Who we are and what this covers
Almanac is operated by Reverie Project, Inc., doing business as Almanac ("Almanac," "we," "us," or "our"). This Privacy Policy applies to usealmanac.com and Almanac's hosted product, Quill, APIs, command-line tools, connected accounts, managed browser, Wikis, and support services (together, the "Service").
Organizations use Almanac to connect work accounts, build a shared source-backed Wiki, and let AI assistants read information and take actions. An Organization usually controls the work data its members place in Almanac. We process that data to provide the Service to the Organization. We separately control account, website, security, billing, and support information used to operate Almanac.
If your employer or another Organization gave you access, its own policies may also apply. Ask that Organization if you have questions about how it uses information available through Almanac.
Information we collect
We collect the following categories of information:
- Account and Organization information. Name, email address, profile image, Organization name, membership, role, invitations, authentication records, and account settings.
- Customer Content. Files and text you upload; Wiki pages, Sources, citations, and guidance; Quill prompts, messages, transcripts, tool calls, outputs, and local agent memory; feedback; and other information you submit to the Service.
- Connected account data. Information you authorize Almanac to access from a Connected Service. "Connected Service" means a third-party or customer-provided account, application, API, MCP server, database, website, device, or other service you choose to connect. Depending on the permissions and feature, this can include communications; files and documents; events and meetings; tasks, projects, customer or support records; recordings and transcripts; operational or developer data; account information; and related metadata.
- Managed browser data.Website content, screenshots, form entries, downloads, actions, and session state that Quill uses at your direction. Browser cookies, local storage, and website credentials are stored with our managed-browser infrastructure, separately from Almanac's product database.
- Provider and action metadata. Connected provider, account label and identifiers, permissions, connection health, synchronization state, source provenance, and audit information such as the action or tool used, outcome, time, and a limited summary. We design these records to exclude authorization secrets and minimize Customer Content.
- Billing and support information.Plan, subscription, trial, usage, invoice and transaction metadata, and communications with us. Payment card details are collected and processed by our payment providers, not stored in Almanac's product database.
- Technical information. IP address, browser and device information, request and event timestamps, diagnostic logs, error reports, security events, and product usage information.
- Product analytics and session replay. We collect page navigation, feature actions and outcomes, device information, and a visual reconstruction of product interactions to understand usage and troubleshoot the Service. We configure replay to mask text, form inputs, and images and to exclude network request and response bodies. We do not intentionally send prompts, responses, Wiki text, search terms, source names, filenames, account identities, payment details, API key values, or raw errors to product analytics.
Customer Content may contain personal information about people who do not have an Almanac account. The Organization that supplies that information is responsible for having authority to do so.
Google Workspace data
If you connect Gmail, Almanac may search and read email threads, messages, drafts, labels, filters, and vacation settings. At your direction, Almanac may also create or manage drafts, send or reply to messages, organize messages and labels, move mail to or from Trash, and manage filters or vacation settings.
If you connect Google Calendar, Almanac may list calendars and read events, attendees, and availability. At your direction, Almanac may create, update, move, respond to, or cancel events.
Google data is used only to provide visible Almanac features: live answers and actions, source-backed Wiki updates you enable, security, and support you request. OAuth credentials are held by our account-connection provider rather than in Almanac's product database. Google data may be processed by our account-connection, hosting, storage, job-execution, and AI providers only to deliver those features. See our Subprocessors page.
We do not sell Google user data, use it for advertising, use it to determine creditworthiness, or use it to train or improve generalized AI models. Humans do not read Google user data except with your specific consent for support, when necessary for security, or when required by law.
Our use of information received from Google Workspace APIs adheres to the Google User Data Policy, including its Limited Use requirements. You can review that policy on the Google Workspace developer policy page.
Disconnecting a Google Account causes Almanac to delete or invalidate the active authorization through our account-connection provider and stops future reads, writes, and Wiki updates. Information already accepted into your Organization's Wiki remains as source-backed organizational knowledge until the Organization deletes it or asks us to delete it. See "Retention and deletion" below.
