SSayScopeOpen workspace

Legal information

Privacy notice

How the SayScope website, workspace and Android app handle personal information under South Africa's Protection of Personal Information Act (POPIA).

Version 2026-09-28 · Updated 21 September 2026

1. Who is responsible

The responsible party is VisaRequest (Pty) Ltd, trading as SayScope. Its supplier, contact and Information Officer details are published on the Legal information page.

2. Information we process

  • Account information: name, email address, mobile number, password hash, verification status, account status and administrator-security records.
  • Security and usage information: session identifiers, hashed request identifiers, login-attempt records, AI operation type, estimated tokens/costs, timestamps and technical error records.
  • Device and app information: browser or Android System WebView user-agent information, device category, screen and viewport dimensions, IP address and technical diagnostics needed to deliver and secure the service. SayScope does not request an Android advertising ID, precise location, contacts, camera or broad device-storage access.
  • Optional website analytics: after consent, page path without its query string, page title, general browser/device information, referral source, campaign measurement identifiers, clicks, form-field focus, scroll milestones and time on page. Click records may include a short visible button or field label and page coordinates, but never a value entered into a field. To measure a completed registration reliably, SayScope may send Meta a one-way hash of the verified email address together with campaign/browser identifiers, technical request information and a deduplication identifier. This excludes conversation and payment content.
  • Billing information: selected credit pack, amount, PayFast transaction references and status, credits and ledger entries. SayScope does not receive or store full card details.
  • Conversation content: WhatsApp exports are inspected and parsed in the browser. New imports synchronize parsed messages, conversation details, selected supported media and saved AI results to the user's account when cloud storage is enabled. The original ZIP is not uploaded. Older browser-only conversations are uploaded only after the user selects and confirms migration. Browser copies support offline use.
  • AI inputs and outputs: only content selected for a transcription, question, insight, attachment analysis or generated file is sent to the AI service for that operation.
  • Media request recovery: when enabled, SayScope temporarily stores voice-note transcripts and attachment analyses privately with account-owned request identifiers, content hashes and credit references, including for chats kept locally. This lets the device retrieve a completed result after an interrupted connection without another AI charge. Recovery does not store the uploaded source file.
  • Support correspondence: information a person chooses to send when requesting help, exercising a privacy right or reporting a problem.

Conversation exports can contain personal information about participants who are not SayScope account holders, including names, contact details, opinions, images, voice recordings and potentially special personal information. Users must have a lawful basis and authority to process that content.

3. Sources, purposes and necessity

Account, support and payment information comes from the account holder or PayFast. Conversation content comes from the user's selected export and may relate to other participants. We process information to create and secure accounts, supply requested features, prevent abuse, administer credits and payments, provide support, meet legal obligations and establish or defend legal claims.

Account fields marked as required are necessary to create and protect an account. Supplying a chat export or invoking an AI feature is voluntary, but the selected feature cannot operate without the relevant content. Refusing required payment information means a live credit purchase cannot be completed.

4. Local storage and cookies

Browser and Android app WebView copies remain until the user deletes them, clears site or app data, uninstalls the app, or a connected device learns that its cloud conversation was deleted. Incoming Android shares can remain in private app cache for retry across restarts until replaced, evicted by Android or removed with app storage; pending exports are removed after success, cancellation or a subsequent fresh launch. Account copies are held in the SayScope database and private media storage for cross-device access. SayScope uses an essential, secure, HttpOnly session cookie to keep a user signed in. Optional first-party website activity, Google Analytics, Meta Pixel and consent-respecting server-side Meta conversion measurement operate only after an affirmative analytics choice and can be rejected without losing product access. Raw first-party activity, campaign attribution and conversion-delivery records are retained for up to 90 days. See the Cookie and local-storage notice.

5. Recipients and operators

  • hosting, database and email delivery providers that operate the service;
  • OpenAI, when the user deliberately invokes an AI feature;
  • PayFast, when the user starts a payment;
  • Google Analytics and Meta Pixel/Conversions API, only for optional website and advertising measurement after consent;
  • Capacitor and Android system components, which provide the SayScope Android app shell, WebView, document picker and share handling on the device;
  • professional advisers, auditors and authorities where reasonably necessary or legally required.

