Skip to main content

[ SYSTEM ]

Privacy

LAST UPDATED // AUGUST 2026

You trust me with your time, your tools, and the details of your work. I keep that trust by telling you plainly what I see, what I hold, and who sees it with me — and by holding as little as I can.

Your account

When you sign in with Google, GitHub, Slack, or a magic link, I receive your profile basics: name, email address, and profile picture. I use them to know it is you, keep your account secure, and address you by name. The sign-in itself does not give me access to your mail or files.

Conversations and tasks

What you write to me — prompts, uploaded files, the tasks you set — is your content. I process it to do the work you asked for and to show you the results. Prompts and responses pass through the AI model providers that power my reasoning; they process that data to generate answers under their own terms.

Connectors

When you connect a service — Google, GitHub, Slack, Telegram — I store the access tokens that let me work on your behalf. I only touch what you ask me to touch, you can review your connectors at any time, and you can revoke any of them in one action.

What I do on your behalf

I can take actions — sending mail, creating calendar entries, running tasks. Every action is logged to your account so you can review what I did. Actions with lasting effects need your clear instruction, and where possible I confirm before anything destructive.

Usage and billing

I keep a record of the work I do for you: requests, tokens, and spend, so your dashboard and your invoice stay honest. That data belongs to your account and travels with your plan.

Email delivery

I send sign-in links and notices through Resend. They see the technical envelope — address, subject, delivery status — so the mail actually reaches you.

Hosting

The site runs on Cloudflare. They handle standard request data — IP address, browser details — to deliver pages and keep the door safe from abuse. Web analytics, when enabled, run through Cloudflare's cookie-free beacon and never follow you across sites.

Payments

Subscriptions and purchases run through Dodo Payments. They process your card; I only ever see the outcome — paid, failed, or refunded — never the card itself.

Retention

I keep your data while your account is active and as long as I need it to serve you. Delete a conversation and it leaves your history. Close your account and I delete your personal data within 30 days, except what the law requires me to keep — billing records, for example.

International transfers

I operate from Saudi Arabia, and some of my service providers — Cloudflare, Resend, Dodo Payments, and the AI model providers — process data in other countries. Wherever your data travels, it goes under contract and only for the purposes described here.

Your rights

You can ask me what I hold about you, correct it, or ask me to delete it — including the rights granted by the Saudi Personal Data Protection Law and, where they apply to you, GDPR-style rights. Write to me and I will act on it. When I am wrong, I say so and fix it.

Age

The service is for people 18 and older. I do not knowingly collect data from children. If you believe a child has given me data, contact me and I will delete it.

Security

Data is encrypted in transit and at rest. Access to production systems is restricted, authenticated, and logged. No system is unbreakable — if something goes wrong that affects your data, I will tell you directly.

Changes

If this policy changes materially, I will say so on this page before the change takes effect. The last-updated date above always reflects the current version.

Contact

Questions, requests, complaints — write to shura@al-shura.ai. I read everything, and I respond within 30 days, or sooner where the law requires.

SIGN-OFF GATE // LEGAL REVIEW OF THIS POLICY IS IN PROGRESS AND COMPLETES BEFORE GENERAL AVAILABILITY.

OPERATOR // DARRAI COMPANY — AL-SHURA, RIYADH, SAUDI ARABIA // DATA CONTROLLER UNDER THE SAUDI PDPL