Privacy Policy
This policy explains what SAIMA collects, why, how long we keep it, who we share it with, and the controls you have. It covers every account type on the platform — individuals, companies and agencies, platform staff, developers, and affiliate partners — and every integration we operate today or add later.
Effective date: 9 August 2026 · Last updated: 9 August 2026
1. Who we are
SAIMA ("SAIMA", "we", "us") operates an AI marketing platform at saimahub.ai that lets customers create marketing content, schedule and publish it to connected social accounts, manage advertising campaigns, and analyse performance from one place.
SAIMA is the data controller for account, billing and platform-usage data. Where you connect a third-party account (for example a Facebook Page or a TikTok Ads account), you remain the owner of that account and its data; SAIMA processes it on your instructions and only within the permissions you grant.
For any privacy question, contact us at privacy@saimahub.ai.
2. Data we collect
We collect only what the platform needs to work. We do not buy personal data from brokers, and we do not collect special-category data (health, religion, biometrics, political views).
- Account data — Name, email address, password (stored only as a salted hash — never in readable form), preferred language, and profile picture if provided by your sign-in provider.
- Registration details — For individual accounts: mobile number and areas of interest, and a CV or portfolio link if you choose to add one. For company and agency accounts: company name, unified national number, company type and size, business sector, contact person name and mobile, and optional website and company profile links.
- Authentication and identity — When you sign in with Google, Microsoft or Facebook we receive your provider user ID, email address and display name. Session records include device type, browser, IP address and last-seen time so you can review and end active sessions.
- Connected account tokens — OAuth access tokens and refresh tokens for the social, advertising and commerce accounts you connect. These are credentials, not content, and are used only to perform the actions you request.
- Content and files — Text, images, video and audio you create in or upload to the platform, together with your brand identity settings (tone, colours, logos) and product catalogue.
- Publishing and scheduling data — Posts, scheduled times, approval history, and the result of each publishing attempt.
- Advertising and analytics data — Campaign settings, budgets, and performance metrics such as reach, engagement and spend, retrieved from the advertising accounts you connect.
- Billing data — Subscription plan, invoice status, AI credit balance and transaction history. Card numbers never reach our servers — see section 5.
- Developer and affiliate data — For developer accounts: application details, API client identifiers, hashed API keys and request logs. For affiliate accounts: referral code, referral events and commission ledger entries.
- Technical data — IP address, browser and device information, and error diagnostics needed to keep the service secure and available.
3. OAuth, access tokens and connected accounts
Connecting an account always goes through the provider's official authorisation flow. You are redirected to the provider, you review and approve the exact permissions requested, and you are returned to SAIMA. We never ask for, receive, or store the password of any third-party account.
We request the narrowest set of permissions each feature needs. Where a provider separates flows — for example TikTok's advertiser API versus its content-posting login — we register and use them separately rather than requesting broader access than required.
Tokens are stored securely, used only to carry out actions you initiate or schedule, and are never sold, rented or shared for advertising or profiling. When a token expires, publishing for that account pauses and we ask you to reconnect rather than attempting to work around the provider's controls.
You can disconnect any account at any time from SAIMA settings, or revoke SAIMA's access from the provider's own security settings. Disconnection stops all reading and publishing for that account immediately.
4. Integrations and the data each involves
The platform integrates with the services below. Each integration is optional and activates only when you connect it. This list evolves as we add integrations; the categories and safeguards described in this policy apply to any new integration equally.
- Meta — Facebook, Instagram, Threads and Meta Ads — Publishing and scheduling posts, reading Page and account insights, and managing advertising campaigns where you grant those permissions.
- TikTok — TikTok for Business and TikTok Login Kit — Advertising campaign management and performance data; and, through a separate flow, publishing video content to a creator account.
- Google and YouTube — Sign-in, and video upload and channel analytics where connected.
- Snapchat — Advertising campaign management and performance reporting.
- LinkedIn and X — Publishing content and reading engagement metrics for connected accounts.
- Microsoft — Sign-in using a personal or work Microsoft account.
- Salla and other commerce platforms — Reading your product catalogue so marketing content can reference real products, and receiving store event notifications.
- AI providers — Anthropic, OpenAI, Google Gemini and ElevenLabs — Generating text, images, video and voice. Your prompt and the brand context needed to fulfil it are sent to the selected provider to produce the result you asked for.
