← Back to Almanac

Privacy Policy

Effective 10 July 2026

The short version:

Who we are

Almanac (almanac.report) is operated from Australia as a sole-trader business. Privacy questions and requests: hello@almanac.report. We handle personal information in line with the Australian Privacy Principles.

What we collect

  • Account details:your email address, a password (stored as a hash by our authentication provider, so we never see it), and your email preferences, such as whether you've opted in to our newsletter.
  • Content you give us: order-confirmation emails you forward or paste (processed to extract items, prices, dates and order numbers), plus subscriptions, client tags, invoices and business details (such as your business name and ABN) you enter. Invoices you create can include client contact details you enter (their name, email address and postal address); this is personal information about other people that we store so we can generate and display the invoice for you.
  • Billing records:your card details go directly to Stripe. We never see or store card numbers. We store only Stripe's identifiers for your customer and subscription, and your plan status.
  • Technical basics: the operational logs any web host keeps (IP address, request times, and the URL requested, which for your spreadsheet feed includes your feed token) to run and secure the service. We currently use no third-party analytics or advertising trackers, and our only cookies are the ones that keep you signed in.

Forwarded emails, specifically

Emails you forward to your personal Almanac address are received by our inbound email processor (Postmark) and parsed to extract order details. The extracted purchase records are stored in your account, where you can edit or delete them. The raw email is not stored in your Almanac account; it is retained temporarily on Postmark's systems in the United States (under their standard retention, currently around 45 days) and then deleted. We never use your email content for anything other than providing the service to you.

Who processes data for us

We use a small set of infrastructure providers to run Almanac:

  • Supabase: our database and authentication, hosted in Sydney, Australia.
  • Vercel: web hosting and delivery (a US company with global infrastructure).
  • Postmark: inbound email processing (US).
  • Stripe: payment processing (US, with Australian operations).
  • ImprovMX: email routing and forwarding for our almanac.report addresses (US).

Because some providers operate overseas, limited personal information may be disclosed outside Australia (mainly to the United States) in the course of running the service. We choose established providers with strong security practices, and we don't permit them to use your data for their own purposes.

Why we use your information

To provide the service you asked for; to secure it and prevent abuse; to bill paid plans; to answer your messages; and to send service emails (like sign-in links or notices about your subscription or these policies). We don't send marketing email without your consent, we don't sell personal information, and we don't use it for third-party advertising.

Children

Almanac isn't designed for children. You should be at least 16 to create an account (and 18 to buy the Business plan). We don't knowingly collect personal information from anyone under 16. If you believe a child has given us their information, email hello@almanac.report and we'll delete it.

Your controls

  • Access & export: your data is visible in the app. Your purchase records export anytime (xlsx download, CSV feed); subscriptions and invoices are viewable in the app, with invoices printable to PDF.
  • Correction: every record can be edited or deleted in the app.
  • Everything else:for personal information that isn't visible in the app (such as operational logs or billing identifiers), email us and we'll give you access to it or correct it.
  • Deletion: email hello@almanac.report and we will delete your account and associated data within 30 days (some billing records must be retained where the law requires, e.g. tax records of payments).
  • Feed token:your spreadsheet feed URL contains a personal token. Because the token travels in the URL, it can appear in server logs and browser history, so treat the feed URL like a password. If it leaks, contact us and we'll rotate it.
  • Newsletter:if you opted in, you can turn it off anytime in Account, and every newsletter includes a one-click unsubscribe link. This doesn't affect essential service emails like sign-in links and billing notices, which we still need to send you.

Security

All traffic is encrypted (HTTPS). Each account's data is isolated with row-level security and per-account scoping. Access to production systems is limited to the operator. No online service can promise perfect security, but if a data breach ever occurs that is likely to result in serious harm, we will notify you and the OAIC as required by the Notifiable Data Breaches scheme.

Retention

We keep your data while your account is active. If you delete your account, we delete your data within 30 days, except minimal records we're legally required to keep (such as records of payments). Backups age out on a rolling basis.

Complaints and changes

If you have a privacy concern, email us first. A human reads it and we'll respond within a reasonable time. If you're not satisfied, you can complain to the Office of the Australian Information Commissioner (oaic.gov.au). If we make material changes to this policy, we'll notify you by email or in the app before they take effect.