Privacy policy
What SureCite collects, and why.
SureCite reads and reviews supplier bills, answers UAE tax-law questions with citations, and — only where a firm turns it on — sends emails and reminders a person approved. This page says exactly what that involves: what reaches an AI model and what never does, what a connected Gmail or Outlook account lets us do, and how to disconnect and get your data deleted.
Effective 30 September 2026. SureCite is operated by Mahdi Kilani.
Signing in
Your identity, not your password.
You sign in through WorkOS, which verifies your identity and hands SureCite your verified email address and a short-lived proof of sign-in. SureCite reads that proof once, then issues its own session cookie for your browser — WorkOS's own tokens are not kept, except a session id used solely so that signing out can also end the WorkOS-side session. SureCite never sees or stores a password.
Google & Microsoft
Connecting a Gmail or Outlook account.
If your firm connects a mailbox so SureCite can send email and reminders on its behalf, here is exactly what that involves.
What we ask for
For Gmail: the gmail.send scope, plus your email address
(openid email). For Outlook: Microsoft's Mail.Send scope,
plus your email address. Both are send-only permissions.
What that does, and does not, let us do
- We can compose and send an email as the connected account.
- We cannot read, search or delete anything in your mailbox, and cannot see your contacts, labels, folders or calendar.
The connected email address itself is stored, so the app can show which account is connected and label who a message was sent from.
How it's used
SureCite only sends an email when it has been approved: either a one-off email or reminder a person at your firm clicked "Send" on, or an email generated from a template your firm has explicitly marked as trusted to send on a schedule. There is no path that sends mail without one of those two approvals.
Storage and protection
The refresh token Google or Microsoft issues is encrypted (AES-256-GCM) before storage and bound to your specific firm and provider, so a copied or relabelled token cannot be used elsewhere. The key lives only in server configuration — never in the database, never in a log.
Disconnecting
Disconnect a mailbox any time from Settings. For Gmail, disconnecting also asks Google to revoke the token. Microsoft gives us no simple way to revoke a token on your behalf, so disconnecting an Outlook account deletes our stored copy immediately; you can also remove SureCite from your Microsoft account's own app permissions to withdraw access completely. Either way, once disconnected we hold no working token and cannot send as that account again until you reconnect.
AI models
What reaches a model, and what never does.
SureCite uses AI models for two things, and they see different, limited data:
Law questions
Your question and passages retrieved from our fixed library of UAE laws and regulations are sent to OpenAI to draft a cited answer. The question and answer are also written to a private log on our own server, never committed to our source code and never shared, so we can review whether the system answered correctly.
"General task" (anything that isn't a law question)
Before anything leaves the server, client and staff names, ID numbers (TRN,
Corporate Tax number, trade licence number) and any line naming a tax are stripped
and replaced with placeholders such as [PERSON-1]. You see exactly that
stripped text before pressing Send, and only the stripped text is sent to the model.
The mapping back to real names lives in server memory only — never written to disk,
never logged — and is discarded the moment you send or cancel.
Search over the law library
Passages of the law library are converted to embeddings with OpenAI's
text-embedding-3-small so questions can be matched to the right page.
This runs over the law library's own text, not your questions or your clients' data.
Gmail and Outlook content is never part of any of this. Nothing sent or received through a connected mailbox is passed to OpenAI, or to any other AI model provider, for any reason — not to answer a question, not to draft an email, and not to train a model.
Supplier bills
Reading a bill stays on our own server.
Structured e-invoices are parsed as XML, and PDFs with a text layer are read locally with a PDF library — both are plain, deterministic parsing with no network call and no AI model involved. Where a firm turns on the scanned-document option, a scanned image or photo is read with Tesseract, an open-source OCR engine that runs on our own server. None of this sends a bill's contents anywhere else to be read.
Storage & security
Where data lives, and how it's kept apart.
Firm data lives in a Postgres database. Every table holding a firm's business data carries a row-level security policy enforced by the database itself, so one firm's rows cannot appear in another firm's queries even if application code has a bug. Outgoing email not sent through your own connected Gmail or Outlook — for example, from SureCite's own address when no mailbox is connected — goes through Resend, our transactional email provider.
SureCite runs today on a machine we operate directly, not a shared commercial cloud platform, and we're moving it to a dedicated machine we operate, physically located in the UAE. We don't publish further location detail here.
Retention & deletion
What happens when a client — or a firm — leaves.
When a client leaves a firm, the firm's owner can review everything SureCite holds about that client and download a full export — documents, bill lines, decisions, assistant actions, the audit trail, and profile fields — at any time.
How long we keep a former client's records is being set with legal advice. Until decided, deletion is not automatic: nothing in this system deletes a client's records on a schedule today. A retention setting and scheduled-deletion date are planned and shown to firms as "waiting for the retention period," but nothing acts on that date yet.
To disconnect a Gmail or Outlook account and have its stored token deleted, use Settings, or write to us below.
Sharing
We do not sell data, and we do not advertise with it.
We do not sell personal data. We do not share Google or Microsoft account data with any third party except the mail provider itself (to send the message you approved) and, where legally required, a regulator or court. We do not use Google user data, or any client data, for advertising, and we do not use it to train any AI model — ours or a provider's.
Google API Services
Google API Services User Data Policy
SureCite's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Contact & changes
Questions, or a request to delete your data.
For questions about this policy, to disconnect a mailbox, or to ask us to delete data we hold about you or your firm, write to mahdi.kilani@gmail.com.
This page was last updated 30 September 2026. If we change what we collect or how we use it, we'll update the date at the top of this page.