Privacy Policy
MoodCheck — Mood Systems Pty Ltd
Effective date: 23 July 2026 · Version 1.0
MoodCheck is a workplace wellbeing platform operated by Mood Systems Pty Ltd ("Mood Systems", "we", "us"), based in Adelaide, South Australia. This policy explains what information the platform handles, how we protect it, and the choices you have. We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
This policy covers the MoodCheck check-in experience, the administrator dashboard, and this website.
Anonymity comes first
MoodCheck is built so that employees can share how they're feeling without identifying themselves. If you complete a check-in, you do not create an account, you do not sign in, and you are never asked for your name, email address, or any other personal detail. This is not a setting — it is how the platform is architected, and it means that in most cases we could not identify who submitted a check-in even if we were asked to.
What we collect
If you complete a check-in (employees). We collect only the content of your check-in: your mood or emotion selections, your answers to the questions asked, any comment you choose to write, the time of submission, and whether you were on a mobile or desktop device. We do not collect or store your name, email address, phone number, account identifier, IP address, or location with your check-in.
Your browser stores a small random token that lets repeat check-ins from the same browser be grouped for data-quality purposes. This token is generated in your browser, contains no personal information, is not connected to any account or identity, and is deleted whenever you clear your browser storage.
One honest caution: the comment box is free text. We ask you not to include details that could identify you or others, because anything you write is part of your response. Comments are only ever reported to your organisation in aggregated, theme-level form.
If you are an administrator (People & Culture users). We collect your work email address, which is used to sign you in and operate your dashboard access. Sign-in is passwordless — we send a one-time link or code to your email, so we never store a password for you — and administrator accounts are protected by enforced multi-factor authentication.
If you visit this website. We do not run advertising, analytics, or tracking services.
How we use information
Check-in data is used to produce anonymised, aggregated wellbeing insights for the organisation running the campaign — participation levels, mood trends, and the themes appearing in comments. Individual responses are not shown to your employer, and nothing in the platform attributes a response to a person. Administrator details are used solely to provide and secure dashboard access. We do not sell personal information, and we do not use it for advertising.
AI-assisted theme analysis
Written comments are analysed by an artificial-intelligence model to identify themes (for example, workload, communication, or recognition). Only the text of the comment and our theme catalogue are sent for analysis — no identifiers accompany it, because none are collected. The analysis is performed server-side through a managed gateway on a pass-through basis: raw text is not retained by the gateway, only the resulting theme tags are stored by us, and we maintain a written opt-out preventing our data from being used to train AI models.
Who processes data on our behalf
We deliberately run MoodCheck on a small number of established providers: Supabase (managed database and authentication, on Amazon Web Services infrastructure), Cloudflare (application hosting, with no persistent data storage), Lovable (managed cloud platform and AI gateway), and Google (the AI model used for theme analysis, accessed via the gateway). These providers operate certified infrastructure (SOC 2 / ISO 27001) and process data only to deliver the service. Our infrastructure providers may process technical data such as IP addresses transiently in the course of delivering and securing the service; this technical data is not stored with check-in responses. We integrate no other analytics, email, marketing, or tracking services.
Where data is stored and how it is protected
All data is encrypted in transit (TLS 1.2+) and at rest (AES-256), with access controlled by row-level security enforced on every database table. Data is hosted on AWS infrastructure in the Asia-Pacific region; for Australian enterprise clients we deploy Australian-region hosting before their engagement data is collected. Where any personal information is handled outside Australia, we take reasonable steps consistent with APP 8 to ensure it is protected to the standards of the Australian Privacy Principles.
Retention and deletion
Check-in data is retained for the duration of the relevant organisation's engagement and deleted or returned on the organisation's written request, subject to any legal retention obligations. Administrator account details are deleted when access is no longer required. Because check-ins are anonymous, we are generally unable to locate or delete an individual employee's specific responses — we cannot identify which responses are yours. This is a deliberate privacy protection, not a limitation we can switch off.
Your rights
If we hold personal information that identifies you (in practice, administrator account details), you may request access to it or correction of it by contacting us. If you have a privacy question or complaint, contact us first and we will respond promptly; if you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (oaic.gov.au).
Contact: nathan@moodcheck.com.au
Changes to this policy
We update this policy when our practices change, and material changes are notified to client organisations. The current version and its effective date always appear at the top of this page.