Privacy Policy
Fambuh AI
Version: 1.1 Effective date: 2026-08-31 Last updated: 2026-08-31
This Privacy Policy describes how ORGAMU SCOOPS ("we", "us") processes personal information in connection with Fambuh AI (the "Service"). It is based on the application's implemented behaviour at the time this version was prepared, not on unverified claims of legal compliance.
This Policy describes how ORGAMU SCOOPS processes personal information for the Service as implemented. It does not claim that the Service is fully compliant with the GDPR, UK GDPR, CCPA/CPRA, COPPA, or any other privacy law. Those regimes apply only where the organisation, hosting, contracts, and target markets bring them into force.
The User Agreement is a separate contract. This Policy explains processing of personal information. Where law requires consent for a specific processing activity, that consent is requested separately and is not hidden inside the User Agreement checkbox.
1. Who is responsible
- Organisation: ORGAMU SCOOPS
- Business address: Mile 4 Nkwen, Bamenda, North West Region, Cameroon
- Privacy contact: [email protected]
- Support: [email protected]
- Data protection contact / DPO (if applicable): [email protected]
ORGAMU SCOOPS operates the Service and decides why and how personal information is processed for it (the organisation responsible for the Service). If you are a business customer who uses the Service to process your own customers' data, your role and ours may differ and should be set out in a separate processing agreement. This Policy does not claim a GDPR "controller" or CCPA "business" status unless those laws actually apply to the live deployment.
2. Scope
This Policy applies to the web application, its API, and related transactional emails. It does not apply to third-party websites or social networks you publish to, except for the limited data we send to them when you instruct us to publish or connect an account.
3. Information we collect
We collect information that you provide, that is generated when you use the Service, and that is created by the systems that run the Service. We do not currently collect government ID, date of birth, telephone number, or billing street address as dedicated account fields.
3.1 Account and profile
- name;
- email address;
- password (stored as a one-way hash, not in recoverable form);
- role (for example user or administrator);
- email-verification status and timestamps;
- last login time;
- account active/deactivated status.
3.2 Workspace, team, and project data
- workspace name and settings (including language, timezone, brand voice, and publishing preferences);
- team membership (email of invited users must already have an account);
- project names, descriptions, and settings;
- content calendars (including brand, audience, goals, schedule, and related configuration you enter);
- posts, captions, scripts, topics, hashtags, keywords, and notes;
- job records (payloads, results, logs, errors);
- uploaded files such as calendars (subject to a maximum upload size configured on the server).
Audience fields may include demographic descriptions you enter for content planning (for example an audience age range). Those fields describe your intended audience; they are not a verified record of your age.
3.3 Generated and media content
- AI-generated text, images, audio, video, and associated metadata;
- uploaded or fetched style-reference information (if you provide a public URL, the server may fetch that URL);
- stock-media search queries and downloaded media attached to posts;
- music library selections and related metadata.
3.4 Social publishing credentials
If you connect a social account, we store platform identifiers and encrypted access tokens or similar credentials when encryption is configured, together with connection status and error messages. Credential types depend on the platform (for example access tokens, page IDs, API keys).
3.5 Provider API keys you supply
If you save your own provider keys in workspace settings, they are stored encrypted when a server encryption key is configured. Treat those keys as secrets. Do not submit keys in prompts.
3.6 Billing and payments
We store subscription plan, status, billing interval, period dates, cancellation flags, credit balances, and credit ledger entries.
We do not store full payment-card numbers or mobile-money wallet secrets in the application database. Payments are handled by CamPay and/or Stripe when those integrations are enabled.
When you start a CamPay payment, we may send your email address and name (split from your profile name) to CamPay together with amount, description, and payment references. When Stripe is used, we may send email, workspace name, and identifiers such as workspace and user id as customer metadata. Webhook payloads from payment providers may be stored for reconciliation.
