Privacy Policy
Last updated: August 24, 2026 (Post-Audit Security Release)
SBF Consultancy ("we", "us", "our") operates Project Pak-LLM. This Privacy Policy transparently explains our hybrid sovereign AI architecture, and how we collect, process, store, and protect your personal information when you use our website and services. We are committed to handling your data responsibly in alignment with Pakistan's Draft Personal Data Protection Bill (PDPB), the Prevention of Electronic Crimes Act (PECA 2016), the National Cybersecurity Policy, and global privacy benchmarks including GDPR.
1Information We Collect
A. Information you provide directly
- Email address and password (for email/password registration)
- Google account name and profile photo (if using Google OAuth)
- Chat messages, uploaded documents, and custom instructions entered in the workspace
- App Connector API credentials (e.g., WhatsApp Business tokens, Google OAuth, Daraz API keys) — automatically encrypted via Post-Quantum Cryptography (ML-KEM-768 + AES-256-GCM)
- Sovereign RAG knowledge collections, custom legal/tax templates, and indexed document chunks
- Visual generation prompts and starting photographs uploaded for animation (under the Pak-Image and Pak-Video tools)
- Folder names, workflow automation pipelines, and thread titles you create
- Contact form submissions and universal feedback reports
B. Information collected automatically & Security Layer
- IP address and approximate geographic region (used for domestic micro-node routing and security)
- Amanah Gate Policy Interceptor: automatically scrubs and redacts Pakistani CNICs (XXXXX-XXXXXXX-X) and payment card numbers before storage
- Browser type, device type, and operating system
- Persistent guest identification cookies (
pak_llm_guest_id) and device metrics cookies (pak_llm_guest_info) - Immutable cryptographic ledger logs recording license subscriptions and workflow verification hashes
- Pages visited and time spent (via anonymized regional telemetry)
- Server-side request logs (retained for up to 30 days for security purposes)
C. Real-Time Sovereign Voice AI & Minimalist Zen Studio
- In-Memory Processing: Microphone audio is processed entirely in volatile RAM for real-time speech recognition (Faster-Whisper) and neural speech synthesis using the Standard English Model and Pak-LLM Voice of Awam across 34 regional languages and dialects.
- NIST SP 800-88 Zero Retention: In compliance with NIST SP 800-88 Media Sanitization Guidelines, raw voice audio recordings are NEVER stored, persisted, or logged to disk or permanent databases. Audio buffers are purged immediately upon transcription.
- Minimalist Clean Interface (No On-Screen Text): The Voice AI Studio interface operates in pure zen mode without printing user speech or AI responses as written text bubbles on the screen, safeguarding your privacy from shoulder-surfing, ambient screen recording, or unauthorized visual capture during spoken sessions.
- NIST FIPS 203 (PQC) Security: Voice WebSocket sessions are sealed using NIST Post-Quantum Key Encapsulation (ML-KEM-768) to protect against future cryptographic attacks.
- Pakistan PDPA Alignment: Strictly aligned with Pakistan's Personal Data Protection Act; only transcribed chat text is associated with your private user thread.
D. Multi-Agent Council, Custom Personas & Onboarding Telemetry
- Multi-Agent Voice Orchestra Telemetry: When interacting in Multi-Agent Voice Orchestra mode, operational telemetry (selected ethnic persona, solo vs council mode, latency in milliseconds, and MCP tools invoked) is logged to domestic database telemetry nodes to optimize cluster routing and speech model load balancing.
- Tenant-Isolated Custom Agent Personas: When you customize or write custom agent personas in the Voice Studio, your custom prompt instructions are stored in an encrypted, isolated database partition tied strictly to your authenticated account ID (
custom_agent_personas). They are never shared with other tenants, exposed publicly, or utilized to train foundation models. - Product Tutorial & Onboarding Discovery Analytics: Anonymized interaction milestones (onboarding launches, step views 1 through 5, skips, and completions) are logged to evaluate feature discoverability and streamline onboarding UX without tracking personally identifying data.
E. External Project API Keys & Webhook Telemetry
- Cryptographic API Key Security: When administrators generate external bearer API keys (
pak_live_...), only a cryptographic SHA-256 hash (admin_api_keys.key_hash) and non-sensitive key prefix are persisted in the database. Raw secret keys are displayed only once upon generation and are never stored in plaintext. - HMAC-SHA256 Signed Outbound Webhooks: Outbound webhook push transmissions to third-party endpoints (e.g. Gravitas Minds, customer CRMs) are signed using per-webhook HMAC-SHA256 secrets in the
x-pakllm-signature-256header. - Delivery Audit Logs & Ephemeral Retention: Outbound webhook delivery logs (
admin_webhook_deliveries) retain the event type, destination URL, delivery timestamp, response status code, latency (ms), and sanitized payload previews for diagnostic troubleshooting and audit verification. - Zero Retention on REST Voice Endpoints: Voice audio generated or transcribed via public REST endpoints (
/api/v1/voice/*) adheres strictly to NIST SP 800-88 zero-retention standards and is streamed ephemeral-only.
