Skip to content
AU NowSUPPORT
SupportGet helpSend feedbackPrivacyTerms

AU NOW: BREAKING NEWS

Privacy Policy

Version v1 / 9 September 2026

Version: v1

Published: 9 September 2026

Effective date: 9 September 2026

1. Who this policy covers

This policy explains how Varsha Raghav, an individual publisher, handles personal information through the AU Now mobile app, related application programming interfaces, support channels and protected administration tools. In this policy, “AU Now”, “we”, “us” and “our” refer to Varsha Raghav.

AU Now is a news discovery and community service. You can read news as a guest. An account is required for community participation.

This policy is designed around the Privacy Act 1988 (Cth) and the Australian Privacy Principles where they apply. It also explains practices that we follow as a matter of transparency even where a particular legal obligation may not apply to an individual operator.

This policy does not govern a publisher’s website or another service that you open from AU Now. Those services have their own privacy practices.

2. The short version

  • We create a random device identifier so guest reading, security, preferences and deletion can work without requiring an account.
  • If you choose a home area, we use the suburb, city, state, postcode and associated map coordinates to provide local news and information. The current app can also make a one-time approximate location suggestion from your IP address. It does not require continuous or background GPS access.
  • If you sign in with Google, we receive the Google identity and profile details described below and create an AU Now account linked to the device.
  • We record reading and interaction signals to operate, secure and personalise the service.
  • Comments and other enabled community content are processed for safety and moderation. Automated checks can reject, obscure or place content into review.
  • Push notifications are optional. Turning them off disables the active push token and news-alert preference for that device.
  • We use service providers for hosting, databases, caching, content delivery, authentication, push delivery, diagnostics, artificial intelligence and moderation. Some processing may occur outside Australia.
  • You can delete guest device data in Settings. Signed-in users can start account deletion in the app after fresh Google reauthentication.

3. Information we collect

What we collect depends on how you use AU Now.

Guest device, network and app information

On first use, AU Now creates a random device ID and a signed device token. These are not advertising IDs, but they can distinguish one installation from another. We also process timestamps such as creation and last-seen time.

When the app communicates with our services, hosting and security systems may process your IP address, request route, time, response status, device platform, app version or build, operating-system locale and technical error information. We use this information for delivery, rate limiting, security, troubleshooting and performance monitoring.

Home area and location information

You may choose or search for a suburb, city, postcode or state. We may store the selected home locality, city, state, postcode and coordinates associated with that place.

On a new installation, AU Now may send your IP address to BigDataCloud to suggest an approximate Australian area. This is optional bootstrap assistance; a failure does not prevent use of the app. Manual place search may send the place words you enter to our database or, for supported place searches, to OpenStreetMap’s Nominatim service.

When you request weather or local-condition features, the coordinates associated with the selected area may be sent to WeatherAPI.com or a relevant public-data provider. These coordinates normally describe the selected place, not continuous movement. The current app does not request continuous or background location access. If a later version requests device location permission, we will provide an in-app explanation and update this policy and the app-store disclosures first.

Account and profile information

If you choose Google Sign-In, Google supplies a verified account subject identifier and may supply your name, email address, email-verification status, given and family names, locale and profile image. We store the details returned by Google so we can create or restore your AU Now account, show your profile and secure account actions.

AU Now also stores an internal user ID, username, display name, avatar, city or state if set, account status, last-active time, a yes/no record that you confirmed you are at least 16, and the version of the Commenting Rules you accepted. We do not collect your date of birth through the current community-access flow.

Access and refresh credentials are stored on your device using the platform’s protected storage where available. The backend stores session-family records and hashed refresh-token values. Normal sign-out revokes the relevant session but keeps the separate guest device identity and its reading preferences.

Reading, search and preference activity

We may process or store:

  • article impressions, opens, reading time, shares and reactions;
  • hides, “show less” choices and source or category preferences;
  • bookmarks, likes, followed publishers, topics, cities and users;
  • selected language, home area and recommendation profile;
  • search words and result-page requests; and
  • aggregate popularity, feed, cache and recommendation signals.

