Skip to main content
Musnad
Home Solutions How It Works About Us Contact Us Privacy Sign in to your dashboard
EN ع
Musnad Document automation · Construction & engineering

Privacy Policy

Last updated: 4 August 2026 Operator: Musnad, Abu Dhabi, United Arab Emirates.

Musnad is a document automation platform for the construction and engineering industry. This policy explains what we collect, how we use it, how long we keep it, and how you control it. We have tried to write it in plain English rather than legal boilerplate.

On this page

  1. Who this policy covers
  2. What we collect
  3. What we do not collect
  4. Your uploaded documents
  5. How we use it
  6. Who else touches it
  7. How long we keep it
  8. Your rights
  9. Security
  10. Deleting your data
  11. Children
  12. Changes
  13. Contact

Short version: we collect the minimum we need to run your workspace. The documents you upload are processed and then deleted from our servers, and they are never used to train anybody's AI model. There is no advertising, no tracking pixel and no analytics SDK anywhere on this site. We have never sold data and we will not. You can ask us for a copy of your data, or for its deletion, at any time.

1. Who this policy covers

Musnad handles two different kinds of information, and it matters which one you are asking about.

We decide

Your account and this website

Your name, work email, sign-in activity and anything you send us through the contact form. We decide how this is handled, so we are the controller for it and this policy governs it in full.

Your client decides

The documents processed in a workspace

Bills of quantities, specifications and the deliverables generated from them belong to the company whose workspace they sit in. We process them on that company's instructions and under its contract with us. If you are an employee asking what happens to a project document, your own employer's policy governs it, and we act on their instructions.

2. What we collect

Category What it is Why we collect it
Account details Your work email address, your name, the workspace you belong to, and whether you are an administrator. To sign you in and to show you only the tools and data belonging to your own company.
Password If your workspace uses password sign-in, a one-way PBKDF2-HMAC-SHA256 hash. We never store, log or transmit the password itself. Workspaces on single sign-on have no password with us at all. To verify it is you, without us ever being able to read it back.
Session cookie A random token (cp_session) that expires after 7 days. The matching record lives on our server, so we can revoke it instantly. To keep you signed in between pages, and to let us end a session the moment it needs ending.
Security cookie A second token (cp_csrf) checked on every form you submit. To stop another website from submitting forms as you. Strictly necessary, and it carries nothing about you.
Documents you upload Bills of quantities, particular specifications and standard specifications, exactly as you supply them. They are the service. See section 4 for precisely how long they exist on our servers, which is not long.
Job records One row per run: the file name, page count, status, processing cost, timestamp and which user started it. To show your activity log, to enforce the document allowance on your plan, and to bill accurately.
Audit log An append-only record of security-relevant actions: who, when, what was acted on, the outcome, and the IP address the request came from. It covers sign-ins, tool runs, downloads and deletions. So that a workspace administrator can answer "who downloaded that, and when". Append-only means it cannot be quietly edited, including by us.
Sign-in attempts A hash of the email address tried, the IP address, the time and whether it succeeded. The email itself is not stored in this table. To lock out password-guessing attacks against your workspace.
Contact form The name, company, email, phone, subject and message you type into the form on our home page. To reply to you. It is emailed to us and is not written to our database.

3. What we do not collect

  • No advertising and no tracking. There is no ad network, no tracking pixel and no marketing SDK on this site or in the platform. We do not follow you to other websites and nobody buys that ability from us.
  • No third-party analytics and no session recording. We do not run Google Analytics, or any product-analytics or session-replay tool. Nothing watches you use the platform.
  • No location data. We never request it.
  • No non-essential cookies. The only two cookies we set are the session cookie and the security token described above. Both are strictly necessary, which is why this site has no cookie banner to click through.
  • No training on your documents. Your specifications and bills of quantities are not used to train any AI model, ours or anyone else's. See section 5.
  • No selling or renting of data. Not to advertisers, not to data brokers, not to anyone.

4. What happens to a document you upload

This is the section most IT departments actually want, so here is the whole sequence.

  1. 01

    Upload

    Your file is checked for size and type, then written to a temporary working directory on the server that is handling your request.

  2. 02

    Processing

    The text is extracted and sent to Anthropic's Claude API, which classifies materials and locates the clauses behind each testing requirement. See section 6 for what that means contractually.

  3. 03

    Deletion of the source file

    The temporary working directory is deleted once the run finishes. That deletion also runs when a job fails, times out or is cancelled, so a failed run does not leave your document sitting on disk.

  4. 04

    The deliverable

    The generated workbook is stored against your workspace so you can download it again. Any link to it is time-limited. You can delete it from the platform, and deleting it removes the stored file.

What survives a run is the job record described in section 2: the file name, page count, cost and timestamp. Not the contents of the document.

5. How we use what we collect

  • To run the service. Reading your documents and producing the schedules you asked for.
  • To keep workspaces separate. Every database query is scoped to your workspace, so a user at one company cannot reach another company's data. This is enforced at the query layer, not by hiding links in the interface.
  • To enforce your plan. Counting documents processed against the allowance on your entitlement.
  • To keep the platform secure. Rate-limiting sign-ins, recording the audit trail, and investigating anything that looks like abuse.
  • To bill you. Aggregating recorded usage.
  • To support you. Replying when you contact us, and diagnosing a specific failure when you report one.

