SameBoat — Privacy Policy
Last updated: 23 July 2026
1. About this policy
In this policy, references to “SameBoat”, “us”, “we” or “our” mean Same Boat Pty Ltd ABN 43 607 659 183, the operator of sameboat.com and any other websites, forums or platforms (including social media platforms) operated or controlled by us (collectively, the “website” or “forum”).
References to “you” or “your” mean you as the person using our website.
This policy explains how we collect, hold, use, and disclose your personal information, and how you can access or correct it. We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Where the EU or UK General Data Protection Regulation applies to you, clause 15 also applies and sets out additional rights you have.
By using the website, you consent to your personal information being handled as described in this policy. If you do not agree, please do not use the website.
We may update this policy from time to time. The current version will always be posted on this page, with the “last updated” date above.
2. Our platform and where your data is stored — important
Our forum runs on Discourse, software and hosting provided by Civilized Discourse Construction Kit, Inc. (“CDCK”), a company based in the United States. CDCK hosts the forum and processes forum data on our behalf and at our direction as our service provider. We remain responsible to you for your personal information under Australian law.
SameBoat’s forum data is primarily stored in CDCK’s Toronto, Canada data centre. Certain supporting functions — including backups, content delivery, spam filtering, and push notifications — are provided by CDCK’s subprocessors, some of whom are based in or process data in the United States and other countries. By using the forum, you acknowledge and consent to your personal information being transferred to, stored, and processed overseas, including in Canada and the United States.
We take reasonable steps to ensure overseas recipients handle your personal information consistently with the APPs, including by relying on CDCK’s data-processing terms. However, once information is held overseas it may also be subject to the laws of those countries, including lawful access by their authorities. If you would like to know the specific country in which your data is currently held, contact us and we will tell you if we can.
CDCK uses sub-processors to run the service, which currently include providers such as Amazon Web Services and Google (storage), Akismet (spam filtering), and analytics providers. CDCK states that it does not sell personal information and does not use customer forum content to train AI models.
3. Staying anonymous
You can browse the website without registering. To post, you must choose a username or tag (which appears publicly) and provide a valid email address. Your email address is not published — we use it to verify your account, let you return to continue conversations, send notifications you’ve asked for, and contact you about your account or important changes.
You can choose a username that does not identify you personally, and we encourage you to do so.
4. What personal information we collect
We try to collect only what we need for you to use the forum. We collect:
Account information you give us when registering — username/tag and email address, and any optional profile details you choose to add (such as a short bio, location, or avatar).
Content you post — topics, replies, messages, likes, bookmarks, and similar activity. Anything you post in a public category is visible to others and is stored by us via the platform.
Information you give us when you contact us — for example through our contact page or by email.
Technical and usage data collected automatically by the platform — including your IP address, device and browser information, server logs, and pages visited. This is used to operate, secure, debug, and improve the forum, and to compile aggregate statistics. The platform usually retains this log data for a short period (typically a few weeks) unless a longer period is needed, for example to investigate a security incident.
We collect information directly from you. We do not buy information about you from data brokers or collect it about you from publicly available sources.
5. Sensitive information — please read
Because SameBoat is a peer-support forum, conversations may touch on sensitive information — including information about your health, mental health, racial or ethnic origin, religious beliefs, sexual orientation, or criminal history.
We do not actively collect sensitive information about you. However, if you choose to post such information, it becomes information we hold, and you consent to us handling it as described in this policy for the purpose of operating the forum. To the extent you post sensitive information in a public category, it will be visible to other users and to the public.
Please think carefully before posting. Do not post details that identify you — such as your full name, email, physical address, or phone number — and exercise your own judgement before sharing sensitive information about yourself or anyone else. Once posted in a public area, information can be seen, copied, or stored by others outside our control.
6. How we use your information
We use your personal information to:
- create and manage your account and identify you on the forum;
- operate, maintain, secure, and improve the forum and respond to your requests;
- send you notifications you have asked for and respond to your enquiries;
- moderate the forum and enforce our Terms & Conditions and these policies;
- send you occasional updates about SameBoat (you can opt out at any time); and
- comply with our legal obligations.
We do not sell your personal information or give away access to it for others’ marketing.
7. Cookies and similar technologies
The platform uses cookies and similar technologies so the forum works properly — for example to remember your login session, your preferences, and to keep your account secure — and to collect the technical and usage data described above. Most browsers accept cookies automatically, but you can usually change your settings to refuse them; some features may not work properly if you do.
Some cookies may be set by third parties (such as the platform’s security, anti-spam, or analytics providers). For full details of the cookies the platform uses, see CDCK’s privacy notice at Privacy policy | Discourse - Civilized Discussion.
8. Social media and third-party links
We may use social networking services (such as TikTok, Instagram, Reddit, YouTube, and Facebook) to communicate with the public, and the website may link to other websites, including the curated external support resources we display on category pages (“Liferings”). These services and sites have their own privacy policies and handle your information for their own purposes. When you interact with us on those platforms, or follow a Lifering to an external service, your information may be collected by that third party under their own privacy practices. We are not responsible for the privacy practices or content of third-party sites and services.