Search terms used for trending suggestions are stored as aggregate, normalised terms in short-lived daily cache buckets and are not deliberately stored with a device ID in that feature. Request logs may still contain the requested URL or query.

We use these signals to remember choices, provide My Activity, rank stories, reduce repetition, improve local relevance, generate aggregate trends and understand whether the service works.

Community content and safety information

Depending on which community features are enabled, we process comments, replies, posts, post images, links or GIF references, follows, blocks and direct messages. Comments and posts intended for public areas can be seen, quoted, reported or shared by other people. Direct messages, if enabled, are not designed as end-to-end encrypted communications.

If you report content or an account, we store the report reason, optional details, relevant content or profile snapshot, reporter and target identifiers, time, review status and outcome. We also store moderation decisions, enforcement actions, appeals or support correspondence, and audit records needed to protect users and the integrity of the process.

Do not place sensitive personal information in public content or reports unless it is genuinely necessary. If you voluntarily include information about health, beliefs, ethnicity, sexuality, political opinions or another sensitive matter, it will be processed as part of hosting, moderation, reporting or responding to that content.

Push notifications

If you enable notifications, we process an Expo push token, platform, device and linked-account IDs where applicable, permission status, app version or build, language, locale, time zone, UTC offset, alert preference, quiet hours and prompt history.

We may record campaign, delivery, provider-ticket, receipt, failure, received, opened or dismissed events. These records help avoid duplicate sends, respect opt-outs and quiet hours, disable invalid tokens, measure delivery and investigate failures. Turning notifications off in AU Now deactivates the current device token and news-alert preference. You can also control notification permission in your phone settings.

Support and feedback

The current in-app feedback and support composer prepares text locally but does not yet transmit it to us. If you use our support website at https://support.californiawebgroup.com or contact support@californiawebgroup.com, we will receive the message, contact details you provide, account or device details needed to find the issue, and related correspondence. We will update the in-app notice before enabling a new transmission path.

Diagnostics and administration

Sentry is configured for mobile and backend error reporting, and New Relic is configured for backend application-performance monitoring. Depending on the event, diagnostic data may include crash stacks, error messages, app or service version, device or operating-system information, route, timing, performance measurements and identifiers needed to trace a failure. We do not intentionally place passwords, access tokens, raw push tokens or submitted community text into operational alerts.

The protected administration portal uses a strictly necessary secure session cookie and Cloudflare Access to authenticate authorised administrators. It is not a public behavioural-advertising cookie. External publisher pages opened from AU Now may set their own cookies or tracking technologies under their policies.

4. How we obtain information

We obtain information:

  • directly from you when you choose an area, change settings, create content, report, block, sign in or contact us;
  • from Google when you use Google Sign-In;
  • automatically from the app and backend when you read, search, interact, receive a notification or encounter an error;
  • from your device or platform when you grant notification permission or use a platform feature; and
  • from news publishers, public-data services and technical providers when they return article, image, location, weather, transport, traffic, emergency or school-zone information.

5. Why we use information and the choices involved

We use information where it is reasonably necessary to provide and secure AU Now, administer our relationship with you, comply with law, protect users, or pursue the ordinary operation and improvement of the service without overriding your rights.

In practical terms, we use it to:

  • deliver national and local news and related information;
  • maintain guest device and signed-in account sessions;
  • remember settings, bookmarks, follows and reading choices;
  • personalise and measure feeds;
  • operate comments and other enabled community features;
  • screen, investigate and enforce safety rules;
  • send notifications you have enabled and record their delivery or interaction;
  • answer requests and complaints;
  • prevent abuse, fraud, spam and unauthorised access;
  • diagnose crashes, latency and outages; and
  • meet legal, regulatory and record-keeping obligations.