We do not profile you, and no decision that affects you is made solely by automated processing. Every deliverable the platform produces is a draft with its evidence attached, reviewed and signed off by a responsible engineer.

6. Who else touches the data

We keep the list of sub-processors deliberately short. It is currently this, in full.

Anthropic

AI processing

Document text is sent to the Claude API to be classified and cited. Anthropic's commercial terms state that data submitted through its API is not used to train its models. Anthropic retains API data only for a limited period for safety monitoring, under its own published policy.

Render

Hosting and database

Runs the application and the PostgreSQL database. Data is encrypted in transit and at rest.

Clerk

Sign-in, where enabled

Workspaces using single sign-on authenticate through Clerk, which handles the credentials so that we never see them. Workspaces on password sign-in do not involve Clerk at all.

Content delivery and fonts

Page assets

Typefaces and two interface libraries are loaded from Google Fonts and the jsDelivr CDN. Serving a file means those providers see the IP address that requested it. They receive nothing else from us: no account data, no document content, no identifiers.

Each provider is engaged as a processor and is contractually barred from using the data for its own purposes. We will update this page before adding a new one.

Where the data sits

Our hosting and AI providers operate infrastructure outside the United Arab Emirates, including in the United States, so running the service involves an international transfer. Where that transfer covers personal data from the EU or EEA, we rely on the European Commission's Standard Contractual Clauses and on each provider's published transfer safeguards. If your organisation needs data to remain in a specific region, raise it with us before signing. It is a configuration decision and we would rather make it deliberately.

7. How long we keep it

WhatHow long
Uploaded source documentsDeleted as soon as the run finishes, including runs that fail.
Generated deliverablesHeld in your workspace until you delete them, or until your workspace closes.
Account detailsFor as long as the workspace is active, then deleted within 90 days of it closing.
Session tokens7 days, or immediately when you sign out.
Job records24 months, for billing and usage history.
Audit log24 months. It is append-only for its lifetime.
Sign-in attempt records12 months.
Contact form messagesKept in our email for as long as the enquiry is live, then deleted on request.

8. Your rights

Under UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data, and under the GDPR where it applies to you, you can ask us to:

  • Give you a copy of the personal data we hold about you.
  • Correct anything that is wrong.
  • Delete your account and the data attached to it.
  • Restrict or object to a particular use of it.
  • Export it in a portable, machine-readable format.
  • Withdraw consent where our use of the data rests on consent.

Email jad.hammoud@musnad.ae and we will respond within 30 days. There is no charge.

One practical caveat. If you are a user inside a client workspace and you ask us to delete a project document, we will normally need to refer that request to the company that owns the workspace, because the document is theirs and not ours to remove. We will tell you when that happens rather than quietly sitting on the request.

Legal basis, if you are in the EU or EEA

We rely on performance of a contract for running your workspace and processing your documents, legitimate interests for security, fraud prevention and the audit trail, and legal obligation for the records we are required to keep. We do not rely on consent for anything except optional communications you opt into.

9. Security

  • All traffic is encrypted with TLS. Data at rest in our database is encrypted by our hosting provider.
  • Passwords, where used, are stored as salted PBKDF2-HMAC-SHA256 hashes at a high iteration count. They cannot be read back, by us or by anyone who obtained the database.
  • Sessions are server-side and revocable, so signing out actually ends the session rather than just discarding a cookie.
  • Every form is protected against cross-site request forgery, and the site sets a Content Security Policy with a per-request nonce.
  • Uploads are size-capped and their type is verified by content, not by the file extension.
  • Workspace separation is enforced in the database queries themselves.

No system is perfectly secure and we will not pretend otherwise. If we become aware of a breach affecting your personal data, we will notify you and the relevant authority as required by law, and we will tell you what we actually know rather than what sounds best.

10. Deleting your data

Ask your workspace administrator to remove your account, or email jad.hammoud@musnad.ae directly. Removing an account deletes the sign-in record, the sessions and the personal details attached to it.

Two things are kept when an account is removed: entries in the append-only audit log, and job records needed for billing, both for the periods in section 7. Keeping them is the point of an audit trail. If you want those purged as well, email us and we will tell you what we can remove and what we are required to keep.

11. Children

Musnad is a business tool sold to companies. It is not directed at children and we do not knowingly collect data from anyone under 18.

12. Changes to this policy

If we make a material change, such as collecting a new category of data or adding a sub-processor, we will update the date at the top of this page and tell workspace administrators by email before it takes effect. The current version always lives at this address.

13. Contact

Privacy questions, data requests, deletion requests or complaints:

Your documents stay yours

Source files are deleted after processing and are never used to train an AI model.

Nothing is tracking you

No ad networks, no analytics tools, no session recording, no non-essential cookies.

We never sell your data

Not to advertisers, not to brokers, not to anyone. There is no version of this we are comfortable with.

Questions?

Email us any time at jad.hammoud@musnad.ae.

Musnad

Document automation for the construction and engineering industry across the UAE.

Abu Dhabi, UAE

Quick links

  • Home
  • Solutions
  • How It Works
  • About Us
  • Contact Us

Platform

  • MTR Generator
  • BOQ Procurement
  • Per-client workspace
  • Clause traceability

Contact

  • jad.hammoud@musnad.ae
  • kareem.tawfik@musnad.ae
  • +971 50 123 5469
  • +971 56 530 0504
© 2026 Musnad. All rights reserved. Document automation · Construction & engineering Privacy Policy United Arab Emirates