Privacy Policy
How the standard Almond service handles account, site, operational, and end-user data.
1. Provider, roles, and scope
Yeira Inc., a United States company provides Almond. Yeira is the controller for personal data it determines how and why to process for Almond accounts, service security, legal compliance, support, and operations. For personal data a customer or its agent places in a site, form, file, or record, the customer generally determines the purpose and means of processing and Yeira generally acts as its processor or subprocessor. The customer's privacy policy, not this one alone, must explain the customer's site-level processing.
2. Data we process
| Category | Account identifiers such as name, email, optional profile image URL, password verifier, Google sign-in identifier, sessions, and authorization records. When Google sign-in is used, Almond validates the ID token with Google and stores the returned Google subject identifier, verified email, profile name, and optional profile image URL. |
|---|---|
| Customer content | Published HTML, files, domains, collection definitions, submitted form fields, structured records, revisions, protected endpoint and credential values supplied for customer-directed actions, and export data chosen by the customer or its agent. Protected values are encrypted and are not returned through normal product interfaces. |
| Operational data | Capability metadata, timestamps, usage counters, browser error messages and optional user-agent strings, hashed client fingerprints used for abuse controls, safe action hostnames, action and trigger metadata, and redacted delivery status. Almond does not retain rendered action URLs or bodies or external-provider response bodies as delivery receipts. Raw source IP addresses are not stored in the rate-limit table by the application, although infrastructure providers may process network request data to deliver and protect the service. |
| Communications | Support, commercial, security, and legal communications provided to the operator. |
3. Why we process data
We process data to provide and secure accounts and sites, execute authorized publication and data operations, authenticate users and agents, maintain revisions and recovery functions, diagnose errors, prevent abuse, provide support, comply with law, and improve service reliability. Depending on context, the legal basis may be performance of a contract, legitimate interests in operating and securing the service, consent, or a legal obligation.
Cookies and browser storage
Almond uses strictly necessary first-party cookies for a seven-day account session and CSRF protection. The session cookie is Secure, HttpOnly, and SameSite=Strict; the CSRF cookie must be readable by the account application so it can prove state-changing requests came from the configured control origin. Almond's account application does not store its session capability in local storage and does not use advertising or analytics cookies. Google Identity Services may receive request metadata and use Google's own cookies or browser storage under Google's policies when its script and sign-in interface load.
4. Agentic harnesses and third parties
Almond receives the requests a connected harness sends to it, but Almond does not control what that harness previously collected, inferred, retained, or disclosed. A harness may send customer or end-user data to model providers, tool providers, observability systems, or other services before or after calling Almond. A customer-configured protected action sends only the approved projected fields to the customer's selected external endpoint, which then processes them under that provider's and customer's terms. The customer must evaluate all of those flows, configure retention and training controls, provide required notices, and enter any required agreements with those providers.
5. Disclosures and subprocessors
Data may be disclosed to infrastructure, authentication, domain, security, and support providers that help operate the service, and when required by law or a valid legal process. The standard deployment uses Convex for application compute, database, and file storage; Google for loading the optional sign-in interface and, when selected, identity verification; and AWS services when managed custom-domain provisioning is used. A customer may request then-current subprocessor information through its contractual contact.
Google sign-in and remote images
The account page loads the Google Identity Services client from Google so the optional sign-in control can be displayed. Google therefore may receive network and browser metadata when the account page loads, even if the user does not complete sign-in. Completing sign-in sends the Google ID token to Almond, which validates it through Google's token-information service. When an account has a remote avatar URL, including a Google profile image, the user's browser contacts that image host directly. That host may receive the user's IP address and browser metadata; account avatar requests are configured with a no-referrer policy.
6. Retention and deletion
Data is retained while needed to provide the service, secure it, meet legal obligations, resolve disputes, and enforce agreements. Retention can differ by data type. Expired sessions, authorizations, and security counters are removed on operational schedules. Successful action inputs are removed promptly; dead-letter inputs remain only through the bounded repair window, and terminal redacted action receipts are scheduled for deletion after 30 days. Revisions, runtime errors, and customer records may persist until removed through site-level product controls, site deletion, or an agreed deletion request. Site transfer erases protected action ciphertext and requires reconnection by the new owner. Account deletion removes the account profile, sessions, authorizations, and domain entitlements only after site access has been deleted or transferred. Backups may age out separately. Customers are responsible for implementing site-level and external-provider retention and handling end-user requests.
7. Security
Almond uses measures designed for the service's risk, including scoped capabilities, hashed credentials, tenant authorization checks, origin separation, rate limits, and restricted infrastructure identities. No system is completely secure. Customers must secure their harnesses, accounts, endpoints, credentials, generated applications, and downstream exports.
8. EEA and UK rights
People in the European Economic Area or United Kingdom may, subject to applicable conditions, request access, correction, erasure, restriction, portability, or objection; withdraw consent where processing relies on consent; and complain to their local data-protection supervisory authority. They may also object to processing based on legitimate interests. Site end users should first contact the customer operating that site because Yeira may act only on that customer's instructions. Yeira will assist the customer as described in the Data Processing Addendum.
9. International transfers
Yeira is established in the United States and Almond's providers may process data in the United States or other countries. Where EEA personal data is transferred to a country without an applicable adequacy decision, the parties will use an available lawful mechanism, such as the European Commission's Standard Contractual Clauses adopted by Decision (EU) 2021/914, with the appropriate module and supplementary measures. UK transfers will use an applicable UK transfer mechanism. A transfer mechanism must be validly incorporated into the applicable Agreement; this policy alone does not execute it.
10. EU representative
If Article 27 GDPR requires Yeira to appoint a representative in the European Union, Yeira will identify that representative here before offering the affected processing. No statement on this page should be read as claiming an exemption or appointment that has not been documented.
11. Children and changes
The standard service is not directed to children and customers must not collect children's data without all required authority, safeguards, and agreements. We may update this policy and will revise the effective date when changes are material.