Privacy Policy
Last updated: April 10, 2026
SoxAI ("we," "our," or "us") operates the SoxAI platform at soxai.io and related services. This Privacy Policy describes how we collect, use, disclose, and safeguard your personal data when you use our website, APIs, and services (collectively, the "Service").
1. Information We Collect
1.1 Information You Provide
- Account Information: When you register, we collect your name, email address, and authentication credentials (password hash or OAuth tokens).
- Payment Information: When you purchase credits, payment is processed by third-party providers (Stripe, PayPal). We store transaction records but do not store full credit card numbers or payment account details.
- API Requests: We log metadata about API requests (model used, token counts, timestamps, costs) for billing, analytics, and abuse prevention. We do not log prompt or completion content by default. You may opt in to request logging for debugging purposes.
- Support Communications: When you contact us, we retain correspondence to provide assistance and improve our services.
1.2 Information Collected Automatically
- Device & Browser Data: IP address, browser type and version, operating system, device type, and referring URL.
- Usage Data: Pages visited, features used, click patterns, and interaction patterns within the Service.
1.3 Tracking Technologies
We use the following technologies to collect data automatically:
- Strictly Necessary Cookies: Required for authentication, session management, and security. Cannot be disabled.
- Analytics Cookies: We use privacy-focused analytics to understand how users interact with the Service. You can opt out of analytics cookies in your browser settings.
- Web Beacons: Small transparent images used in emails to track delivery and open rates.
We do not use third-party advertising cookies or trackers. We do not sell your browsing data to advertisers.
2. How We Use Your Information
- Provide, operate, and maintain the Service
- Process transactions and manage billing
- Authenticate users and prevent fraud
- Send transactional communications (billing receipts, security alerts)
- Analyze usage to improve performance and reliability
- Enforce our Terms of Service and protect against abuse
- Comply with legal obligations
We do not sell your personal data. We do not use your API request content (inputs or outputs) to train AI models.
3. How We Share Your Information
We may share your information with:
- AI Providers: Your API requests are forwarded to upstream AI providers (e.g., Anthropic, OpenAI, Google) to fulfill your requests. Each provider's own privacy policy governs their handling of your data. We do not control how providers process your inputs and outputs.
- Payment Processors: Stripe and PayPal process your payment transactions under their respective privacy policies.
- Service Providers: Hosting, analytics, and infrastructure partners who process data on our behalf under contractual data processing agreements.
- Legal Requirements: When required by law, regulation, subpoena, or legal process, or to protect our rights, safety, and property.
- Business Transfers: In connection with a merger, acquisition, or sale of assets, your data may be transferred. We will notify affected users before data is subject to a different privacy policy.
4. Data Security
We implement industry-standard security measures to protect your data, including:
- Encryption of sensitive credentials (AES-256-GCM) at rest
- TLS 1.2+ encryption for all data in transit
- Argon2id password hashing
- Role-based access control and multi-tenant data isolation
- Regular security audits and vulnerability scanning
- Access logging and anomaly detection
No system is 100% secure. You are responsible for maintaining the confidentiality of your account credentials and API keys. If you believe your account has been compromised, contact us immediately at [email protected].
5. Data Retention
We retain your data for as long as your account is active or as needed to provide the Service. Specifically:
- Account data: Retained while your account is active and for 30 days after deletion request, after which it is permanently removed.
- Request logs (metadata): Retained for up to 90 days for billing reconciliation and analytics.
- Payment records: Retained as required by applicable tax and financial regulations (typically 7 years).
- Security and audit logs: Retained for up to 1 year for security investigations.
6. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data ("right to be forgotten")
- Object to or restrict certain processing
- Data portability (receive your data in a structured, machine-readable format)
- Withdraw consent (where processing is based on consent)
- Lodge a complaint with a supervisory authority
To exercise these rights, contact us at [email protected]. We will respond within 30 days (or as required by applicable law).
7. International Data Transfers
Your data may be processed in countries other than your own, including the United States. We use appropriate safeguards for international transfers, including standard contractual clauses (SCCs) approved by the European Commission where applicable. By using the Service, you consent to the transfer of your data to countries that may have different data protection standards.
8. Legal Bases for Processing (GDPR)
If you are in the European Economic Area (EEA), UK, or Switzerland, our legal bases for processing your personal data include:
- Contract: Processing necessary to perform our contract with you (providing the Service, billing).
- Legitimate Interests: Fraud prevention, security, service improvement, and analytics, where our interests do not override your rights.
- Consent: Where you have given explicit consent (e.g., optional analytics cookies, marketing communications).
- Legal Obligation: Compliance with applicable laws and regulations.
9. U.S. State Privacy Rights
If you are a resident of California, Virginia, Colorado, Connecticut, or other U.S. states with comprehensive privacy laws, you may have additional rights including:
- Right to know what personal information we collect, use, and disclose
- Right to delete personal information
- Right to opt out of the "sale" or "sharing" of personal information
- Right to non-discrimination for exercising your privacy rights
We do not sell or share your personal information as defined under the California Consumer Privacy Act (CCPA) or similar state laws. To exercise your rights, contact [email protected].
10. Age Restrictions
The Service is not intended for users under 13 years of age. We do not knowingly collect personal data from children under 13. If we become aware that we have collected such data, we will promptly delete it and terminate the associated account.
11. Third-Party Links
The Service may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies before providing them with your personal data.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be notified via email or a prominent notice on our website at least 30 days before taking effect. Continued use of the Service after changes constitutes acceptance of the updated policy. The "Last updated" date at the top of this page indicates when the policy was last revised.
13. Contact Us
If you have questions about this Privacy Policy or wish to exercise your privacy rights, please contact us at:
- Email: [email protected]
- Website: https://soxai.io