Legal

Privacy Policy

AI Black Belt Agent and Almero websites · Version 1.9 · 5 September 2026 · Effective 5 September 2026 · Almero Pty Ltd (ABN 76 054 038 489)

This policy explains how Almero Pty Ltd (Almero, we, us) handles personal information when you visit almero.ai, create or use an AI Black Belt Agent account, contact us, or buy a subscription. Almero is the controller for account, website, billing-administration, security and support data. For business-customer content, Almero generally acts as processor/service provider under the Data Processing Addendum (DPA).

Scope note. At launch Almero markets the Service in Australia, the United Kingdom and the United States, not the European Economic Area (EEA). This policy addresses the Australian Privacy Act 1988 (Cth) and Australian Privacy Principles (APPs), the UK GDPR and Data Protection Act 2018, and applicable US state consumer privacy laws. The US State Privacy Notice supplements it.

This page is the formal policy document. A plain-language overview of how the Service handles your project data day to day — encryption, data flow, residency and retention — is on our Privacy page.

01

Who we are and how to contact us

Almero Pty Ltd, ABN 76 054 038 489. Postal correspondence: PO Box 372, Heidelberg, Victoria 3084, Australia. Privacy enquiries, rights requests and security reports: privacy@almero.ai.

UK representative. If you are in the United Kingdom, you may contact Almero’s representative under Article 27 UK GDPR about matters relating to your personal information:

Prighter Ltd 20 Mortlake Mortlake High Street London SW14 8JN United Kingdom

Online contact and privacy-rights portal: https://app.prighter.com/portal/16939150786

02

Information we collect

Category Examples Source
Account and profile name, work email, hashed password, employer, tier, account identifiers you; your organisation
Service content prompts, responses, conversation history, uploaded files and generated deliverables you and authorised users
Transaction data plan, invoice, payment status, tax and billing identifiers; card data is handled by Stripe you; Stripe
Usage, device and security IP address, timestamps, session and device/browser data, security events and feature telemetry automatically from your device/service
Communications support requests, feedback, survey or correspondence content you
Cookie data currency preference and authentication/session identifiers browser/service

The Service is not designed for sensitive or highly regulated personal data. Do not upload health, genetic or biometric data; government identifiers; payment-card details; criminal-record data; precise location data; children’s data; or UK GDPR Article 9 special-category data. Almero may reject, quarantine or delete prohibited content. We do not intentionally collect information from children under 18.

03

Purposes and legal bases

Purpose Data UK lawful basis
Provide, authenticate and support the Service account, service content, communications, usage contract; legitimate interests; customer instructions
Bill and administer subscriptions account and transaction contract; legal obligation
Protect users and the Service account, usage/device/security, service content when necessary legitimate interests; legal obligation
Improve reliability and features aggregated/de-identified telemetry and error data legitimate interests; consent where required
Communicate service notices account and communications contract; legitimate interests
Marketing contact and preference data consent where required; otherwise legitimate interests, with opt-out
Comply with law and establish claims relevant categories legal obligation; legitimate interests
Our legitimate interests are operating a secure, reliable service, preventing misuse, supporting users and improving non-content functionality. We balance these interests against individual rights. We do not use project content for product improvement without permission and do not use it to train foundation models.
04

Disclosures and processors

Recipient Purpose Typical processing location
Anthropic, PBC commercial API model inference; selected conversation context United States
Fly.io, Inc. application hosting, network processing, storage and backups Sydney, Australia; provider support/operations may be global
Stripe Payments Australia Pty Ltd and relevant Stripe affiliates/service providers payments, billing, fraud prevention and tax administration Australia and locations described by Stripe
We may also disclose information to professional advisers, regulators, courts, law enforcement or transaction counterparties when lawful and necessary. We do not sell personal information or share it for cross-context behavioural advertising, and we do not disclose project data to training organisations, referral partners or advertisers.
05

International data transfers

Primary application, file storage and routine backups are configured for Sydney, Australia. Selected model-inference context is sent to Anthropic, PBC in the United States. Stripe Payments Australia Pty Ltd and relevant Stripe affiliates/service providers process billing data in locations described by Stripe. For restricted UK transfers, Almero uses the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, a documented UK Data Protection Test and supplementary safeguards. Australia is not presently covered by a UK adequacy regulation. Copies of relevant safeguards are available at privacy@almero.ai, subject to lawful redactions.

