Privacy Policy

How we handle your information

Effective date: 31 July 2026

Our promise in one line: we don’t sell, rent, share, or use your data — or your clients’ data — for AI training or anything else. Your privacy is taken seriously here.

1. Who we are

Nian Marketing Pty Ltd (ABN 80 149 763 093) (“we”, “us”, “our”) is the operator of the marketing website at voyj.app and the developer and operator of the Voyj Workbench Platform (“Voyj Workbench”).

The application submitted for Google OAuth verification is the Voyj Workbench app, hosted at workbench.voyj.app (the “Workbench Application”), which is one of the products operated by Nian Marketing Pty Ltd.

Our registered office is located in Brisbane, Queensland, Australia. We can be contacted at:

Nian Marketing Pty Ltd (ABN 80 149 763 093)
Email: privacy [at] voyj.app
Phone: 07 3732 4976
Postal: PO Box 3472, Norman Park QLD 4170, Australia

2. What this policy covers

This Privacy Policy explains how we handle personal information collected through:

  • the Voyj marketing website at voyj.app (including any enquiry, waitlist, or sign-up forms), and
  • the Voyj Workbench Platform, where subscribing career coaches (“coaches”) use Voyj Workbench to manage their own client records.

It applies to all personal information we collect, hold, use, and disclose. We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) contained in that Act.

3. The personal information we collect

Depending on how you interact with us, we may collect the following kinds of personal information:

  • Marketing website: your name, email address, optional phone number, and any message or enquiry details you choose to provide.
  • Voyj Workbench: the account and billing information of subscribing coaches, and the client records that a coach chooses to store within the platform (for example session notes, names and contact details of the coach’s own clients).
  • Technical data: standard server logs such as IP address, browser type, referring page, and timestamps, collected automatically for security, debugging, and abuse prevention.
  • Site metrics data: aggregated or pseudonymous usage data about how visitors use our marketing website, such as pages viewed, device type, browser type, and broad location information. We do not intentionally collect names, email addresses, message contents, or other directly identifying information through site metrics tools. The specific tool we use is described in section 11.

We do not knowingly collect personal information from anyone under the age of 16. If you believe we have done so, please contact us and we will delete it.

3A. Google user data we access (Gmail and Calendar)

When a subscribing coach connects their Google account to the Workbench Application, we request the minimum set of Google OAuth scopes needed to provide the email, calendar, and Google Meet features inside Workbench. The Voyj marketing website at voyj.app never accesses Google user data.

We request the following scopes, grouped by the Google service they unlock:

  • Gmail — gmail.modify: a single OAuth scope that grants read, send, and modify access to the coach’s Gmail account. We use it to display the coach’s inbox and message content inside Workbench (including message metadata such as From, To, Cc, Bcc, Subject, Date; threads; labels; and the body of messages the coach opens); to send emails from the coach’s address when the coach clicks send inside Workbench; and to compose drafts, apply labels, archive, delete, and otherwise manage messages on the coach’s behalf, and to attach message threads to a specific client’s record inside Workbench. We do not read the bytes of an attachment unless the coach explicitly opens or attaches that file inside Workbench.
  • Google Calendar — calendar.readonly: to display the coach’s calendar events inside Workbench, including event titles, descriptions, start and end times, time zones, attendees, organisers, locations, recurrence rules, reminders, and free/busy information.
  • Google Calendar — calendar.events: to create, update, and cancel events on the coach’s calendar (such as coaching sessions), and to send Google Calendar invitations to clients and other attendees.
  • Google Meet — calendar (admin-configured, default only): a broader calendar scope that, where enabled by the connected Google Workspace administrator, lets Workbench create and manage Google Meet video-meeting links attached to sessions scheduled in Workbench, and read or update the meeting details stored in the relevant Google Calendar. This scope also covers calendars shared with the coach that are needed for that Meet integration.
  • Google account — userinfo.email: to identify which Google account is connected to Workbench. Requested alongside the Calendar scopes; not requested when only Gmail scopes are in use.
  • Google account — userinfo.profile: to display the coach’s name and profile photo inside Workbench. Requested alongside the Calendar scopes; not requested when only Gmail scopes are in use.
  • Offline access (not a scope): by including access_type=offline and prompt=consent in the Google sign-in URL, we obtain a refresh token so that Workbench can keep calling the Gmail and Calendar APIs on the coach’s behalf without asking them to sign in again every time. Refresh tokens are stored encrypted at rest. How local tokens, synchronisation, imported records, and Google authorisation are handled when an integration is disconnected or permanently deleted is explained in section 7.

