Kiroku
Sign in

Legal

Privacy and Data Policy

Effective for Early Access · Last updated September 2026

Who operates Kiroku

Kiroku (kiroku.studio) is operated by AUGUR SYSTEMS PTY LTD, an Australian company (ACN 702 218 684 · ABN 74 702 218 684). In this policy, "Kiroku", "we", and "us" mean Augur Systems Pty Ltd.

This Privacy and Data Policy explains how we handle personal information through kiroku.studio, studio subdomains, mobile applications and related services (the Services).

The short version

  • We collect information needed to operate Kiroku, secure accounts, and support you.
  • Tattoo studios usually decide how client records are used. Kiroku processes those records for the studio providing the service.
  • Client records may include sensitive health information from waivers and consent.
  • We do not sell personal information or use health data for advertising.
  • Personal information is stored on managed cloud infrastructure, encrypted in transit and at rest, with access checked on the server.
  • We use service providers (hosting, auth, SMS, email, video, payments, analytics) which may process data outside Australia.
  • You can access and update account details, and close your account, in Settings → Account. Full instructions: Data access and deletion.
  • You can also request access, correction, or raise a privacy concern using the contact below.

Who this applies to

Studio owners, staff, artists, clients using bookings/waivers/portals, and visitors to our website. If you are a studio client, contact your studio first about your tattoo or health records; we assist studios where required.

What we collect

Depending on how you use Kiroku: account and contact details; studio and roster information; booking, waitlist and walk-in data; waiver and health answers; messages and call metadata; payment references (card data is handled by our payment provider); and technical logs for security and reliability.

How we handle personal information

Personal information is anything that identifies a person, on its own or with other records: names, contact details, account identifiers, bookings, messages, and uploaded files. Waiver and health answers are sensitive information. We collect and use this to operate Kiroku, secure accounts, send service messages, and support studios and artists.

Tattoo studios decide what client information they collect and why. Kiroku stores and processes those records for the studio running the service. We do not sell personal information. We do not use health answers, waiver content, message bodies, uploaded images, or payment details for advertising.

What someone can see depends on their role and their relationship to the studio, not on whatever the browser happens to load. Owners, managers, front desk, and artists do not automatically get the same records. Client contact details and waiver answers stay with people who need them for the work.

Ending access (leaving a studio, coming off the roster, or closing an account) stops ongoing access. It does not automatically delete studio history. Bookings, waivers, and financial records may need to stay with the studio for legal, insurance, or accounting reasons.

Text messages (SMS)

Kiroku sends transactional text messages: appointment confirmations and reminders, waiver links, booking updates, and one-time sign-in codes. We do not send marketing or promotional texts. Studio staff and the client portal collect consent on Kiroku's behalf before a mobile number is used for these messages; see SMS opt-in.

No mobile information will be sold or shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent will not be shared with any third parties.

Message frequency varies with your bookings. Message and data rates may apply. Reply STOP to any message to opt out, or HELP for help.

How we store and protect information

Kiroku runs on production-grade managed cloud infrastructure. We do not operate our own data centres. Application hosting, authentication, databases, and file storage are handled by specialist providers with their own security programs. Primary production databases and object storage are placed in region-specific locations so we can meet locale-specific regulatory and data-residency requirements.

Connections to Kiroku use HTTPS/TLS. Database records and stored files are encrypted at rest by those providers. Payment card numbers are entered with Stripe and are not stored in Kiroku's application database. Login uses one-time codes. We do not store account passwords.

Access is checked on the server for studio, artist, and client actions. Secrets and elevated database credentials stay on the server and are not exposed to the browser. Uploaded files such as waiver PDFs, reference images, and portfolio photos are served through application-controlled routes, not as an open public folder.

Our cloud providers supply redundancy and backup capabilities for the infrastructure they run. No online service can promise absolute security. Studios should give each person their own login, use the least access needed, and remove people who no longer work there.

Access, correction, and deletion

Signed-in users can review and update account contact details, and close their account, under Settings → Account (including Danger zone → Close account). Closing an account revokes access; it does not automatically erase studio-owned history such as bookings, waivers, and financial records.

Step-by-step instructions for access and deletion requests (including email fallbacks and studio-client requests) are published at Data access and deletion. That page is also the URL we provide for Meta App Review user-data deletion instructions and for app-store privacy listings.

Contact

Privacy requests for Kiroku / Augur Systems Pty Ltd: hello@kiroku.studio
Support: support@kiroku.studio

Related: Terms of Service · Data access and deletion

← Back to Kiroku

Privacy and Data Policy · Kiroku