Privacy Policy
Effective: 2026-08-08 · Version 1.0.0
Who this policy covers
This Privacy Policy explains what QayyimAI ("we", also known as قَيِّم) collects when your business uses QayyimAI Web, QayyimAI Desktop, or the optional Print Agent, why it's collected, and how you can request access, correction, or deletion.
QayyimAI is a business-management tool for small and medium businesses. This policy is written for the pilot phase of the product; see the legal review checklist for items that still require formal legal confirmation before broader public reliance.
Your business's role vs. QayyimAI's role
Your business controls the business data you enter into QayyimAI — your products, customers, sales, employees, and financial records. QayyimAI processes that data to provide the service: storing it securely, running the calculations and reports you use, and enabling features like AI assistance when you choose to use them.
This description is deliberately plain rather than a formal legal classification (such as "data controller"/"data processor" under a specific law) — see the legal review checklist for confirming any such classification with counsel before it is relied on.
What we collect
Account & identity: your name, phone number (used to sign in), role, branch assignment, and a securely hashed PIN — never your PIN itself in readable form.
Business data you enter: products, categories, suppliers, customers (name, phone, notes, balance — no address field exists), purchases, sales, invoices, quotes, expenses, payments, credit notes, and related records.
HR data, if your business uses those features: employee salary/commission fields, attendance check-in/out times, payroll and commission payment records.
Device, Desktop, and sync data: identifiers for devices connected to your account, and — if you use QayyimAI Desktop — a local copy of your business data stored on that device for offline use.
AI-related data: see "AI processing" below and the full AI Use Disclosure page.
Security & operations logs: an audit trail of actions taken in your account, and technical security signals (such as repeated failed sign-in attempts) stored as one-way hashes, never as raw phone numbers or PINs.
Why we use it
To provide the core service: storing and displaying your business data, running your sales/inventory/finance workflows, generating your reports.
To secure your account: authentication, PIN-lockout protection after repeated failed attempts, and audit logging of sensitive actions.
To operate optional features you choose to use, such as AI assistance, WhatsApp document links, or Desktop synchronization.
We do not use your business data for advertising, and we do not sell your data.
Authentication & security processing
Sign-in uses a phone number and a 4-digit PIN. Your PIN is stored only as a one-way cryptographic hash — it cannot be reversed back into the original PIN by QayyimAI or anyone else with database access. Repeated failed sign-in attempts trigger a temporary lockout.
Security-relevant events (such as suspicious sign-in patterns) are recorded using hashed identifiers rather than raw phone numbers, IP addresses, or PINs, specifically so that log data itself cannot be used to reconstruct your credentials.
AI processing
QayyimAI offers an optional AI assistant on paid plans. When you use it, your question and the tenant-scoped business data needed to answer it are sent to our AI provider (Anthropic) to generate a response. Your PIN, session tokens, and other secret values are never included in what is sent, by design and by a runtime safeguard.
The content of your AI conversations is not stored by QayyimAI after the response is generated — only anonymous usage counters (for your plan's monthly limit) are kept. Any change the AI proposes is saved only as a draft that a human on your team must approve before anything actually changes.
QayyimAI does not control Anthropic's own internal data handling and does not represent a specific training-data policy on Anthropic's behalf — see the legal review checklist if you need that confirmed contractually.
Full detail — including exactly what data categories are and are not sent, and how approval works — is published at /legal/ai.
Device, Desktop, and sync data
QayyimAI Web requires an internet connection and does not store business data on your browser between sessions. QayyimAI Desktop is a separate, local-first application: it stores a copy of your business data in a local database on the computer it's installed on, so it can keep working without a constant connection, and synchronizes with the cloud when connected.
If a device running Desktop is lost, stolen, or decommissioned, the local copy of your data on that device is not automatically erased by QayyimAI — see the Terms' Desktop section and the data-request workflow for how to handle that case.
Logs, security, and monitoring
We keep an audit trail of actions taken in your account (who did what, when) for security and accountability. We also run internal operational monitoring to detect service problems. This is engineering telemetry for keeping the service running and secure — it is not a real-time, human-monitored alerting operation today; see the legal review checklist for the current operational maturity of that system.
Third-party service providers
QayyimAI runs on infrastructure and services provided by others. Today, that always/conditionally includes:
• Vercel — hosts the QayyimAI Web application.
• Supabase (PostgreSQL) — hosts the database that stores your business data.
• Anthropic — provides the AI model used by the optional AI assistant, only when you use that feature on a plan that includes it.
The following are not currently in use, and no data is sent to them: a dedicated SMS/email delivery provider for account recovery (self-service PIN recovery exists for verifying a code, but real message delivery is not yet wired to a live provider — recovery today is handled by an authorized person on your team or, if needed, QayyimAI support), a payment processor (billing is currently arranged directly, not through an automated payment system), and any analytics/advertising/tracking service.
If any of these change (for example, a payment processor or a real SMS provider is added), this policy will be updated before that provider starts receiving data.
Hosting & storage location
Your data is stored in a managed PostgreSQL database (Supabase) and served through Vercel's hosting infrastructure. QayyimAI does not independently operate its own data centers.
Data retention
Business records (sales, invoices, customers, etc.) are kept for as long as your account is active, so your reports and history remain accurate.
Security and audit logs (the account action trail, AI usage counters, security event records) do not currently have an automated deletion schedule — they are retained until manually cleared as part of an operational process, not deleted automatically after a fixed period. This is a limitation we disclose honestly rather than promising a retention window that isn't implemented yet.
One narrow exception: short-lived security throttling records (used to detect repeated failed sign-in attempts) are automatically pruned after about 30 days.
Account, employee, and business (tenant) deletion
An individual employee account can be deactivated by your business's owner or a manager at any time — this immediately blocks that person's sign-in while preserving their historical records (their past sales, audit entries, etc., which remain part of your business's own history).
A full business account cannot currently be deleted through a self-service button — it can be suspended (which blocks all sign-in immediately) by QayyimAI. A request to permanently erase an entire business account's data is handled as a manual, verified operational request — see the data-request workflow in the legal review checklist. We do not claim this happens instantly or automatically today.
Backups
QayyimAI does not run its own scheduled, automated application-level backup as a marketed guarantee. Database infrastructure-level backup/recovery is provided by our hosting/database provider; we have not independently verified the exact retention window of that infrastructure-level backup as of this policy's effective date. Practically, this means a deletion may not be instantly and permanently unrecoverable from every layer — see the data-request workflow's backup caveat.
Accessing, correcting, or exporting your data
Your business's owner and managers can already view, correct, and export a substantial portion of your business data directly in the app — including filtered CSV exports of your sales, purchases, expenses, invoices, and customer debts. A request for something beyond what those in-app tools cover (for example, a full account data export or a formal access/correction/deletion request) is handled manually — see the data-request workflow, and reach us through the contact channel below.
Business use only
QayyimAI is a business-management tool intended for use by adults operating a business, not a consumer product directed at children. It is not designed to knowingly collect data about minors.
Changes to this policy
We may update this policy as the product changes. The version and effective date at the top of this page always reflect the current version; material changes will be reflected there.
Contact
For privacy questions or a data-access/correction/deletion request, contact us through the channel listed on our website (the same contact used for sales/support during the pilot phase). A dedicated privacy contact channel may be published here once formally assigned — see the legal review checklist.