Skip to content

CoreBridge Intelligence

Privacy policy

This policy says what personal information we collect, why, where it goes and how long we keep it. It also says how to see, correct or remove what we hold about you.

Takes effect 6 October 2026

1.This policy covers everything we run under the CoreBridge Intelligence name.

CoreBridge Intelligence and CoreBridge Advisory are business names of ACN 690 076 101 Pty Ltd (ABN 25 690 076 101), based in Melbourne, Victoria, Australia. In this policy, "we", "us" and "our" mean that company.

The policy covers:

  • the public website at corebridgeintelligence.com, including the free dashboards, which anyone can use without signing in;
  • the Executive Edition at corebridgeintelligence.com/executive-edition/, a subscription service for named seats;
  • the emails we send, and the records we keep to follow up with people and organisations we work with or hope to work with.

It does not cover CoreBridge Advisory’s consulting work for clients. That work runs under each client’s own engagement terms.

2.We follow the Australian Privacy Principles, and UK law where it applies.

We handle personal information under the Privacy Act 1988 (Cth) and the Australian Privacy Principles.

Some of our readers are in the United Kingdom. Where UK data protection law applies to them, the section near the end of this policy, headed for UK readers, explains their extra rights.

3.Anyone can use the public site and free dashboards without telling us who they are.

You do not need an account to read the public site or the free dashboards. We do not ask for your name or email address to use them.

If you accept analytics in the cookie banner, we record each page view against a random browser number held in a cookie called cb_uid. Each record holds:

  • the page and section you opened, and the time;
  • the page you came from (the referrer), cut to 160 characters;
  • the country your connection comes from, as worked out by Cloudflare, our host;
  • the name and number of the network you connect through. On a campus that is usually the institution or AARNet. At home it is usually your internet provider. It never names you;
  • the first 80 characters of your browser’s user agent, which says what browser and device type you use.

We do not store your IP address in these records.

If you decline, or do not answer, we record no page views for your browser. We do add one to a daily count of how many people accepted or declined on each site. That count holds no cookie, no address and nothing about you.

Cloudflare also counts page views on every page of the public site through its Web Analytics service, without setting a cookie.

To protect the sign-in, trial request and demonstration request forms from abuse, we hold the IP address that sent each request in a short-lived counter. Those counters are deleted after seven days.

4.When you ask for a trial or a demonstration, we keep the details you give us.

The trial and demonstration forms ask for your name, email address, organisation, role and, on the demonstration form, your sector and a question. We keep what you enter so we can reply, set up access and follow up. We may also add you to our sales records, described below.

5.If you hold a seat, we keep what we need to let you in and run the service.

An organisation that licenses the Executive Edition, or our own team, gives us the name, email address and position of each person who holds a seat. We keep those details, which organisation the seat belongs to, and when access starts and ends. For a trial, we also record when you first signed in, because the trial clock starts then.

There are no passwords. You sign in one of four ways:

  • a six-digit code we email to you. We store only a scrambled form (a hash) of the code. It expires after ten minutes and stops working after five wrong tries;
  • a one-time sign-in link in an email. We store only a hash of it. A link in a welcome email lasts seven days and one you ask for lasts a day. Each works once;
  • Sign in with Microsoft or Sign in with Google. See the next section.

When you sign in, we open a session. We store it on our server with the time it started and was last used, a hash of your IP address and the first 200 characters of your browser’s user agent. A session lasts 30 days from its last use and never more than 90 days from sign-in. It ends straight away if you sign out, or if your seat is suspended, released or ends.

We treat the hash of your IP address as personal information. A hash hides the address, but an IP address can be recovered from its hash with enough effort.

Our service log records events on each seat: sign-ins, failed sign-in attempts, the data sets your seat loads, trial starts and ends, and the start of each AI question (see below). We use it to secure the product, to protect the licensed content and to answer questions about who had access and when.

If you have accepted analytics, the page views described above are also linked to your seat while you are signed in. If you have declined, they are not.

6.Signing in with Microsoft or Google shares your name and email address, and nothing else is read.

If you choose Sign in with Microsoft or Sign in with Google, you sign in on Microsoft’s or Google’s own page. We ask for three permissions only: openid, email and profile. Microsoft or Google then tells us your name, your email address and an account identifier.

We use only the email address. We use it to find the seat it belongs to. We accept a Google address only where Google says it is verified. We accept a Microsoft address only where Microsoft says the organisation that owns the domain has verified it.

