are contractually required to handle your data securely and only for the purposes we specify. They include:
- Hosting infrastructure: Australian VPS provider(s) for data storage (see Section 5 — Data Sovereignty);
- AI processing: Anthropic (Claude) for generating coaching feedback;
- Payment processing: A PCI-DSS compliant payment gateway (details disclosed at checkout);
- Email delivery: A transactional email provider for system notifications.
We do not sell, rent, lease, or trade your personal information to any third party for commercial purposes. Ever.
Other Disclosures
We may disclose personal information where required by law, court order, or regulatory authority, or where we have a good-faith belief that disclosure is necessary to protect the safety of any person or prevent fraud.
SECTION 05Data Sovereignty and Storage Location
We take data sovereignty seriously. Our primary infrastructure is hosted on Australian servers located within Australia. For users in other countries, we endeavour to store personal data on servers located within the user's country or jurisdiction, subject to the availability of appropriate hosting infrastructure.
Where data is transferred internationally (for example, via AI processing services or third-party providers), we take reasonable steps to ensure the receiving party maintains privacy protections consistent with the Australian Privacy Principles. By using the Platform, you consent to such transfers where necessary to provide the service.
If you have specific questions about where your data is stored, contact us at enquiries@throwha.com.
SECTION 06Data Retention
We retain your personal information only for as long as necessary to fulfil the purposes for which it was collected, or as required by law:
- Active accounts: Data is retained for the duration of your account;
- Account deletion: Upon account deletion, we will delete your personal data within 30 days, except where we are required to retain it by law (e.g., financial records for tax purposes, retained for 7 years);
- Backups: Deleted data may persist in encrypted backups for up to 90 days before being fully purged;
- Training logs and video: Deleted immediately upon your request or account deletion, subject to the backup window above;
- De-identified data: Aggregated, de-identified analytical data may be retained indefinitely as it cannot be linked to any individual.
SECTION 07Your Privacy Rights
Under the Australian Privacy Act and APPs, you have the following rights regarding your personal information:
Access
Request a copy of the personal information we hold about you.
Correction
Request correction of inaccurate or outdated information.
Deletion
Request deletion of your personal data (subject to legal retention obligations).
Opt-out of marketing
Unsubscribe from marketing communications at any time.
Data portability
Request an export of your training data in a machine-readable format.
Withdraw consent
Withdraw consent where processing is based on consent (e.g., coach data sharing).
To exercise any of these rights, email us at enquiries@throwha.com. We will respond within 30 days. We may need to verify your identity before processing your request. We will not charge a fee for reasonable access requests.
If you are unsatisfied with how we handle your request, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or by calling 1300 363 992.
SECTION 08Cookies and Analytics
We use a minimal set of cookies and similar technologies:
- Essential cookies: Required for the Platform to function (e.g., session authentication). These cannot be disabled.
- Analytics: We may collect anonymised usage data (page views, feature usage) to improve the Platform. We use privacy-preserving analytics that do not build individual user profiles or share data with advertising networks.
- No advertising cookies: We do not use third-party advertising cookies or participate in ad tracking networks.
You can control cookie preferences through your browser settings. Disabling essential cookies may affect Platform functionality.
SECTION 09Children and Minors
The Platform is not directed at children under the age of 13. Users between 13 and 17 years of age may only use the Platform with the verified consent of a parent or legal guardian, who accepts these terms and takes responsibility for the minor's use of the Platform.
If we become aware that we have collected personal information from a child under 13 without appropriate parental consent, we will delete that information promptly. Please contact us at enquiries@throwha.com if you believe we have collected information from a child without consent.
SECTION 10Security Measures
We implement reasonable technical and organisational measures to protect your personal information from unauthorised access, loss, misuse, or disclosure. These measures include:
- Encryption of data in transit (TLS/HTTPS) and at rest;
- Hashed password storage (bcrypt or equivalent);
- Access controls limiting staff access to personal data to those who need it;
- Regular security reviews of our infrastructure;
- Secure, encrypted backups stored in geographically separated locations.
No system is completely secure. We cannot guarantee absolute security of information transmitted over the internet. You use the Platform at your own risk and are responsible for maintaining the security of your account credentials.
SECTION 11Notifiable Data Breaches
We are subject to the Notifiable Data Breaches (NDB) scheme under the Privacy Act 1988 (Cth). In the event of an eligible data breach — one that is likely to result in serious harm to any affected individual — we will:
- Assess the breach as quickly as possible (within 30 days of becoming aware);
- Notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as required by law;
- Take immediate steps to contain the breach and prevent further harm.
If you believe your account has been compromised, contact us immediately at enquiries@throwha.com.
SECTION 12Third-Party Links
The Platform may contain links to third-party websites. This Privacy Policy does not apply to those websites. We encourage you to review the privacy policies of any third-party sites you visit. We are not responsible for the privacy practices of third parties.
SECTION 13Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email and/or by posting a prominent notice on the Platform. The "Last updated" date at the top reflects the most recent revision.
Your continued use of the Platform after the effective date of any change constitutes acceptance of the revised policy.
SECTION 14Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our handling of your personal information, please contact us:
We aim to respond to all privacy enquiries within 30 days.