Legal

Privacy Policy

Looking for a plain-language walkthrough of how the AI Black Belt Agent handles your project data day to day — encryption, data flow, residency and retention? That lives on our Privacy page. This page is the formal policy document.
01

Information we collect

We collect the following categories of information:
02

How we use your information

We use your information to:
We do not sell, rent or trade your personal information, and we do not use your data or prompts to train AI models (see section 8).
03

Storage, security & location

Your account data and uploaded files are held in encrypted, Australian-region storage in Sydney, Australia.

We protect personal information with AES-256 encryption at rest, TLS 1.3 in transit, per-user key isolation (no cross-tenant access), password hashing (bcrypt), and continuous monitoring. A fuller technical and organisational security description is available in our Privacy & Security Pack on request (see section 6).

04

Sub-processors

We disclose personal information only to the sub-processors that help us operate the Service, and only to the extent needed. No training organisation, referral partner, advertiser or analytics broker is ever in the data path. Our current sub-processors are:
[table placeholder]
We maintain the current list here and notify subscribers before adding or changing a sub-processor.
05

International data transfers

The Service is used internationally, so your data may cross two borders: from your own country to our hosting in Sydney, Australia, and — for AI model inference only — onward to the United States, where inference is performed by Anthropic PBC via its commercial API. No other data leaves Australia.

We handle cross-border disclosure in line with APP 8. Anthropic’s commercial terms prohibit the use of your inputs to train models and provide for deletion of inputs and outputs within 30 days of receipt, subject to Anthropic’s published exceptions.

Lawful access: like any provider, we may be subject to lawful government-access requests in the jurisdictions where data is held. The Service is designed to minimise what could be compelled — its tools operate on process metrics rather than personal data, and you can delete any project or file at any time.

06

Data processing agreement

For business, IT and Security teams, our pre-signed Data Processing Agreement, sub-processor disclosure and Australian Privacy Principles compliance matrix are provided in the Privacy & Security Pack, available on request at privacy@almero.ai

07

Data retention & deletion

You can delete any project or file from within the Service at any time; deletion is immediate in the app, and the copy held in encrypted backups is removed on the backup cycle.
08

Training

Your project data is never used to train AI models. Inference runs on Anthropic’s commercial API under terms that prohibit training on your inputs. This is contractual — not a setting you need to enable.
09

Your rights

Under the Australian Privacy Principles you may: access the personal information we hold about you; ask us to correct it; request its deletion (subject to lawful retention); request a portable copy; and complain to us or to the Office of the Australian Information Commissioner (OAIC).

To exercise any right, contact privacy@almero.ai.

10

Cookies & similar technologies

We use a small number of cookies: a currency-preference cookie on the almero.ai website, and secure session cookies for signed-in use of the Service. We do not use third-party advertising or cross-site tracking cookies.
11

Changes to this policy

We may update this Policy from time to time. We will post the current version here and, for material changes, notify you by email and in-product before they take effect. The effective date appears at the top of this Policy.
Questions about this policy?

Contact us at privacy@almero.ai, or through the contact page.