Legal

Privacy Policy

Effective date: September 6, 2026 · Operated by Simha Online, Dubai, UAE · Contact: hello@simhaonline.ai

1. What we collect

Account data: email address, hashed password (PBKDF2), role, and consent records.
Operational telemetry: request timestamps, model names, token counts, and HTTP status codes — never prompt or response content.
Provider credentials: API keys and OAuth tokens for the Upstream Accounts you connect, stored encrypted at rest.
Security data: hashed IP addresses for signup/login abuse prevention and audit logs.

2. What we do NOT do

We do not read, store, or train on your prompts or completions. We do not sell personal data. We do not share your provider credentials with anyone — they are decrypted only in-memory to authenticate your requests to the provider you chose.

3. Why we process data (legal bases)

Contract: to operate your account and route your requests. Legitimate interests: fraud/abuse prevention and platform security. Consent: optional marketing email, withdrawable at any time.

4. Sharing

Data is processed by our infrastructure providers (hosting, managed database) under data-processing agreements, and by Stripe for billing. Requests are forwarded to the model providers you explicitly connect — your prompts go to those providers under their terms, not ours.

5. Retention

Telemetry is rolled up and retained for usage analytics and billing integrity; request-level rows age out on a rolling window. Account data is kept until you delete your account, after which it is removed within 30 days except where law requires retention (e.g., billing records).

6. Your rights

You can access, correct, export, or delete your personal data from the dashboard, or by emailing hello@simhaonline.ai. EU/UK users may lodge a complaint with their supervisory authority; UAE users with the UAE Data Office.

7. Security

Encryption in transit (TLS) and at rest for credentials, session cookies are HttpOnly/Secure/SameSite, login throttling and lockouts, audit logging of administrative actions. No system is perfectly secure; we monitor continuously and will notify affected users of any breach as required by law.

8. Cookies

We set one essential cookie (simha_session) to keep you signed in. No advertising or third-party tracking cookies are used.