Trust & AI Data Handling

Sophyx runs prompts against AI assistants on your behalf, which means we handle data about your brand and, sometimes, about your customers. This page answers the questions security and legal teams actually ask — what we log, how long we keep it, whether it trains anything, who else touches it, and how to get rid of it.

Draft — pending internal confirmation

The answers below are placeholders in lib/trust-facts.ts. This page is set to noindex and is excluded from the sitemap and navigation until Sophyx confirms each statement and flips TRUST_FACTS_CONFIRMED to true.

The short version

What we log

[CONFIRM: list exactly what is stored when Sophyx runs a prompt — e.g. the prompt text, the full model response, the cited source URLs, the timestamp and engine, and the brand/competitor names matched. State clearly whether any end-customer personal data is ever included.]

Where it lives

[CONFIRM: name the regions where data is stored and processed. The Privacy Policy currently states data 'may be transferred to and stored in countries outside of the jurisdiction you are in, pursuant to appropriate safeguards' — this page should be more specific than that.]

Training usage

[CONFIRM: state plainly whether customer prompt/answer data is used to train or fine-tune any model, including your own. If you send prompts to third-party AI providers, state whether those calls are made under zero-retention / no-training API terms and name the providers.]

Deletion

[CONFIRM: describe how a customer requests deletion, what gets deleted, how long it takes, and what (if anything) is retained afterwards for legal or billing reasons. Include the contact route — currently info@sophyx.io.]

Sub-processors

Every third party that touches data on our behalf, and why.

Sophyx sub-processors and their purpose
ProviderPurposeScope
VercelWebsite hosting, edge delivery, and first-party analyticsRequest metadata, IP address, device and browser information
SupabaseApplication database and authenticationAccount records, workspace data, and stored analysis results
BrevoMarketing email and contact managementName and email address for contacts who opted in
ResendTransactional email deliveryRecipient email address and message content
Cloudflare TurnstileBot protection on public formsChallenge token and IP address at time of submission
[CONFIRM: AI providers][CONFIRM: e.g. running prompts against ChatGPT, Gemini, Claude, Perplexity][CONFIRM: prompt text sent, and under which retention/training terms]

[CONFIRM: verify this list is complete and current, and add any AI providers used by app.sophyx.io. We will notify customers before adding a new sub-processor — confirm whether that commitment is one you want to make.]

Data handling FAQ

[CONFIRM: state plainly whether customer prompt/answer data is used to train or fine-tune any model, including your own. If you send prompts to third-party AI providers, state whether those calls are made under zero-retention / no-training API terms and name the providers.]

Questions we have not answered

Security reviews are welcome and we would rather answer a hard question than lose you to ambiguity. Email info@sophyx.io and we will respond with specifics.

Full legal detail lives in our Privacy Policy and Terms of Use.