We do not request scopes for Google Drive, Contacts, YouTube, Maps, or any other Google product. The full list of scopes currently granted to Workbench is always visible — and revocable — at https://myaccount.google.com/permissions.

4. How we collect personal information

We collect personal information directly from you when you submit a form on our website, register for Voyj Workbench, or otherwise provide it to us in the course of using our services.

We also collect limited technical information automatically through your interaction with our website and platform. We use one analytics tool — Google Analytics 4 — to measure aggregate site traffic, as described in section 11. We do not use advertising trackers, and we do not use analytics to profile your behaviour across other sites.

Google user data is collected by exchanging OAuth tokens via Google after the coach explicitly connects their Google account inside the Workbench Application. We never read or request Google data from the Voyj marketing website at voyj.app, and we never read or request Google data until the coach clicks “Connect Google” inside Workbench and grants the requested scopes on the Google consent screen.

5. Why we collect it and how we use it

We only collect personal information that is reasonably necessary for, or directly related to, one or more of our functions or activities (APP 3). Specifically, we use personal information to:

  • respond to enquiries you submit through the marketing website and to contact you about those enquiries (for example, notifying you at launch, or following up on a question you have asked us);
  • provide, operate, secure, and improve the Voyj Workbench Platform and the services coaches deliver through it;
  • manage our relationship with subscribing coaches, including billing, support, and product updates;
  • measure and understand general website usage, performance, and content effectiveness using site metrics tools, without recording directly identifying personal information in those metrics;
  • detect and prevent fraud, abuse, and security incidents; and
  • comply with our legal obligations.

We will never use your personal information, or the personal information of your clients, to train, fine-tune, evaluate, or otherwise develop any artificial intelligence or machine-learning model. Not for our use, and not for anyone else’s. This commitment applies to all data collected through voyj.app and Voyj Workbench.

5A. How we use Google user data

Google user data accessed through the scopes listed in section 3A is used only to provide the email and calendar features inside the Workbench Application. Specifically:

  • Gmail: to display messages and threads inside Workbench so the coach can read, search, and triage their inbox without leaving the platform; to compose, send, reply to, label, archive, and delete messages on the coach’s behalf when the coach asks Workbench to do so; to attach message threads to a specific client’s record inside Workbench; and to match inbound mail against the coach’s existing client list so the right client record is updated.
  • Google Calendar: to list the coach’s events by day, week, or month inside Workbench; to create new events on the coach’s calendar (including coaching sessions); to send Google Calendar invitations to clients and other attendees; to update, cancel, or delete events created by Workbench; to detect scheduling conflicts with sessions stored in Workbench; and to surface “today’s events” to the coach at the start of the working day.
  • Google Meet (where the broader calendar scope is enabled by the connected Google Workspace administrator): to attach a Google Meet video link to a coaching session scheduled in Workbench, and to read or update the meeting details stored in the relevant Google Calendar.
  • OAuth tokens: to authenticate API calls to Google on the coach’s behalf. Tokens are never used to log into Google services as the coach outside Workbench, and never used to take actions the coach has not initiated inside Workbench.

We do not use Google user data for any other purpose. In particular, we do not use Google user data to train, fine-tune, evaluate, embed, or otherwise develop any artificial-intelligence or machine-learning model — ours or anyone else’s — and we do not transfer Google user data to any third party for any of those purposes. We do not use Google user data for targeted advertising, retargeted advertising, interest-based advertising, personalised advertising, user advertisements, audience profiling across services, building advertising databases, selling to data brokers, providing to information resellers, credit decisions, lending decisions, or any other commercial purpose unrelated to providing the Workbench Application to the coach who connected the account.

6. Disclosure to third parties

We take a strict, no-sharing approach. We do not sell, rent, trade, lease, or otherwise share personal information of our clients, or the personal information of their clients, with any third party — for marketing, advertising, data-brokerage, lead-generation, or any other purpose.

