Privacy Policy

Last updated: 30 August 2026 · Applies to Floosi and the web app at app.floosi.net
The Arabic version of this policy is the legally binding text. This English version is provided for convenience only; if the two differ, the Arabic prevails.

Floosi is a personal finance assistant on WhatsApp and on the web that helps you follow your spending from bank statements you upload yourself. This policy explains what we process, why, who we share it with, and how you control it.

1. Data controller

The data controller for the purposes of Jordanian Personal Data Protection Law No. 24 of 2023 is:

The company behind the service

Legal nameAl-Maseer for Software & Computer Systems LLC
Legal name (Arabic)شركة المصير لبرامج وأنظمة الحاسوب ذ.م.م
Legal formLimited liability company
Commercial register no.82636
National entity no.200213727
Tax no.40394166
Registered addressOffice 1, 5th floor, Building 150, Wasfi Al-Tal Street, Tla' Al-Ali, Amman, Jordan
Emailinfo@almaseer.co
Company phone+962 77 147 7178
Floosi WhatsApp+962 77 147 7131
Company websitealmaseer.co

2. What we process

3. Legal basis and purpose

We process your data on the basis of your explicit consent when you begin using the Service, and on the necessity of performing the contract between us under the Terms & Conditions. The purposes are limited to: reading your statements and categorising your transactions; answering your financial questions; producing budgets, reports and financial statements; managing your subscription; and protecting the Service from abuse.

We do not use your financial data for advertising. We do not sell it, rent it or trade it, and we do not use it to train AI models.

4. Encryption — and why we cannot read your data

Your financial data is stored in a separate database belonging to you alone. Encrypting that database is something you switch on, and we invite you to when you start. Once you do, it is encrypted at rest with AES-256-GCM using a key derived from a passphrase only you know; we hold neither the passphrase nor the key, and the data is decrypted only during your active session. From that point the company's staff and operators cannot read the contents of your financial data.

Until you switch it on, your database is not encrypted. It is protected by the access controls on our servers, but not by cryptography. We say so plainly, because "all data is encrypted" is not true while switching it on is optional — and a sentence that reassures the reader without describing reality is worse than one that unsettles them and does.

We do not make encryption compulsory, and the reason matters: the passphrase is yours alone. If we forced it, forgetting it would mean losing your data permanently with no one able to bring it back. That is the same reason we cannot recover your data if you forget your passphrase — not a policy we chose, but a consequence of not holding the key.

Your account record — logins, plan, trial dates and language — is kept separately from that and is encrypted at rest with a key the Service manages. A third database holds currency exchange rates only, and no personal data.

5. Who we share with, and transfers outside Jordan

We share only what is necessary, with providers acting as processors on our behalf under contractual obligations:

What is never sent to any of them: your encryption passphrase, the keys to your database, and the database file itself — no processor ever receives your complete financial records. What is sent is set out above, processor by processor: the PDF statement to the extraction provider, and the transaction data needed to answer a question to the AI provider.

In the web app the text transcribed from your voice is placed in the message box for you to read, and nothing is sent until you press send. It is a proposal, not a submission: if the transcription is wrong you edit it or delete it, and words you never said never enter your record. Anything you had already typed is kept — the transcript is added to it rather than replacing it.

Some of these processors are located outside the Hashemite Kingdom of Jordan, which means a cross-border transfer of data. By using the Service you consent to that transfer to the extent necessary to operate it. We disclose your data to no one else unless required by Jordanian law or a judicial order.

6. Statement files

The statement file you upload is passed to the extraction provider without being saved as a file on our server; what we keep is the transaction data extracted from it, held as described in clause 4.

The file itself stays with the extraction provider for 90 days and is then deleted. That 90 days is a setting we choose on our own mailbox there, not a schedule it imposes on us — we say so because a policy that hands a processor the responsibility for a setting its customer controls sends the reader to the wrong party to ask. Its own policy says a deleted document leaves its active systems immediately and its backups within 45 days.

