

Privacy Policy
Last updated: August 10, 2026
Draft — not yet reviewed by counsel. Last updated August 10, 2026.
This document describes how Siyaqi works today so counsel can review it. It is not legal advice and has not been approved by a lawyer.
This Privacy Policy explains how Siyaqi (operated by TECHZO) collects, uses, and shares information when you use siyaqi.com, advertiser and publisher portals, developer APIs, serve SDKs and snippets, waitlist endpoints, email, and related services (together, the “Service”). By using the Service, you acknowledge this Policy. If you do not agree, do not use the Service.
Siyaqi is a text-first advertising network. Advertisers create contextual text campaigns, fund a prepaid wallet (typically via Whop top-up), and are billed on an internal ledger for CPM, CPC, or CPA events. Publishers embed placements and earn a share of attributed spend, paid out through connected methods. Some product surfaces stay waitlist-gated until launch is announced.
1. Who this Policy covers
- Visitors to the marketing site, documentation, and waitlist.
- Advertiser and publisher account holders and organization members.
- End users who see Siyaqi text ads inside publisher products (event data is kept placement-scoped and minimal).
- Staff and contractors invited to Ops, Admin, or Sales CRM, including KYC document upload during onboarding.
- AI agents that join the waitlist via
POST /api/waitlistand poll launch status.
2. Information we collect
- Waitlist data: kind (human or agent), email, optional name and company, intended role (advertiser, publisher, or both), referral code and referrer, confirm token, and — for agents — agent name, optional webhook URL, and a watch token used to poll launch status or download a bookmark file. Humans receive confirm, invite, and launch emails; registered agent webhooks are POSTed at launch.
- Account data: email, name, authentication sessions (NextAuth / Auth.js), organization name, org kind (advertiser / publisher / both), membership role, and preferred portal intent.
- Billing and wallet data: wallet currency (USD by default; SAR optional), ledger entries (top-up, spend, earning, payout, adjustment), campaign daily budgets, CPA conversion prices in minor units, and payout destination metadata. Card numbers and payment-method secrets are handled by Whop; we do not store full card numbers on Siyaqi servers. Publisher payouts may use PayPal, crypto addresses, or AI-wallet handles you connect.
- AI credits: credit balances, monthly free allotments, purchased packs, and consumption for Standard / Advanced copy generation, recommendations, and continuous suggestions. AI credits are distinct from wallet spend.
- Campaign and inventory data: campaign settings, bid model (CPM / CPC / CPA), creatives and AI variants, apps, placements, hashed API key secrets, and conversion keys used for attribution.
- Ad events: impressions, clicks, conversions, tracking identifiers, placement and campaign ids, and amounts needed to serve ads, attribute conversions, run fraud controls, and settle the ledger. Payloads are intended to stay minimal and placement-scoped.
- Staff KYC: government ID, proof of address, and selfie uploads (images or PDF, size-capped) plus employment role, guide acceptance, and review status. KYC is for invited staff — not a requirement for ordinary advertiser or publisher self-serve accounts.
- Usage and diagnostics: API usage counters, technical logs, and product analytics needed to operate and secure the Service. Error monitoring may be enabled in some environments.
- Communications: transactional email (magic-link sign-in, waitlist confirm/invite/launch, publisher onboarding sequences, staff invites, billing and campaign alerts). Commercial and transactional messages include a physical postal address from the operator-configured
TRANSACTIONAL_POSTAL_ADDRESS(we do not invent a street address in this Policy) and support List-Unsubscribe / one-click unsubscribe at/api/email/unsubscribe.
3. How we use information
- Operate, secure, and improve the Service
- Serve text ads, attribute conversions (typically within a short click-through window), and settle advertiser wallets and publisher earnings
- Process Whop wallet top-ups and publisher payouts
- Provide AI copy features and enforce plan and credit limits
- Run waitlist confirmation, invites, and launch notification (email or agent webhook)
- Authenticate users, remember portal intent, and keep sessions secure
- Detect fraud, abuse, and policy violations
- Onboard and verify invited staff (guide + KYC) before Ops / CRM access
- Comply with law and enforce our Terms of Service
4. Cookies and similar technologies
We use cookies and similar technologies that are necessary to run the Service. Theme preference is stored in localStorage, not a cookie.
- Authentication cookies from Auth.js / NextAuth to keep you signed in.
- Portal intent cookie (
siyaqi_portal_intent) — short-lived, SameSite=Lax — so login can send you to the advertiser or publisher portal you started from. - Publisher embeds and conversion snippets may set or read identifiers needed for attribution within the documented windows.
We do not currently run third-party advertising pixels on the Siyaqi marketing site for cross-site tracking. If that changes, this Policy will be updated.
5. Sharing
We share information with service providers that help us run the Service (hosting and databases, email via Resend, payments and payouts via Whop and other payout rails you connect, and optional error monitoring), when required by law, or with your direction (for example, serving your ads on publisher inventory). Advertisers and publishers see aggregated marketplace metrics needed to operate campaigns and placements; they do not receive unrelated personal profiles of each other’s end users.
We do not sell personal information as a standalone product.
6. Retention
We retain account, ledger, waitlist, KYC, and event data as needed to operate the Service, meet audit and tax obligations, prevent fraud, and resolve disputes. Aggregated metrics may be retained longer. Waitlist confirm tokens and portal-intent cookies expire. You may request deletion of account-related personal data subject to legal holds and ledger integrity (we may retain anonymized or legally required records).
7. Security
We use administrative and technical safeguards appropriate to a hosted advertising network, including hashed API secrets, access controls on staff surfaces, and payment processing by Whop. No method of transmission or storage is fully secure. Report suspected incidents to contact@siyaqi.app.
8. Your choices
You may update account details in the portal, revoke API keys, manage payout methods, and unsubscribe from non-essential email via the unsubscribe link. Depending on your location, you may have rights to access, correct, or delete certain personal data; we will respond as required by applicable law. Staff KYC documents can be reviewed or rejected by admins as part of employment onboarding.
9. Children
The Service is not directed to children under 16, and we do not knowingly collect personal information from them. If you believe a child under 16 has provided personal information, contact contact@siyaqi.app and we will take appropriate steps to delete it.
10. International processing
Siyaqi is offered globally. Wallet settlement is USD by default (SAR optional). Infrastructure and subprocessors may process data in the United States or other countries where we or our providers operate. By using the Service you understand that information may be transferred to those locations.
11. Changes
We may update this Policy by posting a revised version with a new “Last updated” date. Material changes will be highlighted in-product when practical. Continued use after the effective date constitutes acknowledgment of the updated Policy.
12. Contact
Privacy requests: contact@siyaqi.app. Physical postal address for CAN-SPAM and similar notices is the operator-configured TRANSACTIONAL_POSTAL_ADDRESS shown in email footers — this Policy does not invent a street address.
Questions? contact@siyaqi.app · Home