Privacy Policy
What SBMM Cloud collects, why, who else is involved, and what SBMM AI Studio keeps on your own computer instead of sending to us.
1. Who We Are
SBMM Cloud (sbmmcloud.com) provides a web application with SEO tools and an account system, and licenses SBMM AI Studio, a desktop application for Windows.
The service is provided by SBMM, House# CB-92 Liaqat Rd, Bhabra Shah Wali Colony, Wah Cantt, Pakistan, which is responsible for the personal data described here.
For privacy questions, use the route on our contact page. A published contact address is still being configured: support email.
2. The Short Version
Two sentences carry most of this policy. The work happens on your computer: SBMM AI Studio stores your projects, briefs, prompts, research and finished articles locally, and does not send them to us. We hold the account: who you are, what plan you are on, how much of your allowance you have used, which computers are signed in, and what you have paid.
We do not use analytics, advertising or tracking technology of any kind on this website, and we do not sell or share personal data for marketing.
3. What We Collect, And Why
Account Identity
Your email address, an optional name, and a password stored only as an argon2id hash. We use these to identify you, sign you in, send service email and issue invoices. Email is required; a name is optional and appears on invoices when given.
Authentication And Security
For each web session we store a hash of the session token, the IP address and the browser user-agent string, and timestamps. We also record security events - sign-ins, password changes, session revocations - with an IP address and a hashed user-agent. These let you review and revoke your own sessions and let us detect abuse.
SBMM AI Studio Devices And Sessions
When you approve a computer, we store the name you gave it, its platform, the app and engine versions, the identifier of the engine build, and that computer's public keys. We store hashes of its session tokens, never the tokens. This is what enforces the device limit, lets you remove a computer, and lets support see which computer had a problem.
Article Jobs
When a run is authorised, we record the workflow, the app and engine versions, the state of the run, how it ended and how it was charged - and a salted hash of the title instead of the title itself. We do not receive the title, the brief, the sources or any part of the article.
Usage And Entitlements
We count what you use against your plan: a reservation when work starts and a settlement when it ends, plus per-period counters. This is how allowances and failed-article releases work.
Subscriptions, Orders, Payments And Invoices
We store the plan you bought, the term, amounts, currency, the payment provider's transaction reference, the payment method name, and the invoice we issue. We do not receive or store your card number: payment happens on the payment provider's own page.
SEO Tool Inputs And Results
When you run a tool, we store the input you submitted - typically a URL, a domain or pasted text - and the result the tool produced, so you can return to it. Whatever you submit is processed to run the tool, and our crawler fetches the pages you name.
Logs
Our servers log the method, path, host, IP address and a request identifier for each request, for operational and security purposes. Credential-shaped values - tokens, licences, signatures, keys, cookies and payment query strings - are redacted before a log line is written.
Support Correspondence
If you contact us, we keep what you send so we can answer it. There is no contact form on this site today, so this applies only to messages you send to a published address once one exists.
4. What Stays On Your Computer
SBMM AI Studio stores the following locally and does not transmit it to SBMM Cloud:
- projects, their settings and your website profile;
- briefs, prompts and rendered agent instructions;
- research, source URLs and crawled pages;
- drafts, finished articles, reports and exports;
- run history, run steps and snapshots.
Crawling for research runs from your own computer and IP address. Generation runs through the Claude or ChatGPT command-line tool under your account, so what that provider receives and retains is governed by your agreement with them, not by us.
5. Cookies And Local Storage
This website sets one cookie: a session cookie that signs you in. It is marked HttpOnly and SameSite=Lax, is served only over HTTPS in production, and is scoped to this site so no subdomain can read it. It is strictly necessary - without it you cannot stay signed in.
Our cross-site request protection uses a token returned in the page's own data rather than a second cookie. We set no preference, analytics or advertising cookies, and the site does not use localStorage, sessionStorage or any similar browser storage.
Because the only cookie is strictly necessary, there is no consent banner. If that ever changes, we will ask before setting anything that is not.
6. Who Else Is Involved
We use a small number of service providers to operate SBMM Cloud:
- Email delivery
- A mail provider delivers service email - address verification, password reset, password changed, payment receipts and payment failures. It receives your email address and the message.
- Payment processing
- PayFast (Pakistan) processes card payments on its own page and returns a verified notification to us. It receives what it needs to take the payment; we receive the result, not the card.
- Page speed measurement
- When the PageSpeed tool is run against Google's PageSpeed Insights service, the URL you submitted is sent to Google to be measured.
- Map on the contact page
- The contact page shows our address on an embedded Google Map. Opening that page loads the map from Google, which receives your IP address and browser details as it would for any Google Maps visit. No other page loads anything from Google.
- Hosting
- Our application and database run on infrastructure operated by a hosting provider. The provider and its location are being finalised: hosting provider.
We may disclose information where the law requires it. We do not sell personal data, and we do not share it for advertising.
7. How Long We Keep Things
Where the software already enforces a period, it is stated here:
- Ended web sessions and expired verification tokens: removed seven days after they end.
- SEO tool results: retained for a limited period per tool - 30 days for most tools, and 14 days for the heavy crawls - then the result payload is purged automatically.
Account records, device and session records, article-job records, usage records, invoices and logs are retained while your account exists and for the period we are required to keep financial records. The exact periods are being finalised as part of our launch preparation: retention schedule. We will state them here before the service is offered commercially, and we will not keep personal data for longer than we need it.
8. Your Choices And Rights
You can view and change your name and email, review and revoke your web sessions, remove a signed-in computer, and download your invoices from your account at any time.
You may ask us for a copy of the personal data we hold about you, ask us to correct it, or ask us to delete your account and the data associated with it. Records we must keep for legal or accounting reasons - invoices in particular - will be retained for the required period. Self-service export and deletion are not built yet; until they are, these requests are handled manually through our contact route.
Depending on where you live, you may have additional statutory rights. Nothing in this policy is intended to limit them.
9. Children
SBMM Cloud is for people aged 18 or over, and is not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child has given us personal data, contact us and we will remove it.
10. How We Protect Information
Passwords are stored only as argon2id hashes and session and device tokens only as hashes. Access to your account is decided on our servers on every request. Administrative actions are recorded in an append-only audit log. Credential-shaped values are redacted from logs. Our security page describes the model in more detail.
No service can promise perfect security, and we do not. If a breach affects you and we are required to tell you, we will.
11. Changes To This Policy
If we change how we handle personal data, we will update this page and its date. Material changes will be notified to the email address on your account.