How we use information
We use information to:
- provide, maintain, secure, and troubleshoot the Service;
- authenticate users, maintain Organization memberships, and enforce permissions;
- connect accounts, answer questions, create and update Wikis, cite Sources, and perform actions that users request;
- operate Quill sessions and managed browser sessions, preserve continuity, and return results through web, CLI, and connected channels;
- process subscriptions, measure plan usage, and communicate about billing;
- respond to support, prevent abuse, investigate incidents, and protect users and the Service;
- improve reliability and product experience using feedback, diagnostics, and aggregated or de-identified information; and
- comply with law and enforce our agreements.
For people in the European Economic Area, United Kingdom, or Switzerland, our legal bases are performance of our contract, legitimate interests in operating and securing the Service, consent where requested, and compliance with legal obligations.
AI processing
Almanac sends relevant prompts, Customer Content, Wiki context, and connected account data to AI models to generate responses, organize Sources, maintain Wikis, and decide how to use tools. AI output can be incomplete or incorrect. Users should review important output and actions.
We use business API services whose inputs and outputs are not used to train provider models by default. We do not use Customer Content, including raw or derived Google Workspace data, to train or improve generalized AI models. AI providers may retain limited request data for abuse prevention and service operation under their business terms and data controls.
Retention and deletion
We retain information for as long as needed to provide the Service, maintain continuity and source-backed citations, comply with law, resolve disputes, enforce agreements, and protect the Service. Retention depends on the kind of information and why we hold it.
- Account, Organization, and billing records are generally kept while the relationship is active and for a reasonable period afterward.
- Wiki pages, accepted Sources, uploads, citations, Quill sessions, transcripts, and browser Contexts are kept to preserve the product experience until deleted by the Organization, the applicable provider lifecycle, or a verified deletion request.
- Disconnecting an Account deletes or invalidates its active authorization through our account-connection infrastructure and stops future provider access. Removing an Account from an Organization stops that Organization's future use. Neither action automatically erases previously accepted Sources or facts already incorporated into the Wiki.
- Security, diagnostic, action, and transaction records may be kept for a limited period after other data is removed. Backup copies may persist until overwritten through normal backup cycles.
To request deletion of an account, Organization, Source, connected data, or other personal information, email founders@usealmanac.com. We will verify the requester's identity and authority. An Organization may need to act on requests concerning Customer Content it controls.
Security
We use administrative, technical, and organizational safeguards designed to protect information. These include access controls, tenant scoping, encrypted transport, managed secret stores, separation of provider credentials from product content, short-lived authorization links, and restricted service credentials.
No system is perfectly secure. You are responsible for protecting your account, using appropriate Organization permissions, and deciding what data and websites to expose to an AI assistant. Tell us promptly at founders@usealmanac.com if you believe your account or data has been compromised.
International transfers
Almanac and its service providers operate in the United States and other countries. Information may therefore be processed outside the country where you live. Where required, we rely on contractual and other lawful transfer mechanisms designed to protect personal information.
Your rights and choices
Depending on where you live, you may have rights to access, correct, delete, or receive a copy of personal information; object to or restrict certain processing; withdraw consent; or appeal a privacy decision. You will not be discriminated against for exercising a privacy right.
You can manage memberships, Connected Services, Wiki feeds, and Channels through available Organization controls. You can also revoke access through a Connected Service's own permissions controls, such as the Google Account permissions page. Revoking access at the provider stops future access but does not itself delete data already stored in Almanac.
Send requests to founders@usealmanac.com. We may need to verify your identity, location, and authority. If an Organization controls the requested Customer Content, we may direct the request to that Organization. You may also use an authorized agent where applicable.
If you are in the EEA or UK, you may complain to your local data protection authority. California residents can request the categories and specific pieces of personal information collected, correction, deletion, and information about disclosures. Almanac does not sell or share personal information for targeted advertising.
Children
Almanac is a business service and is not directed to children under 13. We do not knowingly collect personal information directly from children under 13. If you believe a child has provided personal information, contact us so we can investigate and delete it as appropriate.
Changes and contact
We may update this Privacy Policy as Almanac changes. We will post the updated policy and effective date here. If a change materially affects how we use personal information, we will provide additional notice or seek consent when required.
Questions or privacy requests can be sent to founders@usealmanac.com.
Reverie Project, Inc., doing business as AlmanacSan Francisco, California, United States