CaseOnMe by S6 Security Labs is a consent-led public-source review. This page explains the service boundary, your responsibilities, data handling, retention, and contact options.
Back to intake · How to read a report · Synthetic demo report
Status: In force for the current service. This notice describes how CaseOnMe
handles personal information. It is not legal advice.
Last updated: 2026-07-02. Data controller: S6 Security Labs. Contact:
We handle personal information consistently with the Australian Privacy Principles
(APPs) under the Privacy Act 1988 (Cth), and apply those principles as our baseline
regardless of whether S6 currently meets the Act's small-business turnover
threshold. We collect only what is needed for a consent-led, one-off
public-footprint review.
To validate consent/scope, run the authorised review, generate the private report,
deliver it, prevent abuse, troubleshoot, and satisfy privacy requests. We do not sell
personal information and do not use it for advertising.
CaseOnMe must not intentionally collect private/access-controlled
content, passwords, secret tokens, or credential material. Public demos use
synthetic or consented data only.
CaseOnMe does not offer dedicated child/minor scanning. Do not submit a
minor's accounts for a child-targeted scan, even if you are a parent or guardian.
Guardian/family authority is for authorised adult household, family,
client, or representative scopes, and may only include minor-related public
information when it is incidental to an authorised adult/family review. These cases
receive additional safety review and are not run as child-targeted scans.
We use a small number of providers to host and operate the service. They process
personal information only to provide their service to us:
We will update this notice if our provider arrangements materially change.
Some providers may process data on servers outside Australia. By using the service
and receiving email from us, you acknowledge that limited data such as your email
address and request metadata may be processed overseas under provider terms.
Case artifacts are retained for 30 days after delivery and security and consent
records for up to 12 months.
Encrypted backups are retained on a 30-day rolling window, so a deleted case may
persist in a backup for up to 30 days after deletion — this limitation is disclosed
to anyone who requests deletion.
You may request access to, correction of, export of, or deletion of your personal
information, and may complain about how we handle it. We verify your identity and
authority before disclosing, exporting, correcting, or deleting. Contact
[email protected]; target response time is 30 days.
If a data breach likely to cause serious harm occurs, we will assess and respond
consistently with the Notifiable Data Breaches scheme, including notifying affected
individuals and the OAIC where required.
Contact [email protected] first. If you are not satisfied with our
response, you may escalate to the Office of the Australian Information Commissioner
(OAIC) at oaic.gov.au.