Privacy · Updated May 12, 2026

The shortest honest privacy policy we could write.

No dark patterns, no opaque consent layers, no resale of behavioral data. Here's exactly what we collect, why we collect it, and how to get rid of it.

Your logs are yours

Activity logs, estimates, journal entries — everything is exportable as JSON or CSV at any time. Delete an account and the data is gone within 30 days.

No third-party tracking

We don't load Google Analytics, Meta pixels, or session-replay tools. The only analytics we run are product events on our own infrastructure.

Models trained on aggregates

Coaching models are trained on aggregated, de-identified patterns — never on the literal text of your sessions or journal entries.

Sub-processors disclosed

Every vendor that touches user data is listed on this page. We notify Pro and Team customers 30 days before adding a new one.

01

What we collect

To run Sopheron we collect three categories of data:

  • Account data: email, name, hashed password, billing details.
  • Activity data: session timestamps, estimates, actuals, energy ratings, and any text you write in your decision journal.
  • Product analytics: page views, button clicks, and feature usage — all keyed to a rotating pseudonymous ID, never to your name.

We don't collect IP-based location, device fingerprints, or anything from third-party data brokers.

02

How we use it

Activity data is used solely to power your own coaching loop and analytics — never to advertise, never to train shared models on your literal content. Aggregated, de-identified patterns may be used to improve coaching heuristics for everyone.

Account data is used for billing and for letting you sign in. Product analytics tell us which features are worth keeping and which are silently broken.

03

Where it lives

By default, your data lives on managed Postgres in Frankfurt, Germany (eu-central-1). Team customers can choose Virginia, USA (us-east-1) at signup. We do not replicate primary data across regions without your written consent.

Backups are encrypted at rest with AES-256 and retained for 14 days before being shredded.

04

Your rights

Wherever you live, you can:

  • Download all your data, in machine-readable format, from Settings → Export.
  • Delete your account in one click. Hard-delete completes within 30 days; backups age out within 14.
  • Ask us anything about your data by emailing privacy@sopheron.com. We answer within five business days.
05

Sub-processors

VendorPurposeRegion
Fly.ioApplication hostingEU / US
NeonManaged PostgresEU / US
CloudflareCDN + WAFGlobal
StripeBillingIreland / US
PostmarkTransactional emailUS
LinearInternal issue tracking (no user data)US
06

Changes to this policy

We'll email you 30 days before any material change. The full revision history of this page lives in our public GitHub repo — diff anything you like.

Questions about your data?
privacy@sopheron.com
Get in touch