Trust
Trust and AI data handling
Sophyx asks AI assistants questions on your behalf, so we handle data about your brand and sometimes about your customers. This page covers what we log, how long we keep it, whether it is used for training, who else processes it, and how to delete it.
Draft, waiting for internal confirmation
The answers below are drafts. This page is not indexed by search engines and is left out of the sitemap and navigation until Sophyx confirms each statement.
The short version
What we log
[CONFIRM: list exactly what is stored when Sophyx runs a prompt, e.g. the prompt text, the full model response, the cited source URLs, the timestamp and engine, and the brand/competitor names matched. State clearly whether any end-customer personal data is ever included.]
Where it lives
[CONFIRM: name the regions where data is stored and processed. The Privacy Policy currently states data 'may be transferred to and stored in countries outside of the jurisdiction you are in, pursuant to appropriate safeguards'. This page should be more specific than that.]
Training usage
[CONFIRM: state plainly whether customer prompt/answer data is used to train or fine-tune any model, including your own. If you send prompts to third-party AI providers, state whether those calls are made under zero-retention / no-training API terms and name the providers.]
Deletion
[CONFIRM: describe how a customer requests deletion, what gets deleted, how long it takes, and what (if anything) is retained afterwards for legal or billing reasons. Include the contact route, currently info@sophyx.io.]
Sub-processors
Every third party that handles data for us, and why.
| Provider | Purpose | Scope |
|---|---|---|
| Vercel | Website hosting, edge delivery, and first-party analytics | Request metadata, IP address, device and browser information |
| Supabase | Application database and authentication | Account records, workspace data, and stored analysis results |
| Brevo | Marketing email and contact management | Name and email address for contacts who opted in |
| Resend | Transactional email delivery | Recipient email address and message content |
| Cloudflare Turnstile | Bot protection on public forms | Challenge token and IP address at time of submission |
| [CONFIRM: AI providers] | [CONFIRM: e.g. running prompts against ChatGPT, Gemini, Claude, Perplexity] | [CONFIRM: prompt text sent, and under which retention/training terms] |
[CONFIRM: verify this list is complete and current, and add any AI providers used by app.sophyx.io. We will notify customers before adding a new sub-processor. Confirm whether that commitment is one you want to make.]
Data handling FAQ
- [CONFIRM: state plainly whether customer prompt/answer data is used to train or fine-tune any model, including your own. If you send prompts to third-party AI providers, state whether those calls are made under zero-retention / no-training API terms and name the providers.]
- [CONFIRM: state the retention window for prompt and answer records, for account data, and for logs, e.g. 'Prompt and answer records are retained for the life of the account plus N days. Application logs are retained for N days.' Include what happens on account closure.]
- [CONFIRM: list exactly what is stored when Sophyx runs a prompt, e.g. the prompt text, the full model response, the cited source URLs, the timestamp and engine, and the brand/competitor names matched. State clearly whether any end-customer personal data is ever included.]
- Sophyx uses a small set of named sub-processors: Vercel (Website hosting, edge delivery, and first-party analytics); Supabase (Application database and authentication); Brevo (Marketing email and contact management); Resend (Transactional email delivery); Cloudflare Turnstile (Bot protection on public forms); [CONFIRM: AI providers] ([CONFIRM: e.g. running prompts against ChatGPT, Gemini, Claude, Perplexity]). [CONFIRM: verify this list is complete and current, and add any AI providers used by app.sophyx.io. We will notify customers before adding a new sub-processor. Confirm whether that commitment is one you want to make.]
- [CONFIRM: describe how a customer requests deletion, what gets deleted, how long it takes, and what (if anything) is retained afterwards for legal or billing reasons. Include the contact route, currently info@sophyx.io.]
- [CONFIRM: name the regions where data is stored and processed. The Privacy Policy currently states data 'may be transferred to and stored in countries outside of the jurisdiction you are in, pursuant to appropriate safeguards'. This page should be more specific than that.] Our full Privacy Policy covers cross-border transfer safeguards, the legal basis for each category of processing, and how to exercise your rights.
- [CONFIRM: only list frameworks you can actually stand behind. If Sophyx is not yet SOC 2 / ISO 27001 certified, say so honestly and describe the controls that are in place instead. Do not imply certification you do not hold.]
Other questions
We answer security reviews and specific questions. Email info@sophyx.io and we will reply with specifics.
The legal details are in our Privacy Policy and Terms of Use.