7. Retention and deletion

We keep your transaction data for as long as your account exists, because that data is the Service. You can delete your account and everything in it at any time, from the web app's settings or by sending the deletion request to the bot; both run the same code, because this product has one deletion path and no second one. On deletion:

Floosi's data has no backup outside the server it runs on. Its backups sit on the same disk as the live data. We say so because a copy that never leaves the machine it protects does not protect against losing that machine, and implying a redundancy that does not exist is worse than admitting it is missing.

Backups are never opened, searched or edited to remove one record; they age out in rotation within the period above, and are only ever used to bring the Service back after a failure. A backup carries exactly the encryption the live file had: if you switched encryption on, the copy is unreadable to us as well; if you did not, the copy is no better protected than the original. We may keep billing records for the period required by Jordanian income and sales tax law.

8. Your rights

Under Personal Data Protection Law No. 24 of 2023 you have the right to:

To exercise any of these, write to info@almaseer.co and we will respond within the period set by law.

9. Complaints

If our response does not satisfy you, you may complain to the Personal Data Protection Unit at the Ministry of Digital Economy and Entrepreneurship, the supervisory authority in the Hashemite Kingdom of Jordan.

10. Security

We apply technical and organisational measures including encryption in transit always, and at rest whenever you have switched it on (clause 4), a separate database per user, administrative server access restricted to a private network, and backups that carry their source's encryption. No system is completely secure, but the design aims to keep the contents of your data unreadable even to the people who run it.

11. Children

The Service is for people aged 18 and over. We do not knowingly collect minors' data, and we delete it if we discover we have.

12. Changes to this policy

We may update this policy. The last-updated date appears at the top of the page, and we will notify you of any material change through the bot or by email before it takes effect.

Change log
30 August 2026the AI provider named in section 5 changed from Together AI to OpenRouter, Inc. What we do with your data did not change; who serves the model did. The model is the same open-weights DeepSeek V4 Pro build, and the commitment that your data is not stored and is not used to train models still stands — it now rests on the Zero Data Retention condition set on our OpenRouter account rather than on section 2.6 of Together's policy, which no longer describes the route your data takes and whose citation has been removed. Speech-to-text moved with the model and is covered by the same condition. Nothing else about what is sent, or not sent, changed.

30 August 2026 — four statements in this policy were corrected because they did not match what the system does. Hosting: section 5 named DigitalOcean in Singapore; Floosi in fact runs on WafaiCloud in Riyadh. That clause is about transfers across borders, so the correction is not a detail. Encryption: section 4 said your data is encrypted without qualification; encryption is something you switch on and you may not have. It now says so. Backups: the policy promised encrypted off-site backups, and Floosi has no copy outside its own server. Section 7 now says that too. Processors: Google sign-in, our website's content-delivery provider and the exchange-rate sources were in use and unnamed, and are now named with what each receives. Section 6 also now states that the 90 days at the extraction provider is a setting we choose rather than a schedule it imposes, and section 7 states in full what deletion destroys. None of this changed what we do with your data; it changed what this policy says about it.

23 August 2026Resend was added to the processor list in section 5. It has received your email address since email sign-up shipped and was not named, while the list closes by saying we disclose your data to no one else. In the same section: the hosting provider is now named with its region, spreadsheets are stated as never reaching the extraction provider, and what is never sent to any processor is spelled out. What we do with your data has not changed — what this policy says about it has.

23 August 2026 — the AI provider named in section 5 changed from Anthropic PBC to Together AI. What is sent to it, and what is not, did not change: we do not send the statement file itself, your name, your email address or your phone number. The commitment that this data is not stored and is not used to train models still stands, and no other clause in this policy changed.
24 August 2026 — voice input was added to the web app, and voice notes now reach the same AI provider named in section 5. This adds a new category of personal data leaving the Service: audio recordings of your voice. They are sent to be transcribed and are covered by the same Zero Data Retention terms as your transaction data — not stored, not used for training. We do not keep the audio either: it is held in memory, transcribed, and dropped. Only the resulting text is saved, as part of your conversation history, and you can delete that history at any time.

13. Language

The Arabic version is the legally binding text; this English version is for convenience only.

14. Contact

info@almaseer.co · +962 77 147 7178 · Office 1, 5th floor, Building 150, Wasfi Al-Tal Street, Tla' Al-Ali, Amman, Jordan.