F. Information we do NOT collect
- Raw payment card or banking passwords (payment processing is handled directly via PCI-DSS certified gateways: Swich, JazzCash, EasyPaisa, Raast)
- Biometric voiceprints, voice recordings on persistent media, genetic records, or unencrypted government ID numbers
- Precise GPS location
2How We Use Your Information
We use the information we collect to:
- Provide, operate, and improve the Pak-LLM Sovereign Services
- Execute deterministic local MCP tools and App Connectors (WhatsApp, Trax, FBR, Gmail) securely on domestic clusters
- Index and query private RAG knowledge collections strictly within your tenant boundary
- Process AI queries and media animations by forwarding requests through local micro-nodes and dedicated serverless endpoints
- Save and retrieve your conversation threads, generated media, and folder organization
- Enforce Amanah Gate ethical policies, Shariah compliance, anti-riba checks, and rate limits
- Mint tamper-evident cryptographic ledger receipts and electronic FBR POS Tier-1 digital fiscal invoices (POSID: 198968) under the PSEB registered IT entity regime
- Comply with legal obligations and regulatory standards
3Data Storage & Security
Pak-LLM implements a Hybrid Sovereign Architecture:
- Domestic Sovereign Control Plane: User account policies, Amanah Gate PII redaction (CNIC/card stripping), RAG knowledge collection metadata, and cryptographic audit ledgers are orchestrated under sovereign Pakistani tenant boundaries.
- Enterprise Ephemeral Inference: LLM chat queries and media generation prompts are processed through enterprise endpoints (Groq LPU, HuggingFace Inference, Render GPU) bound by strict Zero Data Retention (ZDR) terms. User prompts are never logged to disk or used for foreign foundation model training.
- Database & Vault Isolation: Conversation threads and encrypted credentials are stored in PostgreSQL (Neon serverless) with row-level tenant isolation, protected at rest with AES-256-GCM and Post-Quantum ML-KEM-768 key encapsulation.
We implement comprehensive technical defense controls:
- HTTPS with HSTS (2-year, preload-eligible, TLS 1.3)
- Strict Firebase ID token validation with claims verification on every API request
- Strict Content Security Policy (CSP) with automated violation telemetry (
/api/security/csp-report) - Environment-driven CORS allowlist preventing unauthorized cross-origin execution
- Two-Factor Authentication (2FA) for admin and workspace accounts
Despite these measures, no system is 100% secure. You use the Services at your own risk.
4Data Retention
We retain your conversation threads and account data for as long as your account remains active. If you delete a conversation thread through the workspace interface, it is permanently deleted from our database. You may request full account deletion by contacting us — we will process such requests within 30 days.
Generated media (Pak-Image & Pak-Video): Images and videos generated and saved to your history are retained for as long as your account remains active or until you explicitly delete them via the workspace interface. Deleting a generated asset permanently removes it from our database. Starting photographs uploaded for Image-to-Video animation are processed transiently and are not stored beyond the duration of that generation request.
Server logs are retained for up to 30 days for security purposes, then automatically purged.
5Third-Party Service Providers
We share data with the following providers only to the extent necessary to operate the Services:
| Provider | Purpose | Data Shared |
|---|---|---|
| Google Firebase | Authentication | Email, OAuth tokens |
| Neon (PostgreSQL) | Data storage | Conversation threads, folder names, generated media assets |
| Groq | LLM inference | Chat messages (no persistent storage per Groq ToS) |
| HuggingFace | LLM, Pak-Image & Pak-Video inference | Chat query fallback, image/video generation prompts (processed under serverless ToS — not stored) |
| Render | Pak-Image & Pak-Video inference backend | Generation prompts and source images forwarded transiently — not persistently stored by Render |
| Vercel | Hosting & CDN | Anonymized page analytics, request logs |
We do not sell, rent, or trade your personal data to any third party for marketing purposes.
6Your Rights
Subject to applicable law, you have the right to:
- Access — Request a copy of the personal data we hold about you
- Rectification — Request correction of inaccurate data
- Erasure — Request deletion of your account and associated data
- Portability — Export your conversations via the in-app export feature (PDF, DOCX, Markdown)
- Objection — Object to processing of your data for certain purposes
To exercise these rights, contact us at info@sbf-consultancy.net.
7International Transfers
To deliver state-of-the-art tokenization and inference speeds, our sovereign control plane communicates with international cloud infrastructure (Vercel CDN, Firebase Auth, Neon Postgres, Groq, Render, HuggingFace):
- Zero Retention & Training Safeguards: Prompts sent to Groq LPU and HuggingFace inference backends are processed in volatile RAM only. Under enterprise Terms of Service, customer inputs are never stored, logged, or utilized to retrain foundation models.
- Transient Media Processing: Generation prompts and source photographs for Pak-Image and Pak-Video are transmitted via encrypted tunnels to dedicated GPU instances for the duration of the generation request only and are purged immediately.
We enforce technical safeguards (Amanah Gate pre-flight PII scrubbing, TLS 1.3 encryption, and PQC key exchange) to ensure that all cross-border communications comply with Pakistan's Draft Personal Data Protection Bill (PDPB)and international data transfer standards.
8Children's Privacy
The Services are not directed to individuals under 18 years of age. We do not knowingly collect personal information from minors. If we become aware that a minor has provided us with personal data, we will promptly delete it.
9Changes to This Policy
We may update this Privacy Policy periodically. The "Last updated" date at the top will reflect changes. For material changes, we will notify registered users via email or an in-app notice.
Privacy Contact
For privacy-related enquiries, data access requests, or complaints: info@sbf-consultancy.net — SBF Consultancy, Karachi, Sindh, Pakistan.