Draft Privacy Policy
Draft dated August 14, 2026 · not effective
Microcis, a California limited liability company (“Microcis,” “Simurgh Labs,” “we,” “us,” or “our”), provides the Simurgh Desktop application and the support portal at simurghlabs.ai (together, the “Service”). This draft describes the personal information the desktop-first Service is intended to process and the choices available to you.
1. Information the Service processes
Account and device-connection information. We process your name, email address, authentication method, email-verification status, and secure account-session records. When you connect Simurgh Desktop, we process a bounded request identifier, device name, operating system, app version, approval status, and expiration time. Browser sessions use secure HttpOnly cookies; the desktop receives a separate, short-lived authorization and never receives the browser cookie.
Billing information. Stripe processes payment-method details. We do not store your full card number. We receive subscription, billing-status, allowance, usage, and customer-reference information needed to provide and manage paid access.
AI-human preference. We store the AI human you choose as your active/default desktop expert together with the version and integrity identity required to reproduce that selection safely.
Selected screen and voice content. Simurgh Desktop processes only the display, window, or application you explicitly select and microphone audio you explicitly enable. During guidance, selected visual frames, audio, questions, generated responses, and visual-cue coordinates may be transmitted to our service providers and processed to understand what is visible and speak the next step. Raw audio, screenshots, screen tiles, partial speech captions, provider prompts, and hidden model reasoning are not kept as session history. Depending on the access level you choose, the desktop may also perform a closed set of actions under its visible consent and interrupt controls.
Guide-session history. We store the finalized semantic history of an authenticated guide session for your account: typed input labeled “Chat,” finalized speech-to-text input labeled “Voice,” the expert’s validated response, timestamps, delivery state, and bounded action or failure events. Transcript and session-goal values are encrypted separately from ordinary database protection. They are not sent as content to product analytics or error monitoring. Restricted support personnel may inspect a session only for an approved purpose and case reference, and that access is itself recorded.
Support, usage, and diagnostics. We process messages you send to support, guidance minutes used, product events, IP address, browser or app version, operating-system information, security signals, error reports, and bounded diagnostic data needed to operate, secure, meter, and improve the Service. Diagnostic and analytics systems receive closed operational labels and aggregate measurements, not transcript text, user goals, raw media, prompts, or session identifiers. We must verify the final production retention schedule and diagnostic-field allowlist before this draft can become effective.
Cookies. The portal uses strictly necessary cookies for authentication and security. We do not use advertising cookies or sell cross-site browsing profiles.
2. How we use information
- create, authenticate, secure, and support your account;
- approve and maintain a connection to Simurgh Desktop;
- provide real-time screen-aware voice and visual guidance;
- remember your selected AI human across supported devices;
- process subscriptions, meter allowances, and prevent fraud;
- respond to support requests and service notices; and
- diagnose failures and improve reliability and safety.
AI processing. Selected visual and voice content is processed by artificial-intelligence, speech-recognition, and voice systems to produce guidance. AI output may be inaccurate. Before this draft becomes effective, the final policy must name or link the approved subprocessor list and accurately state each provider’s retention and training controls.
3. How we disclose information
We do not sell personal information or share it for cross-context behavioral advertising. We disclose information only to providers that support authentication, payment processing, AI and voice processing, cloud delivery, email, security, and error diagnostics; when required by law; to protect users or the Service; or as part of a business transaction subject to appropriate protections. The approved subprocessor list will be available from support@simurghlabs.ai before launch.
4. Retention, deletion, and local data
We retain account and billing records while needed to provide the Service and satisfy legal obligations. Security and diagnostic records are retained only for an approved, documented period. The desktop may retain local settings, permission state, and the active-expert identity. Finalized semantic guide-session history is retained for your account. Customer history, export, selective-deletion, and bulk-clear controls are planned but are not available in the current release. Until the reviewed clear surface ships, those records remain retained; the current product does not claim that you can already clear or export them. Raw visual frames, raw audio, partial captions, and provider prompts are not retained as session history. These rules, the operational retention schedule, and the process for applicable data-rights requests must be verified against production behavior and approved by counsel before this draft can become effective.
5. Security
We use measures designed to protect information, including encrypted transport, secure password hashing, HttpOnly cookies, bounded desktop authorization, access controls, and abuse protection. No system is completely secure. You should avoid displaying or speaking information you do not want processed and stop capture or microphone access when it is not needed.
6. Your rights and choices
You control which screen or application is selected, whether microphone access is enabled, which AI human is active, and whether the desktop app remains connected. You may manage billing through the support portal. Applicable law may provide additional rights, including California and EEA/UK privacy rights. Before this draft becomes effective, the final policy must include counsel-approved jurisdiction-specific notices and a verified process for access, correction, export, and deletion requests. Questions about that future process may be sent to support@simurghlabs.ai.
7. International processing and age requirement
Microcis is based in the United States, and providers may process data in the United States and other countries. Required transfer safeguards will be documented in the approved policy. The Service is intended for people age 16 or older and is not directed to children under 16.
8. Contact
Questions about this counsel-review draft: support@simurghlabs.ai.