3.7 Technical, security, and usage information
- IP address on many authentication and audit events (for example registration, login, logout, password reset);
- IP address and browser user-agent on legal acceptance records (to evidence which version you agreed to);
- rate-limiting by IP address;
- API usage metrics (provider name, token/unit counts, cost estimates, latency, success/failure);
- job and application logs.
We do not currently store a dedicated device-fingerprint. Client authentication uses a first-party HttpOnly session cookie. The session token is not returned in API JSON and is not stored in localStorage.
3.8 Cookies and similar technologies
See Section 8.
3.9 Information we do not intentionally collect as product analytics
The application code reviewed for this Policy does not integrate Google Analytics, Mixpanel, Segment, PostHog, Hotjar, Amplitude, or similar product-analytics SDKs. If the Platform Owner later adds them, this Policy must be updated and, where required, additional consent obtained.
4. How we use information
We use personal information to:
- create and authenticate accounts;
- provide workspace, calendar, generation, storage, and publishing features;
- send prompts and necessary context to AI and media providers to perform your requests;
- process payments and allocate credits;
- provide customer and administrative support;
- maintain security, prevent abuse and fraud, and debug failures;
- produce operational metrics and improve reliability;
- communicate about the account (verification, password reset, magic-link sign-in);
- record and audit legal-document acceptance;
- comply with law and enforce the User Agreement.
We do not currently use a separate marketing-email list. Transactional auth emails are sent because they are needed to operate the account.
5. AI processing and third-party models
To generate content, the Service sends prompts and related generation context to configured AI providers. That context can include topics, scripts, captions, brand voice, audience descriptions, calendar briefs, style-reference summaries, and (for some video providers) still images.
Default providers in the software configuration (any of which may be changed per deployment) include:
- text: OpenAI or Anthropic;
- images: OpenAI and optional alternatives (including ModelsLab, Stable Diffusion-compatible endpoints, ComfyUI, Automatic1111, Flux);
- video: Runware and optional alternatives (including Runway, Luma, Pika, Kling, Veo);
- speech: OpenAI and optional alternatives (including ElevenLabs, Azure Speech, Google TTS).
What we do not claim: we do not assert that a given provider will or will not train models on your data, retain prompts, or delete them after a stated period, unless the Platform Owner has a current contract or the provider's then-current terms that say so. You should review the provider terms that apply to your deployment.
Minimisation: we send what is required to fulfil a generation or media request. We do not intend to send your password or payment-card number to AI providers. Avoid putting unnecessary personal data about identifiable people in prompts. Workspace "bring your own key" options, if used, send requests under your provider account.
Stock search sends search queries (not your full account profile) to Pexels and/or Unsplash when those features are used. Music import by an administrator may call Pixabay. Publishing sends captions and media to the social networks you connect.
6. Categories of third parties
Depending on configuration, personal information may be processed by:
| Category | Examples present in the software | Typical data | |----------|----------------------------------|--------------| | AI / media generation | OpenAI, Anthropic, Runware, and other configured providers | Prompts, scripts, images | | Stock media | Pexels, Unsplash | Search queries | | Music | Local library; Epidemic Sound if configured; Pixabay import | Queries / files | | Social networks | Meta, LinkedIn, TikTok, YouTube, Pinterest, X, Threads | Tokens, captions, media | | Payments | CamPay, Stripe | Name, email, amounts, references | | Email delivery | Configured SMTP provider | Email, name, auth links | | Storage | Local disk or Amazon S3 | Files you generate or upload | | Infrastructure | Hosting, Redis/Celery | Operational/task data | | Error monitoring (optional) | Sentry when SENTRY_DSN is set | Exception type/stack, request path, job/task identifiers, and optional warning/error structured logs (e.g. payment reference and amount). Info-level logs are not sent. Cookies, Authorization headers, and likely API keys are stripped. No browser Sentry SDK is loaded. | | Productivity | Google Sheets API if calendar import is configured | Spreadsheet content you import |
We do not sell personal information in the sense of a dedicated data-brokerage feature. Whether "sale" or "sharing" under CCPA/CPRA or similar laws applies (including advertising or other optional third-party tools if they are added later) requires legal analysis of the live deployment and is not asserted here.
