Know exactly where our data goes.
At Almero, we treat your privacy as a first principle. Every project you run lives on our managed cloud, held in encrypted storage isolated to your account — and we document exactly where every byte travels, so your IT, Security and Procurement teams can sign off before a single project begins.
Your process data is your commercial property. Cycle times, defect rates, yields, supplier performance — it is confidential to you. It is never used to train models, never shared, never reachable across tenants, and you can purge it at any time.
Encrypted & isolated
Your files sit in per-user storage, encrypted with AES-256 at rest and TLS 1.3 in transit. Keys are isolated per account — no cross-tenant access.
Never used to train
Inference runs on Anthropic’s commercial API under a contract that prohibits training on your inputs — your project data trains nothing.
Yours to purge
Delete any project or file from within the app at any time. On account closure, everything is removed within 30 days.
How a request travels
You type a message
The request goes to Almero’s managed cloud, hosted in Sydney, Australia.
Agent calls the model
Conversation context is sent to Anthropic’s frontier LLM via the commercial API over TLS. The only onward transfer.
Tools run
Statistical tools — charter, SIPOC, capability, MSA, VSM — execute server-side on your inputs.
Files stored
Uploads and generated deliverables are held in per-user encrypted storage (AES-256), user-purgeable anytime.
Managed cloud · Sydney, Australia
Anthropic frontier LLM (US) — inference only
AES-256 at rest, TLS 1.3 in transit, per-user key isolation. The only onward transfer is model inference on
Anthropic’s US commercial API — no other data leaves Sydney. Input data is never used to train the models.
How long it's stored — and when it's gone
Training and retention. Your inputs are never used to train the models — that is contractual. Retention is a separate matter: Anthropic deletes API inputs and outputs within 30 days of receipt. Your own projects and files are unaffected — they stay until you delete them.
Your files. Uploads and generated deliverables are kept only while your account is active, and you can purge any project or file at any time from inside the app — no support ticket, no waiting. Deletion is immediate in the app; the copy held in our encrypted backups is purged within the 30-day backup cycle.
On cancellation. When you close your account, your data is deleted from active systems within 30 days, then removed from routine backups on their normal rotation.
Full retention windows, backup schedules and deletion timelines are set out in the Privacy & Data Flow Brief.
For your IT & Security team
Questions from your security team? security@almero.ai — we’ll answer them, or complete your vendor questionnaire.
For the formal legal document, read our full Privacy Policy.