1. Summary in plain English
We collect what we need to run the Service: your email, the queries you submit, the reports we generate for you, and how you use the product. We use that to provide and improve the Service. We share what's necessary with our service providers (Stripe, Supabase, PostHog, Anthropic, Perplexity). We don't share your individual data with other Almonax users (unless you join a Team and explicitly authorize it). We don't sell your data.
2. Data we collect
When you sign up:
- Email address
- If you join via referral: the referrer's code
When you use the Service:
- Queries you submit (topics, filters, instructions)
- Generated reports + their content
- Feedback you provide (ratings, edits, comments)
- Library organization (folders, naming)
- Watchlist + Trigger + Project subscriptions and configurations
- Sources you add to track
Automatic via analytics:
- Page views, button clicks, session timing (via PostHog)
- Device + browser info (IP, user agent, screen size)
- Geographic region (inferred from IP, country-level only)
- Error events (technical diagnostics)
When you pay:
- Payment processed by Stripe (we do not store full card details; Stripe does, per their terms)
- We retain: transaction amount, date, last 4 digits of card, billing zip — for accounting + tax purposes
3. How we use your data
We use your data to:
- Provide the Service (generate reports, track Watchlists, fire Triggers, deliver digests)
- Process payments and manage your credit balance
- Improve the Service (train and tune AI models, refine prompts, build new report types)
- Derive aggregate insights (e.g., "what topics are users researching most" — anonymized only)
- Communicate with you (operational emails, billing, important updates)
- Detect abuse, prevent fraud, and enforce our Terms
- Comply with legal obligations
4. AI model training using your data
We use your queries, generated reports, and feedback ratings to improve our AI models, prompts, and report templates. This includes:
- Fine-tuning models on high-quality reports and accepted edits
- Building prompt-engineering improvements informed by what works
- Identifying gaps in our corpus or report-type coverage
Model training and aggregate analysis are done in ways that avoid exposing individual user content to other users. Specifically: an individual user's query is not surfaced to another user's session, and individual reports are not retrieved by other users (only the user who generated a report can see it, unless shared via Team).
5. Sharing your data
We share data with the following third-party service providers as necessary to operate the Service:
- Supabase — user accounts, database, authentication
- Stripe — payment processing and credit purchases
- PostHog — product analytics and error tracking
- Anthropic — AI model inference (Claude family) for report generation
- Perplexity — augmented search for ingestion and synthesis
- Vercel — application hosting and deployment
- Rewardful — affiliate program tracking (if you participate)
- Resend / Postmark (or similar) — transactional email delivery
- Mercury / Stripe Atlas — banking and corporate ops
Each provider has their own privacy policy governing their use of data shared with them. We minimize what we share — for example, Anthropic receives the query and corpus chunks needed to generate a report, but not your account email or payment information.
We do not sell your data.
We may share data when required by law (subpoena, court order), to enforce our Terms, to protect our rights, or in the event of a corporate transaction (merger, acquisition, sale of assets) — in which case data may transfer to the acquirer subject to their adherence to this Privacy Policy.
6. Teams and shared content (when available)
If we offer Teams functionality, you may join or create a Team that explicitly shares specified content (queries, reports, Watchlists, Projects) with other Team members. Teams sharing is:
- Opt-in (you choose to join)
- Configurable (you choose what to share — not all content automatically syncs)
- Revocable (you can leave a Team; future-shared content stops, but previously-shared content remains visible to those who accessed it)
Outside a Team you have explicitly joined, your individual data is not visible to other Almonax users.
7. Your rights
You have the right to:
- Access — request a copy of the personal data we hold about you
- Correction — ask us to fix inaccurate data
- Deletion — request deletion of your account and associated data, subject to legal/accounting retention requirements (typically 7 years for financial records)
- Portability — receive your data in a machine-readable format
- Opt-out of model training (beta-period exception): During the beta period, opting out of model training would require us to disable your account because the Service is in active development. Post-beta, we will offer a model-training opt-out option in Account settings.
To exercise any of these rights, contact hello@almonax.com. We respond within 30 days.
8. Data retention
We retain your data for as long as your account is active and as needed to provide the Service. After account deletion:
- Account profile, queries, reports, and library: deleted within 30 days
- Aggregated, anonymized data (used for model improvement): retained indefinitely (no longer linked to you)
- Financial records (transactions, invoices): retained 7 years for tax and accounting compliance
- Backups: rolled off within 90 days
9. Security
We use industry-standard security practices including encryption in transit (TLS), encryption at rest, access controls, and regular security reviews. No system is 100% secure; we cannot guarantee absolute security but we work continuously to protect your data.
You are responsible for: keeping your password secure, not sharing your account credentials, and reporting suspected unauthorized access promptly to hello@almonax.com.
10. International users
Almonax is based in the United States. If you access the Service from outside the US, your data is transferred to and processed in the US. By using the Service you consent to this transfer.
EU/UK residents: We rely on Standard Contractual Clauses for data transfers from the EU/UK to the US. You have rights under GDPR including access, rectification, erasure, restriction, portability, and the right to lodge a complaint with your local supervisory authority.
11. Children's privacy
The Service is not intended for users under 18. We do not knowingly collect data from anyone under 18. If you believe a minor has provided us data, please contact us and we will delete it.
12. Cookies and tracking
We use cookies and similar technologies for:
- Authentication (keeping you logged in)
- Preferences (dark mode, etc.)
- Analytics (PostHog session tracking)
- Referral attribution (Rewardful affiliate tracking, when applicable)
You can disable cookies via your browser settings; some features may not work without them.
13. Changes to this policy
We may update this Privacy Policy. Material changes will be communicated via email and/or prominent notice on the Service at least 14 days before they take effect.
14. Contact
Questions about this Policy or your data: hello@almonax.com
Almonax LLC
[registered address — to be added post-LLC formation]