For Australian disclosures overseas, we take reasonable steps consistent with APP 8 and identify likely overseas locations where practicable. Legal demands are assessed for validity and scope; notice is given when lawful.

06

Retention

Record Retention approach
Projects, files and conversation history while the account is active; in-app deletion removes the active copy promptly
Closed accounts deleted from active systems within 30 days, subject to legal, fraud, security and dispute holds
Fly Volume snapshots daily snapshots retained for 5 days under the launch configuration
Fly Managed Postgres backups approximately 10-day recovery window
Billing and tax records for the period required by tax, accounting and corporate law
Security logs only as long as reasonably needed for security, investigation and legal obligations
Anthropic API inputs/outputs under the commercial API terms and DPA then in force
We periodically review retention and securely delete or de-identify information when it is no longer needed. A request for deletion may be limited by legal obligations, security, fraud prevention, contractual records or the rights of others.
07

Security and incidents

We use TLS for data in transit, Fly’s provider-managed encryption for production volumes at rest, bcrypt password hashing, named administrative accounts, least-privilege access, account-level isolation, logging, monitoring, Sydney backups and an incident-response process. Administrative MFA is enabled on Fly.io, GitHub and Microsoft 365; end-user accounts do not currently offer MFA. Encryption keys are managed by Fly and are not per-user keys. No system is completely secure. We notify customers, affected individuals and regulators without undue delay and within periods required by law.
08

Your choices and rights

Submit requests to privacy@almero.ai. We aim to acknowledge within five business days, verify through the registered account or email where practicable, and ordinarily complete requests within 30 days subject to the applicable legal period. Authorised agents must show appropriate authority. We explain refusals and extensions. US users may appeal by replying “Appeal”; the founder conducts a fresh review. We offer access, correction, deletion and portability to all verified US users even where a state threshold does not apply.

09

US State Privacy Notice

United States residents should read our US State Privacy Notice, which supplements this policy with state-specific disclosures and information about privacy rights.

Download: https://almero.ai/privacy-policy/us-state-privacy-notice.docx

10

Automated processing and AI

The Service generates statistical analysis and draft work products from user instructions. Almero does not use personal information to make decisions that produce legal or similarly significant effects about individuals. Users must review outputs and must not use the Service for prohibited high-impact decisions without an appropriate lawful basis, notices, human oversight and risk controls.
11

Cookies and communications

Type Purpose Status / duration
Strictly necessary authentication, server-side sessions, security and load balancing session or limited persistent duration; required for signed-in Service
Functional remember a currency selected by the user set only after the user requests that preference; current duration recorded in the production inventory
Forms and site components WordPress, Elementor and Gravity Forms provide pages and the free-trial form; an external Font Awesome kit supplies icons no analytics or advertising purpose represented
Analytics none active at launch not used
Advertising / cross-site tracking none not used
Cookies are small text files placed or read by a website. Browser storage and similar technologies may serve comparable purposes.

Cookie controls. You may block or delete cookies in your browser settings, but the Service may not function without strictly necessary cookies. We do not use a general consent banner because analytics and advertising cookies are not active. The currency preference is set only when you select that functionality. If we introduce other non-essential cookies, we will provide a consent control that permits acceptance and refusal by category and allows consent to be withdrawn as easily as it was given.

Cookie inventory and updates. We maintain a production cookie inventory recording exact names, providers, purposes and durations, and re-scan after material website changes. Questions about cookies may be sent to privacy@almero.ai.

Communications. Marketing emails include an unsubscribe method. Essential service messages may still be sent.

12

Complaints and changes

Send complaints to privacy@almero.ai. We will investigate and explain our decision and available escalation. Australian individuals may complain to the OAIC, UK individuals to the ICO, and US residents to an available state regulator or attorney general. Material updates will be posted with a new effective date.

Questions about this policy?
Contact us at privacy@almero.ai. Formal privacy complaints: privacy@almero.ai. You can also contact the OAIC at oaic.gov.au.

Continue on desktop

The AI Black Belt Agent is a desktop workspace; enter your name & email and we’ll send you a one-click link to start your free trial at your computer.