7. International transfers
The Platform Owner's hosting region, and the regions used by OpenAI, Anthropic, CamPay, Stripe, Google, Meta, Amazon, and other providers, may differ from your country. Personal information may be processed in other countries. Transfer tools (adequacy decisions, standard contractual clauses, or other mechanisms) must be put in place by the Platform Owner where required. This Policy does not claim that a particular transfer mechanism is in place until that is verified.
8. Cookies, local storage, and similar technologies (Cookie Policy)
This section is the Service's cookie / similar-technologies notice. It describes browser storage the application code actually uses. It is not a claim that any category is legally exempt from consent in every jurisdiction.
The Service is primarily a browser application. Authentication uses a first-party HttpOnly cookie. Some preferences use localStorage, and one payment return flow uses sessionStorage.
Essential / strictly necessary
- Session cookie (
cap_session, HttpOnly, SameSite=Lax, Secure in production). It holds a time-limited JWT used to authenticate API requests. The token is not placed in the login JSON body and is not readable by JavaScript. Logout and password changes increment a server-side token version so outstanding cookies stop working. Cookie lifetime follows the configuredJWT_EXPIRE_MINUTESvalue.
Functional preferences
- Theme (
cap_theme) and language (cap_locale) inlocalStorage. These remember UI appearance and language. They are not advertising identifiers. - Optional storage-consent choice (
cap_cookie_consent) inlocalStorageif a consent banner is shown.
Other client storage
- Temporary CamPay checkout references in
sessionStorage(campay_pending) during payment return so the application can verify the payment with the server. This is discarded after verification.
Fonts
- Interface fonts (IBM Plex Sans, IBM Plex Mono, and Sora) are self-hosted with the application. The browser loads them from the same origin as the app. The application does not request fonts from
fonts.googleapis.comorfonts.gstatic.com.
YouTube video embeds (optional)
- The Platform Owner may configure YouTube video IDs for promotional or tutorial videos instead of (or in addition to) storing MP4 files on the Service.
- The application does not load YouTube automatically on page load. A YouTube embed (
youtube-nocookie.com) is created only after you allow optional third-party storage or click a control to play that YouTube video. - If a local copy of the video is stored on the Service and you have not allowed YouTube, the application plays that local file instead.
- Loading a YouTube embed causes your browser to contact Google/YouTube. Google may set cookies or similar technologies and process data under YouTube's and Google's terms and privacy policies, which this Policy does not control.
Third-party cookies, analytics, and advertising
- The application code does not currently set advertising cookies.
- The application code does not currently load product-analytics, advertising, marketing-pixel, or similar tracking scripts in the browser.
- Checkout may redirect you to CamPay or Stripe hosted payment pages. Those providers operate their own sites and may use cookies under their policies while you are on their pages. That is not a cookie set by this application's origin.
A storage/consent banner is not shown while the application only uses the essential and functional storage listed above. If optional third-party browser technologies are enabled (for example configured YouTube video embeds, or analytics or advertising if added later), they are isolated behind consent gating and/or a click-to-play control, and COOKIE_CONSENT_REQUIRED may be used to display a notice. Essential storage required to operate a logged-in session cannot be disabled if you choose to use an account.
For the current Cameroon-established deployment, a consent banner is not shown while only the essential and functional storage listed above is used. If YouTube video IDs are configured, embeds load only after consent or click-to-play (youtube-nocookie.com). This Policy does not claim that first-party cookies or localStorage are exempt from every cookie law (for example ePrivacy/GDPR if EEA users are later targeted).
