Legal

Privacy Policy

How Bimble collects, uses, stores, and protects your personal and health information.

Last updated 12 July 2026

1. About this policy and about us

Bimble is a digital health platform that connects patients with allied health professionals. It comprises a mobile application (the Bimble App), a web portal used by registered health practitioners (the Provider Portal), and the marketing website at bimble.health (together, the Platform).

In this Policy, we, us and Bimble mean Bimble Health Services Pty Ltd (ACN 696 487 895), which operates the Platform. You means any individual whose personal information we handle, whether you use the Bimble App as a patient, use the Provider Portal as a practitioner, or interact with our website.

This Policy explains what personal information we collect, why we collect it, how we hold and protect it, when we disclose it, and the choices and rights you have. We handle your personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), and (because we handle health information) the additional protections that apply to sensitive information.

An important distinction. Unlike traditional practice-management software that a clinic operates on its own patients' records, Bimble collects health information directly from you when you create your own account, and puts you in direct control of who may access it. This means Bimble is responsible to you as the entity that collects and holds your information, not merely as a vendor to a clinic.

2. Your consent to collect health information

Health information is a special category of sensitive information under the Privacy Act. Under APP 3, we only collect it with your consent and where it is reasonably necessary for the Platform's functions.

When you create a Bimble account and choose to record health information, you consent to us collecting and handling that information as described in this Policy. Health tracking in the Bimble App is opt-in for each category: nothing in categories such as meals, glucose, menstrual cycle, sleep, weight, vitals or mood is collected unless you switch that category on. If you never enable a category, no data of that kind is created or stored, encrypted or otherwise.

You can withdraw consent at any time by disabling a tracking category, deleting the tracking data you have recorded, or revoking a provider's access (see sections 8 and 10). Withdrawing consent may mean we can no longer provide some features to you.

There is an important exception. Where a health professional has been involved in your care through the Platform (for example, a telehealth consultation, referral or clinical note), the record of that care cannot be withdrawn or erased on request. Health-records law requires these records to be retained for a minimum period (see section 11), and we are obliged to keep them for that time regardless of any withdrawal of consent.

3. What personal information we collect

3.1 Patient information

Depending on which features you use, we may collect:

  • Identity and contact details: your name, gender, date of birth, mobile number and email.

  • Health information you record or upload: this depends on which features you use and may include, for example, medications and dose history; pathology reports and uploaded documents; appointments, bookings and referrals; telehealth session records, chat messages, provider notes, transcripts and AI-generated summaries; and health-tracking categories you opt into (such as meals, water, weight, vitals, blood glucose, wellbeing/mood, sleep, exercise, menstrual cycle, body temperature and respiratory readings). As we add features, the categories of health information you can record may grow; any new category is handled in accordance with this Policy, and health tracking always remains opt-in.

  • Family member profiles: where you add a family member (including a child), the information you record about them, held under your account (see section 9).

  • Payment references: a Stripe customer identifier and subscription status. We do not store card numbers, CVVs or bank account details (see section 6).

  • Technical and device data: device push-notification tokens and information needed to deliver notifications and operate the App securely.

3.2 Provider Portal information (practitioners, clinics and clinic staff)

Practitioners and clinics use a single web application, the Provider Portal. What we collect depends on your role.

If you are a registered health practitioner, we collect your name, title and email; your AHPRA registration number and ABN; your availability; payout references (a Stripe Connect account identifier and invoice records); and the credentials used to secure your account, including your password (which is stored only in hashed form) and the encrypted data needed to operate your multi-factor authentication.

For a clinic, we collect information about the clinic as a business, including its name, ABN, locations, rooms and resources, and its list of members. We verify the clinic's ABN against the Australian Business Register.

If you are a member of clinic staff who is not a registered health practitioner (for example, reception or a practice manager), we collect your name, contact details, your role at the clinic, and the credentials used to secure your account (including your password, stored only in hashed form, and any multi-factor authentication data, held encrypted). What you can see and do in the Provider Portal is limited to what your role requires.

Where you use the Provider Portal as part of a clinic, the patient health information you handle is held by Bimble and protected in the same way as for any other user of the Platform (see section 8 on consent, and section 8.3).

