🤖 AI Assistant Policy

AI Assistant Privacy Policy

How we handle your data when you interact with our AI-powered services — transparently, responsibly, and in compliance with Saudi Arabia's PDPL.

Last updated: July 2026
Saudi Arabia PDPL Notice: This policy is designed in alignment with the Kingdom of Saudi Arabia's Personal Data Protection Law (PDPL) and its Implementing Regulations, overseen by the Saudi Data & AI Authority (SDAIA). If you are a resident of the Kingdom, you have specific rights regarding your personal data as detailed in Section 12 of this policy.

This AI Assistant Privacy Policy ('AI Policy') governs the collection, processing, storage, and use of data generated when you interact with Elbetron's AI Assistant features and services ('AI Services'). This AI Policy supplements — and should be read alongside — our main Privacy Policy. By using our AI Services, you acknowledge that you have read, understood, and agreed to the practices described in this document. If you do not agree with any part of this AI Policy, please refrain from using the AI Services.

1. Scope of This Policy

This AI Policy applies specifically to all interactions you have with Elbetron's AI Assistant, including but not limited to: text-based chat conversations, voice queries and audio input, file uploads submitted for analysis, document processing requests, and any automated AI-generated responses you receive. This policy does not apply to third-party websites, products, or services that may be linked from our AI interface. We encourage you to review the privacy policies of any third-party services you access through our platform.

2. Data We Collect When You Use the AI Assistant

When you interact with the AI Assistant, we may collect and process the following categories of data:

We do not sell, rent, or trade any of the data collected through your AI interactions to third parties for marketing or advertising purposes.

3. Data We Do NOT Collect or Store

To protect your privacy and minimize data exposure, our AI Assistant is designed with the following explicit exclusions:

4. How We Use Your Data

The data collected through your AI interactions is used strictly for the following purposes:

5. Voice & Audio Input Processing

If you use voice input features with our AI Assistant, the following practices apply:

6. File & Document Uploads

When you upload files or documents to the AI Assistant for analysis, summarization, translation, or other processing tasks:

7. Data Retention

We retain different categories of AI-related data for varying periods based on their purpose and our legal obligations:

8. Data Storage & Geographic Residency

Elbetron's AI Assistant is fully self-hosted on infrastructure we control inside the Kingdom of Saudi Arabia:

9. Personal Data Detection & Handling in AI Conversations

Because users may inadvertently include personal information in their AI queries, we have implemented the following protections:

10. Fully Self-Hosted AI — No Third-Party Providers

Elbetron's AI Assistant runs entirely on self-hosted, open-source models on hardware we control: a locally-run large language model (Qwen3, via llama.cpp) for text, a local speech-recognition model (Whisper) for voice, and local models for embeddings and document text-extraction. Your data is never sent to OpenAI, Google, Anthropic, or any other external AI provider — there is no third-party inference and no external model API in the pipeline. This is a deliberate design choice for data protection and offline capability.

11. Security Measures

We employ multiple layers of technical and organizational security measures to protect your AI interaction data:

12. Your Rights (Including PDPL Rights)

Depending on your location and applicable law, you have the following rights regarding your personal data processed through our AI services. Saudi Arabian residents have these rights under the PDPL:

To exercise any of the above rights, you can use the privacy controls built into the AI Assistant (Download my data / Delete this conversation / Delete all my data), or email [email protected] with the subject line 'AI Data Rights Request'. We verify your identity before processing and respond within 30 days.

13. Consent & Withdrawal

Before you start using the AI Assistant, we show you a data-processing notice and ask for your explicit, affirmative consent (a required checkbox). This consent is recorded with a timestamp and the version of the notice you agreed to, and processing does not begin until it is given. You can withdraw your consent at any time using 'Delete my data' in the assistant's privacy settings, which also deletes your conversation content. If you do not consent, please do not use the AI Services, as some processing is technically necessary to operate them.

14. Data Breach Notification

In the event of a personal-data breach affecting your AI interaction data, Elbetron will: (a) contain the breach and begin investigation immediately upon discovery; (b) notify the Saudi Data & AI Authority (SDAIA) in accordance with PDPL Article 20 and its Regulations where the breach is likely to cause harm; (c) notify affected users without undue delay where the breach is likely to result in a high risk to their rights or interests; (d) include in that notice a description of the breach, the data affected, the likely consequences, and the measures taken; and (e) keep an internal record of breaches. For any breach concern, contact [email protected].

15. AI Services & Minors

Our AI Assistant services are intended for use by individuals who are 18 years of age or older. We do not knowingly collect personal data from children under 18 years of age through our AI Services. If you are a parent or guardian and believe your child has interacted with our AI Assistant and provided personal data without your consent, please contact us immediately at [email protected] with the subject line 'Minor Data Removal Request'. We will promptly investigate and delete any data related to minors upon verified notification. We have implemented technical age-verification prompts during account registration; however, we acknowledge that determined users may misrepresent their age, and we rely on parents and guardians to supervise minors' internet use.

16. Changes to This AI Privacy Policy

We may update this AI Privacy Policy from time to time to reflect changes in our AI services, applicable laws, or industry best practices. When we make material changes, we will: (a) Post the updated policy on this page with a revised 'Last Updated' date. (b) Send an in-app notification or email to registered users at least 15 days before material changes take effect. (c) Where required by law (such as changes affecting how we process sensitive data or how we share data with third parties), we will seek your renewed consent before the new practices take effect. Your continued use of the AI Services after the effective date of any changes constitutes your acceptance of the updated policy. If you do not agree with the updated policy, you should discontinue use of the AI Services and request deletion of your data before the effective date.

17. Contact Us & Data Protection Officer

For any questions, concerns, or requests related to this AI Privacy Policy or to exercise your data rights, please contact us through any of the following channels: