Privacy policy
How SMSF Cockpit handles personal information. Last updated 26 September 2026.
Who we are
SMSF Cockpit is a registered business name of Warwick Aubin, a sole trader (ABN 64 799 581 029). In this policy, “we” and “us” mean Warwick Aubin trading as SMSF Cockpit.
Our approach
SMSF Cockpit holds personal information about self-managed super fund trustees, so we take it seriously. We may not be legally required to follow the Privacy Act 1988, but we handle personal information in line with the Australian Privacy Principles as a matter of good practice.
What we collect
- On the waitlist: your email address, the option that best describes you, and (only if you choose to give them) your name, roughly how many SMSFs you look after, and any message you write. We also record when you agreed to be emailed.
- Your account: your name (if you give it), your email address, and your password, which we store only as a one-way scrambled value (a hash) that can’t be turned back into the password. We also record when you accepted the Terms, and whether you’ve asked for the weekly reminder email.
- Your fund: the fund’s name and the records you choose to add, such as the members’ names and dates of birth, trustee minutes, binding death benefit nominations (including the beneficiaries you list), contributions and pension amounts, where documents are kept, insurance and audit notes, and your succession plan.
- Your advisers and contacts: the names, firms and contact details of people such as your accountant, lawyer or adviser, if you type them into the Succession Plan.
- People you invite: their email address and the access level you give them. If they accept, the account they create is described above.
- Change history: for each record added, changed or deleted in a fund, who did it (their name and email), when, and the old and new values. It can’t be edited, and every person with access to the fund can read it.
- Technical information: your IP address is used for about 15 minutes so we can slow down repeated sign-in or sign-up attempts, and that record is then deleted within two days; every sign-in attempt, successful or not, is separately recorded (the email tried, the account if one matched, and the IP address) for up to 90 days, so we can notice unusual activity on an account; our hosting provider keeps its usual server logs; and when something breaks we keep a record of what went wrong, where, and which account it happened to, so we can fix it.
What we ask you not to enter
Please don’t enter tax file numbers, passwords or PINs, card numbers, or copies of identity documents. The service isn’t designed to hold them. The Succession Plan has a free-text line for each bank account: the bank, what it’s used for and the last 4 digits of the number are enough, so please don’t enter full account numbers.
How we collect it
Mostly directly from you. If another trustee invites you to a fund, they give us your email address so we can send the invitation. The sign-in cookie (see “Cookies” below) and our logs collect some technical information automatically.
Why, and who sees it
We use personal information to:
- run your account and give the people you’ve invited access to the fund’s information
- send service emails: a confirm-your-email link when you sign up, invitations, password resets, a thank-you email when you join the waitlist, and (only if you turn them on) weekly reminders
- tell you when SMSF Cockpit opens up, if you joined the waitlist, and understand who is interested
- keep the service secure, prevent misuse, and find and fix faults
- meet legal obligations
We don’t sell personal information and we don’t use it for advertising.
It can be seen by:
- Other people on your fund, according to the access level the fund’s owner gives them. Everyone with access can read the fund’s records and its change history.
- The people who run SMSF Cockpit, when needed to operate, secure and support the service (for example to fix a fault you report).
- Service providers that host the app, store the database and send email for us. They may use the information only to provide that service to us.
- Google, only if you choose to sign in with “Continue with Google” instead of a password: it confirms your name and email address to us. This never creates an account by itself — it only signs you into one you already have — and we don’t receive or store your Google password.
- Authorities or courts, where the law requires it.
Where it’s stored
The app is hosted, and its database is stored, in Sydney, Australia. Our email service is provided by Resend, which may process the email address and the text of an email (for example an invitation) outside Australia while it delivers it. If you use “Continue with Google”, Google processes your sign-in outside Australia too.
Adding other people’s information
If you add details of another person (an adviser, a co-trustee or a beneficiary), you confirm that you’re entitled to share them for managing your fund. We email people you invite, and that email tells them you gave us their address and how to ask us to delete it.