- Moyasar (payments) — Processing subscription payments. You are redirected to Moyasar's hosted payment page; card details are entered there and never pass through SAIMA.
- Cloudinary (media storage) — Storing and delivering images and media you upload or generate.
- Resend (email delivery) — Sending transactional email such as verification codes, password resets and account status notifications.
- Supabase / PostgreSQL (database hosting) — Hosting the platform database in which your account and platform data is stored.
5. How we use your data
We use your data to provide the service you asked for, to keep it secure, and to meet legal obligations. We do not use your content to build advertising profiles about you, and we do not sell personal data.
- Operating core features: creating content, scheduling, publishing, and reporting on performance.
- Authenticating you, maintaining sessions, and letting you review and end sessions on other devices.
- Processing subscriptions, calculating AI credit usage, and issuing invoices.
- Sending transactional email you need to use the account, such as verification codes and account status updates.
- Detecting and preventing abuse, fraud and unauthorised access.
- Diagnosing faults and improving reliability and performance.
- Complying with applicable law and responding to lawful requests.
6. AI processing of your content
When you ask SAIMA to generate content, the prompt you write and the brand context needed to fulfil it are sent to the AI provider you selected for that request. The generated result is returned to your workspace as a draft.
AI output can be inaccurate. Names, figures, claims and legal or medical statements must be reviewed by a human before publishing. You remain responsible for everything published from your account.
Each AI provider processes data under its own terms. We choose providers that support business use and do not require your content to be used for model training as a condition of service.
8. Data retention
- Active accounts — We keep your data for as long as your account is active and you continue to use the service.
- Suspended organisations — Default platform retention places an organisation into read-only status after 30 days of suspension, and deletes its data after 90 days.
- Deletion requests — Account and personal data are deleted within 30 days of a verified deletion request. See our Data Deletion page for the exact procedure.
- Disconnected accounts — Tokens for a disconnected account are invalidated immediately on disconnection.
- Records we must keep — Invoices and financial records are retained for the period required by applicable tax and commercial law, even after account deletion. Security and abuse logs are retained for a limited period for fraud prevention.
- Backups — Data may persist in encrypted backups for a short period after deletion, and is removed as those backups age out on their normal cycle.
9. Security
- Traffic between your browser and SAIMA is encrypted in transit using TLS.
- Passwords are stored only as salted hashes and are never recoverable in readable form, including by our own staff.
- API keys issued to developers are stored as hashes; the full key is shown once at creation and cannot be retrieved afterwards.
- Access to your organisation's data is governed by roles and permissions that you control, and every administrative endpoint verifies authorisation on the server.
- You can review every active session with its device, browser and last-seen time, and end any session immediately. Changing your password invalidates all other active sessions.
- No system is perfectly secure. If a breach affects your personal data, we will notify affected users and the relevant authorities as required by applicable law.
10. Your rights and controls
Subject to applicable law, you have the following rights. To exercise any of them, contact privacy@saimahub.ai from the email address registered to your account.
- Access — Request a copy of the personal data we hold about you.
- Correction — Correct inaccurate or incomplete data, much of which you can edit directly in settings.
- Deletion — Request deletion of your account and associated data — see the Data Deletion page.
- Portability — Request your data in a structured, machine-readable format.
- Restriction and objection — Ask us to restrict or stop certain processing.
- Withdraw consent — Disconnect any integration at any time, in SAIMA or from the provider's own settings.
- Complain — Lodge a complaint with your local data protection authority.
12. Children
SAIMA is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a minor has provided us data, contact privacy@saimahub.ai and we will delete it.
13. International transfers
SAIMA operates primarily in the Kingdom of Saudi Arabia. Some service providers described in section 4 process data on infrastructure located outside the Kingdom. Where data is transferred internationally, we rely on the provider's contractual safeguards and process it under the terms of this policy.
14. Changes to this policy
We may update this policy as the platform develops. When a change materially affects your rights or how we use your data, we will notify account holders by email or an in-platform notice before it takes effect. The effective date at the top of this page always reflects the current version.
15. Contact us
Privacy and data protection: privacy@saimahub.ai
General support: support@saimahub.ai
Data deletion requests: privacy@saimahub.ai — or use the Data Deletion page for the step-by-step procedure.
SAIMA, Riyadh, Kingdom of Saudi Arabia.
Related documents