You choose whether to sign in, select a home area, enable notifications, publish community content or contact support. Some processing is necessary for a requested function: for example, we cannot publish community content without account, age/rules and safety checks. Where consent is required, you may withdraw it for future processing, but that does not undo processing already lawfully completed or information that must be retained for a permitted reason.

6. Personalisation and automated processing

AU Now uses software rules and activity signals to rank stories, select local content, reduce repetition and build aggregate trends. It also uses artificial-intelligence services to summarise and translate publisher material. Article AI processing is based on source material and is not designed to receive your Google account profile or private reading identity.

Community text is checked against a safety policy by Groq’s moderation service before publication or update. The original submitted text is assessed before any deterministic profanity obscuring. Depending on the result, content may be allowed, automatically obscured, rejected, hidden or sent for normal or urgent review. If the moderation provider is unavailable or returns an invalid result, the current write path is designed to fail closed rather than publish unchecked content.

Automated systems can make mistakes. Reporting, blocking, human review and appeal channels remain important. These systems affect content ranking, publication or visibility; they are not used to make employment, credit, insurance or similar decisions about you.

7. Who processes or receives information

We do not currently sell or rent personal information. The current mobile build does not include an enabled programmatic advertising SDK. Advertising must not be activated without updating this policy, consent flows and app-store disclosures where required.

We disclose information only as needed for the purposes above, including to:

  • Supabase for the primary database and stored application records;
  • Upstash Redis for caching, short-lived seen/search signals, locks and operational state;
  • Google Cloud for the user-facing application service and Google Cloud Storage used for accepted community post images;
  • Hostinger for portable background workers and the protected administration service;
  • Cloudflare, including R2 and Access, for image delivery, network protection and protected administrator access;
  • Google for Google Sign-In and, where applicable, Android push delivery;
  • Expo and the relevant Apple or Google push service for push-token registration and notification delivery;
  • Sentry and New Relic for crash, error, performance and operational monitoring;
  • Groq for community-text safety classification;
  • configured article-processing providers, including Mistral models through DeepInfra or OpenRouter, for publisher-article enrichment or translation rather than account authentication;
  • BigDataCloud, OpenStreetMap Nominatim, WeatherAPI.com and relevant government or public-data providers for requested location and local-information features;
  • news publishers and their hosting or image providers when AU Now retrieves, displays or links to their material; and
  • limited operational alerting channels, including Telegram where configured, which receive incident metadata designed to exclude report text, reporter identity, screenshots and raw moderation scores.

We may also disclose information when reasonably necessary to comply with law, respond to a valid legal process, address a serious safety risk, investigate unlawful conduct, protect rights or operate a business transfer. A transfer does not authorise a recipient to ignore this policy or applicable law.

8. Overseas processing

Some providers operate global infrastructure or support teams. Personal information may therefore be processed or accessible outside Australia. The countries can change according to provider infrastructure and routing, and we do not make a claim about a country unless it has been verified.

Before publication, we will verify the material providers, their likely processing locations and the safeguards reasonably available. Where Australian Privacy Principle 8 applies, we will take reasonable steps required for overseas disclosures and recognise that we may remain accountable for the handling of personal information by an overseas recipient.

9. Advertising

Advertising presentation is disabled in the current pre-launch mobile build, and no AdMob SDK is installed. AU Now has backend support for direct advertising campaigns and related device-level eligibility, impression or click events, but those records are used only if an advertising feature is enabled.

Before enabling direct or programmatic advertising, we will identify the advertising providers and data uses, distinguish sponsored material, update this policy and the Apple and Google disclosures, and implement consent or tracking controls where required. This draft does not authorise undisclosed personalised advertising.

10. Retention

We keep information only for as long as it is reasonably needed for the purpose for which it was collected, to provide a feature you continue to use, to maintain security and audit integrity, or to meet legal, safety, accounting or dispute requirements. The period depends on the kind of information, its sensitivity, the risk of harm, whether it can be de-identified, and whether it is part of a public thread or safety record.

