Fambuh AI

English Français

Privacy Policy

Version 1.1 · Effective 2026-08-31T05:30:48.531476+00:00 · Last updated 2026-08-31T05:30:48+00:00

French is a convenience translation for Cameroon’s bilingual public. If a translation conflicts with the English original, the English text controls unless mandatory local law requires otherwise.

Privacy Policy

Fambuh AI

Version: 1.1 Effective date: 2026-08-31 Last updated: 2026-08-31

This Privacy Policy describes how ORGAMU SCOOPS ("we", "us") processes personal information in connection with Fambuh AI (the "Service"). It is based on the application's implemented behaviour at the time this version was prepared, not on unverified claims of legal compliance.

This Policy describes how ORGAMU SCOOPS processes personal information for the Service as implemented. It does not claim that the Service is fully compliant with the GDPR, UK GDPR, CCPA/CPRA, COPPA, or any other privacy law. Those regimes apply only where the organisation, hosting, contracts, and target markets bring them into force.

The User Agreement is a separate contract. This Policy explains processing of personal information. Where law requires consent for a specific processing activity, that consent is requested separately and is not hidden inside the User Agreement checkbox.


1. Who is responsible

ORGAMU SCOOPS operates the Service and decides why and how personal information is processed for it (the organisation responsible for the Service). If you are a business customer who uses the Service to process your own customers' data, your role and ours may differ and should be set out in a separate processing agreement. This Policy does not claim a GDPR "controller" or CCPA "business" status unless those laws actually apply to the live deployment.


2. Scope

This Policy applies to the web application, its API, and related transactional emails. It does not apply to third-party websites or social networks you publish to, except for the limited data we send to them when you instruct us to publish or connect an account.


3. Information we collect

We collect information that you provide, that is generated when you use the Service, and that is created by the systems that run the Service. We do not currently collect government ID, date of birth, telephone number, or billing street address as dedicated account fields.

3.1 Account and profile

3.2 Workspace, team, and project data

Audience fields may include demographic descriptions you enter for content planning (for example an audience age range). Those fields describe your intended audience; they are not a verified record of your age.

3.3 Generated and media content

3.4 Social publishing credentials

If you connect a social account, we store platform identifiers and encrypted access tokens or similar credentials when encryption is configured, together with connection status and error messages. Credential types depend on the platform (for example access tokens, page IDs, API keys).

3.5 Provider API keys you supply

If you save your own provider keys in workspace settings, they are stored encrypted when a server encryption key is configured. Treat those keys as secrets. Do not submit keys in prompts.

3.6 Billing and payments

We store subscription plan, status, billing interval, period dates, cancellation flags, credit balances, and credit ledger entries.

We do not store full payment-card numbers or mobile-money wallet secrets in the application database. Payments are handled by CamPay and/or Stripe when those integrations are enabled.

When you start a CamPay payment, we may send your email address and name (split from your profile name) to CamPay together with amount, description, and payment references. When Stripe is used, we may send email, workspace name, and identifiers such as workspace and user id as customer metadata. Webhook payloads from payment providers may be stored for reconciliation.

3.7 Technical, security, and usage information

We do not currently store a dedicated device-fingerprint. Client authentication uses a first-party HttpOnly session cookie. The session token is not returned in API JSON and is not stored in localStorage.

3.8 Cookies and similar technologies

See Section 8.

3.9 Information we do not intentionally collect as product analytics

The application code reviewed for this Policy does not integrate Google Analytics, Mixpanel, Segment, PostHog, Hotjar, Amplitude, or similar product-analytics SDKs. If the Platform Owner later adds them, this Policy must be updated and, where required, additional consent obtained.


4. How we use information

We use personal information to:

We do not currently use a separate marketing-email list. Transactional auth emails are sent because they are needed to operate the account.


5. AI processing and third-party models

To generate content, the Service sends prompts and related generation context to configured AI providers. That context can include topics, scripts, captions, brand voice, audience descriptions, calendar briefs, style-reference summaries, and (for some video providers) still images.

Default providers in the software configuration (any of which may be changed per deployment) include:

What we do not claim: we do not assert that a given provider will or will not train models on your data, retain prompts, or delete them after a stated period, unless the Platform Owner has a current contract or the provider's then-current terms that say so. You should review the provider terms that apply to your deployment.

Minimisation: we send what is required to fulfil a generation or media request. We do not intend to send your password or payment-card number to AI providers. Avoid putting unnecessary personal data about identifiable people in prompts. Workspace "bring your own key" options, if used, send requests under your provider account.

Stock search sends search queries (not your full account profile) to Pexels and/or Unsplash when those features are used. Music import by an administrator may call Pixabay. Publishing sends captions and media to the social networks you connect.