3.3 Information we do not collect or store

We do not store payment card numbers or bank details; these are held by our payment processors. We do not store your health information in plain readable form: every health field listed above is encrypted before it is written to our database (see section 7). We do not collect your location history; the App's optional clinic check-in feature is described in section 5.4.

4. How we collect your information

We collect most information directly from you: when you register, record health data, book or attend a consultation, or contact support. We verify practitioners' professional details against public registers: AHPRA registration numbers against the AHPRA register, and ABNs against the Australian Business Register. Where you connect an external service (for example, calendar sync, or, once available, My Health Record), we collect information from that service with your authorisation. We may also collect limited technical information through our website; see section 12 on cookies.

5. Why we use your information

5.1 To provide the Platform

We use your information to create and secure your account; to let you record and manage your health information; to enable bookings, referrals and telehealth consultations; to process payments; and to send you appointment reminders and service notifications.

5.2 Artificial intelligence features

Some features use AI to help you and your practitioners work with information you have already provided, such as extracting structured data from a pathology report you upload, scanning a meal photo you take, or summarising a telehealth session. These features run on Amazon Web Services (AWS Bedrock) and process your data transiently to generate the output; the underlying model does not retain your data or use it to train itself.

AI features are administrative and record-keeping aids only. Bimble's AI features log, organise and summarise information you provide. They do not diagnose conditions, make clinical recommendations, or predict health outcomes. Any clinical decision is made by a qualified health practitioner, not by Bimble.

5.3 Telehealth

Telehealth video and audio are carried over an encrypted connection (AWS Chime) and are not recorded or stored as media. Where you and your practitioner use session transcription or summaries, the resulting text is stored in your record as encrypted health information and treated like any other health data under this Policy.

5.4 Optional clinic check-in (location)

If you enable automatic check-in, the App detects when you arrive at a clinic and marks you as arrived. This detection happens entirely on your device. Your GPS coordinates are never transmitted to or stored by Bimble; only the check-in event itself (which appointment, which clinic, and the time) is sent. The feature is off unless you turn it on, and you can disable it at any time without affecting other features.

5.5 Marketing and service communications

We send different kinds of messages, and you can control most of them.

Service notifications support your use of the Platform, such as appointment reminders, running-late alerts, and follow-up prompts. You can turn many of these on or off, and choose how you receive them (push or SMS), in the Bimble App's notification settings.

Essential messages are a small set we need to send while you hold an account, such as security and account notices and confirmations directly tied to your care (for example, an appointment confirmation or a message from a provider involved in your care). Because these are part of providing the Platform safely, they cannot be switched off while your account is active.

Optional updates about Bimble are marketing. You can opt out of these at any time using the unsubscribe mechanism in the message, by replying STOP to an SMS, or in your notification settings. Opting out of marketing does not affect your service notifications or essential messages. We handle electronic marketing in accordance with the Spam Act 2003 (Cth).

6. Payments

Payments for consultations and services are processed by Stripe, and subscriptions by RevenueCat. Practitioner payouts use Stripe Connect. When you make a payment, your card details are collected and held by the payment processor under their own security standards (including PCI-DSS); they pass through the processor, not through Bimble. We retain only a non-sensitive reference (such as a Stripe customer ID) so we can match a payment to your account. No health information is shared with payment processors.

7. How we protect your information

Protecting health information is central to how the Platform is built. Our key measures are:

  • Encryption of health data at rest. Every health field is encrypted using AES-256-GCM before it is written to our database. We use envelope encryption backed by AWS Key Management Service (KMS): each user has their own data encryption key, and the master key never leaves AWS KMS and cannot be exported by our staff. A database breach alone would yield only unreadable ciphertext.

  • Encryption in transit. All communication between the apps, our servers, our database and our cache is protected with TLS.

  • Strong authentication. Patients sign in using one-time SMS codes (no passwords to be stolen). Practitioners use email, password and mandatory multi-factor authentication. Patient and practitioner sign-ins are handled by separate systems.

  • Access control and least privilege. A practitioner can only access a patient's data where the patient has granted consent, checked on every single request (see section 8). Internal access to systems is restricted and logged.

