Beta · An independent service by O AI — not a government website or legal advice

Draft — pending lawyer review
مسودة — بانتظار مراجعة المحامي
This text is an early draft that a lawyer has not reviewed yet, and it may change before launch. Questions: info@oai.sa

Privacy Policy

This Policy explains how we handle your personal data in Dalni: what we collect, why, where it is stored, who sees it, how long we keep it, and what your rights are. It is written under the Saudi Personal Data Protection Law and its Implementing Regulations.

Dalni is run by O A I Company For Artificial Intelligence (commercial registration no. 7053520024), based in Al Khobar, Saudi Arabia. We are responsible for your data in Dalni.

On every visit: a random identifier for this browser kept in a cookie, and, when you ask for a sign-in code, send a report without signing in or start a purchase, the result of a check that the request comes from a person. We use the browser identifier to limit how fast usage events are sent, to remember for a day that this browser passed the check, and to link usage events (see "Technical data" below) [to be reviewed by the lawyer]. A question gets an answer only once you are signed in.

When you sign in: your email address, which we store encrypted, with a partly hidden copy and a one-way fingerprint used to look it up; your name, if you add it; and a record of your consent: the age confirmation, the terms version, when you accepted, and a fingerprint of your network address. When your account receives the welcome credits: a one-way fingerprint of your email address and when they were given, so that address never gets them twice [to be reviewed by the lawyer].

Your chats: your questions and their answers, the complaint texts we prepare for you, your ratings of answers, and your reports of wrong answers with any note you add.

Credits and purchases: your balance and its history, and your purchases (pack, amount, status, receipt number). Your card details are entered on the payment provider's page and never reach us.

Sessions: for each sign-in session, when it started and when it was last used, so you can see your sessions in Account and sign out of other devices, plus one-way fingerprints of the browser identifier and of the network address it started from, for protection.

Technical data: your network address (used for protection and to apply limits, and stored as a one-way fingerprint where possible), your browser type, and error logs. Also usage events, such as which pages were opened, that a question was asked and how it was answered, purchases started and completed, and the campaign and the website (its name only) that brought you to us, if any. Each event is linked to the random browser identifier, and to a coded reference to your account when you are signed in, so we can count visitors and users and see where people stop. An event never holds your name, email address, question text or network address.

Before we store your question, note or complaint text, and before any text is sent to the AI provider, we hide anything that looks like a national ID or iqama number, a border number, an IBAN, a card number, a phone number, an email address, a passport number, or a verification code, replacing it with "[•••]".

Do not write sensitive details about yourself or others in a question — such as health, financial or criminal details — beyond what is needed to understand it.

To provide the service you asked for: answering your questions, keeping your chats, managing your credits and purchases, and sending sign-in codes and receipts.

To protect the service: preventing abuse and bots, applying usage limits, and investigating faults.

To improve the answers: we review questions we could not answer, after sensitive numbers are hidden, to add new answers, and we may use such masked questions in answer-quality tests [legal basis — to be reviewed by the lawyer].

To understand how the service is used: from the usage events (section 2) we count visitors, questions and purchases and see where people stop, to improve Dalni [legal basis — to be reviewed by the lawyer].

To meet legal obligations: such as keeping purchase records for as long as accounting and tax rules require.

We do not sell your data. We do not use it to train AI models, and our providers do not use it for that either.

When the answer to your question is not among the prepared answers, we may send the question, with sensitive numbers hidden, to a cloud AI provider that processes it in the European Union, to write a summary from official pages or from the prepared answers. The provider does not use what we send to train its models.

We keep a record of each such call (cost, timing and the result of checking the answer) to monitor quality and cost.

Normally, your browser's or device's speech service turns your voice into text, and the company behind your browser or device may process it to do so. Only the text reaches Dalni, never the recording.

If we turn on our own speech-to-text and you are signed in, a short recording of your voice is sent to Dalni to be turned into text by the cloud AI provider, then the recording is deleted — we do not keep it — and the text stays in your chat like any question you type. For each recording we keep metadata only, such as its length and whether the conversion worked.

