Privacy
Socria exists so your thinking stays yours. That principle is worth very little if we are vague about what we hold, so this page says plainly what is collected, why, and how to get it back or have it deleted.
Effective August 2026 · Last updated September 2026 · Data controller: Socria — hellosocria@gmail.com
What we collect
What you write
Your messages, and Socria’s replies. If you use Logos, that also means the Thinking Map built from those messages — your claims, assumptions, tensions and evidence — along with anything you write in Draft Space and any material you attach or paste.
What Socria works out about your thinking
This is the part most people would not guess, so it comes first rather than buried. To hold a conversation across turns and sessions, Socria keeps notes on it:
- Thread memory — goals, values, constraints, preferences, decisions, uncertainties and insights extracted from a conversation, so it does not ask you the same thing twice.
- The Thinking Journey — a short running account, kept across conversations, of what you appear to be working through, which threads are still open, and a timeline of moments. It is written in terms like “weighing whether to launch before fixing onboarding”.
The Journey is an evolving description of how you think, not a log of what you typed. If you would rather Socria did not keep one, there is a control for exactly that: Data & Privacy clears the Journey and every thread’s memory and leaves your own words untouched.
Your account
Your email address and sign-in details, handled by our authentication provider. If you subscribe to Socria One, our payment processor holds your billing details — we never see or store your card number.
Technical data
Standard request information, plus a rate-limiting counter keyed to your account. If you are not signed in, that counter is keyed to your IP address instead, because there is nothing else to key it to.
Why we hold it
| Purpose | What it uses |
|---|---|
| Running the conversation | Your messages, sent to our AI provider to generate a reply and to build your map |
| Continuity | Thread memory and the Journey, so a conversation picks up where it left off |
| Your account and plan | Email, sign-in, subscription status |
| Student access | A verified university email address, to check that it is at a school we have approved — and for nothing else |
| Keeping the service up | Rate limiting and abuse prevention |
| Understanding usage | Aggregate, privacy-preserving page analytics |
We do not sell your data, we do not share it for cross-context behavioural advertising, and we do not use your conversations to train models — we do not have a model of our own to train. Under OpenAI’s published API policy, data sent through their API is not used to train their models by default, and inputs and outputs are retained for up to 30 days for abuse monitoring before deletion. That is their policy rather than a contract we hold, and we have not signed a data processing agreement or enabled zero retention with them — if you need either, ask us before you rely on it.
Who it is shared with
Socria is built on services that each see one slice. We share only what each needs to do its job:
| Sub-processor | Purpose | Receives |
|---|---|---|
| OpenAI, L.L.C. | AI inference | Your messages and conversation history, to generate replies, maps and summaries |
| Supabase, Inc. | Database and storage | Everything stored: conversations, maps, drafts, memory, the Journey |
| Clerk | Authentication | Email and sign-in credentials |
| Stripe, Inc. | Subscription and payment processing | Billing details, for Socria One only |
| Vercel, Inc. | Application hosting | Request metadata; your account id, or your IP when signed out |
| Vercel, Inc. | Analytics | Aggregate page views |
| Upstash, Inc. | Rate limiting | A counter keyed to your account id, or your IP when signed out. No content. |
| Serper / Tavily | Web search | The search phrase only, when Research looks something up |
| Resend, Inc. | Email delivery | Your email address and the note itself, on the few occasions we send one. No content. |
When Research looks something up, a search provider receives the search phrase and nothing else — your conversation is never sent to it. A rate-limiting service receives a counter keyed to your account id, or your IP when you are signed out, and no content at all. If you connect Google or Notion yourself, your searches and the documents you choose reach those services too; both are listed on the register.
The full register, with each company’s role, location and privacy policy, is at subprocessors.
Where it lives
Signed in, your conversations and maps are stored in our database and follow you across devices.
Signed out, they are never written to our database — they live in your browser’s local storage, and clearing your browser data clears them. Be precise about what that does and does not mean: to answer you at all, each message still passes through our server and on to our AI provider. It is not stored; it is not anonymous. Your personality settings, your custom instructions, and which maths solutions you chose to reveal stay on your device either way, signed in or out.
Your choices
- See it — everything you have written is visible in the app.
- Delete a conversation — deleting one removes it, and its map, draft and memory, from our database.
- Forget what Socria worked out — Data & Privacy has a control that clears thread memory and the Thinking Journey from every conversation while leaving your own words, maps and drafts exactly where they are. Being forgotten and losing your notes are different requests.
- Export — one click in Data & Privacy downloads everything we hold about you as a JSON file: conversations, maps, drafts, memory, profile and subscription status. Connected accounts are listed as connected; their access tokens are never included.