Access after death or incapacity
The way a successor gets access today is that a current owner invites them as a co-trustee, or as a view-only accountant or adviser. If nobody who has access is able to do that, contact us. We’ll ask for evidence of the person’s authority, such as a death certificate and grant of probate or an enduring power of attorney, and we may refuse or delay access if we can’t verify the request.
Security
Connections to the site are encrypted. Passwords are stored only as hashes. Every page and download checks that you have access to the fund it belongs to, and the fund’s owner decides who can edit and who can only view. Invitation links work once and expire after 7 days. No system is completely secure. If a breach is likely to cause serious harm, we’ll tell the people affected and, where appropriate, the Office of the Australian Information Commissioner.
How long we keep it
- Waitlist details: until you ask us to remove them, or until we no longer need them to tell you about the launch.
- Your account: while it’s open. You can delete it yourself on the Your account page. It is frozen straight away and deleted for good after 7 days; signing in again during those 7 days cancels the deletion. When it is deleted, any fund that only you were in is deleted with it, and you are removed from every other fund. If you own a fund that other people use, you need to remove them or delete the fund first, so that we never delete other people’s records because an owner left. You can also ask us to close it, and we’ll start the same process within 30 days.
- Fund records: they belong to the fund, so they stay for its other people. A fund’s owner can delete the whole fund at any time in its Settings; it is deleted straight away, with everything in it including its change history, and can’t be recovered. Until then, the change history is the fund’s permanent record: it keeps the name and email of the person who made each change for as long as the fund exists, including after that person deletes their account.
- Never-used accounts: an account that was created but never used (you didn’t accept the Terms, join a fund or invite anyone) is deleted 30 days after it was created. We don’t delete an account or fund that has been used just because it has gone quiet.
- Technical records are deleted automatically once they have done their job: sign-in and sign-up attempt records (which hold IP addresses and the email addresses typed into those forms) within two days; the sign-in record kept for unusual-activity monitoring (see “What we collect” above) after 90 days; error records 90 days after the problem last happened; password-reset links 7 days after they expire; and invitation records 12 months after the invitation was accepted, cancelled or expired. Copies of the database in our provider’s backups are overwritten on its schedule.
Unsubscribing
Every marketing or waitlist email we send has an unsubscribe link, and mail apps such as Gmail and Apple Mail also show their own unsubscribe button. It works straight away and needs no login. When you unsubscribe we keep your email address on a do-not-email list, so that it isn’t contacted by mistake. If you’d rather it was deleted completely, just ask. Service emails you asked for, such as an invitation or a password reset, are not marketing.
Your choices
You can ask to see the personal information we hold about you, to correct it, or to have it deleted, at any time. You can delete your account, or a fund you own, yourself in the app (see “How long we keep it”). For anything else, email smsf.cockpit@gmail.com. We aim to respond within 30 days. For a fund with several people, we may need to check with the fund’s owner before deleting shared records.
Cookies and analytics
We use a cookie to keep you signed in and a security cookie that protects the sign-in form. Your browser also remembers a few small preferences (such as a dismissed checklist) on your own device only. We don’t use advertising or tracking cookies, and we don’t send personal information to analytics tools.
On the public website and the sign-in and sign-up pages we use Vercel Web Analytics to count visits and a few named actions, such as joining the waitlist, trying the demo or creating a practice fund. It doesn’t use a cookie, doesn’t track you across other websites, and doesn’t identify who you are — it’s aggregate counts only. Nothing you do inside your fund is sent to it.
Complaints
Email smsf.cockpit@gmail.com and we’ll respond within 30 days. If you’re unhappy with our response, you can contact the Office of the Australian Information Commissioner.
Changes
We’ll update this page when our practices change and tell account holders about significant changes by email. Use of the app is also covered by the Terms & disclaimer.