The current SayScope Android app does not include Firebase, Google Mobile Ads or another native advertising SDK. The hosted service can load the consent-gated Google Analytics and Meta measurement tools described above inside its WebView. SayScope does not sell personal information. If the app's services or SDKs change, this notice and the Google Play Data safety declaration must be updated before the changed collection or sharing begins.

API content is not used by OpenAI to train its models unless the API customer explicitly opts in. Depending on the endpoint and account controls, OpenAI may retain customer content for abuse monitoring or application-state purposes. SayScope sends Responses API requests with storage disabled, but the provider's documented abuse-monitoring rules still apply. Audio transcription has different documented retention characteristics.

6. Cross-border processing

OpenAI and other infrastructure providers may process information outside South Africa. Cross-border processing must be limited to circumstances permitted by POPIA section 72, including appropriate contractual or other legally recognised safeguards. The responsible party maintains and periodically reviews its provider and transfer records.

7. Retention

  • browser-local chats remain until the user deletes them, clears site data or a connected device observes deletion of its cloud copy;
  • live cloud conversations and media are removed when the user deletes them, subject to normal backup retention; offline browser copies on other devices are invalidated when those devices reconnect;
  • temporary media recovery records are accessible for 24 hours from the request timestamp and removed by the next hourly application-maintenance run; clear-uploaded-data and account-deletion operations remove these records and invalidate old recovery requests. During service inactivity, physical cleanup resumes at the next maintenance run. Credit-ledger evidence remains subject to the billing retention policy;
  • expired sessions, password-reset tokens, verification tokens and temporary security challenges are deleted through scheduled or application maintenance;
  • login-attempt records are retained briefly for abuse prevention;
  • account records are kept while the account is active and then deleted or de-identified when no longer lawfully required;
  • payment and credit-ledger records may be retained for accounting, tax, fraud, refund and dispute obligations.

When self-service account tools are enabled, Clear uploaded data deletes live account-owned conversations, messages, uploaded media, saved AI results and import records while preserving the account and the billing, credit, legal, security and audit records described above. The self-service Delete account action first starts a cancellable 24-hour window, revokes access and cancels recurring billing; after the window, SayScope deletes uploaded content and credentials and replaces direct account identifiers with an anonymous tombstone needed for restricted retained evidence.

Use the public SayScope account and data deletion page for request instructions, including when the app is no longer installed. Account suspension or deactivation is not treated as an account-deletion request.

Current-device account-linked IndexedDB copies are cleared by the account tool. SayScope cannot remotely erase inaccessible or offline devices, and legacy browser-only records that cannot safely be attributed to the account remain unless the user chooses the separate all-local-data action. Active-system deletion does not instantly remove immutable backups or limited records that PayFast, OpenAI, email, analytics, hosting or other providers may lawfully retain under their documented safety or legal policies.

The responsible party reviews retention needs periodically. Backup deletion timing and provider-specific retention depend on approved operational schedules and applicable legal or provider constraints; immediate removal from those systems is not promised. Records are deleted or de-identified when no longer reasonably required, subject to applicable accounting, tax, fraud, dispute, security and legal-retention obligations.

8. Security and incidents

Measures include encrypted HTTPS transport, server-only provider credentials, password hashing, verified email, expiring sessions, administrator 2FA, access controls, rate and spend limits and transaction validation. No internet service can promise absolute security. Where POPIA requires it, the responsible party will notify the Information Regulator and affected data subjects of a security compromise.

9. Your rights

A data subject may ask whether personal information is held, request access, request correction or deletion where legally available, object to processing, withdraw consent where consent is relied on, opt out of optional analytics, or complain. Use Cookie choices to change analytics consent, the account and data deletion page for deletion instructions, or contact info@sayscope.co.za. Identity may be verified before fulfilling a request.

Complaints may also be submitted to the Information Regulator at POPIAComplaints@inforegulator.org.za or 010 023 5200.

10. Children and changes

SayScope is intended for people aged 18 or older and is not designed for processing children's information. We will identify material changes by publishing a new version and, where appropriate, require renewed acceptance.

PrivacyTermsRefundsAcceptable useCookiesAccount deletionPAIALegal & contact