This policy explains what data Sopu collects, why, where it lives, and the control you have over it. It is written to be read, not skimmed past.
Who we are
Sopu is operated by Sopu Software (business ID: 3520778-1), the data controller for the information described here. For any privacy request — access, correction, deletion, or a question — email support@sopu.app.
What we collect
We collect only what the product needs to work.
- Your email address. Sopu uses magic-link sign-in, so your email is your identity. We do not collect or store passwords.
- Your workspace contents. The contacts, interactions, notes, next actions, projects, and invoices you create. This is the data you came to Sopu to keep.
- Interaction logs. The record of communication you log against a contact — the institutional memory Sopu exists to protect.
- Captured email replies. When you use Sopu's per-contact capture addresses, the inbound replies your contacts send there — including subject and message body — are logged against the contact. Replies we can't match to a contact are held in a triage area for you to attach or discard.
- Voice notes. If you record a voice note, the audio is transcribed to text. See the “Voice notes” section below for how the audio itself is handled.
- AI assistant conversations. If you use the built-in AI assistant, your prompts and its replies are stored so the conversation persists for you.
- Imported files. Contact data you import (for example, a CSV) and a record of that import.
- Agent and integration activity. When you connect an agent or the MCP integration, Sopu records what actions ran (the tool called, when, and the outcome) so you can review and, where possible, undo them.
- Billing data. When subscription billing is active, a mapping between your workspace and your Stripe customer record. Card details are held by Stripe, not Sopu.
- Technical data for authentication. Your IP address and basic session metadata, used to issue and validate sign-in sessions and to protect your account from abuse.
We do not run advertising, sell your data, or share it with an outside analytics company. The product analytics we do keep are first-party and self-hosted: they run on PostHog on Sopu's own servers in the EU, and the data does not leave our infrastructure.
That analytics covers two things. Usage events — which features you open and the steps you take through them — so we can see what works and where people get stuck. And masked session recordings — a replay of how the interface was used (navigation, clicks, scrolling). Recordings are masked before anything is stored: the text you type and the contact details shown on your screen are hidden, so a recording shows the shape of a session, not its content. We never capture the content of your notes or who you reached out to, and workspace identities are pseudonymised by default. You can turn product analytics and recording off for your browser at any time from Settings → Your data. Separately, the operational and audit logs that run and secure the service (for example, the agent-activity record described above) can contain action metadata such as a contact reference; those logs are not the analytics system and are kept only as long as needed to operate and protect Sopu.
Why we collect it
- To provide the CRM: store, display, and search your workspace.
- To authenticate you: send magic links, maintain your session.
- To send transactional email: sign-in links and account-related notices. We do not send marketing email.
- To keep the service secure: detect and prevent abuse of accounts.
- To improve the product: first-party, self-hosted usage analytics and masked session recordings (described above) — what gets used and where people get stuck. Never the content of your notes or who you reached out to, and you can turn it off in Settings.
- To run AI-assisted features you choose to use: transcribing a voice note, drafting from a capture, or answering in the AI assistant.
keeping that service secure and improving how it works for you. Providing this data is a contractual matter, not a statutory one: you are not legally required to give it to us, but it is needed to use Sopu — without your email there is no way to sign you in, and without your workspace contents there is nothing for the CRM to store.
Where your data lives
- Hosting. Sopu runs on servers operated by Hetzner, within the EU.
- Product analytics. Usage events and masked session recordings are processed by PostHog running on Sopu's own servers in the EU. This is first-party — the data is not shared with PostHog the company or any other third party.
- Transactional email. Sign-in links and account notices are delivered through Resend.
- Inbound contact email. Postmark provides the per-contact email addresses Sopu uses to capture replies from your contacts and log them into your workspace.
- Payments. When subscription billing launches, payments will be processed by Stripe. Sopu will not store your full card details — Stripe handles that. This policy will be updated when billing goes live.
