Data & privacy
Fig Almanac is a journal first. These notes describe how your data is handled, in plain language. The short version: what you add is yours, it starts private, publishing is always your explicit choice, and we don’t sell anything to anyone.
What we store
Your email address — it’s your account’s identity however you sign in: invites are addressed to it, and the emailed sign-in link uses it. If you sign in with Google, we also store your Google account’s id so we can recognize you next time, and the name on your Google profile becomes your starting display name (editable anytime). We never see or store a password either way, and we take nothing else from Google. Beyond that: your chosen handle and profile details, and the culture entries — the figs — you add: books, films, music, podcasts, shows, performances, places, and the notes and images you attach to them. If you connect an outside service to import listening or watching history, we store what’s needed to run that sync and the data it returns.
Private by default
Everything you add is visible only to you until you decide otherwise. Publishing works at three levels: your whole almanac, a single category (say, just your books), or an individual fig. Each level has a middle setting, neighbors, described below. Anything you don’t publish stays private — on shelves, in lists and their progress counts, in search, in the preview cards shared links show, and in season harvests, which include only figs you have published. You can unpublish at any time, though pages already seen or indexed elsewhere may take time to fall out of caches; the preview image for a shared list link can linger up to a day. Two things sit outside per-fig controls and follow their category’s setting instead: Up Next notes and lanes, and the list names on a fig’s card.
Neighbors
Neighbors are keepers you have mutually accepted in The Grove. Whatever either of you sets to neighbors — an almanac, a category, a fig — opens to the other, and to nobody else. Asking someone shows them your handle and display name; nothing else. Any signed-in keeper can find an account by typing its exact handle or exact email address (that is how family reaches a private almanac); the address itself is never shown, and lookups are rate-limited. Declining or withdrawing is silent.
Cookies and sign-in
One cookie, for keeping you signed in. No advertising cookies, no cross-site trackers, no fingerprinting. Sign-in links work once, expire in fifteen minutes, and only sign you in when you press the button on the page they open. If a device you no longer trust is signed in, “Sign out everywhere” in Settings ends every session at once. Sign-in requests, the contact form, and searches are rate-limited; the counters hold a hashed address for a couple of days, never the address itself.
Who else touches the data
Fig Almanac runs on a small set of infrastructure providers: Vercel (hosting), Neon (database), Resend (transactional email), and Cloudflare (DNS). Each processes data only as needed to run the service. Basic, aggregate hosting analytics may exist (page counts, not people). No data is ever sold or shared for advertising.
Your data is yours
You can export everything you’ve added as a spreadsheet anytime — it’s the “Download my data” entry in the ☰ menu, one click, no asking. And you can ask for your account and all its data to be deleted — permanently, from the live database. (Backups age out on their own schedule.) For deletion, use the contact page while account tooling is still growing.
It won’t just disappear
The database lives on redundant cloud storage, and every night an automatic snapshot of everything is written to a second storage provider as a private, access-controlled file, kept on a rolling schedule of daily, weekly, and monthly copies. Restores are rehearsed, not assumed. If the site ever winds down, you’ll get notice and an export well before anything goes dark — an almanac is a decades-long record, and we treat it that way.
Beta honesty
Fig Almanac is in an invite-only beta. Features described here — publishing controls, exports, deletion — are being built in the open, and this page will be updated as they land. If anything here changes in a way that affects your data, you’ll hear about it by email first.
Last updated September 2, 2026.