Privacy Policy

Last updated 8 August 2026

This policy explains what personal data Sofia collects, why we collect it, who we share it with, and how you can have it deleted. Sofia is operated by ALY CONSULTORIA E GESTAO EM TECNOLOGIA LTDA (Aly Studios), São Paulo, Brazil. Questions: [email protected].

Data we collect

We collect only what the product needs to function:

  • Account data — your name, email address, and password hash. If you sign in with Google, we receive your name, email address, and profile picture from Google instead of a password.
  • Workspace content — the brands, prompts, chat conversations, posts, slides, captions, and calendar entries you create in Sofia.
  • Connected social account data — when you connect Instagram or TikTok, we receive an access token plus your account id, username, display name, and profile picture. Access tokens are encrypted at rest with AES-256-GCM.
  • Billing data — subscription and plan status. Card details are handled entirely by our payment processor; Sofia never sees or stores them.
  • Operational logs — server and job logs used to diagnose failures.

Sofia has no advertising trackers, no analytics pixels, and no third-party cookies. We do not sell personal data, and we do not use your content to train our own models.

How we use social account data

Data obtained through the Instagram and TikTok APIs is used solely to operate the features you asked for:

  • instagram_business_basic — to identify which Instagram account is connected and show its handle, name, and avatar in your workspace.
  • instagram_business_content_publish — to publish or schedule the posts you create in Sofia to that account.

We do not use Instagram or TikTok data for advertising, profiling, resale, or model training, and we do not share it with any party other than the infrastructure providers listed below.

Who we share data with

We use a small set of processors, each limited to what its function requires:

  • netcup GmbH (Germany) — hosting. Our database and object storage are self-hosted on this infrastructure.
  • Polar — subscription billing and payment processing.
  • Vercel AI Gateway and the model providers it routes to (currently xAI and Black Forest Labs) — generating the content you request. Prompts and generated output pass through these providers.
  • Resend — transactional email such as password resets and address verification.
  • Google — only if you choose Google sign-in.
  • Meta / Instagram and TikTok — only for accounts you explicitly connect, and only to publish what you ask us to publish.

We may also disclose data where legally required, or to a successor entity in a merger or acquisition, in which case this policy continues to apply.

Retention and deletion

We keep your data for as long as your account is active. You can delete data at any time:

  • Disconnect a social account — open Sofia → Integrations → Disconnect. The stored tokens and cached profile details for that account are removed.
  • Remove Sofia from Instagram — in Instagram, go to Settings → Website permissions → Apps and websites and remove Sofia. Instagram notifies our deauthorization endpoint and we revoke the connection and destroy its tokens.
  • Request full deletion — email [email protected], or use Instagram's data deletion request flow. Instagram-originated deletion requests are processed immediately on receipt and return a confirmation code you can check at the status URL provided.

Deleting your Sofia account removes your workspaces, content, and connected-account records. Backups and operational logs are purged on a rolling 30-day cycle.

Your rights

Depending on where you live — including under Brazil's LGPD and the EU/UK GDPR — you may have the right to access, correct, export, restrict, or delete your personal data, and to object to certain processing. Email [email protected] and we will respond within 30 days. You may also lodge a complaint with your local data protection authority (in Brazil, the ANPD).

Security

All traffic is served over HTTPS. Social access and refresh tokens are encrypted at rest with AES-256-GCM. Passwords are hashed with argon2id. Access to production systems is limited to the operator of Aly Studios. No system is perfectly secure, but we will notify affected users without undue delay if a breach affects their personal data.

Children

Sofia is not directed at children and is not intended for anyone under 18. We do not knowingly collect data from children. If you believe a child has provided us data, contact [email protected] and we will delete it.

International transfers

Aly Studios is established in Brazil and our servers are located in the United States and Germany. Using Sofia involves transferring your data across borders. Where required, we rely on standard contractual clauses or equivalent safeguards with our processors.

Changes to this policy

We will update the "last updated" date above when this policy changes, and will notify account holders by email for material changes before they take effect.

Contact

ALY CONSULTORIA E GESTAO EM TECNOLOGIA LTDA
São Paulo, Brazil
[email protected]