Privacy Policy
This policy explains what SAJEEL AI WALA collects when you use sajeel-ai-wala.pages.dev or the SAJEEL desktop app for Windows, why we collect it, and the control you have over it. We keep this short and readable on purpose.
1. What we collect
- Account basics: your name, email address and profile photo. If you sign in with Google or GitHub, we receive these from that provider (with your permission) — we never see your password for those services.
- Email accounts: your name and email, plus a salted cryptographic hash of your password. Passwords are never stored in readable form.
- Email sign-in codes: if you use "Email me a code", we send a 6-digit code to your address through our email sender (Brevo). Codes expire in 10 minutes, work once, and we store nothing beyond what's needed to validate them.
- Passkeys: if you add a passkey (Windows Hello, face, fingerprint), we store only the public half of the key plus a label. The private half never leaves your device and cannot be reconstructed from what we hold.
- Chat content: the messages you send to the SAJEEL agent and its replies, stored so your conversation history works across visits, devices and the desktop app.
- Security logs: failed sign-in attempts on your own device, to protect accounts from brute-force attempts. These stay on your machine.
2. What we do not do
- We do not sell your data. Ever. To anyone.
- We do not run advertising or third-party tracking pixels.
- We do not use your conversations to train AI models.
3. AI providers — how your messages are processed
To generate answers, the text you type is forwarded from our server to the AI model provider answering your request. We use a pool of providers — including an aggregator (OmniRoute) and direct providers such as Atria AI and Vyce AI — chosen automatically for availability. Their systems process your message to produce a reply, under each provider's own privacy terms.
- We send only the conversation text needed to answer — never your password, session tokens or account records.
- In the browser agent, nothing from your computer is sent — only chat text.
- In the desktop app, coding requests include the contents of files in your chosen project folder when the task needs them. The agent only reads inside the workspace folder you opened (or the default SAJEEL workspace), never your whole PC.
4. Where your data lives
Account records, passkey public keys and chat history are stored in Cloudflare Workers KV, Cloudflare's managed database, in data centers close to where you use the app. Sessions are stored as tokens with a 3-day sliding expiry — as long as you keep using the app you stay signed in; after 3 idle days you're asked to sign in again.
5. Third-party services
- Google — optional "Sign in with Google" (name, email, avatar only).
- GitHub — optional "Sign in with GitHub" (profile and email only).
- Brevo — delivers one-time email sign-in codes. It receives only your email address and the code email content.
- Cloudflare — hosting, database and the API between you and the AI pool.
- AI model providers (OmniRoute, Atria AI, Vyce AI and others in the pool) — process your messages to generate replies, as described in section 3.
Each provider handles your data under its own privacy policy. We only request the minimum read-only scopes needed to identify you.
6. Deleting your data
Want your account and chat history deleted? Email syedsajeel2000@gmail.com from the address on the account and we'll remove it within 7 days. Passkeys can be removed by asking us, or by deleting the SAJEEL passkey in your device's settings at any time. You can also clear local sign-in data any time via your browser settings, or by signing out.
7. Children
SAJEEL AI WALA is not directed at children under 13, and we do not knowingly collect their data. If you believe a child has created an account, contact us and we'll remove it.
8. Who is responsible for your data
SAJEEL AI WALA (the “Service”) is operated by its developer, an individual based in Pakistan, who is the data controller for the personal data described in this policy — the person who decides why and how it is handled. Where a sign-in provider (Google, GitHub) shares data with us, that same person is responsible for it. You can reach them at syedsajeel2000@gmail.com.
9. Government and law-enforcement requests
We have not received a national security request, and we have not handed personal data to any public authority, in the past 12 months. If we ever are asked:
- We review the legality of every request first. A request must be valid, in writing, and issued by an authority with the power to compel us. Anything informal, broad, or unsupported by law is refused.
- We challenge requests we consider unlawful — we ask for the scope to be narrowed or the demand withdrawn, and we use every legal route available before complying.
- We disclose the minimum necessary. If we are legally required to comply, we provide only the specific records the request names, and never bulk data: no handover of full chat history, passwords or passkeys. Passkeys never leave your device, so we cannot hand them over at all.
- We document every request we receive, our response, the legal reasoning, and the people involved, and we will publish the number of requests received and complied with if we are ever permitted to.
Because the Service stores as little as possible — an email address, a display name, and the messages you choose to send — there is very little to ask us for.
10. Changes
If this policy changes materially, we'll update the date below and, for signed-in users, show a notice in the app.
Last updated: September 26, 2026