Privacy Policy
Last updated: 1 October 2026
Who we are
FMCG Lens is provided by Muasher AI Company (شركة مواشر إيه آي), a single-member limited liability company registered in the Kingdom of Saudi Arabia. Commercial Registration (Unified National Number) 7054820092. Registered address: Al Sufyani (السفياني), Al Andalus Dist., Jeddah 23326, Kingdom of Saudi Arabia.
We are the controller of the personal data in this policy, except for personal data inside the files you upload, where we act for your business (section 3).
Privacy contact: support@fmcglens.com. We have not appointed a data protection officer. This address reaches the people responsible for privacy at our company.
Launch status
FMCG Lens is launching soon and subscriptions are not open yet. Until we open, no payment is taken and Paddle collects no billing data for us. Before launch, what we hold is what you give us on the founding list, any email you send us, and the website visit counts and server logs described below.
The short version
- Your files are encrypted in your browser before they are stored. We cannot open them.
- Your dashboards and reports are calculated in your browser by our own software. No AI calculates any figure or writes any sentence of a report.
- To recognise your columns, we send our AI provider your column headers (headers that read as business names are masked) and value-free descriptions of each column. Your cell values stay in your browser unless you approve a specific preview. If you use the translator's helper chat, it sends what section 4 lists.
- We use no advertising and no third-party trackers.
- Our service providers are outside Saudi Arabia. Section 6 lists every one.
1. What we collect and why
- What
- Founding request: work email, company name, business type
- Where it comes from
- You, through the form on our website
- Why we use it
- To answer your request and invite you
- Legal basis
- Steps you asked us to take before a contract
- Required?
- Optional. Without it we cannot reply.
- What
- Account: email address, sign-in identifier, sign-in events (time, IP address, browser)
- Where it comes from
- You, through our sign-in provider Auth0
- Why we use it
- To create your account, sign you in and keep it secure
- Legal basis
- Contract; security is our legitimate interest
- Required?
- Required to use FMCG Lens
- What
- Billing: name, email, billing country and address, tax number if you give one, payment details
- Where it comes from
- Paddle, our reseller, collects this at checkout
- Why we use it
- To sell and bill your subscription and apply tax
- Legal basis
- Contract; legal obligation (tax and accounting)
- Required?
- Required to subscribe
- What
- What Paddle shares with us: your plan, subscription status, country and transaction records. We never receive your full card number.
- Where it comes from
- Paddle
- Why we use it
- To give you the plan you paid for
- Legal basis
- Contract
- Required?
- Required to subscribe
- What
- Records about your encrypted files: the kind of data a file holds (for example "receivables aging"), its size, dates and processing status. Your account identifier is part of each file's storage path.
- Where it comes from
- The product
- Why we use it
- To store, list and deliver your files
- Legal basis
- Contract
- Required?
- Required
- What
- Consent records: when you approve sending column information for a file
- Where it comes from
- The product
- Why we use it
- To keep proof of your approval
- Legal basis
- Contract; legal obligation
- Required?
- Required to use column recognition
- What
- Usage counters and error codes: how many reports you have run this month; content-free event and error codes with times
- Where it comes from
- The product
- Why we use it
- To apply your plan's allowance and keep the service working
- Legal basis
- Contract; legitimate interest (reliability)
- Required?
- Required
- What
- Network logs: IP address, browser, the page requested, the result and the time
- Where it comes from
- Our hosting and sign-in providers
- Why we use it
- Security and reliability
- Legal basis
- Legitimate interest
- Required?
- Required
- What
- Support emails
- Where it comes from
- You
- Why we use it
- To help you
- Legal basis
- Contract; legitimate interest
- Required?
- Optional
- What
- Website visit totals: page views, an estimated number of visitors per day, the referring website, country, and device type (phone, tablet or computer)
- Where it comes from
- Our own server, when you visit our public pages
- Why we use it
- To understand how our website is used
- Legal basis
- Legitimate interest
- Required?
- Automatic; no cookie is set
- What
- Marketing preference
- Where it comes from
- You, only if you opt in
- Why we use it
- To send you product news
- Legal basis
- Your consent
- Required?
- Optional
Our sign-in does not ask for your name. We use legitimate interest only for security, reliability and answering requests you send us. You can object to that at any time (section 10).
2. What we cannot see
- The contents of any file you upload.
- Your dashboards and reports.
- Your file names. They are stored encrypted.
- Your encryption password and recovery key. They never leave your device.
This is how the system is built, not a policy choice. There is no tool, support process or database view on our side that can decrypt your content. Our support promise says it plainly:
We can see whether your run succeeded and how large your file was. We cannot see your data, and we cannot be given access to it.
One consequence: if you lose both your encryption password and your recovery key, your stored data cannot be recovered by us or by anyone.
3. Personal data inside your files
Your files may contain personal data your business holds, for example the names of salespeople, or customers named after their owners. For that data, your business is the controller: it decides what to upload and must have the right to do so. We act on your business's behalf only to provide FMCG Lens. We store that data only in encrypted form we cannot read, and it never reaches our AI provider except as described in section 4.
