Donnı
Draft, pending legal review. This page explains our privacy policy and does not replace it.

Your data

How we look after your data.

Donni holds sensitive health information about the people you care for. Here is where it lives, who can see it, and what we do to keep it safe.

Stored on Australian servers
Only people you invite
Every change recorded
Never sold, never used for ads

Where your data lives

On Australian servers, in Sydney. That covers the database, file storage, backups and logs.

Backups let us restore the record to a point in time, and they stay in Australia too.

Who can see it

  • Only people the family invites.
  • Each person has their own sign-in and PIN.
  • Roles (admin, carer, medical professional) limit what each person sees.
  • Each family's record is kept separate inside the database itself, not just hidden on screen.
  • Emergency information shows only after sign-in. There is no public link to it.
  • Everyone accepts the user agreement before they can see anything. Saying no twice pauses their access until an admin reopens it.
  • A new phone or forgotten PIN needs a one-time code sent to the person's own email. Nobody else can sign in as them.

Doctors and specialists

  • They see only the report sections the family chooses.
  • They never see carers' names or the raw records.
  • The family's admins are told every time a report is exported.
  • Medication chart approval online saves time for everyone, and gives the care team confidence the right medications are being given.

Nothing is quietly changed

Every time someone adds, edits, unlocks or signs in, we record who, when and what changed, with the before and after. That gives families confidence the right information is being shared and the right decisions are being made.

  • Medication records and shift notes are locked once saved.
  • Corrections go through an admin and keep their history.
  • Records are voided, never deleted.

Emails and alerts

You control when you and your carers are notified, and about what. Alert emails never contain health details: they only say something needs attention, and the app shows the rest.

Security

No health data in logs

Not in logs, analytics, error reports or web addresses. App logs are deleted after 90 days.

Encrypted

In transit (HTTPS) and at rest.

Watched around the clock

Leading security monitoring watches our systems day and night and alerts us to anything unusual.

A record of every system change

Every change to our systems is recorded and kept for 7 years in protected storage in Australia, so it can always be checked.

Imported history

We provide templates for the app you're moving from, and can help with the move, so changing to Donni is easy for your family. Imported records are marked "Imported" and locked, and the family chooses whether they show in reports.

The AI summary (optional)

  • It is off unless your admin chooses to turn it on, with the guardian's consent.
  • It runs on Australian-based AI servers. Your data is not used to train AI.
  • Only facts the app has already worked out are sent, with the person's preferred first name and never carers' names.
  • The draft is labelled as AI-drafted and is not stored.

Your rights

You can ask for a copy of your data, ask us to correct it, or close your account. Email support@donni.com.au and we'll help.

Someone from our team reviews every request and replies within 30 days.

If something goes wrong, we follow Australia's Notifiable Data Breaches scheme and will tell affected families.

We never sell your data, and we do not use it for advertising. Read the full privacy policy (draft).

Last updated 8 October 2026.