Sovi logo

Privacy Policy

Last updated: May 2026

Mengel Enterprises LLC · Sovi

Your sovi is private. We do not sell your data, share it with advertisers, or use your personal content to train AI models.

Data We Collect

  • Account information: name, email address, and password (hashed — we never store plaintext passwords).
  • Profile data: timezone, preferences, brief time, and onboarding responses you provide.
  • Usage data: features you use, pages you visit, and actions you take within the app — used to improve the product.
  • Content you create: tasks, goals, journal entries, notes, decisions, and venture data stored in your account.
  • Health data (optional): sleep, readiness, and activity data from connected wearables (Oura, Fitbit; Apple Health and Whoop coming soon). This data is stored only in your account and is never shared.
  • Financial data (optional): if you connect bank or credit card accounts via Plaid, we receive transaction and balance data to populate your Finance module. We do not store raw account credentials.
  • OAuth tokens: if you sign in with Google, Microsoft, or Apple, we receive an access token and basic profile information. If you connect Google Calendar, we also request read-only access to your unread Gmail (subject line and a short snippet only, never the full message body) to surface time-sensitive email in your daily brief — you see and approve this scope on Google’s own consent screen before it’s granted.

How We Use Your Data

  • To provide and operate the Sovi service, including your daily brief, AI assistant, and module features.
  • To personalize your experience — your context is what makes Sovi useful.
  • To send transactional emails: account confirmation, password reset, billing receipts.
  • To improve the product through aggregate, anonymized usage analytics. We do not sell individual usage data.
  • We do not use your personal content (journal entries, notes, decisions, tasks) to train AI models. Your sovi is private.

Data Sharing

  • We do not sell your data to third parties. Ever.
  • We do not share your data with advertisers or analytics companies that build user profiles.
  • We share data only with the service providers necessary to operate Sovi: Azure (cloud infrastructure and database), OpenAI (AI features — data is processed subject to OpenAI's data policies and is not used to train OpenAI models per our API agreement), Plaid (financial data aggregation), and Stripe (payment processing).
  • We may disclose data if required by law, legal process, or to protect the rights and safety of our users or the public.

Google User Data and Limited Use

  • When you connect your Google Account to sync your calendar, Sovi requests access to your Google Calendar data (the https://www.googleapis.com/auth/calendar scope) solely to read and display your events and to create or update events you initiate in the app.
  • Sovi's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements: Google user data is used only to provide the calendar features you request, is not transferred to third parties except to operate those features, is not used for advertising, and is not accessed by humans except with your consent or for security, abuse-prevention, or legal reasons.
  • You can disconnect your Google Account at any time, which revokes our access and deletes the stored tokens.

Data Retention

  • Your account data is retained as long as your account is active.
  • If you delete your account, we delete your personal data within 30 days, except where we are required to retain it for legal or financial compliance purposes (e.g., billing records for up to 7 years).
  • You may request deletion of your data at any time by contacting info@sovi.studio.

Security

  • All data is encrypted in transit (TLS) and at rest (AES-256).
  • Passwords are hashed using bcrypt and are never stored in plaintext.
  • Authentication tokens are short-lived JWTs. We support HttpOnly cookie sessions for additional security.
  • We use Azure cloud infrastructure with role-based access controls and audit logging.
  • We conduct regular security reviews. If you discover a security vulnerability, please report it to info@sovi.studio.

Your Rights

  • Access: you can export your data at any time from your account settings.
  • Correction: you can update your account information and profile data in your settings.
  • Deletion: you can delete your account and all associated data from your settings, or by contacting us.
  • Portability: your data is yours. We provide export functionality for your content.
  • If you are located in the European Economic Area, you may have additional rights under GDPR. Contact us at info@sovi.studio for GDPR-specific requests.

Cookies

  • We use session cookies to maintain your authenticated session.
  • We do not use third-party advertising cookies.
  • We may use minimal, privacy-preserving analytics cookies (e.g., page view counts) to understand product usage. These do not track you across other sites.
  • You can disable cookies in your browser settings. Note that disabling session cookies will prevent you from staying signed in.

Contact

  • Sovi is operated by Mengel Enterprises LLC.
  • For privacy-related questions, requests, or concerns, contact us at: info@sovi.studio
  • We will respond to privacy requests within 30 days.

This policy may be updated from time to time. We will notify users of material changes via email or in-app notification. Continued use of Sovi after changes constitutes acceptance of the updated policy.