← Birdsong

Privacy policy

Last updated 29 July 2026

1. What this policy covers

This policy explains what personal information Birdsong collects, why, and what we do with it. Birdsong is business growth software built and run by Birdcage Group for local Australian businesses: leads and a customer record, bookings and quotes, marketing content drafts, an ad campaign planner, an AI coach, and a check on how visible a business is in AI answer engines. It sits alongside the Terms of Service.

Two different groups of people read this policy. If you are a business owner or team member with a Birdsong account, this is about your account and the data you put into it. If you are a customer, client or lead of a business that uses Birdsong (for example, you booked an appointment, asked for a quote, or filled in an enquiry form on that business’s website), you never signed up to Birdsong: the business you dealt with collected your details, and section 3 explains how Birdsong holds them on that business’s behalf.

2. What we collect

  • Account details: your email address, and a password if you use one (signing in with a magic link does not need one). If you belong to a business, we know which business or businesses.
  • Business details: your business name and industry, and the strategy, positioning and content you enter or that Birdsong drafts for you.
  • Your own customers’ details: names, emails and phone numbers of the people you serve, held in your customer record and inside the leads, bookings and quotes you create, whether you type them in yourself or they arrive automatically through your website’s enquiry form.
  • Marketing account data: if you connect a Facebook Page, Instagram account, Google or TikTok account under Connections, the name or email that identifies which account is connected, plus performance figures for the content and ads on it. Section 6 sets out exactly what those figures are.
  • Payment information: if you buy AI coaching credits or book a coach, Stripe collects your card details directly. Birdsong never sees or stores your card number, only that a payment was made and for how much.
  • Usage information: which pages and features you use, collected automatically so we can see how Birdsong is actually used.

3. Who is in charge of your information

If you run a business on Birdsong, you own your business’s data and your customers’ data. You decide what to collect, who to contact, and what to do with it. Birdsong is the software that stores and processes it for you, on your instructions: we do not decide how or from whom you collect information, and we do not use your customers’ details for our own purposes.

If you are a customer of a business that uses Birdsong, that business is who you gave your details to and who is responsible for that relationship. Birdsong holds the information on the business’s behalf, the way a filing cabinet holds paper. To have your details corrected or removed, ask the business directly, not Birdsong.

4. Where it is stored

Your account and business data lives in a Supabase database run in Sydney (ap-southeast-2). The Birdsong application itself runs on Vercel’s hosting.

Some information leaves Australia. When Birdsong drafts something for you, or checks how your business shows up in AI answer engines, the relevant text is sent to AI providers based overseas (see section 7). Stripe, Resend and Twilio, described below, are also based overseas. This is a disclosure of personal information outside Australia, which the Australian Privacy Principles require us to tell you about plainly: this is that notice.

5. Who else sees it

These are the providers Birdsong actually sends data to, and what each one does:

  • Supabase stores your data and runs the app’s database, in Sydney.
  • Vercel hosts the Birdsong application itself.
  • Stripe processes payment for AI coaching credits and coach bookings. If you connect your own Stripe account, your customers’ payments are charged on that account and paid to you directly, never held by Birdsong, and Birdsong takes a service fee on top of Stripe’s own fees. Because the charge is on your own account, it appears in your own Stripe dashboard and statements, so you are not relying on our word for any of it.
  • Resend sends transactional email, such as appointment reminders, on Birdsong’s behalf. Supabase separately sends the sign-in emails you would expect: confirming your address, magic links, and password resets.
  • Twilio sends appointment reminders by text message, on Birdsong’s behalf, where a booking has a mobile number and reminders are switched on. Twilio is based overseas, so a reminder sent this way includes your customer’s number and the reminder text leaving Australia (see section 4).
  • Anthropic (Claude) generates the drafts Birdsong writes for you: strategy, content ideas, ad copy, the scope of a quote, and AI coach replies. The AI-visibility check also puts the same questions to OpenAI (ChatGPT) and Google (Gemini), to see how each one answers.
  • Meta, Google and TikTok, only if you choose to connect your own account under Connections. Birdsong reads performance figures from those accounts so it can show them back to you. If you turn on conversion tracking, it also sends your completed sales back to your own advertising account, so the platform can tell which of your ads led to real money. It does not post, message anyone, or change your campaigns. Section 6 sets out what is read, what is sent, and what is not.
  • PostHog collects product usage data (pages viewed, features used) so we can see how Birdsong itself is used. It does not receive your customers’ details.

6. Marketing accounts you connect

Birdsong can connect to the marketing accounts your business already has, so you can see how your marketing is going next to what it brought in, without logging into four different places. Connecting is optional, you choose which accounts to connect, and you can disconnect any of them at any time.

What Birdsong reads. When you connect a Facebook Page or Instagram account, Birdsong reads the performance figures for that account and its posts: reach, impressions, views, likes, comment and share counts, saves, follower numbers, and the date and type of each post. When you connect an advertising account (Meta, Google or TikTok), it reads the campaign and ad names, the amount spent, impressions, clicks, results and cost per result. When you connect Google Search Console or Google Analytics, it reads the clicks, impressions, search positions and visit counts for your website.