The Listen button reads the answer aloud with your own device's voice and sends nothing to us.

We use service providers, each under a contract that limits what it may do with the data: a cloud hosting provider (servers and database), an email delivery provider (sign-in codes and receipts), a bot-protection provider (checks that a request comes from a person and sees signals from your network and browser), a cloud AI provider in the European Union (sections 5 and 6), and a payment provider (payments and refunds).

We may also disclose data where a competent Saudi authority lawfully requires it.

Database and servers: [hosting region — to be confirmed before launch].

Some data is processed outside the Kingdom: text sent to the AI provider (in the European Union), email sent through the email provider, and the bot-protection check's signals. Each carries the minimum the task needs and is covered by contractual commitments consistent with the Law's rules on transfers outside the Kingdom [mechanism — to be reviewed by the lawyer].

Sign-in codes: deleted within 7 days.

The email fingerprint for the welcome credits: kept even after the account is deleted, because it is what stops the same address getting them twice [period — to be reviewed by the lawyer].

The chats in your account: kept while your account exists, until you delete them or the account.

Usage events: each is deleted 400 days after it happened. Deleting your account does not delete them sooner, but the account they point to no longer holds your email or name [deleting them with the account — for the lawyer to decide].

Records of AI calls, and payment notifications as received from the payment provider: 90 days.

Purchase and receipt records: kept, with what identifies you removed, for as long as accounting and tax rules require [period — to be reviewed by the lawyer and the accountant].

Backups: deleted data may stay in backups for up to [7–14] days before it is erased.

Under the Law you may ask to know how your data is processed, to access it, to receive a copy, to have it corrected or deleted, and to withdraw your consent.

In Account you can delete your chats and delete your account. For any other request, write to info@oai.sa from the email address on your account [in-app request form — to be decided]. We verify your identity before acting and reply within 30 days, or within a further 30 days for a complex request, after telling you why.

If you are not satisfied with our answer, you may complain to the Saudi Data & AI Authority (SDAIA).

When you delete your account, we delete your chats and everything in them, sign you out on every device, remove your email and name from the account, and any unused credits are lost. Your purchase records are kept, with what identifies you removed, for as long as accounting rules require, and usage events stay until their period ends, as does the email fingerprint for the welcome credits (section 9). Deletion is final and cannot be undone.

The connection between your browser and our servers is encrypted, your email is stored encrypted, and sign-in codes and session identifiers are stored only as one-way fingerprints. Your questions and email address are never written to system logs. Our team's access to data is limited and recorded.

If a personal data breach happens, we notify the Authority within 72 hours where the Law requires it, and we tell you without delay if the breach could harm you — what happened, which data was involved, and what we are doing about it.

Dalni is not meant for anyone under 18, and we do not knowingly open accounts for them.

We use four cookies: the sign-in session; the browser identifier, used for limiting how fast usage events are sent, for remembering for a day that this browser passed the person check, and for usage statistics (section 2) [to be reviewed by the lawyer]; the theme you chose (light or dark); and a short-lived one that carries a question you typed on a public page to the chat page, deleted when the chat opens or after 10 minutes at most. The public topic pages on oai.sa/dalni set only the browser identifier and the theme, and only Dalni's part of that site reads them; sign-in, chats and credits are on dalni.oai.sa alone. When the person check runs (asking for a sign-in code, a report without signing in, a purchase), the bot-protection provider may set a cookie of its own and read signals from your browser for that check [to be reviewed by the lawyer]. The browser also keeps, for this session only, a question waiting for sign-in, the email address a sign-in code was just sent to, the campaign source, if any, and that you closed the notice bar. This device also remembers if you chose slower reading for Listen. We use no advertising cookies [whether usage statistics need prior consent — to be reviewed by the lawyer].

If we change this Policy in a material way, we tell you inside Dalni before the change takes effect. The Policy is published in Arabic and English; if the two differ, the Arabic text prevails.

Questions, requests and complaints about privacy: info@oai.sa [data protection officer — to be named].