Privacy policy
Last updated: 4 September 2026
This policy describes the data Safi processes, what the repository confirms today, and what needs external verification. It is written to be accurate rather than reassuring and is not Legal or Security approval.
1. Who we are
The Safi service is operated by Safi (legal entity being established), the controller of the personal data described in this policy.
Incorporation is not yet complete, which is why this site displays no commercial registration (CR) or VAT registration number. We will update this policy and the site as soon as registration completes.
For any question or request about your data, write to us at support@safi.sa.
2. What we collect
Account data: your name, email address, your role in the business, and your password stored as a cryptographic hash (scrypt) from which the password cannot be recovered.
Business profile: name, city, commercial registration number, VAT number, and VAT filing period.
Accounting data: customers, products, invoices and their lines, quotations, payments, expenses, and journal entries with their lines.
Conversation data: the text of your messages and the assistant's replies, plus associated results and suggested actions. Some older records may contain a raw exchange with a former provider in a legacy field that we temporarily retain for stored-data compatibility and safe schema migration; the current assistant does not read or write it at runtime.
Original request text: when an invoice record, quotation, or expense is created through the conversation, we store your request in your own words against that document, so every figure keeps the story of where it came from. This text forms part of the audit record and follows the current retention practice described below. Exact duration, scope, and legal sufficiency remain under qualified Saudi legal and tax review.
Usage data: operational events describing what happened in the product (for example: an invoice was created, a report was generated), which may include SAR amounts. These events do not carry your conversation text, your customers' names, or invoice line descriptions.
3. Why we process it, and on what basis
To provide the service itself: keeping your books, issuing invoice records, computing reports, and preparing preliminary VAT-return figures from supported Safi records. Some fields are not computed; review the figures before filing. Safi does not submit the return to ZATCA. The legal basis is performance of our contract with you.
For the current retention practice: accounting records and invoice records remain stored as described below. Exact duration, scope, and legal sufficiency remain under qualified Saudi legal and tax review.
To operate the assistant: your message and your business context are sent to the AI provider to generate a response and to execute accounting tools after you confirm them.
To improve the product and measure usage: our legitimate interest in understanding how the service is used and detecting faults.
4. Where your data lives and who processes it
Cross-border processing may occur. We do not establish an actual processing location, retention term, or data processing agreement for any processor from a provider name or local configuration alone; those facts are pending external verification.
The application uses Supabase for the database and Vercel for application hosting and request processing. The actual processing location, retention, and data processing agreement for each are pending verification.
The assistant uses OpenAI's Responses API. Your conversation text and the business context needed to fulfil a request are sent to it; tool results can include customer names and accounting figures. Every request sets store: false, which means Safi does not ask OpenAI to store the response for later API retrieval. This is not a zero-retention claim; location, retention, and a data processing agreement are pending verification.
Browser PostHog does not load until explicit analytics consent. It uses pseudonymous user and company identifiers, and current identity properties do not include name or email. Its location, retention, and data processing agreement are pending verification.
The Google Ads tag for acquisition measurement does not load until explicit analytics consent. Advertising storage, advertising user-data, and ad-personalization consent remain denied. The exact page URL, query fields, and measurement properties sent to Google Ads are pending runtime and vendor verification. Location, retention, and a data processing agreement are pending verification.
Vercel Web Analytics does not load until explicit analytics consent. Processing location, retention, and a data processing agreement are pending verification.
Chatwoot is optional support and runs only when configured. For an authenticated user it may receive a stable identifier, name, and email. Location, retention, and a data processing agreement are pending verification.
Moyasar provides the browser payment form and card tokenization, plus recurring payment-token APIs. Card details are entered into Moyasar's form; Safi code receives payment and token identifiers, masked card metadata, and amount, currency, and callback context, not the raw PAN or CVC. Production activation, location, retention, contracting entity, and a data processing agreement are pending verification; cross-border processing may occur.
The code uses Resend for transactional email when sending keys are configured. Production activation, location, retention, and a data processing agreement are pending verification.
Optional Axelor synchronisation: if your business enables the Axelor integration, accounting records are mirrored to a server that you nominate, which may be in any country. This option is disabled unless you request it.
These processes may include cross-border transfers of personal data. We do not claim KSA-only data residency or a specific processing region until documented external evidence is available.
5. How long we keep it
Accounting records and invoice records: currently remain stored in the application, including after account deletion completes. Retention duration, document scope, legal sufficiency, and any erasure exceptions remain pending qualified Saudi legal and tax review.
Account data: retained for as long as your subscription is active.
Conversations, assistant results, and any legacy exchange logs: currently retained in Safi's database with no fixed limit until you ask us to delete them. We are working on an explicit retention period and will publish it here.
Usage events: processor retention is pending verification and no specific period is claimed.
6. Your rights
You can contact us to request access, correction, erasure, or to ask about your data. This description is not a statement of blanket legal compliance; the legal framework needs specialist review.
To make a request about your data, write to us at support@safi.sa.
A copy of your data: Settings provides a link to download a ZIP export of company data and the signed-in user's private data. If you prefer, email us and we will help.
Current account-deletion behavior: when deletion completes, conversations are deleted, public invoice links are revoked, and company identity is anonymized, while financial records remain. This describes the current implementation; retention duration, document scope, legal sufficiency, and any erasure exceptions remain pending qualified Saudi legal and tax review.
Analytics consent: browser PostHog, Google Ads, and Vercel Web Analytics do not load until your explicit opt-in via the banner. Advertising user-data and ad-personalization consent remain denied. You can change your choice by deleting the safi-analytics-consent key from browser storage; the banner will appear again.
7. Security
What follows describes what is actually in place, without embellishment.
HTTPS/TLS on the public origin and processor connections in the actual production environment is pending operational verification; URLs in code are not treated as blanket evidence for every connection.
Passwords are stored as scrypt hashes with a unique per-user salt and compared in a timing-safe manner.
Login sessions are cryptographically signed and cannot be forged from the browser.
Each business's data is logically isolated from every other business in the database.
At-rest encryption evidence for the current production storage is pending verification; we do not infer it from a provider name.
To be completely clear: we do not hold SOC 2 or ISO 27001 certification, we have not commissioned an independent penetration test, and we do not apply field-level encryption within the database. When any of that changes we will say so here, with the date.
8. Changes to this policy
For any material change, and in particular a change in where your data is hosted or the addition of a new processor, we will update this page, revise the last-updated date above, and notify account holders by email.
9. Contact
For any question about this policy or your data, or to raise a complaint, write to us at support@safi.sa and we will answer plainly.
You also have the right to lodge a complaint with the competent personal data protection authority in Saudi Arabia.
Contact: support@safi.sa