Privacy Policy
Last updated: 29 September 2026
SOPHE AI helps people and their families decide what to trust online. To do that, we need to handle some of your personal data, including the messages, links and screenshots you ask us to check. This policy explains what we collect, why, who we share it with, how long we keep it and the rights you have. We have tried to write it in plain language.
1. Who we are
SOPHE AI is operated by SOPHEAI, with its registered office at [address] ("we", "us"). We are the controller of your personal data under the EU General Data Protection Regulation (GDPR).
For anything about your privacy, contact us at contact@sopheai.com.
2. What we collect
Your account
- Your name and email address.
- Your password, stored only as a one-way hash, so we can never read it. If you sign in with Apple, Google or Microsoft instead, we receive your name, your email address and an identifier for that account. We never receive your password for those services.
- If you sign in with Apple, a token Apple gives us, stored encrypted and used only to cancel Apple's link to SOPHE AI when you delete your account.
- When your account was created, when your email was confirmed, and your account status.
Your family
- Who belongs to your family on SOPHE AI, and the names and email addresses of people you invite. We use an invited person's email address only to send the invitation.
Your subscription and payments
- Your plan, billing period, renewal dates, and any voucher or invitation you used.
- A record of each payment (amount, currency, date). Card details are entered on our payment provider's page and never reach us.
What you ask us to check
- The content you submit: text, links, email contents, screenshots and descriptions, plus your answers to any follow-up question.
- The result: the verdict, the explanation and the recommended next steps.
- Technical records of each check (which AI model was used, how long it took, how much processing it needed), which we use to run and pay for the service.
Please avoid submitting more personal data than you need to, such as other people's bank details or passwords. If a message you check contains someone else's personal data, we process it only to give you the result.
Technical data
- Your IP address, browser and device type, and the times of your requests, in our server logs, for security and troubleshooting.
- Sign-in tokens stored in your browser's local storage, which keep you signed in. We do not use advertising or analytics cookies.
3. Why we use it, and on what legal basis
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Creating and running your account, signing you in, running your checks, managing your family | Performing our contract with you |
| Taking payments and managing your subscription | Performing our contract with you |
| Sending service emails (confirming your address, password resets, invitations, changes to your plan) | Performing our contract with you |
| Keeping the service secure, preventing abuse and fixing problems | Our legitimate interest in a safe, working service |
| Measuring usage and cost of the AI analysis, and improving the quality of our checks | Our legitimate interest in improving the service |
| Keeping accounting and tax records | Legal obligation |
We do not sell your personal data, and we do not use the content of your checks for advertising.
4. How the AI analysis works
When you submit a check, its content is sent to the AI services we use, which analyse it and return a verdict. If your check contains a link, the AI services may open that page and search the web for information about the website, from their own servers, not from your device. We only use AI services whose terms do not allow them to use your content to train their models, and which delete it after a limited period.
Our verdicts are automated guidance to help you decide. They are not legal or financial advice, they do not produce legal effects for you, and they can be wrong. You always decide what to do.
5. Who we share it with
We share personal data only with service providers who process it on our behalf, under contract and only on our instructions:
- AI services (analysing the content you submit and producing the verdict).
- Apple, Google or Microsoft, only if you choose to sign in with them. Their own privacy policies apply to your account with them.
Other members of your family on SOPHE AI see your name and email address. They do not see your checks. We may also disclose data where the law requires it, or to protect our users' rights and safety.
6. Transfers outside the European Economic Area
Some of our providers, including AI services, may process data outside the EEA, for example in the United States. Where that happens, we rely on the EU–US Data Privacy Framework where the provider is certified, or on the European Commission's Standard Contractual Clauses. You can ask us for a copy of the safeguards that apply.
7. How long we keep it
- Your account: for as long as you have it. You can delete it at any time from your Account page.
- Accounts whose email was never confirmed: deleted after 30 days.
- Your checks: kept in your history until you delete your account. When you delete your account, the content of every check (text, screenshots, results) is erased. We keep anonymous technical figures (such as processing volume and cost) for reporting.
- Payment and subscription records: 5 years after the payment, as accounting law requires, even after your account is deleted.
8. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you and get a copy of it;
- have inaccurate data corrected (you can change your name yourself in the app);
- have your data deleted (you can delete your account yourself from the Account page, which removes your details and the content of your checks straight away);
- restrict or object to how we use it, including processing based on our legitimate interests;
- receive your data in a portable, machine-readable format;
- withdraw your consent at any time, where we rely on consent.
To use any of these rights, email contact@sopheai.com. We will answer within one month. You also have the right to complain to a data protection authority, in particular the one where you live.
9. How we protect it
All traffic to SOPHE AI is encrypted (HTTPS). Passwords and one-time links are stored only as hashes, provider tokens are encrypted, and access to production systems is limited to the people who need it. No system is perfectly secure; if a breach affects your data, we will tell you and the authorities as the law requires.
10. Changes to this policy
We may update this policy as SOPHE AI changes. The date at the top shows the latest version. If a change significantly affects how we use your data, we will tell you by email or in the app before it takes effect.
11. Contact
SOPHEAI. Email: contact@sopheai.com.
