Legal

Data & Privacy Policy

Version: privacy-v1.0-draft  ·  Last updated: July 2026

Afiyah Infinity AI Ltd. · Dubai International Financial Centre (DIFC) · DIFC Innovation Licence technology company

Draft for review. This policy is a design-stage draft published for transparency ahead of the August 2026 launch. It will be finalised following legal review.

1. Who we are

Afiyah Infinity AI Ltd. ("Afiyah", "we") is a technology company registered in the Dubai International Financial Centre (DIFC) operating under a DIFC Innovation Licence. We process personal data consistent with DIFC Data Protection Law No. 5 of 2020.

2. Our core commitment

We treat your data as an Amanah — a trust, not an asset to be exploited. We do not sell your personal data. We do not use member data to train foundation models.

3. What we collect

  • Account data: name, email, and optionally phone, country and language preference.
  • Consent records: which acknowledgements you gave, the document version, and when — recorded append-only.
  • Product data you create: goals, reflections, habit logs, learning progress and Noor conversations.
  • Sensitive wellbeing data (optional): cycle and wellbeing information, only where you have separately enabled it.
  • Verification reference (optional): if you request access to a verified-only surface, we store a provider reference — not your identity document.

4. How we protect it

  • Row-level security on every user-scoped table, so by default you can access only your own records.
  • Append-only consent: consent is never overwritten; grants and withdrawals both leave a record.
  • Provider-isolated verification: sensitive verification artifacts are never commingled with profile data and never surface in the AI layer.
  • Least-privilege access and auditable administrator actions.

5. Your rights

You may access, export, correct or delete your data, and withdraw any consent at any time. The design treats you as the owner of your data. To exercise any right, write to info@afiyahinfinity.com.

6. Data we never put in notifications

We do not include sensitive wellbeing, cycle, health, verification or financial detail in emails or push notifications.

7. Honest limitations

We do not currently hold SOC-type attestations or completed penetration-test reports, and we do not claim to. These are sequenced in our roadmap as we move from prototype to production.

Questions about this document? Write to info@afiyahinfinity.com.