We do not store your name or account identifier from Microsoft or Google. We do not keep the access tokens they issue. We never read your email, calendar, contacts, files or any other account data.

Having a Microsoft or Google account does not give you access. The email address must already hold a seat. If it does not, we record the address and the attempt in our service log, as we do for the other sign-in methods.

7.If you try to sign in without a seat, we may contact you about getting one.

When someone enters an email address that holds no seat, we record the address and the time. Our team may add it to our sales records and get in touch to ask whether you would like access. If you do not want that, tell us and we will not contact you.

8.Questions to the AI assistant are sent to Anthropic to write the answer.

The Executive Edition has an Ask box and an assistant called Rosie. Both are AI. When you ask a question, we send these to Anthropic’s Claude model through Anthropic’s API:

  • your question;
  • up to four of your earlier questions in the same session on that page, each with a short summary of its answer;
  • the figures from the Edition that the answer needs.

We do not send your name or email address with the question.

We keep the first 120 characters of each question in our service log, against your seat. We do not keep the answer. If you press thumbs up or thumbs down on an answer, we record which, and the page, but not the question or the answer.

Anthropic processes the question in order to answer it. Do not type confidential or personal information into the Ask box or to Rosie.

The talking avatar. If you start a spoken conversation with Rosie, the video and voice run on a service called LiveAvatar. It hears what you say in order to reply. We delete the transcript of each spoken session from LiveAvatar when the session stops, and again at your next session in case a closed window did not tell us.

AI writes the answers. AI does not make decisions about you. Whether you can sign in, and what you can see, is set by your seat and its dates, not by AI.

9.If you write to us through the help channel, your message comes to our inbox.

The Executive Edition lets you send a question, a problem, a possible data error or an idea to a person. We send your name, email address, message, the page you were on and your seat to our team by email. Our service log keeps the page and your email address.

10.We record whether our emails arrive, and you can stop them at any time.

We send sign-in codes and links, welcome emails, trial emails, a single reminder four days after access opens if you have not yet signed in, and a monthly brief to people on its list. Trial emails are also copied to our own team so we can see what was sent.

Our email provider, Resend, tells us whether each email was delivered, opened, clicked, bounced or marked as spam. We keep those events with your address and the subject line. Our emails say so in the footer.

Every email that is not part of signing in carries an unsubscribe link. If you use it, or ask us, we add your address to a do-not-email list. We keep that list so we never email you again by mistake.

11.We keep sales and relationship records about people we work with or hope to work with.

Like most businesses that sell to organisations, we keep records to manage our relationships. For each person they can hold a name, role, organisation, work email address, phone number, LinkedIn page and notes of our calls, meetings and emails. They also record product events, such as when a trial started or a seat signed in.

We collect these details from you, from the person who introduced us, from your public professional profiles, from events, from our own correspondence with you, and from the sign-in attempts and forms described above.

Our analytics show the names of networks that read the site. We use those as a sign that an institution is interested. They never tell us who you are.

These records are seen by our team and by the sales partners who work with us under written agreements. We do not sell them, and we do not share them for anyone else’s marketing.

12.Journalist seats are kept out of sales use.

Working journalists can hold a free press seat. For those seats we keep the journalist’s name, outlet, role, beat, email address, country and the public profile we found them through. Their reading is not used as a sales lead, not reported to anyone and not shared with any institution.

13.We use cookies to sign you in and, only if you agree, to count page views.

These are the cookies our own systems set:

CookieWhat it is forHow long it lasts
__Host-cbi_sessionKeeps you signed in. Holds a random session number and nothing else. Essential.30 days from last use, never past 90 days
__Secure-cbi_edgeThe same session number, so the Edition’s pages can check you are signed in. Essential.As above
cbi_oauthHolds security values while you sign in with Microsoft or Google. Essential.10 minutes
cbi_welcomeMarks your first sign-in so the welcome tour runs once.1 day
cbi_signinHolds the time you signed in so a welcome film plays once per sign-in. No identity.10 minutes
cb_consentRemembers whether you accepted or declined analytics.365 days
cb_uidA random browser number for analytics. Set only if you accept.395 days
CF_AuthorizationSet by Cloudflare Access for our own staff in the admin area only.8 hours

The Edition also keeps small items in your browser’s own storage, such as which welcome film this device has already played. Cloudflare, our host, may set its own security cookies to tell people from automated traffic.

