Privacy Policy

Effective date: July 28, 2026 · Operated by Microcis LLC (“Simurgh”, simurghlabs.ai)

This policy explains what Simurgh collects when you work with an AI expert, why we use it, who processes it, how long we keep it, and the choices available to you.

1. Who controls your data

Simurgh is operated by Microcis LLC, San Francisco, California. Microcis LLC determines why and how the personal data described here is processed. Privacy questions and rights requests may be sent to privacy@simurghlabs.ai.

2. Data we collect

Account and subscription data

  • Your name, email address, authentication records, account settings, organization membership, and subscription or entitlement status.
  • Payment processors may collect billing details when paid plans are offered. Simurgh receives transaction, plan, and status information but does not need to store full payment-card numbers.

Expert-session and workspace data

  • The expert you choose and the goals, questions, feedback, files, and availability information you provide.
  • Live audio is transmitted and processed so speech can be recognized and the expert can respond. Raw audio or video is retained only when the product gives an applicable recording notice.
  • Transcripts, plans, plan edits, progress, workspace content, session status, and safety or quality signals associated with your account.

Technical and support data

  • Device, browser, IP address, timestamps, diagnostic, security, usage, and performance information needed to operate and protect Simurgh.
  • Messages and files you send to support, including information needed to resolve the request.

3. How we use data

  • Provide accounts, expert discovery, live voice sessions, shared workspaces, saved plans, and progress tracking.
  • Personalize a session using its conversation and plan history.
  • Authenticate users, enforce entitlements, prevent abuse, investigate incidents, and maintain service reliability.
  • Respond to support requests and communicate material service, security, policy, and account updates.
  • Measure and improve quality using access-controlled evaluations, de-identified or aggregated analysis where practical, and human review when authorized and necessary.
  • Comply with law and enforce our agreements.

4. AI processing

Session content is processed by speech, language-model, retrieval, safety, and text-to-speech systems to provide the service. This may include contracted AI infrastructure or model-routing providers. We limit the information sent to what is needed for the request and require service providers to process it for Simurgh under applicable contractual and security obligations.

Simurgh does not treat an AI expert as a human. Expert names, portraits, and voices are platform identities and are displayed with an AI disclosure.

5. When data is shared

We disclose data only as needed to:

  • infrastructure, hosting, content-delivery, storage, communications, authentication, observability, AI-processing, and payment providers acting for Simurgh;
  • an organization administrator for an account managed by that organization, subject to the organization’s agreement and permissions;
  • comply with law, valid legal process, or a necessary safety or security response; or
  • support a corporate transaction, subject to appropriate confidentiality and continued protection.

We do not sell personal information or share it for cross-context behavioral advertising.

6. Legal bases

Where the GDPR or similar law applies, we process account, session, and plan data to perform our contract with you; security and service-improvement data for our legitimate interests in operating a safe and reliable service; payment and compliance records to meet legal obligations; and optional processing on consent when the product asks for it. You may withdraw consent without affecting earlier lawful processing.

7. Retention

We keep account, conversation, workspace, and plan data while your account is active and as needed to provide the service. When you ask us to delete your account, we delete or de-identify personal data within 30 days unless a longer period is required for security, fraud prevention, payment records, legal obligations, dispute resolution, or short-lived protected backups. Diagnostic and security logs are kept only for the operational period assigned to that log category.

8. Security

We use technical and organizational safeguards designed to protect personal data, including encrypted transport, access controls, environment separation, logging, and least-privilege service access. No system can guarantee absolute security. We will provide legally required notice if a qualifying breach occurs.

9. International processing

Simurgh is operated from the United States and may use providers in other countries. Where required, we use recognized transfer mechanisms and contractual safeguards for international transfers.

10. Your choices and rights

Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a portable copy of personal data, and to appeal or complain to a privacy regulator. You may also withdraw consent where processing relies on it. We do not discriminate against users for exercising privacy rights.

Send a request to privacy@simurghlabs.ai. We may verify your identity and authority before fulfilling it.

11. Children

Simurgh is not offered to people under 18, and we do not knowingly collect personal data from them. Contact us if you believe a minor has provided personal data.

12. Changes

We may update this policy as the service or law changes. We will post the new effective date and provide additional notice before a material change when required.

13. Contact

Microcis LLC, San Francisco, California. Email privacy@simurghlabs.ai.