Effective date: July 21, 2026
Privacy Policy
This policy explains how Alma collects, uses, stores, and shares information when you use the Alma website, desktop app, web app, and related services.
Who We Are
Alma is currently operated by Noah Lloyd Robson, who is the controller of the account, billing, support, and product analytics information described in this policy. In this policy, "Alma," "we," "us," and "our" refer to Noah Lloyd Robson operating the Alma service.
Alma is an AI workspace for working with documents, including local Markdown files and Google Docs or Google Sheets that you choose to connect.
You can contact us through the in-app support chat or at privacy@almagrants.com.
Information We Collect
We collect information you provide or authorize, including:
- Account information, such as your name, email address, and profile image when you sign in with Google.
- Document information you create, import, connect, edit, share, or ask Alma to use, including document text, titles, metadata, comments, suggestions, folders, chats, and settings.
- Google user data you authorize Alma to access, such as your Google account profile, the Google Docs or Sheets you select, file metadata, document content, comments, suggestions, thumbnails, and edits needed to provide the app.
- Support messages and attachments you send to us.
- Agent session traces you choose to share, which can include prompts, conversation context, responses, visible reasoning, document content passed through agent tools, tool inputs and results, file changes, errors, model information, and timing information.
- Billing information handled by payment providers, such as Stripe. We do not store full card numbers.
- Basic technical information, such as device, browser, app version, logs, and the product analytics described below.
How We Use Information
We use information to:
- Provide, maintain, secure, and improve Alma.
- Sign you in, keep your session active, and manage your account.
- Show, search, edit, share, and sync documents you choose to use with Alma.
- Send document content and instructions to AI providers only when needed to perform actions you request inside Alma.
- Process payments, subscriptions, support requests, and service notices.
- Detect, prevent, and investigate abuse, security issues, and service errors.
- Comply with legal obligations and enforce our terms.
Product Analytics
Product analytics is enabled by default on new Alma desktop installations. You can turn it off at any time in Settings under Privacy. Turning it off stops Alma from sending new product analytics events from that installation.
When product analytics is enabled, Alma sends limited usage events to PostHog. These events can include app launches, sign-in and account connection events, feature actions, agent run starts and outcomes, run duration, broad error categories, app version, operating system, selected AI engine and model, billing mode, and whether a run had a document or project context. Alma also sends a stable installation identifier before sign-in, the Google account identifier after sign-in, and the domain portion of the signed-in email address so we can understand usage across organizations.
Alma does not send document text, document titles, prompts, outputs, file paths, API keys, OAuth tokens, or full email addresses to PostHog. PostHog processes this data for Alma in its European Union cloud region.
We use product analytics to understand adoption, see which features are useful, improve reliability, and decide what to build. Where applicable, we rely on our legitimate interests in operating and improving Alma. We limit the fields collected, keep document content out of analytics, use European Union hosting, and provide the in-app opt-out to protect users' interests. You may also object by contacting us.
Optional Agent Session Sharing
Agent session sharing is off by default. You can choose to turn it on in the desktop app under Settings and Privacy. When it is on, Alma shares future agent sessions so we can investigate failures and improve agent quality. We process these sessions based on your consent.
A shared session can contain sensitive information from your work, including prompts, prior conversation context sent into that session, responses, visible reasoning, document passages the agent read, tool inputs and results, and changes the agent made. Alma compresses the session, sends it over HTTPS, and encrypts the session contents before database storage. Access is limited to the operator through the private administrator interface.
Shared sessions are deleted within 30 days. You can stop sharing future sessions at any time by turning the setting off. You can also delete every session currently stored for your account from the same settings page. Withdrawing consent does not affect processing that occurred before withdrawal.
Legal Bases
Depending on where you live, we process personal information on these legal bases:
- To perform our agreement with you, including signing you in, providing requested document features, and managing subscriptions.
- For our legitimate interests in operating, securing, supporting, and improving Alma, provided those interests are not overridden by your rights and interests.
- With your consent where we specifically ask for it.
- To comply with legal obligations.
Google User Data
Alma requests access to Google user data only so the app can sign you in and work with the Google Docs or Sheets you choose to connect. We use Google user data to display your connected files, read document content for requested app features, apply edits you approve or direct, show comments or suggestions, and keep your document library in sync.
We do not sell Google user data. We do not use Google user data for advertising. We do not transfer Google user data to third parties except as needed to provide or improve Alma, comply with law, protect users, or complete an action you request, such as sending selected document content to an AI provider for a prompt you run.
Alma's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
How We Share Information
We share information only in limited situations:
- With service providers that help us run Alma, such as PostHog for product analytics, and providers for hosting, databases, payments, email, support, and AI infrastructure.
- With people you choose to share documents with, according to the permissions you set.
- With Google when you use Google sign-in, Google Picker, or Google APIs.
- When required by law or needed to protect rights, safety, and security.
- In connection with a merger, acquisition, financing, or sale of assets, subject to this policy or a replacement policy disclosed to users.
Security and Retention
We use reasonable administrative, technical, and organizational measures to protect information, including HTTPS, access controls, and server-side storage of OAuth tokens. No internet service can guarantee perfect security.
We keep information for as long as needed to provide Alma, comply with legal obligations, resolve disputes, and enforce agreements. If you disconnect Google, we remove the stored Google authorization token for that connection. If you delete content, we remove it from active use subject to backups, logs, legal requirements, and abuse prevention needs.
We retain account-linked product analytics for no longer than 12 months after collection. We may retain aggregated or deidentified information that no longer identifies a user or account for longer.
Your Choices
You can choose which Google files to connect, disconnect Google access, delete or edit Markdown files, change sharing permissions, and stop using the service. You can also manage or revoke Alma's Google access from your Google account permissions page.
You may contact us to request access, correction, deletion, or export of personal information, or to object to processing based on legitimate interests, through the in-app support chat or at privacy@almagrants.com, subject to identity verification and applicable law.
Children
Alma is not directed to children under 13, and we do not knowingly collect personal information from children under 13.
Changes
We may update this policy from time to time. If changes are material, we will take reasonable steps to notify users, such as posting an updated policy or providing an in-app notice.