  • Service providers: we engage a small number of trusted service providers who help us operate the marketing website, the Voyj Workbench Platform, cloud hosting, and email delivery. These providers are bound by confidentiality and data-processing obligations and may only use personal information on our written instructions. The current list is: Google LLC (marketing-website analytics as described in section 11, governed by the Google Ads Data Processing Terms); our cloud-hosting provider; and our transactional-email provider.
  • Legal: where we are required or authorised by law, or where it is reasonably necessary to investigate or prevent a breach of law, we may disclose personal information to law enforcement, regulators, or courts.
  • Business transfers: if we sell, merge, or restructure part of our business, personal information may be transferred under protections no weaker than this Privacy Policy. You will be notified where lawful and practical.
  • Google user data: Google user data accessed via the scopes listed in section 3A is not sold, rented, leased, licensed, brokered, transferred, or otherwise shared with any third party, except to the small set of contracted subprocessors (cloud hosting and email/log delivery) that help us operate the Workbench Application. Those subprocessors are bound by written agreements that prohibit them from using the data for any purpose other than providing services to us, and they have no rights to use Google user data for their own purposes, including advertising, profiling, AI/ML training, or resale. This commitment is given in compliance with, and is not exceeded by, the Limited Use requirements of the Google API Services User Data Policy.

No selling. No renting. No sharing. No exceptions for marketing or advertising.

6A. Limited Use compliance

Our use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In plain language, this means:

  • We use Google user data only to provide the email and calendar features inside the Workbench Application, and for the purposes described in section 5A above.
  • We do not transfer Google user data to any third party except to subprocessors that help us operate Workbench, and only on the terms described in section 6.
  • We do not use Google user data for serving advertisements (including targeted, retargeted, interest-based, personalised, or user-to-user advertising), for building advertising profiles, for sale to data brokers or information resellers, for credit or lending decisions, or for training or improving any artificial-intelligence or machine-learning model.
  • We do not allow humans to read Google user data unless (a) the coach has opened or interacted with that data inside Workbench, (b) it is strictly necessary for a security investigation or abuse investigation that we have logged, or (c) we are required to do so by law.

7. Storage, security and retention

We take privacy and security seriously. Personal information is stored on systems that are protected by multiple layers of encryption, both in transit and at rest. Access to personal information is restricted to staff and contractors who genuinely need it to perform their work, and all such access is logged.

We retain personal information only for as long as reasonably needed for the purposes set out in this policy, after which it is securely deleted or de-identified, subject to legal, audit, accounting, security, fraud-prevention, and legal-claim obligations. In particular:

  • Marketing enquiries: kept until you ask us to delete them, or 24 months of inactivity, whichever is sooner.
  • Voyj Workbench organisation records: active contacts, cases, notes, emails, calendar events, files, recordings, and transcripts are retained while required by the organisation. There is no universal age-based deletion period for active organisation records.
  • Client portal account deletion: a client can schedule deletion from the client portal by typing the required confirmation phrase. The request has a seven-day cooling-off period and may be cancelled before processing begins. After that period, the client sign-in identity is deleted, the client account and linked contact records are sanitised, and client links are revoked. Removal of unshared files and stored artifacts is attempted as part of the deletion and may complete asynchronously. Deletion also revokes any other client portal access connected to the same contact record, so any other client sharing that contact will lose access to the shared record as part of this deletion. Records we are legally required to retain, or that are needed for audit, accounting, security, fraud prevention, or legal claims, may be retained only for that purpose.
  • Connected provider accounts: Disconnect stops synchronisation and removes local credentials and watches for the selected integration. It does not delete imported organisation business records, including emails, calendar events, contacts, cases, or notes. Permanent provider deletion is a separate action that removes provider account data and unshared attachments. Emails linked to CRM records may remain as organisation business records.
  • Google authorisation: when a Google integration is disconnected or permanently deleted, Voyj Workbench revokes the Google authorisation only if it was the final active Voyj Google integration for that Google account. Another active Voyj Google integration for the same Google account keeps the Google authorisation active for that integration. You may revoke Voyj Workbench access at any time through Google Account permissions.
  • Backups: application backup archives are deleted after 14 days. Database automated backups are retained for seven days.
  • Soft-deleted emails: permanently deleted after 30 days; because the cleanup runs monthly, deletion may occur up to about 60 days after soft deletion.

