Privacy Policy

Last updated: May 27, 2026

This Privacy Policy describes how Salym ("we", "us", or "our") handles information in connection with your use of the Salym mobile application ("App"). Salym is a point-of-sale and inventory management app for small retail businesses. The App was previously distributed under the name "PosAi"; the rename to "Salym" does not change how data is collected, stored, or shared.

1. Information We Collect

The App may collect the following types of information:

Account Information: When you register, we collect your full name, phone number, optionally your email address, company name, and role (owner or staff) to authenticate your account and identify you within your organization.

Business Data: Product names, prices, sales records, inventory data, expense records, supplier records, and employee commission information that you enter into the App. This data is stored securely in Supabase and used solely to provide the App's functionality.

Customer Contact Information (entered by the merchant): When the merchant records a debt sale or an installment plan, the merchant may enter the customer's name and phone number so the merchant can later track repayment. This information is entered manually by the merchant on the merchant's own device — the App does not read your phone's Contacts list and does not collect any information from the customer directly.

Camera and Photo Library: The App requests access to your camera and photo library for the purposes described in Section 5.

Support Messages: When you contact support through the App, your message along with your name, phone number, and company name are collected to respond to your request.

2. How We Use Your Information

We use the information we collect to:

— Provide, operate, and maintain the App
— Authenticate users and manage access for owners and staff
— Display sales history, inventory, debts, installments, and reports within the App
— Generate receipts (PDF) for completed sales
— Generate AI-powered product recommendations for cashiers
— Recognize products from photos using AI (inventory screen, POS screen, and product creation)
— Autofill product fields from a photo when adding a new product
— Send local notifications about sales, refunds, stock movements, low stock, debt repayments, and supplier delivery reminders
— Respond to support requests
— Improve and optimize the App's performance

3. Data Storage

Your data is stored securely using Supabase cloud infrastructure (PostgreSQL database and authentication). We take reasonable measures to protect your information from unauthorized access, loss, or misuse, including row-level security policies that restrict each user's access to their own organization's data.

Local storage on device: The App stores certain data locally on your device using AsyncStorage, including:

— A queue of sales transactions created while offline (synced automatically when connection is restored)
— App settings: language preference, theme, currency, exchange rate, and notification preferences
— Your bank payment QR code image URI (stored locally, never uploaded)
— Your authentication session token (JWT)
— A short on-device history of local notifications (latest 200) so you can review them inside the App

4. Data Sharing and Third-Party Services

We do not sell, trade, or rent your personal information to third parties. The App uses the following third-party services to operate:

Supabase — Cloud database and authentication provider. All your account data, sales, products, customers, debts, installments, suppliers, and employees are stored in Supabase. Learn more: supabase.com/privacy

Anthropic (Claude API) — AI processing service used for the following features:

Cashier recommendations: When items are added to the cart, the names of products in the cart and suggested products are sent to Anthropic's API to generate a short recommendation phrase for the cashier.
Inventory photo recognition (Inventory screen): When you use the AI inventory scan feature, a photo taken by your camera and a list of your store's product names are sent to Anthropic's API for recognition.
Product search by photo (POS screen): When you use the AI camera on the cashier screen, a photo and your product list are sent to Anthropic's API to find matching products.
Product autofill (Add Product screen): When you photograph a product to create a new item, the photo is sent to Anthropic's API to automatically fill in the product name, price, and other fields.

In all cases, photos are transmitted securely over HTTPS. Anthropic does not retain images or data after processing the request. Learn more: anthropic.com/privacy

Telegram (via Supabase Edge Function) — When you send a message through the in-app support chat, the following information is forwarded to our support Telegram bot: your name, phone number, company name, and the text of your message. This data is used solely to respond to your support request. Additionally, owners may optionally connect their own Telegram account to receive notifications (sales, refunds, edits) about their store; these notifications are sent to the owner's personal Telegram chat ID, which the owner provides voluntarily in the App's settings.

5. Camera and Photo Library Access

The App uses your camera and photo library for the following purposes:

Barcode scanning (POS screen): Scans product barcodes to quickly add items to the cart. The scanned data is used locally only and is never transmitted outside your device.
Bank QR code upload (Settings): Allows you to upload or photograph your bank's payment QR code. The image URI is stored locally on your device only and is never uploaded to any server.
Product photos (Add Product / Edit Product): Allows you to attach product photos to your catalog. These photos are uploaded to Supabase Storage and shown inside the App.
Supplier invoice photo (Stock receiving): Allows you to attach a photo of a supplier's invoice to a stock-receiving record. The photo is uploaded to Supabase Storage.
AI inventory recognition (Inventory screen): Takes a photo of your stock shelves and sends it to Anthropic's Claude API for AI-powered item recognition.
AI product search by photo (POS screen): Takes a photo on the cashier screen and sends it to Anthropic's Claude API to find matching products in your catalog.
AI product autofill (Add Product screen): Photographs a product and sends the image to Anthropic's Claude API to automatically fill in product details when creating a new item.

Photos sent to Anthropic are transmitted securely over HTTPS and are not retained by Anthropic after processing. Photos uploaded to Supabase Storage are stored in your organization's private bucket and are only accessible to authenticated members of your organization.

6. No Advertising or Tracking

The App does not contain any advertising. We do not use any third-party analytics SDKs (such as Firebase Analytics, Amplitude, Mixpanel, or similar). We do not track your behavior across other apps or websites. No data is used for targeted advertising or sold to data brokers.

7. Notifications

The App uses local notifications (scheduled on your device by the App itself) to inform you about events that happen inside your own store, including: sales completed by cashiers, refunds, stock received, low-stock warnings, debt repayments recorded against a receiving, and reminders about scheduled supplier deliveries. These notifications are generated locally on your device and are not delivered through any external push-notification provider.

The App also requests permission to register an Expo push token. This token is currently used only for delivery of local notifications on iOS and is not transmitted to any remote server controlled by us. You can disable notifications at any time in your device's system settings or via the notification preferences inside the App.

8. Data Retention

We retain your data for as long as your account is active. You may request deletion of your data at any time by contacting us at the email address below.

9. Children's Privacy

The App is intended for business use by adults. We do not knowingly collect personal information from children under the age of 13.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any significant changes by updating the date at the top of this page.

11. Contact Us

If you have any questions about this Privacy Policy, please contact us at:
nursultanadylovich@gmail.com