Examples from the current system include:

  • aggregate trending-search buckets expire after 48 hours;
  • some cache-only opened or impression signals expire after hours or days;
  • a signed-in account deletion request disables access and public visibility immediately and is scheduled for final identity detachment no earlier than seven days after the request;
  • deleted-comment structure may be retained as a no-identity tombstone so replies remain coherent; and
  • moderation, security, delivery and audit records may be retained where needed to investigate abuse, preserve the integrity of prior decisions, prevent repeat harm, resolve disputes or comply with law.

Backups and distributed caches may take additional time to cycle out. We will delete or de-identify personal information when it is no longer required for a permitted purpose.

11. Deleting an account or guest device

Guest device deletion

A guest can choose Delete this device’s data in Settings. The backend verifies the current device, refuses the guest route if the device is linked to an account, removes device-owned preferences and activity through database deletion or cascading relationships, deactivates its push data, clears associated cache state, and creates a fresh anonymous device identity after local data is cleared.

Signed-in account deletion

A signed-in user can start deletion in the app. The flow requires fresh Google reauthentication and an explicit DELETE confirmation. The request immediately revokes account sessions and push access, removes the public profile presentation, hides authored comments and posts, removes post image references, replaces sent direct-message text where that feature exists, and removes user-follow relationships. After the waiting period, the Google identity link and device-account link are detached.

The system retains a tombstoned account row and may retain moderation, safety, fraud-prevention, audit or dispute records. Information required by law may also be retained. The final treatment of stored Google profile claims and underlying uploaded image objects must be confirmed before this draft is published; the policy must be updated if the production deletion behaviour differs.

An account-deletion assistance path outside the app is available at https://support.californiawebgroup.com/account-deletion.

12. Access, correction and privacy complaints

You may ask to access personal information we hold about you or ask us to correct information that is inaccurate, out of date, incomplete, irrelevant or misleading. Some profile details are refreshed from Google when you sign in. You can change certain settings, notification preferences and home-area information in the app.

Send access, correction or privacy requests to support@californiawebgroup.com or use https://support.californiawebgroup.com. We may need enough information to verify that the request concerns you. We will respond within a reasonable period and explain any lawful reason why we cannot provide access or make a requested correction.

If you believe we have mishandled personal information, contact us first with enough detail to investigate. If you are not satisfied with our response and the Privacy Act applies, you may be able to complain to the Office of the Australian Information Commissioner at https://www.oaic.gov.au/privacy/privacy-complaints.

13. Children and community participation

AU Now is a general news service and is not designed as a children’s service. People may read news as guests without creating an account. You must be at least 16 to use comments or other community features. The current flow records a self-confirmed 16+ status rather than collecting a birth date.

Do not post personal information about a child or content that exploits, sexualises, grooms or endangers a child. We may restrict content or accounts and escalate serious safety concerns where appropriate. If you believe a child is in immediate danger, call 000. AU Now reports are not an emergency service.

If you believe a person under 16 has created an account or supplied personal information through community features, contact support@californiawebgroup.com.

14. Security

We use safeguards including signed device and account tokens, protected device storage, hashed refresh-token records, access controls, role-based database access, rate limits, restricted administration routes, monitoring and audit records. Providers and external networks remain separate systems, and no security measure can guarantee that information will never be lost, misused or accessed without authority.

If you believe your account or information has been compromised, contact support@californiawebgroup.com.

15. Changes to this policy

We may update this policy when AU Now’s features, providers or legal obligations change. We will publish the updated version and effective date. If a change materially affects how we use personal information, we will provide additional notice or seek consent where required. A materially new Commenting Rules version is handled separately and may require acceptance before further community participation.

16. Contact

Operator: Varsha Raghav

Operator location: Ahmedabad, Gujarat, India

Privacy email: support@californiawebgroup.com

Support: https://support.californiawebgroup.com

Support email: support@californiawebgroup.com

AU Now: Breaking News / Delete account / Privacy Policy / Terms of Use / Commenting Rules

Support messages are delivered by email and are not stored by this site.