We do not publish detailed system architecture, infrastructure providers, or specific security controls, on the basis that doing so could assist attackers. We are happy to provide a summary of our security posture to verified customers on request.

8. Overseas disclosure

Some of our service providers may be located outside Australia. Where personal information is disclosed overseas, we take reasonable steps to ensure the recipient handles it in a manner consistent with the APPs. By using our services you consent to the overseas disclosure of personal information to providers located in countries where comparable safeguards apply, in accordance with APP 8.

9. Your rights

Subject to the APPs and the Privacy Act 1988, you have the right to:

  • request access to the personal information we hold about you (APP 12);
  • request correction of personal information that is inaccurate, out-of-date, incomplete, or misleading (APP 13);
  • request deletion of personal information we hold about you, where it is no longer required for the purposes for which it was collected;
  • opt out of receiving marketing communications from us at any time by using the unsubscribe link in our emails or contacting us directly;
  • disconnect a Google integration from the Workbench Application at any time. Disconnect stops synchronisation and removes local credentials and watches for that integration, but does not delete imported organisation business records. Google authorisation is revoked by Voyj Workbench only when the disconnected integration is the final active Voyj Google integration for that Google account. You can revoke Voyj Workbench access directly at https://myaccount.google.com/permissions at any time.

We will respond to a valid request within 30 days. There is no charge for making a request, although a reasonable fee may apply for manifestly unfounded or excessive requests. We may need to verify your identity before acting on a request. For step-by-step instructions on how to make a privacy or deletion request, see our Data Deletion and Privacy Requests page.

10. Complaints

If you have a concern about how we have handled your personal information, please contact us first using the details in section 13. We take complaints seriously and will respond within 30 days. If you are not satisfied with our response, you can lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at https://www.oaic.gov.au.

11. Cookies and online tracking

We use one analytics tool on the Voyj marketing website: Google Analytics 4 (GA4), supplied by Google LLC. GA4 sets a pseudonymous client identifier cookie so we can measure sessions and traffic sources in aggregate. We do not enable advertising features, Google signals, remarketing, audience building, or data sharing, and we do not collect names, email addresses, phone numbers, message contents, or client records through this tool.

The data GA4 collects from this website includes: the page URL, the page that referred you (for example, a search engine or social network), your country (derived from your IP address; we do not store the full IP), your device category, browser type, screen size, and the random client identifier described above. We use this data to measure general site performance only — how many people visit, from where, via which channels, on which devices, and which pages they read.

We do not enable Google signals, advertising features, remarketing, audience building, enhanced conversions, or data sharing in our GA4 property. We do not link GA4 to Google Ads or to Google Search Console. We do not send any custom data to GA4 from this website (no names, email addresses, phone numbers, message contents, or client records). GA4 data retention is set to the minimum period of 2 months in our GA4 admin settings.

Under the Privacy Act 1988 (Cth), analytics cookies of this kind do not require opt-in consent where their purpose is site measurement and the user is provided with clear disclosure under APP 5. We do not show a cookie banner. Our full disclosure under APP 5 is set out above and in sections 3, 4, and 5.

Voyj Workbench uses cookies and similar technologies only to keep you securely signed in to your account. These are strictly necessary for the service to work and are not used for tracking.

12. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or the law. The “Effective date” at the top of this page indicates when it was last revised. Material changes will be communicated by email to affected users and/or by a notice on voyj.app. Your continued use of our services after an updated policy takes effect constitutes acceptance of the revised policy.

13. How to contact us

For any privacy questions, access or correction requests, or complaints, please contact us at:

Nian Marketing Pty Ltd (ABN 80 149 763 093)
Email: privacy [at] voyj.app
Phone: 07 3732 4976
Postal: PO Box 3472, Norman Park QLD 4170, Australia

Have a question? Back to voyj.app

Be the first to know

Drop your email and we'll let you know the moment Voyj launches in July 2026.

Protected by reCAPTCHA. Privacy & Terms.

By submitting this form you agree to our Privacy Policy and Terms of Service . We will use the information you provide to contact you about your enquiry.