SoxAIDocs
Security

Data Privacy

What data SoxAI collects, stores, and how it is processed

Data Privacy

Data We Collect

Account Data

  • Email address
  • Hashed password (Argon2id, never plaintext)
  • Name (optional)
  • OAuth provider identity (Google, GitHub user ID)

Usage Data

For every API request, we log:

  • Timestamp
  • Request ID and trace ID
  • Model used
  • Token counts (input and output)
  • Cost
  • HTTP status code
  • Response latency

We do not log:

  • The content of your prompts or responses
  • Conversation history
  • Uploaded files

Billing Data

  • Payment transaction records (amounts, timestamps)
  • Invoice history
  • Balance history

Data Retention

Data TypeRetention Period
Account dataUntil account deletion + 30 days
Usage logs12 months (Enterprise: 7 years)
Audit logs7 years (not deletable)
Billing records7 years (regulatory requirement)

Data Residency

SoxAI infrastructure is hosted in data centers located in the United States and European Union. Enterprise customers can request data residency in a specific region.

Prompt Data

SoxAI acts as a transparent proxy. Your prompts and responses pass through the gateway but are not stored. We do not train models on your data.

For the purposes of billing settlement, we temporarily hold token counts (numbers only) — not the text content. This data is discarded after settlement.

Subprocessors

SoxAI relies on the following subprocessors:

SubprocessorPurposeLocation
StripePayment processingUS
AWS / GCPInfrastructureUS, EU
PostmarkTransactional emailUS

When you make API requests, your prompts are forwarded to AI providers (OpenAI, Anthropic, Google, etc.) per your request. Their data policies apply to the content you send.

Data Access

Console: Settings → Privacy → Export Data to download a copy of your account data in JSON format.

To request account deletion: Settings → Privacy → Delete Account or email [email protected]. Deletion removes all personal data within 30 days, subject to legal retention requirements for financial records.

Security of Stored Data

  • All data at rest is encrypted (AES-256)
  • All data in transit uses TLS 1.2+
  • Database access is restricted by VPC network rules — not accessible from the public internet
  • Backups are encrypted and stored in a separate region

Third-Party AI Providers

When you use the SoxAI gateway, your prompts are forwarded to AI providers. Review each provider's data policies:

Enterprise customers can configure provider-specific data handling agreements (e.g. OpenAI's Zero Data Retention option).