Trust & AI Data Handling
Sophyx runs prompts against AI assistants on your behalf, which means we handle data about your brand and, sometimes, about your customers. This page answers the questions security and legal teams actually ask — what we log, how long we keep it, whether it trains anything, who else touches it, and how to get rid of it.
Draft — pending internal confirmation
The answers below are placeholders in lib/trust-facts.ts. This page is set to noindex and is excluded from the sitemap and navigation until Sophyx confirms each statement and flips TRUST_FACTS_CONFIRMED to true.
The short version
What we log
[CONFIRM: list exactly what is stored when Sophyx runs a prompt — e.g. the prompt text, the full model response, the cited source URLs, the timestamp and engine, and the brand/competitor names matched. State clearly whether any end-customer personal data is ever included.]
Where it lives
[CONFIRM: name the regions where data is stored and processed. The Privacy Policy currently states data 'may be transferred to and stored in countries outside of the jurisdiction you are in, pursuant to appropriate safeguards' — this page should be more specific than that.]
Training usage
[CONFIRM: state plainly whether customer prompt/answer data is used to train or fine-tune any model, including your own. If you send prompts to third-party AI providers, state whether those calls are made under zero-retention / no-training API terms and name the providers.]
Deletion
[CONFIRM: describe how a customer requests deletion, what gets deleted, how long it takes, and what (if anything) is retained afterwards for legal or billing reasons. Include the contact route — currently info@sophyx.io.]
Sub-processors
Every third party that touches data on our behalf, and why.
| Provider | Purpose | Scope |
|---|---|---|
| Vercel | Website hosting, edge delivery, and first-party analytics | Request metadata, IP address, device and browser information |
| Supabase | Application database and authentication | Account records, workspace data, and stored analysis results |
| Brevo | Marketing email and contact management | Name and email address for contacts who opted in |
| Resend | Transactional email delivery | Recipient email address and message content |
| Cloudflare Turnstile | Bot protection on public forms | Challenge token and IP address at time of submission |
| [CONFIRM: AI providers] | [CONFIRM: e.g. running prompts against ChatGPT, Gemini, Claude, Perplexity] | [CONFIRM: prompt text sent, and under which retention/training terms] |
[CONFIRM: verify this list is complete and current, and add any AI providers used by app.sophyx.io. We will notify customers before adding a new sub-processor — confirm whether that commitment is one you want to make.]
Data handling FAQ
- [CONFIRM: state plainly whether customer prompt/answer data is used to train or fine-tune any model, including your own. If you send prompts to third-party AI providers, state whether those calls are made under zero-retention / no-training API terms and name the providers.]
- [CONFIRM: state the retention window for prompt and answer records, for account data, and for logs — e.g. 'Prompt and answer records are retained for the life of the account plus N days. Application logs are retained for N days.' Include what happens on account closure.]
- [CONFIRM: list exactly what is stored when Sophyx runs a prompt — e.g. the prompt text, the full model response, the cited source URLs, the timestamp and engine, and the brand/competitor names matched. State clearly whether any end-customer personal data is ever included.]
- Sophyx uses a small set of named sub-processors: Vercel (Website hosting, edge delivery, and first-party analytics); Supabase (Application database and authentication); Brevo (Marketing email and contact management); Resend (Transactional email delivery); Cloudflare Turnstile (Bot protection on public forms); [CONFIRM: AI providers] ([CONFIRM: e.g. running prompts against ChatGPT, Gemini, Claude, Perplexity]). [CONFIRM: verify this list is complete and current, and add any AI providers used by app.sophyx.io. We will notify customers before adding a new sub-processor — confirm whether that commitment is one you want to make.]
- [CONFIRM: describe how a customer requests deletion, what gets deleted, how long it takes, and what (if anything) is retained afterwards for legal or billing reasons. Include the contact route — currently info@sophyx.io.]
- [CONFIRM: name the regions where data is stored and processed. The Privacy Policy currently states data 'may be transferred to and stored in countries outside of the jurisdiction you are in, pursuant to appropriate safeguards' — this page should be more specific than that.] Our full Privacy Policy covers cross-border transfer safeguards, the legal basis for each category of processing, and how to exercise your rights.
- [CONFIRM: only list frameworks you can actually stand behind. If Sophyx is not yet SOC 2 / ISO 27001 certified, say so honestly and describe the controls that are in place instead. Do not imply certification you do not hold.]
Questions we have not answered
Security reviews are welcome and we would rather answer a hard question than lose you to ambiguity. Email info@sophyx.io and we will respond with specifics.
Full legal detail lives in our Privacy Policy and Terms of Use.