6. Categories of third parties

Depending on configuration, personal information may be processed by:

| Category | Examples present in the software | Typical data | |----------|----------------------------------|--------------| | AI / media generation | OpenAI, Anthropic, Runware, and other configured providers | Prompts, scripts, images | | Stock media | Pexels, Unsplash | Search queries | | Music | Local library; Epidemic Sound if configured; Pixabay import | Queries / files | | Social networks | Meta, LinkedIn, TikTok, YouTube, Pinterest, X, Threads | Tokens, captions, media | | Payments | CamPay, Stripe | Name, email, amounts, references | | Email delivery | Configured SMTP provider | Email, name, auth links | | Storage | Local disk or Amazon S3 | Files you generate or upload | | Infrastructure | Hosting, Redis/Celery | Operational/task data | | Error monitoring (optional) | Sentry when SENTRY_DSN is set | Exception type/stack, request path, job/task identifiers, and optional warning/error structured logs (e.g. payment reference and amount). Info-level logs are not sent. Cookies, Authorization headers, and likely API keys are stripped. No browser Sentry SDK is loaded. | | Productivity | Google Sheets API if calendar import is configured | Spreadsheet content you import |

We do not sell personal information in the sense of a dedicated data-brokerage feature. Whether "sale" or "sharing" under CCPA/CPRA or similar laws applies (including advertising or other optional third-party tools if they are added later) requires legal analysis of the live deployment and is not asserted here.


7. International transfers

The Platform Owner's hosting region, and the regions used by OpenAI, Anthropic, CamPay, Stripe, Google, Meta, Amazon, and other providers, may differ from your country. Personal information may be processed in other countries. Transfer tools (adequacy decisions, standard contractual clauses, or other mechanisms) must be put in place by the Platform Owner where required. This Policy does not claim that a particular transfer mechanism is in place until that is verified.


8. Cookies, local storage, and similar technologies (Cookie Policy)

This section is the Service's cookie / similar-technologies notice. It describes browser storage the application code actually uses. It is not a claim that any category is legally exempt from consent in every jurisdiction.

The Service is primarily a browser application. Authentication uses a first-party HttpOnly cookie. Some preferences use localStorage, and one payment return flow uses sessionStorage.

Essential / strictly necessary

Functional preferences

Other client storage

Fonts

YouTube video embeds (optional)

Third-party cookies, analytics, and advertising

A storage/consent banner is not shown while the application only uses the essential and functional storage listed above. If optional third-party browser technologies are enabled (for example configured YouTube video embeds, or analytics or advertising if added later), they are isolated behind consent gating and/or a click-to-play control, and COOKIE_CONSENT_REQUIRED may be used to display a notice. Essential storage required to operate a logged-in session cannot be disabled if you choose to use an account.

For the current Cameroon-established deployment, a consent banner is not shown while only the essential and functional storage listed above is used. If YouTube video IDs are configured, embeds load only after consent or click-to-play (youtube-nocookie.com). This Policy does not claim that first-party cookies or localStorage are exempt from every cookie law (for example ePrivacy/GDPR if EEA users are later targeted).


9. Data retention

Unless the Platform Owner configures otherwise:

LEGAL_ACCOUNT_RETENTION_DAYS, LEGAL_CONTENT_RETENTION_DAYS, and LEGAL_LOG_RETENTION_DAYS set to 0 mean there is no additional timed purge of active accounts, content, or logs beyond the deletion-request process above.


10. Access, correction, deletion, and other rights

Depending on the laws that apply to you, you may have rights to access, correct, delete, restrict, or object to certain processing, to receive a copy of personal information, to withdraw consent, and to complain to a supervisory authority.

Not every user has every right in every country. For example, GDPR rights apply to people protected by that law; CCPA/CPRA rights apply under California law when that statute covers the organisation; other regions differ.

The Service provides:

Deletion has limits: we may retain information we must keep for security, billing disputes, legal claims, or the integrity of acceptance records. Workspace content belonging to other members, or that we must keep by law, may not be erased on the same timeline. Consent records are not rewritten by users.

To exercise rights, use the in-product controls or email [email protected]. We may need to verify your request.

You may also complain to a competent authority in your country if that authority has jurisdiction. ORGAMU SCOOPS is established in Cameroon. Cameroonian users may raise concerns with the competent Cameroonian authority for electronic communications and cybersecurity matters. Users in the EEA, United Kingdom, or other regions with a dedicated data-protection authority may complain to that authority. We do not claim that a particular foreign statute applies solely because this contact path exists.


11. Children's privacy

The Service is directed at users who are at least 18 years old. You confirm this at registration. We do not knowingly create accounts for children below that age.

This is not a claim of COPPA or equivalent compliance. The Service does not collect a verified date of birth. If you believe a child has an account, contact [email protected] so we can disable it.


12. Security

We implement reasonable technical and organisational measures appropriate to a SaaS application of this type, including:

No method of transmission or storage is 100% secure. We do not claim military-grade, unbreakable, or guaranteed security. You should use a strong unique password and protect devices on which you use the Service.


13. Automated decision-making

The Service uses automation and AI to generate content you request. It does not currently implement a consumer credit-scoring or similarly legally defined "solely automated decision producing legal effects" as a product feature. If that changes, this Policy will need an update and legal review.


14. Changes to this Policy

We may update this Policy. Each version has a version number and effective date. Prior versions are retained. If a new version is configured to require renewed acknowledgement, the Service will ask for an active acknowledgement before you continue with features that depend on it.

The current Policy is published at /privacy.


15. Contact

ORGAMU SCOOPS Mile 4 Nkwen, Bamenda, North West Region, Cameroon Privacy: [email protected] Support: [email protected] Data protection contact: [email protected]

Contact

ORGAMU SCOOPS
Mile 4 Nkwen, Bamenda, North West Region, Cameroon

Privacy: [email protected]
Support: [email protected]

Jurisdiction notice: Courts of Yaoundé, Centre Region, Cameroon (interim relief and award enforcement)