  • Independent assurance. We use continuous security monitoring and are undergoing a SOC 2 examination of our security controls.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security; but we take reasonable steps, appropriate to the sensitivity of health information, to protect it. If a data breach likely to cause serious harm occurs, we will respond in accordance with the Notifiable Data Breaches scheme under the Privacy Act, including notifying affected individuals and the Office of the Australian Information Commissioner (OAIC) where required.

8. Who can access your health information, and your consent controls

You decide which practitioners and clinics can see your health information. No practitioner can access any of your data unless access has been granted, and we check that access on every request, so in almost all cases revoking it takes effect immediately, on the next request. The exception is continuity of care: where a practitioner is actively treating you, they may need continued access for a limited period to complete that care safely (for example, to review results or follow up after a consultation). This is described below. It is bounded in time, does not widen the categories you have shared, and is always visible to you.

8.1 How access is granted

Type of access

How it is created

How it ends

Manual grant

You grant a specific practitioner or clinic access from the App.

You revoke it at any time.

Booking access

Created automatically when you book a consultation, so the practitioner has context.

Expires with the booking window; ending the booking ends the access.

Preferred provider

You convert a temporary booking access to ongoing access after a consultation.

You revoke it at any time.

Continuity of care. A practitioner who is treating you has professional and legal obligations to provide safe, complete care, which can include following up after a consultation, for example to review results, act on an abnormal finding, or arrange ongoing treatment. So that they can meet those obligations, a practitioner treating you under a booking may extend that booking-linked access for a limited further period. This extension does not create access to categories you have not shared, and it does not let a practitioner obtain access to a patient they are not treating. Any extension is shown to you in the App alongside your other access grants. You can end a manual or ongoing grant at any time; however, while a practitioner is completing an active episode of care, we may keep their access in place for the limited duration needed to do so safely, in the same way that access created for a booking cannot be cut off mid-consultation. If you are concerned about a specific practitioner's access, contact us (see section 16) and we will work with you and the practitioner to resolve it.

8.2 Limiting what you share

By default, a practitioner you grant access to can see all of your opted-in categories. You can narrow this for any individual practitioner or clinic (for example, sharing pathology and medications but excluding wellbeing and menstrual-cycle data) from the App's data-access screen, at any time. Restricting categories may affect a practitioner's ability to provide some services.

8.3 Grant to an individual or a clinic

You can grant access to a single practitioner, or to a clinic (so the practitioners and authorised staff at that practice who are involved in your care can see the categories you have shared). We only allow active, AHPRA-verified practitioners and active clinics to receive access.

Granting a clinic access does not change who is responsible for your information. Bimble remains the entity that holds and protects your health information; the clinic and its staff can view the categories you have shared, for the purpose of providing your care, but the information continues to be held and secured by Bimble under this Policy.

8.4 A record of your consent decisions

When you revoke consent we retain a record that the grant existed and was revoked (we do not simply erase it), so that there is an accurate audit trail of who could access your information and when. This record is kept to meet our accountability and regulatory obligations.

9. Who else we share information with, and overseas storage

We do not sell your personal information. Besides the practitioners and clinics you authorise, we share information only with service providers that help us run the Platform, and only as needed for them to perform their function. Our key providers are:

Provider

Purpose

Health data involved

Amazon Web Services (AWS)

Cloud hosting, encryption key management (KMS), storage, telehealth media, notifications, email, AI processing

Yes, encrypted; AI processing is transient

MongoDB Atlas

Primary database

Yes, sensitive fields encrypted

Stripe / Stripe Connect

Payments and practitioner payouts

No

RevenueCat

Subscription management

No

HubSpot

Customer relationship management and waitlist, used for our sales and marketing to practitioners and clinics and for general enquiries and waitlist sign-ups

No

We do not share patient health information with HubSpot. It holds contact details and enquiry or waitlist information for practitioners, clinics and people who ask to hear from us, so that we can respond and manage those relationships.

