Privacy
Privacy policy
Last updated: 7 September 2026
1. What we collect
At sign-up: your business name, email address, phone number with country code, and a password stored encrypted (we cannot read it or recover it).
When you build your identity: brand name, type of business, its description, tone of voice, dialect, brand colours, and a description of your target audience.
While you use it: the images you upload, the posts and captions you generate, your products and their photos, and a record of the credits you spend.
What we do not collect: we never ask for a credit card, and we store no card data on our servers.
2. Site visitors
For every visit to a public page we record: the page visited, the referring source, campaign tags, device and browser type, and the country.
We do not store your IP address. We turn it into a one-way hashed fingerprint that tells us only "is this the same visitor as before?" — there is no route back to the address.
The visit log is deleted automatically after 180 days.
3. Where your data goes
Generating content means sending the text of your request (the post description, business name, content type) to external AI providers:
Cloudflare Workers AI — image generation and text writing.
Google Gemini — writing captions and ideas.
Pollinations — fallback image generation when the primary provider is unavailable.
We do not send them your email, your phone number or your password — and we do not sell or rent your data to anyone, nor use it to train models of our own.
And if you connect an Instagram or Facebook account, we send the post you chose to publish to Meta on your instruction, and keep the access token encrypted so scheduled publishing can run.
4. Advertising measurement
We use the Meta pixel on our public pages so we can tell which ad actually brought visitors and which one wasted our budget. It records: opening a page, opening the sign-up page, completing sign-up, and trying the caption writer before signing up.
With advanced matching, your email and phone number are sent to Meta hashed one-way at sign-up — Meta can match you to your account there, and cannot recover the address or the number from the hash.
We do not send Meta your content, your images, your captions or your password, and we do not sell your data to anyone.
You can stop all of this from your browser: any tracking blocker or your browser privacy settings will block the pixel, and the site works fully for you without it.
5. Your content is yours
The images, designs and captions you generate belong to you. Use them commercially with no restriction from us, and download them whenever you want.
We do not use your content in our ads or our examples without your explicit written permission.
6. Deleting your account
You can delete your account yourself from Settings → Delete account, and this immediately deletes with it: your visual identity, your posts, your generated and uploaded images, your products, and any tokens linking social accounts.
Backup copies are erased within thirty days.
Download your designs before deleting — deletion is permanent and cannot be undone.
7. Your rights
You may ask for a copy of your data, or to have it corrected or deleted, or withdraw your consent to processing. Email us and we act within thirty days.
These rights are guaranteed to you under the Saudi Personal Data Protection Law.
8. Security
The whole site runs over an encrypted connection (HTTPS), passwords are stored one-way hashed, and social account tokens are encrypted in the database.
Even so, no system is a hundred per cent secure — if a breach affects your data, we notify you within seventy-two hours.
9. Children
The platform is for business owners. It is not directed at anyone under eighteen, and we do not knowingly collect their data.
10. Changes to this policy
If we change something material — adding a new provider or a new type of data — we notify you by email before it takes effect, and update the last-updated date at the top of the page.
Have a question?
Email us at hello@anshrly.7okm.com and we reply within two working days.