SANA
HomeWallet
01Home02Wallet

Review draft · Not final

SANA Privacy Policy — English draft

Draft for review; not ready to publish. Complete the bracketed fields and the checks in the data map.
Effective date: [DATE]
Operator: [LEGAL NAME], [POSTAL ADDRESS], Kyrgyz Republic
Privacy contact: [PRIVACY EMAIL]

1. Who this policy covers

SANA is a tool for merchants to manage inventory, sales, and customer balances. This policy explains how the operator named above handles information from merchant account holders and information merchants enter about their customers. A merchant should give its customers an appropriate notice about the records it keeps in SANA and have a lawful reason to enter their information.

2. Information we handle

  • Account information: an email address or phone number, a password, an optional display name, account role, and default location. We store a password hash, not the password in readable form. We use a session token to recognize a signed-in account.
  • Merchant records: product names, prices, quantities, location names, sales and stock changes, invoices, customer assignments, payment entries, dates, amounts, payment methods, and notes.
  • Customer records entered by a merchant: a customer's name, optional phone number, and any customer-related information in invoices, payments, or notes. Merchants should avoid putting unnecessary sensitive details in free-text fields.
  • AI inputs and outputs: typed instructions, uploaded voice recordings, transcripts, proposed command cards, card edits, inventory questions, and answers. The backend keeps up to three recent pending inventory-command turns in temporary server memory until they are cleared, replaced, or the server restarts.
  • Technical information: account identifiers and operation times used to limit AI requests. A separate wallet-pass API, if used, temporarily uses a requester's IP address to limit requests. Server, network, and cloud services may also generate operational logs. Some current backend log statements can include command text or proposed card details.

3. How we use information

We use this information to create and secure accounts; display and update the records a merchant asks us to keep; transcribe speech; interpret and edit inventory commands; answer inventory questions; limit misuse; troubleshoot service failures; and respond to support, privacy, and legal requests. AI-generated commands are proposals until a merchant submits an action for execution.

4. AI and other service providers

SANA currently sends text AI requests to OpenAI. A request may include the merchant's instruction or voice transcript, known product names, known location names, a pending command card, an inventory question, generated SQL, and up to 100 rows of matching inventory or logbook results. Depending on the task, it may also include SANA's internal user ID, current date and time, and transcription confidence information. SANA sets store: false on OpenAI Responses API requests. OpenAI may still keep abuse-monitoring logs under its own controls. OpenAI data controls.

SANA sends uploaded audio and selected product and location names as recognition hints to ElevenLabs for transcription. If real-time transcription is used, the app may send audio directly to ElevenLabs using a short-lived token issued through SANA. ElevenLabs' normal transcription API has logging enabled by default; SANA's current batch request does not ask for zero retention. ElevenLabs transcription reference.

If a wallet pass is requested through SANA's pass API, the submitted pass details are forwarded to WalletWallet for generation. [Confirm whether this API is used by the published app and add WalletWallet's privacy link before publication.]

We store application data in AWS RDS in Frankfurt, Germany. AI and other providers may process information in other countries. [Confirm backup locations, provider regions, and any other app or infrastructure providers before publication.]

5. How long information remains

Account and merchant records currently have no automatic expiry. Deleting a product hides it from active inventory but preserves the record and related history. Voiding an invoice preserves the invoice. Reversing a payment adds a reversal entry and preserves the original entry. Self-service account deletion is not yet available.

The backend creates temporary files for uploaded audio and attempts to delete them when processing finishes. Pending command memory and rate-limit data are held in server memory, subject to the limits described above. Copies held by external providers, backups, and operational logs follow separate retention settings. [Add verified backup and log retention periods and any legally required retention before publication.]

6. Choices and requests

Merchants can correct many account and business records in SANA, log out, and clear pending command memory. A merchant can hide a product from active inventory; this does not erase its history. To ask about access, correction, or deletion of personal information, contact [PRIVACY EMAIL]. We will verify the request and handle it under applicable law. The in-app Delete Account control does not yet complete account deletion. Deleting a SANA account, when available, will not by itself cancel an Apple subscription.

If your information was entered by a merchant as a customer record, contact that merchant about the underlying transaction or correction. You may also contact us at [PRIVACY EMAIL] so we can help route an appropriate request.

7. Security and changes

We use password hashing and account tokens to protect access. No system can guarantee absolute security. Please keep your password and session token private, and contact us if you believe your account has been misused.

We may update this policy as SANA changes. We will post the revised text with a new effective date and give any additional notice required by law. Contact [PRIVACY EMAIL] with privacy questions.

SANAsupport@sana.software
HomeWalletPrivacy PolicyTerms of Use

© 2025–2026 SANA