What Birdsong does not read, and does not do. It does not read the personal details of the people who follow, like, comment on or click your posts and ads. It reads counts and totals, not the individuals behind them. It does not read your private messages, your friends or contacts, or anyone’s profile. It does not post or publish anything, comment, reply or message anyone, does not spend money on your behalf, and does not create or change your campaigns.

There is one thing Birdsong sends outward rather than reads, and it is set out in full below under Conversion tracking. Everything else in this section is read-only.

Why. These figures exist so Birdsong can show you what happened, and set it next to your own leads, appointments and revenue. That is the whole purpose. They are used only to produce that view for your business.

What we never do with it. We do not sell it. We do not share it with other businesses on Birdsong. We do not use it to advertise to you, and we do not run advertising of our own off the back of it. We do not combine it with data from other Birdsong businesses to build a profile of you or your customers. The one outward flow is conversion tracking, described next, and it goes only to your own advertising account.

6a. Conversion tracking

What it is. Advertising platforms decide who to show your ads to based on what you tell them is working. If the only thing they hear about is a form being submitted, they will find you more form-fillers, including the time-wasters. Conversion tracking tells your ad account when someone actually paid, so it can go looking for more people like the ones who pay. It is optional and off until you connect an advertising account and it is switched on.

What is sent, precisely. When one of your customers pays an invoice in Birdsong, we send a single event to your own advertising account containing: the amount and currency, the time, a reference to that payment, and match keys for the customer. Those match keys are their email address and phone number, converted to an irreversible SHA-256 fingerprint before they leave Birdsong. The platform can compare that fingerprint to one it already holds, but it cannot read the address or number back out of it. We never transmit the raw values. Where a payment has no linked customer, the event is not sent at all.

Where it goes.Only to the advertising account belonging to the business that authorised the connection. Never to another Birdsong business, never to a data broker, never to us for our own advertising. Each business’s conversions are kept entirely separate.

Who is responsible, and what that means for you. If you are a business using Birdsong, this is your customer’s personal information and you are the one responsible for it. Birdsong acts on your instruction. Before you switch conversion tracking on, make sure your own privacy notice tells your customers that you share data with advertising platforms for measurement, and that you have a lawful basis for doing so. If you are unsure, leave it off.

How to stop it. Disconnect the advertising account under Connections and no further conversions are sent. Events already delivered to the platform are held under that platform’s own terms, not ours, so ask them to remove those. To have a specific customer excluded, or to have their conversion history removed from Birdsong, email hello@birdcagegroup.com and we will action it and confirm when it is done.

How long we keep it, and how to remove it. Figures already collected are kept while the account stays connected, so you can see how things have changed over time. Disconnecting an account under Connections stops all further collection immediately, deletes the stored access token, and deletes the performance figures Birdsong collected from that account. Closing your Birdsong account (section 9) deletes them too, along with everything else. If you would rather ask us to delete them, email hello@birdcagegroup.com and we will action it and confirm when it is done.

Where a platform’s own terms give you rights over data held about you, those rights are unaffected by this policy. Meta Platform data handled by Birdsong is handled in line with Meta’s Platform Terms and Developer Policies.

7. AI and your information

When you use a Birdsong feature that drafts something (strategy, content ideas, ad copy, a quote, or the AI coach), the text involved, including, for a quote, your customer’s name and the words of their enquiry, is sent to Anthropic’s Claude to generate the draft. The AI-visibility check sends only questions about your business, not your customers’ details, to Claude, ChatGPT and Gemini, to see what each one says.

These providers process that content to generate a response; they are not shown your whole customer list, and Birdsong does not send customer data to them beyond what a specific drafting request needs. Everything they return is a draft: see the Terms of Service for what that means before you use it.

8. How long we keep it

We keep your account and business data for as long as your account is open. There is no fixed retention period or automatic deletion after a period of inactivity: closing your account is what deletes it (see below).

9. Getting your information out, and deleting it

You can download everything Birdsong holds for your business, including your customers’ names, emails and phone numbers, as a single file from Settings. Keep that file somewhere safe rather than emailing it around, since it carries your customers’ personal information.

You can close your account from Settings at any time. If you are the sole owner of a business, this permanently deletes that business and everything in it (leads, customers, bookings and quotes) and cannot be undone. If someone else also works in a business you own, you will need to remove them first, the same rule as in the Terms of Service.

10. Cookies and things like them

Signing in uses a small number of essential cookies: one to keep you signed in (set by Supabase), and one to remember which business you are currently viewing if you belong to more than one. Birdsong could not work without these.

PostHog, described above, uses its own cookie or local storage to tell your visits apart from anyone else’s, so we can see how the app is used.

11. Your rights under the Australian Privacy Principles

We handle personal information in line with the Australian Privacy Principles under the Privacy Act 1988 (Cth), rather than a European framework. If you have seen a GDPR privacy policy before, this is the Australian equivalent, not the same document.

You can ask to see what personal information we hold about you, or ask us to correct it. If you are a Birdsong account holder, Settings already gives you both of those directly: your data export and your account deletion, described in section 9. If you are a customer of a business that uses Birdsong and want your details corrected or removed, contact that business directly: they hold the relationship, and Birdsong acts on their instructions (see section 3).

12. Changes to this policy

Birdsong is under active development, so this policy will change as the product does. We will update the date at the top when it does.

13. Contact

Questions about this policy, or a request about your personal information: hello@birdcagegroup.com.