- AI features. Sopu offers AI-assisted features in two modes. In the default (Sopu-managed) mode, Sopu sends the minimum necessary content to Groq — currently the only large-language-model provider Sopu uses, serving a model from OpenAI — for the AI assistant, draft generation, and voice-note transcription. Depending on the request, this may include contact names, notes, interaction text, and tag values; it does not include your authentication credentials, billing details, or full inbox contents. Sopu uses Groq on its paid API tier, where its published policy states customer content is not used to train models — see Groq's current terms for the binding statement. Groq operates primarily in the United States, so transfers from the EU rely on the EU-US Data Privacy Framework (where certified) or standard contractual clauses, plus supplementary measures. In the bring-your-own-key mode, the request goes to the provider you connect under your own agreement with them; Sopu is only the transport. If we change or add an AI provider, we will update this policy.
These AI features assist you — they suggest drafts, transcribe a note, or answer a question you ask. They do not make automated decisions that produce legal or similarly significant effects about you, so the GDPR Article 22 rules on solely-automated decision-making do not apply.
Each of these is a processor acting on our instructions, or — in the bring-your-own-key case — a provider you have your own relationship with.
Voice notes
When you record a voice note, the audio is sent to Groq for transcription into text, and the text becomes a draft you can edit and save. We keep the transcribed text as part of your workspace.
- The audio recording is not kept once it has been used. On a successful transcription, the audio is discarded immediately and only the text remains. The audio is retained only when something goes wrong — a failed or empty transcription — so we can diagnose the failure, and is then removed during routine cleanup, typically within 24 hours.
- No voice biometrics. Sopu transcribes what was said. It does not perform speaker recognition, voice identification, or diarization, and does not build a voiceprint. We do not use voice notes as biometric data.
We process voice notes to provide the transcription feature you chose to use — the lawful basis is performance of our contract with you.
How long we keep it
- Workspace contents and interaction logs: kept for as long as you keep your account — they are the institutional memory Sopu exists to hold. You can delete individual records at any time.
- Authentication and IP data: sign-in sessions expire on their own schedule; the IP and session metadata tied to them are removed when your account is permanently deleted. Separately, we keep minimal operational logs (request and error records used to keep Sopu running and diagnose outages); these are operator records, not part of your workspace data, and are not included in your export.
- Voice-note audio: discarded immediately on success; failed-transcription clips are removed during routine cleanup, typically within 24 hours (see “Voice notes” above).
- Product analytics: pseudonymised usage events and masked session recordings (see “What we collect”) are kept to track how Sopu is used over time; they do not contain your notes or messages, and you can turn them off in Settings → Your data.
- After deletion: when you delete your account, your data enters a 7-day grace period during which deletion can still be reversed. After 7 days the deletion is final: your account can no longer be restored and your data is permanently erased. Backups roll off on their normal cycle.
Your rights
Under the GDPR you have the right to:
- Access — export a copy of your workspace data at any time from Settings.
- Portability — that same export is provided in a structured, machine-readable format.
- Rectification — correct any data directly, by editing it in the product.
- Erasure — delete your account and its data from Settings; see the retention section above for timing.
- Object or restrict — contact us and we will address it.
To exercise any right not covered by an in-product control, email support@sopu.app. You also have the right to lodge a complaint with a data protection authority. Sopu is established in Finland, so the lead authority is the Finnish Office of the Data Protection Ombudsman (Tietosuojavaltuutettu, tietosuoja.fi); you may also complain to the authority in your own country.
We have not appointed a Data Protection Officer — Sopu's scale and processing do not meet the GDPR Article 37 threshold that requires one. Privacy questions and requests go to support@sopu.app.
Cookies
Sopu uses strictly necessary cookies for your sign-in session, plus first-party analytics cookies — set by our self-hosted PostHog — that recognise your browser across visits so usage events and recordings tie together. There are no advertising or cross-site tracking cookies, and you can turn the analytics ones off from Settings → Your data. See the Cookie Policy for detail.
Changes to this policy
If this policy changes materially, we will note it here and update the date at the top. Continued use of Sopu after a change means you accept the revised policy.
Contact
support@sopu.app — privacy questions and requests.