1. Information We Collect
Account Information
Name, email address, password (hashed), timezone, profile preferences.
Billing Information
Payment processing is handled by Paddle. We do not store card numbers or banking details on our servers.
Usage Data
Pages visited, features used, content created, posts scheduled, AI credits consumed. Used to improve the service.
Connected Account Data
When you connect social media accounts we store access tokens (encrypted), account IDs, profile information and performance metrics returned by platform APIs.
AI Content Data
Prompts you enter, content generated, images created. Stored to power your content history and brand voice system.
Technical Data
IP address, browser type, device information, log files. Used for security and performance monitoring.
2. How We Use Your Data
- To provide and operate the SophieFlow service
- To process payments and manage subscriptions
- To publish content to your connected social accounts on your instruction
- To generate AI content using your brand voice and prompts
- To send transactional emails — account confirmations, billing receipts, security alerts
- To send product updates and feature announcements (you can opt out anytime)
- To improve our AI models and product features using aggregated, anonymized usage data
3. Data Sharing
We do not sell your personal data. We share data only with:
- Paddle — payment processing
- Google (Gemini) — AI content and image generation
- Social media platforms — when publishing content on your behalf
- Infrastructure providers — hosting, database, CDN services
- Law enforcement — when required by valid legal process
4. Data Security
We implement industry-standard security:
- All data encrypted at rest and in transit (TLS 1.3)
- Social media tokens encrypted in database
- Regular security audits
- Access controls and audit logging
5. Data Retention
- Account data retained while your account is active
- Deleted account data removed within 30 days
- Billing records retained 7 years for legal compliance
- Log files retained 90 days
6. Your Rights
You have the right to:
- Access your personal data
- Correct inaccurate data
- Delete your account and data
- Export your data (GDPR)
- Opt out of marketing emails
- Withdraw consent for data processing
To exercise these rights email support@sophieflow.com
7. Cookies
We use essential cookies for authentication and session management. Analytics cookies to understand usage (you can opt out). No advertising or tracking cookies.
8. Children
SophieFlow is not directed at children under 18. We do not knowingly collect data from minors.
9. International Transfers
SophieFlowAI LLC is based in the United States. If you use SophieFlow from outside the US your data may be transferred to and processed in the US.
10. GDPR (EU Users)
Our legal basis for processing is:
- Contract performance for service delivery
- Legitimate interests for security and improvement
- Consent for marketing communications
EU users may lodge complaints with their local data protection authority.
11. Changes
We will notify you of material changes by email and by updating this page.
12. Contact
Privacy questions: support@sophieflow.com
SophieFlowAI LLC
30 N Gould St, Ste 52509
Sheridan, WY 82801, United States