Data Privacy
What data SoxAI collects, stores, and how it is processed
Data Privacy
Data We Collect
Account Data
- Email address
- Hashed password (Argon2id, never plaintext)
- Name (optional)
- OAuth provider identity (Google, GitHub user ID)
Usage Data
For every API request, we log:
- Timestamp
- Request ID and trace ID
- Model used
- Token counts (input and output)
- Cost
- HTTP status code
- Response latency
We do not log:
- The content of your prompts or responses
- Conversation history
- Uploaded files
Billing Data
- Payment transaction records (amounts, timestamps)
- Invoice history
- Balance history
Data Retention
| Data Type | Retention Period |
|---|---|
| Account data | Until account deletion + 30 days |
| Usage logs | 12 months (Enterprise: 7 years) |
| Audit logs | 7 years (not deletable) |
| Billing records | 7 years (regulatory requirement) |
Data Residency
SoxAI infrastructure is hosted in data centers located in the United States and European Union. Enterprise customers can request data residency in a specific region.
Prompt Data
SoxAI acts as a transparent proxy. Your prompts and responses pass through the gateway but are not stored. We do not train models on your data.
For the purposes of billing settlement, we temporarily hold token counts (numbers only) — not the text content. This data is discarded after settlement.
Subprocessors
SoxAI relies on the following subprocessors:
| Subprocessor | Purpose | Location |
|---|---|---|
| Stripe | Payment processing | US |
| AWS / GCP | Infrastructure | US, EU |
| Postmark | Transactional email | US |
When you make API requests, your prompts are forwarded to AI providers (OpenAI, Anthropic, Google, etc.) per your request. Their data policies apply to the content you send.
Data Access
Console: Settings → Privacy → Export Data to download a copy of your account data in JSON format.
To request account deletion: Settings → Privacy → Delete Account or email [email protected]. Deletion removes all personal data within 30 days, subject to legal retention requirements for financial records.
Security of Stored Data
- All data at rest is encrypted (AES-256)
- All data in transit uses TLS 1.2+
- Database access is restricted by VPC network rules — not accessible from the public internet
- Backups are encrypted and stored in a separate region
Third-Party AI Providers
When you use the SoxAI gateway, your prompts are forwarded to AI providers. Review each provider's data policies:
Enterprise customers can configure provider-specific data handling agreements (e.g. OpenAI's Zero Data Retention option).