4. What our AI provider receives
Two features use AI, both only while you map a file: recognising your columns and the translator's helper chat. Both use our AI provider, Anthropic (USA).
Recognising your columns. With your approval for that file, we send Anthropic:
- your column headers, with any header that reads as a business name masked;
- value-free descriptions of each column, such as "numeric, two decimals", never a cell value;
- the file's shape: its sheet name (masked on the same terms), its row count and its file type.
Your cell values are not sent for column recognition. The request passes through our relay, which stores nothing.
The helper chat. The translator's helper chat also uses our AI provider, Anthropic. When you use it, Anthropic receives what you type in the chat and the conversation so far, the description you gave the file, your column headings and the names of your file's sheets as written, the file's size, any error message shown to you, and a masked outline of the file in which every number and word is replaced by a placeholder. The helper can also ask for up to ten rows of the grid, with every data value replaced by a placeholder. Two rows of your actual values are sent only if you approve it, and only once. Using the helper chat means you accept Anthropic as a subprocessor for these requests.
Under Anthropic's commercial terms, this content is not used to train AI models.
AI is not used to calculate any figure, to write any part of a report, or to make any decision about a person. We make no automated decisions that have legal or similar effects on anyone.
5. Where your data is kept
| Data | Provider | Location |
|---|---|---|
| Encrypted files and their records; founding requests | Amazon Web Services (encrypted at rest with AWS Key Management Service) | Frankfurt, Germany |
| Account and sign-in | Auth0 (Okta) | European Union |
| Usage counters and subscription status | Upstash, through Vercel | Frankfurt, Germany |
| Website hosting and network logs | Vercel | United States and global network |
| Billing | Paddle | United Kingdom |
| Support email | Google Workspace | United States and global |
| Column recognition (in transit only) | Anthropic | United States |
Your personal data is transferred to and processed outside the Kingdom of Saudi Arabia. We transfer it only as the Personal Data Protection Law and its Regulation on Personal Data Transfer outside the Kingdom allow, with the safeguards that regulation requires in our contracts with each provider.
6. Who receives your data
The providers in section 5 are the complete list. Each receives only what it needs for its role. Paddle acts as the seller of your subscription (the Merchant of Record) and is responsible for the billing data it collects at checkout under its own privacy policy. We will update this list before any new provider receives personal data.
We do not sell personal data. We disclose it to authorities only when the law requires.
7. Cookies and browser storage
- Sign-in cookies (Auth0) keep you signed in. They are necessary for the service.
- Checkout. When you open the checkout, Paddle may set its own cookies for payment and fraud prevention. Paddle's policy describes them.
- "Trust this device" is optional. If you turn it on, an encrypted unlock helper is kept in your browser's local storage for the period you choose (7, 30 or 90 days). You can turn it off at any time in Settings.
We use no advertising cookies, no third-party analytics and no trackers.
How we count website visits. We count visits to our public pages on our own server, without cookies and without any third party. We do not store your IP address. To count unique visitors, a one-way code is made from your connection details and a random value that is replaced every day; the day's codes are deleted within 24 hours, so no visitor can be followed from one day to the next. Only daily totals are kept.
8. How long we keep data
| Data | How long |
|---|---|
| Your account and your encrypted files | Until you delete them or your account |
| Deleted encrypted files | Earlier versions are purged within 30 days of deletion |
| Usage counters | Expire automatically about 40 days after the month they count |
| Website visit totals | 13 months; the daily one-way visitor codes are deleted within 24 hours |
| Consent records | While your account is open |
| Founding requests | Until we have answered. If you do not open an account, deleted within 12 months. |
| Billing and transaction records | As long as tax and accounting law requires |
| Network logs | Up to 30 days, kept by our hosting and sign-in providers |
| Support emails | As long as needed to help you and keep a record of the support we gave. Any business data sent to us is deleted on receipt. |
When data is deleted, it is destroyed so that it cannot be recovered.
9. How we protect it
- Your files are encrypted in your browser with keys derived from your password. The keys never leave your device.
- Stored data is also encrypted at rest by our storage provider, and all traffic is encrypted in transit.
- Access to our systems is limited to the people who run them, and none of them can read your stored content.
- If a personal data breach happens, we will notify the Saudi Data and AI Authority (SDAIA) within 72 hours of becoming aware of it, and we will tell you without undue delay when it may harm you.
10. Your rights
Under the Saudi Personal Data Protection Law you have the right to:
- be told how your personal data is used (this policy);
- access your personal data and get a copy in a readable format;
- have it corrected;
- have it deleted;
- withdraw any consent you gave;
- object to direct marketing.
To use any right, write to support@fmcglens.com from your account email. We reply within 30 days. You can also export your data and delete your account yourself in the product.
If you are not satisfied with our answer, you can complain to the Saudi Data and AI Authority (SDAIA).
11. Marketing
We send marketing emails only if you opt in. Every marketing email identifies us and has an unsubscribe link, and you can opt out at any time. Emails about your account, billing, security or changes to our terms are not marketing.
12. Children
FMCG Lens is a business service and is not for anyone under 18. We do not knowingly collect personal data from children.
13. Changes to this policy
We will publish any change here and update the date at the top. We will email you before a material change takes effect.