Privacy Policy
Sanad.dev provides account-based AI coding access for software engineers and engineering teams, plus a separately provisioned PDF OCR beta. This policy explains what we collect for sign-in, registration, billing, access control, requested OCR processing, support, and abuse prevention.
Information we collect
- OAuth account profile data from Google or Microsoft, such as name, email address, provider account id, and profile image when the provider returns it.
- Registration and account data, including first name, last name, mobile number, city, timezone, acceptance timestamps, account status, and activation timestamps.
- Business workspace data, including organization name, member emails, roles, policy settings, invitations, billing state, and audit events.
- Balance and payment records, including Stripe checkout identifiers, payment status, balance transactions, invoice metadata, and usage-charge ledger entries.
- API key metadata and usage records, including hashed API keys, key prefixes, historical access-control records, request timestamps, selected model, token usage, cost calculations, and metadata needed to enforce balance, rate, and account controls.
- Cloudflare country signal, IP-derived request metadata, user agent, and security-relevant request context used to protect the service.
- Support and operational notes you send to us when asking for help.
How we use information
We use this information to authenticate users, maintain accounts and workspaces, process balance top-ups, send account and access-status emails, issue API keys, charge token usage against account or business balance, enforce the selected funding identity plus account and rate controls, detect key sharing or abuse, troubleshoot access problems, and improve service reliability.
OCR beta document processing
The synchronous transcription endpoint processes uploaded PDFs, transient rendered page images, and OCR output only in the active request. The Sanad application does not persist, cache, or log that endpoint's PDF, rendered pages, or extracted output.
The asynchronous document-answer endpoint temporarily stores the PDF, question, processing artifacts, and answer in private service storage for a 24-hour service window. It deletes intermediate content earlier after successful processing and configures remaining artifacts to expire after that window. Lifecycle deletion processing may take additional time after the expiration threshold, but an expired answer is no longer available through the API. Sanad does not put this document content in application logs.
Infrastructure and inference processors necessarily process this content to provide the requested service under their own terms and policies. Those processors may have their own technical handling and retention practices; Sanad does not control or promise their retention periods. Sanad does not use OCR document content to train models.
Sanad may retain operational, authentication, and usage metadata needed to authenticate requests, enforce limits, account for usage, prevent abuse, and maintain reliability. This may include API-key digests, request identifiers, timestamps, response status, upload and page counts, quota events, and token or cost totals. After the asynchronous service window, document content is not retained as operational metadata.
Sharing
We do not sell personal data. We share data only with infrastructure, identity, payment, and model providers needed to operate Sanad, such as Cloudflare for hosting, security, geolocation, and transactional email delivery, Google or Microsoft for sign-in, Stripe for payments, and model processors for requested AI responses. Provider access is limited to what is needed for the requested service.
Google API data
When Google sign-in is used, Sanad requests identity scopes for authentication. Sanad's use and transfer of Google API information follows the Google API Services User Data Policy, including the Limited Use requirements.
Retention and security
We keep account, business workspace, payment, key, session, and usage records for as long as needed to operate Sanad, resolve support issues, enforce abuse rules, and meet legal or accounting obligations. API keys are stored as hashes, not plaintext. We use access controls, HTTPS, Cloudflare security controls, and least-privilege operational practices.
Your choices
You can choose not to register, stop using the service, or stop topping up balance. To request access, correction, or deletion of your account data, contact Sanad support. Some records may be retained where needed for security, abuse prevention, billing, tax, accounting, or legal obligations.
Legal information
Sanad.dev is operated by Jubba Cyber Services B.V., trading as Sanad B.V..
- Jubba Cyber Services B.V.
- Trade nameSanad B.V.
- Emailsupport@sanad.dev
- TelegramJoin Telegram group
- LinkedInFollow Sanad on LinkedIn
Contact
For privacy questions, contact support@sanad.dev.