The cookie banner appears on the free dashboards and in the Executive Edition, the only places page views are counted against a cookie. You can change your choice at any time with the cookie link at the bottom of those pages. Declining changes nothing about what you can use.

14.We use personal information only to run, protect, improve and sell the service.

  • to sign you in, check your seat and end access when it ends;
  • to protect the service and its licensed content from misuse;
  • to answer your questions, including through the AI assistant;
  • to send the emails described above;
  • to understand which parts of the site get used, so we can improve them;
  • to follow up with people and organisations about trials, licences and renewals;
  • to manage each organisation’s licence, including how many of its seats are in use.

We do not sell personal information. We do not use it for advertising, and we do not allow advertising networks on our sites.

15.A small number of service providers handle data for us, some of them overseas.

ProviderWhat it does for usWhere
CloudflareHosts the site and the service, runs our database and file storage, counts page views, and guards the admin area.Global network
Resend, sending through Amazon SESSends our emails and reports delivery, opens and bounces.Resend: United States . Sending: Amazon’s Tokyo region, Japan
AnthropicWrites AI answers to questions.United States
LiveAvatarRuns Rosie’s spoken video conversations.Outside Australia
Microsoft and GoogleConfirm who you are, only if you choose to sign in with them.Global

Because some of these providers are outside Australia, your information may be held or processed in the United States, Japan and other countries where they operate. We choose providers that protect data to a standard we judge comparable to the Australian Privacy Principles.

We may also share information with our professional advisers, or where the law requires it.

16.We protect personal information with design choices as well as technical controls.

  • There are no passwords to steal. Sign-in codes and links are stored only as hashes and work once.
  • Sessions are held on our server, so we can end one straight away.
  • Our admin area sits behind Cloudflare Access as well as our own sign-in.
  • Every grant, change or removal of access is written to a log with the person who made it.
  • All traffic is encrypted in transit.

No system is perfectly secure. If a data breach is likely to cause you serious harm, we will tell you and the Office of the Australian Information Commissioner as the law requires.

17.We delete short-lived data automatically and keep other records only as long as we need them.

RecordHow long we keep it
Sign-in codesDeleted after they expire (ten minutes), in a nightly clean-up
SessionsDeleted when they end
IP addresses in abuse countersDeleted after seven days
Spoken avatar transcripts at LiveAvatarDeleted when the session stops
Page-view records26 months
Service log2 years
Email delivery records2 years
Sales and relationship records3 years after our last contact with you
Do-not-email listKept, so we never email you again

When we remove a person’s seat, we delete their account record and unlink their past page views, which stay only as anonymous counts.

18.You can see, correct or remove what we hold about you.

Email benjie@corebridgeintelligence.com to:

  • ask for a copy of the personal information we hold about you;
  • correct anything that is wrong;
  • ask us to delete your details or stop contacting you;
  • ask a question or make a complaint about how we handle your information.

We may need to confirm who you are first. We aim to reply within 30 days. We will tell you if we cannot do what you ask, and why.

If you are not satisfied with our reply, or we have not replied within 30 days, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au or on 1300 363 992.

19.Readers in the United Kingdom have further rights under UK law.

If UK data protection law applies to you, ACN 690 076 101 Pty Ltd (ABN 25 690 076 101) is the controller of your personal data. You have the right to access your data, correct it, have it erased, restrict or object to its use, and receive it in a portable form. You can withdraw consent at any time where we rely on it.

We rely on these legal bases:

  • contract, to provide a seat to you or your organisation;
  • legitimate interests, to secure the service and to follow up with people at organisations we work with or hope to work with;
  • consent, for analytics cookies and for marketing email where the law requires it.

You can complain to the Information Commissioner’s Office at ico.org.uk. We would like the chance to fix the problem first, so please contact us.

20.The service is for adults working in and around tertiary education.

Our sites are not directed at children, and we do not knowingly collect information from anyone under 18.

21.We will tell you when this policy changes.

We will post any change on this page with a new date. If a change matters to people who hold seats, we will also email them.

22.Contact us about privacy at any time.

Privacy contact: Benjie, benjie@corebridgeintelligence.com

ACN 690 076 101 Pty Ltd (ABN 25 690 076 101), trading as CoreBridge Intelligence and CoreBridge Advisory, Melbourne, Victoria, Australia.

See also our terms of use.