- Delete everything — the same page deletes your account outright. It cancels any subscription first, then removes every row keyed to you, then the account itself. It is immediate and it is not reversible. If you would rather a person did it, write to hellosocria@gmail.com from your account address.
- Correct it — tell Socria in the conversation when it has read you wrong; correcting the record is never a paid feature.
- Notes by email — Socria may send you an occasional note about your thinking here, such as that a map is where you left it; none of them contains anything you wrote, and every one carries a link that stops them, as does the switch under Data & Privacy. None is ever addressed to a university address added for student access.
We keep what you write for as long as your account exists, because it is what the product is for; deleting a conversation removes it, and deleting your account removes all of it. If you are in the EU, the UK or California you have further rights over your data — access, correction, erasure, portability and objection — and the right to complain to your local supervisory authority. Write to us first and we will try to settle it directly.
How long we keep it
Nothing you write expires on a timer. A conversation stays until you delete it, because a thinking record you lose track of is not a thinking record. Deleting a conversation removes it immediately; deleting your account removes all of it immediately. Neither is a soft delete — we do not keep a copy in a bin.
Three things survive that, and you should hear it from us:
- Payment records. Stripe keeps invoice and transaction records to meet its own tax and legal obligations after a subscription ends. That retention is theirs, and not ours to override.
- Abuse-monitoring logs at OpenAI, for up to the 30 days described above.
- Encrypted database backups, which contain a deleted row until they age out of their retention window and are overwritten.
Our own application logs record route names, error codes and counts. They do not contain your messages, and they never contain an access token.
Legal bases, and rights by region
For people in the EEA, the UK and Switzerland, we rely on contract to run the service you asked for — holding your conversations, generating replies, maintaining memory and managing your subscription — and on legitimate interests for keeping the service up and preventing abuse, which is the rate limiting described above. We do not rely on consent for any of it, so there is no consent to withdraw; the equivalent is to stop using Socria and delete your account, which you can do in one click.
You have the right to access, correct, erase and port your data, to object to or restrict processing, and to complain to your local supervisory authority. The export and delete controls above are that access, portability and erasure, available without asking us. All of our sub-processors are United States companies, so your data is transferred to and processed in the US; those transfers rely on the Standard Contractual Clauses and each vendor’s own transfer framework.
For people in California and other US states with comparable laws: we do not sell personal information, and we do not share it for cross-context behavioural advertising — there is nothing to opt out of, because we do not do it. You have the right to know, delete and correct what we hold, and to portability, and we will not treat you differently for exercising any of it. If you use an authorised agent, we will ask for proof they are acting for you.
We honour these rights for everyone, wherever you live, rather than gating them by jurisdiction. We answer within 30 days, and tell you if we need longer and why.
Students
Socria One is free for students at universities we have approved, and the way we check is a verified email address at that university — added to your ordinary account the way anyone adds a second address, and verified by a code sent to it, because anyone can type a domain. The programme runs only where we have switched it on; where it is not running, adding a university address does nothing beyond adding an email address.
That address is on your account for one purpose: to confirm you are eligible. Specifically, we do not:
- Market to it. No note Socria sends is ever addressed to a university address. If it is the only address we hold, we send you nothing rather than send it there — this is enforced in the sending code, not just promised here.
- Advertise to you. We run no advertising, here or anywhere else, and we do not share anything for advertising.
- Sell it, or your data, to anyone. Not to a data broker, not to a list, not to your school.
- Tell your university anything. Not that you have an account, not that you use Socria, and certainly not what you write. There is no report, no dashboard and no channel back to any institution.
- Receive anything from them. We hold no enrolment record, no student record and no education record; nothing about you reaches us from a school.
- Treat you differently for it. Being a student changes the price and nothing else — not what we collect, not how long we keep it, not what Socria does or how it answers.
Socria is not affiliated with, endorsed by, or acting on behalf of any university. Remove the address from your account and the free access ends with it; nothing else about your account changes, and everything you have written stays yours. The age rule below applies to students in exactly the same way as to everyone else.
Children
You must be at least 13 to use Socria, and older where your country sets a higher digital age of consent — several EU member states set it at 14, 15 or 16. We do not knowingly collect data from anyone below that age; if you believe a child has given us data, write to us and we will delete it.
Changes and contact
If this policy changes in a way that matters, we will say so rather than quietly re-dating the page. If a breach ever puts your data at real risk, we will tell you and the relevant authority within the deadlines the law sets, and we will say what happened rather than what sounds best. How we protect the data in the first place is set out on the security page. Questions, or a request about your data: hellosocria@gmail.com.