9. When we disclose your information
We do not sell, trade, or rent your personal information. We may disclose it:
- to CDCK and its sub-processors, who host and operate the platform on our behalf (see clause 2);
- to other service providers who help us run SameBoat, on the basis that they keep it confidential and use it only for that purpose;
- where required or authorised by law, or to a court, regulator, or law-enforcement authority;
- where we reasonably believe disclosure is necessary to enforce our policies or to protect the rights, property, or safety of you, us, or others; and
- to professional advisers where reasonably necessary.
Anything you post in a public category is, by its nature, disclosed publicly.
10. Security
Our platform provider and we take reasonable steps to protect your personal information from misuse, loss, and unauthorised access, including password protection and access controls. However, no online platform is completely secure, and continuous availability depends on third-party services. We cannot guarantee the security of information transmitted to or stored on the website, and you provide it at your own risk. You are encouraged to use a strong, unique password and keep it secret. Where possible, use Multi-Factor Authentication.
11. Accessing and correcting your information
You can view and update most of your account information at any time through your profile settings. You may also request a copy of the personal information we hold about you, and ask us to correct it if it is inaccurate, out of date, or incomplete. We will respond within a reasonable time. If we do not agree to a correction, we will note your request alongside the information.
12. Deleting your information
You may close your account and request that the personal information we hold about you be deleted. To make a request, contact us at the address in clause 16, using the email address associated with your account so we can verify your identity. We will action deletion within a reasonable time (we aim for 30 days), except where we are required or permitted by law to retain certain information. Note that closing your account starts a process of erasing or anonymising your account data, and that content already shared publicly, quoted by others, or held in backups may persist for a period after deletion.
13. Data retention
We keep your personal information for as long as your account remains open and for as long as we need it for the purposes described in this policy, or as required by law. Technical log data is generally kept only for a short period. When information is no longer needed, we take reasonable steps to delete or de-identify it.
14. Data breaches
If we become aware of unauthorised access to, or disclosure or loss of, personal information we hold, we will assess it promptly. Where a breach is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner as required under the Notifiable Data Breaches scheme. Where the GDPR applies, we will notify the relevant supervisory authority within 72 hours of becoming aware of a reportable breach, and affected individuals where the breach is likely to result in a high risk to their rights and freedoms.
15. Additional rights for EU and UK users (GDPR)
This clause applies if you are located in the European Economic Area or the United Kingdom and the EU or UK General Data Protection Regulation applies to your personal data. Where this clause conflicts with another clause of this policy, this clause prevails for those users.
Data controller. Same Boat Pty Ltd is the controller of your personal data. Contact details are in clause 16.
Legal bases for processing. We process your personal data on the following bases:
Performance of a contract — to create and operate your account and provide the forum you have signed up to use.
Legitimate interests — to keep the forum secure, prevent abuse and spam, moderate content, enforce our terms, and improve the service. We have assessed these interests against your rights and freedoms.
Consent — for optional communications, and for the processing of any special-category data you choose to post (see below). You may withdraw consent at any time, though this does not affect processing already carried out.
Legal obligation — where we are required by law to retain or disclose data.
Special-category data. Content posted on SameBoat may reveal special-category data under Article 9 GDPR — including data about health, mental health, sexual orientation, religious or philosophical beliefs, racial or ethnic origin, or alleged offences. We do not require or solicit this data. Where you choose to post it, we rely on your explicit consent under Article 9(2)(a), and on Article 9(2)(e) to the extent you have manifestly made that data public by posting it in a public category. Please consider carefully before posting such information, and note that once posted publicly it may be copied or stored by others outside our control.
Your rights. Subject to the conditions and exemptions in the GDPR, you have the right to:
- access the personal data we hold about you and receive a copy;
- rectify inaccurate or incomplete data;
- erase your data (“right to be forgotten”);
- restrict processing in certain circumstances;
- object to processing based on our legitimate interests, and to direct marketing at any time;
- data portability — receive data you provided to us in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible;
- withdraw consent at any time where processing is based on consent; and
- not be subject to a decision based solely on automated processing that produces legal or similarly significant effects. We do not currently carry out such decision-making. Automated tools we use for spam and content moderation are subject to human review before an account is permanently closed.
To exercise any of these rights, contact us using the details in clause 16. We will respond within one month, which may be extended by two further months for complex or numerous requests, in which case we will tell you within the first month. There is no fee unless a request is manifestly unfounded or excessive. We may need to verify your identity before acting.
International transfers. Where we transfer personal data outside the EEA or UK, we do so on the basis of appropriate safeguards under Article 46 GDPR. CDCK’s standard data-processing addendum incorporates the European Commission’s standard contractual clauses (Commission Decision 2010/87/EU) for transfers out of the EEA. We are in the process of formally executing this addendum with CDCK. You may request a copy by contacting us.
Retention. We retain personal data in line with clause 13, and only for as long as necessary for the purposes for which it was collected or as required by law.
Complaints. You have the right to lodge a complaint with a supervisory authority — in the EU, the data protection authority of your country of residence, work, or the place of the alleged infringement; in the UK, the Information Commissioner’s Office (ico.org.uk).
We would appreciate the chance to address your concerns first.
16. Complaints and contact
If you have any questions or concerns about how we handle your personal information, please contact us at sameadmin@proton.me (or via our contact page). We will respond within a reasonable time, and aim to do so within 30 days (or one month for GDPR requests, as set out in clause 15).
If you are not satisfied with our response, you can contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or by phone on 1300 363 992. If you are in the EU or UK, see clause 15 for your right to complain to your local supervisory authority.