Privacy Policy
Last updated 5 July 2026
This is legal information, not legal advice. The Arabic text of any law governs.
1. Our approach
Alqanoni's public website is anonymous-first. We collect the minimum needed to run a fast, fair, abuse-resistant service, in line with the Saudi Personal Data Protection Law (PDPL).
2. What we collect
What we process depends on whether you are signed in.
- Anonymous visitors: a signed, random identifier in an httpOnly cookie to count free usage; a one-way hash of your IP address for rate-limiting and abuse prevention — we never store your actual IP address, and the current day is mixed into the hash so the same address produces a different value each day; approximate country (from network routing, not precise location) to apply regional availability; and the text of your searches and AI questions, to produce answers and improve quality.
- Signed-in account holders: your email and, if set, a display name; a verified phone number only if you complete phone verification; your saved searches, AI conversations and law-change watches; and your subscription and billing history (amount, status and date — never card details, which are handled by our payment provider).
3. Don't enter confidential data
Anonymous search and AI are not a secure channel. Do not submit client names, case facts, or anyone's personal data. Treat your inputs as you would a public forum. Confidential work belongs in an authenticated Alqanoni OS account governed by its own data-processing terms.
4. AI inputs
Questions you send to the AI assistant are processed by our model provider to generate an answer. We send only your question and retrieved public-law passages — never your identity. We do not use anonymous questions to train third-party foundation models.
5. Product analytics
We measure coarse, privacy-preserving product analytics — for example how fast pages load and how often features are used — counted by day. These measurements contain no identifier that points to you: no account or visitor id, no IP address, and none of your search or question text.
6. Law-change watches and email digest
Signed-in users can watch an area of law to be notified when its underlying sources are refreshed, and can opt in to a summary email digest. The digest is off by default and you can turn it off again at any time in your account settings. We use your account email only to send a digest you have asked for.
7. Retention
Anonymous usage counters and IP hashes are short-lived and pruned automatically once they are no longer needed for rate-limiting; because the current day is mixed into each hash, the same address produces a different value on different days. Anonymous query text is kept only briefly for quality and abuse review, then deleted. Product-analytics counts are aggregate and non-personal. Signed-in account data is kept while your account is active and removed when you delete it (see Your rights), except the limited records described there that the law requires us to keep.
8. Data residency
Personal data for the service is hosted in regional data centres, with transfers limited to what is necessary to deliver the service and handled under PDPL-compliant safeguards. We prioritise in-region hosting, security and privacy.
9. Cookies
We use a small number of strictly necessary cookies (the signed anonymous id, your language and consent choices). We do not use advertising cookies on the public site.
10. Your rights
Under the PDPL you can access, export, correct and delete your personal data.
- Access and export: signed-in users can download a complete copy of their personal data — profile, saved research, watches, subscription and billing history — as a single JSON file from Account settings. For your security we ask you to confirm your password, and the download is available once a day.
- Deletion: you can request deletion of your account from Account settings after confirming your password. We sign you out immediately and permanently delete your account and personal data after a 30-day grace period. To cancel within those 30 days, email [email protected].
- What deletion keeps, and why: we keep a minimal record of subscription and payment events (amount, date, status — never card details) for the period required by financial, tax and anti-fraud law; when you delete your account these records are anonymised — detached from your name, email and account — so they can no longer be linked back to you. To stop one person from repeatedly creating accounts to abuse the free tier, we keep an irreversible one-way fingerprint of a verified phone number (never the number itself); it cannot be turned back into your phone number and is not linked to your deleted account. We also keep a dated record that a request was made and completed, as the PDPL requires.
- Withdraw consent: you can turn off marketing messages and the email digest at any time in Account settings; a verified phone is needed before a marketing-SMS choice can apply.
- Correction: update your name, email or password in Account settings, or contact us for anything else. Some anonymous data may not be readily linkable to you, which can limit our ability to locate it.
11. Pre-release trial and waitlist requests
If you ask for a pre-release trial of the Management plan, or to be notified when it becomes generally available, we store what you tell us — your name, work email, and (for a trial) your phone, office name, team size and any company activity — as a lead. We use it only to contact you about that request; we never store your raw IP address (only a short-lived, one-way hash for rate limiting), and you can ask us to delete your lead at any time by emailing [email protected].
12. Contact
For privacy requests, email the address below or [email protected]. We respond within the period required by the PDPL.