9. Data retention
Unless the Platform Owner configures otherwise:
- account and workspace content are retained while the account remains active;
- a user deletion request deactivates the account immediately and records
AccountDeletionRequest; - after the configured grace period (
ACCOUNT_DELETION_GRACE_DAYS, default 30 days), pending requests are purged: workspace files, API keys, and social credentials are deleted, cloned voices are removed, and the account is anonymised; - administrators may retain a request (legal hold) so auto-purge does not run, or purge earlier;
- legal acceptance records are retained as evidence of agreement (IP address and user-agent on those records may be removed after Fambuh AI's configured consent-metadata retention period; the acceptance itself is kept);
- payment-provider records follow the processor's retention plus copies stored in billing event records;
- audit logs are retained until deleted by operations processes;
- residual copies may remain in encrypted backups until those backups rotate.
LEGAL_ACCOUNT_RETENTION_DAYS, LEGAL_CONTENT_RETENTION_DAYS, and LEGAL_LOG_RETENTION_DAYS set to 0 mean there is no additional timed purge of active accounts, content, or logs beyond the deletion-request process above.
10. Access, correction, deletion, and other rights
Depending on the laws that apply to you, you may have rights to access, correct, delete, restrict, or object to certain processing, to receive a copy of personal information, to withdraw consent, and to complain to a supervisory authority.
Not every user has every right in every country. For example, GDPR rights apply to people protected by that law; CCPA/CPRA rights apply under California law when that statute covers the organisation; other regions differ.
The Service provides:
- profile name and password update in the account area;
- a downloadable copy of core account information you request from the account area (portability export of account, acceptance, and workspace summary data);
- an account deletion request that deactivates the account immediately and records the request; workspace files are purged after the grace period unless retained for a legal hold.
Deletion has limits: we may retain information we must keep for security, billing disputes, legal claims, or the integrity of acceptance records. Workspace content belonging to other members, or that we must keep by law, may not be erased on the same timeline. Consent records are not rewritten by users.
To exercise rights, use the in-product controls or email [email protected]. We may need to verify your request.
You may also complain to a competent authority in your country if that authority has jurisdiction. ORGAMU SCOOPS is established in Cameroon. Cameroonian users may raise concerns with the competent Cameroonian authority for electronic communications and cybersecurity matters. Users in the EEA, United Kingdom, or other regions with a dedicated data-protection authority may complain to that authority. We do not claim that a particular foreign statute applies solely because this contact path exists.
11. Children's privacy
The Service is directed at users who are at least 18 years old. You confirm this at registration. We do not knowingly create accounts for children below that age.
This is not a claim of COPPA or equivalent compliance. The Service does not collect a verified date of birth. If you believe a child has an account, contact [email protected] so we can disable it.
12. Security
We implement reasonable technical and organisational measures appropriate to a SaaS application of this type, including:
- hashing of passwords;
- encrypted storage of certain secrets when a server encryption key is configured;
- access control and administrator-only areas;
- rate limiting on sensitive routes;
- security headers and CORS restrictions;
- audit logging of important account events;
- hashed storage of email verification and reset tokens.
No method of transmission or storage is 100% secure. We do not claim military-grade, unbreakable, or guaranteed security. You should use a strong unique password and protect devices on which you use the Service.
13. Automated decision-making
The Service uses automation and AI to generate content you request. It does not currently implement a consumer credit-scoring or similarly legally defined "solely automated decision producing legal effects" as a product feature. If that changes, this Policy will need an update and legal review.
14. Changes to this Policy
We may update this Policy. Each version has a version number and effective date. Prior versions are retained. If a new version is configured to require renewed acknowledgement, the Service will ask for an active acknowledgement before you continue with features that depend on it.
The current Policy is published at /privacy.
15. Contact
ORGAMU SCOOPS Mile 4 Nkwen, Bamenda, North West Region, Cameroon Privacy: [email protected] Support: [email protected] Data protection contact: [email protected]