Our primary data hosting for the Platform (AWS and MongoDB Atlas) is located in Australia (the Sydney region), and our customer-relationship and waitlist provider (HubSpot) also hosts its data in Australia. Some service providers may nonetheless process limited information outside Australia in the course of providing their service. Where we disclose personal information to an overseas recipient, we take reasonable steps under APP 8 to ensure it is handled consistently with the Australian Privacy Principles. We may also disclose information where required or authorised by law, or to a court, regulator or law-enforcement agency where we are compelled to do so.

10. Accessing, correcting and deleting your information

You can view and update much of your information directly in the Bimble App. Under the Privacy Act you may also ask us to give you access to the personal information we hold about you, and to correct it if it is inaccurate, out of date or incomplete. We will respond within a reasonable period. There is no fee to request access, though a reasonable fee may apply for providing it in some cases. We may need to verify your identity first, and in limited circumstances the law allows us to decline access; if so, we will explain why.

10.1 Deleting data and account deletion

Different kinds of information are treated differently, depending on whether the law requires us to keep them.

Health-tracking data you record yourself (such as meals, water, weight, vitals, glucose, wellbeing, sleep, exercise, menstrual cycle, temperature and respiratory readings, along with any tracking categories added in future) is yours, and you can delete it. You can remove individual entries in the Bimble App, and you can delete all data in a tracking category at any time. Deleted tracker data is destroyed and is not subject to any statutory retention obligation.

Records of care provided by a health professional (such as telehealth consultations, referrals and clinical notes) cannot be deleted on request, because we are legally required to retain them for the minimum periods set by applicable law (see section 11).

Because your account may hold records of both kinds, we do not currently offer full account deletion on request, since that would delete records we are obliged to keep. What you can do at any time is stop new information being collected and control who can see your existing information: disable any tracking category, delete the tracker data you have recorded, revoke providers' access (other than access needed to complete an active episode of care, as described in section 8), and ask us to deactivate your account so it is no longer active. If you have never had a consultation or other health-professional interaction through the Platform, contact our Privacy and Compliance team (see section 15) and we will tell you what deletion options are available in your circumstances.

When we are eventually permitted to destroy data that was subject to a retention obligation (once that period has ended, or where deletion is otherwise lawful), we do so by destroying the encryption key that protects your data, which renders your health information in our live systems permanently unreadable.

Please note: backups. When data is destroyed, it may remain recoverable from encrypted database backups for a limited period. Backups are retained for up to 30 days before they are automatically and permanently purged, after which the data cannot be recovered by any means.

11. How long we keep your information

We keep your information for as long as you hold an account and for as long as we need it to provide the Platform. When it is no longer needed, we destroy or de-identify it, subject to the backup window described above.

Some information must be kept longer to meet legal obligations, and we retain it for as long as those obligations require. In particular, records of care provided by a health professional (such as telehealth consultations, referrals and clinical notes) are subject to the minimum retention periods required by applicable law. Financial records are separately retained to meet tax law requirements. These retention obligations apply even if you withdraw consent or ask us to deactivate your account.

12. Our website and cookies

Our marketing website uses cookies and similar technologies to make the site work and to understand how it is used. You can set your browser to refuse cookies, though some parts of the site may not work as intended. Our website may link to third-party sites; we are not responsible for their privacy practices, and we encourage you to read their policies.

13. Age and family accounts

You must be at least 16 to hold your own Bimble account, consistent with the age at which a person can generally make their own healthcare decisions and the threshold used by the My Health Record system. You can add family members (including children under 16) as linked profiles under your account; their information is held under your account's protections and covered by the access decisions you make. When a child reaches 16, their profile can be converted to an independent account with its own key and its own consent controls, after which you no longer have access unless they grant it.

14. Changes to this Policy

We may update this Policy from time to time. When we make a material change, we will take reasonable steps to notify you (for example, through the App or by email), and we will update the effective date at the top of this document. The current version is always available in the App and on our website.

15. Contact us and complaints

If you have a question about this Policy, want to exercise a privacy right, or wish to make a complaint about how we have handled your information, please contact our Privacy and Compliance team:

Bimble Health Privacy and Compliance team

Email: compliance@bimble.health

We ask that complaints be made in writing in the first instance so we can investigate properly, and we will respond within the timeframes required by law. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or on 1300 363 992.