Sofa.st
← Back to home

Legal

Privacy Policy

Last updated: August 14, 2026

This Privacy Policy explains how Sofa.st (“Sofa.st”, “we”, “us”) collects, uses, and protects personal data when you visit our website, create an account, or use our service. Sofa.st is operated by Mohamed Bariki, based in Morocco. You can reach us at [email protected] for any privacy-related question or to exercise your rights.

1. Who is the controller of your data

For data about your own account and use of Sofa.st (your email, billing, and usage), Sofa.st is the data controller.

For the content you upload and the questions your website visitors ask your chatbot, you (our customer) are the controller and Sofa.st acts as a data processor on your behalf, processing that data only to provide the service. Business customers who need a Data Processing Agreement (DPA) can request one at [email protected].

2. Data we collect

3. How we use your data

4. Legal bases (GDPR)

Where the GDPR applies, we rely on: performance of a contract (to provide the service you signed up for); legitimate interests (to secure and improve the service and prevent abuse); legal obligation (tax and accounting); and consent where specifically requested — which is the basis for analytics and session recording, and for nothing else.

5. Sub-processors

We rely on a small number of vetted providers to run the service. Each processes data only as needed to perform its function:

6. International transfers

Two of our sub-processors operate in the United States, so some data may be transferred outside your country, including outside the EEA:

Such transfers rely on the safeguards offered by the provider, such as Standard Contractual Clauses where applicable. You can withdraw consent for the PostHog transfer at any time, which stops it going forward.

7. Data retention

We keep account and content data for as long as your account is active. When you delete a source, a chatbot, or your account, the associated content and its embeddings are deleted from our systems. We may retain limited billing and transaction records where required by law.

8. Cookies and local storage

Our dashboard uses a single essential authentication cookie to keep you signed in. The chat widget stores a random visitor identifier and the current conversation in the visitor’s browser (local and session storage) so a conversation stays coherent.

On our own website and dashboard we also use PostHog for product analytics and session recording, and we ask before switching it on. Nothing is collected until you accept: no analytics cookie is written and no data is sent while the choice is unanswered or declined. Session recording captures the pages you saw and what you clicked; text you type into form fields is masked in the browser and never reaches us. You can change your answer at any time through “Analytics choices” in the footer.

We do not use advertising trackers, and we place nothing at all on your own website visitors’ browsers beyond what the chat widget needs to work.

9. Your rights

Subject to applicable law, you may request access to, correction of, or deletion of your personal data, object to or restrict certain processing, and request a portable copy of your data. To exercise any of these, email [email protected]. You also have the right to lodge a complaint with your local data protection authority.

10. Security

We use access controls, encryption in transit, and tenant isolation so that each customer’s content is only reachable by that customer. No method of transmission or storage is perfectly secure, but we work to protect your data against unauthorized access.

11. Children

Sofa.st is not directed to children under 16 and we do not knowingly collect their personal data.

12. Changes to this policy

We may update this policy from time to time. When we do, we will revise the “Last updated” date above, and for material changes we will take reasonable steps to notify you.

13. Contact

Questions about this policy or your data? Email [email protected].