Privacy Policy
Information we collect
- Account information — your name, work email, a hashed password, your employer (if you provide it), and your subscription tier.
- Billing information — processed by Stripe on our behalf; we do not store payment-card details.
- Service content — the prompts you submit, the responses generated, and any files you upload. Uploads are at your discretion: the Service is built around process data (cycle times, defect counts, process steps, yields) and does not require personal data, customer records or identifying information. Almero does not automatically detect or redact personal data at ingest.
- Usage and security data — session metadata (time, duration, and IP address for security logging) and aggregate usage telemetry used to operate and improve the Service.
How we use your information
- deliver the Service — respond to your prompts, generate deliverables, and store your conversation history and files;
- administer your account — authentication, billing and subscription management;
- keep the Service secure — detect and prevent abuse, fraud and unauthorised access;
- improve the Service — aggregate analysis of feature usage and errors; we do not use the content of your projects for product improvement without your consent; and
- meet legal obligations — where required by law or a lawful regulatory request.
Storage, security & location
Your account data and uploaded files are held in encrypted, Australian-region storage in Sydney, Australia.
We protect personal information with AES-256 encryption at rest, TLS 1.3 in transit, per-user key isolation (no cross-tenant access), password hashing (bcrypt), and continuous monitoring. A fuller technical and organisational security description is available in our Privacy & Security Pack on request (see section 6).
Sub-processors
International data transfers
The Service is used internationally, so your data may cross two borders: from your own country to our hosting in Sydney, Australia, and — for AI model inference only — onward to the United States, where inference is performed by Anthropic PBC via its commercial API. No other data leaves Australia.
We handle cross-border disclosure in line with APP 8. Anthropic’s commercial terms prohibit the use of your inputs to train models and provide for deletion of inputs and outputs within 30 days of receipt, subject to Anthropic’s published exceptions.
Lawful access: like any provider, we may be subject to lawful government-access requests in the jurisdictions where data is held. The Service is designed to minimise what could be compelled — its tools operate on process metrics rather than personal data, and you can delete any project or file at any time.
Data processing agreement
For business, IT and Security teams, our pre-signed Data Processing Agreement, sub-processor disclosure and Australian Privacy Principles compliance matrix are provided in the Privacy & Security Pack, available on request at privacy@almero.ai
Data retention & deletion
Training
Your rights
Under the Australian Privacy Principles you may: access the personal information we hold about you; ask us to correct it; request its deletion (subject to lawful retention); request a portable copy; and complain to us or to the Office of the Australian Information Commissioner (OAIC).
To exercise any right, contact privacy@almero.ai.
Cookies & similar technologies
Changes to this policy
Questions about this policy?
Contact us at privacy@almero.ai, or through the contact page.