01Who we are
FINdustries, LLC (“FINdustries,” “we,” “us”) operates Sofia, an AI assistant platform, and getsofia.io. This policy covers our website, applications, and related services (the “Service”). Contact us at support@findustries.co with privacy questions or requests.
If your organization provides Sofia, its administrators may control your account, integrations, permissions, and workspace records. We process organization-provided content on its behalf where applicable; your organization’s policies and agreement with us may also apply.
02Information we collect
- Account and workspace information: name, email address, account identifiers, organization, roles, preferences, and settings.
- Content you provide: prompts, conversations, uploaded files, instructions, feedback, support requests, and information you ask Sofia to remember.
- Connected-service information: account and connection identifiers, authorization tokens, and content and metadata made available through permissions you or your administrator grant. Depending on the integration, this may include email and attachments, calendars and events, contacts, documents, files, folders, cloud storage content, and collaboration records.
- Generated and operational information: responses, summaries, saved context, task and tool results, activity records, usage and performance information, error reports, and security logs. Website and service providers may also receive IP addresses, browser and device information, and request timestamps.
Connecting a service does not mean Sofia accesses every category listed above. Actual access depends on the enabled features, granted permissions, and your instructions.
03How we use information
We use information to provide and secure Sofia: authenticate users; maintain authorized connections; find and summarize information; generate responses; carry out requested tasks and automations; preserve conversation context; support collaboration; diagnose errors; respond to support requests; prevent abuse; and meet legal obligations.
Where an integration permits changes or external actions, Sofia may perform them within the permissions and instructions provided by you or your organization. Access to a service does not by itself authorize unrelated uses of its data.
04Google, Microsoft, and other integrations
You choose which external services to connect, subject to your organization’s controls. Authorization is handled by the provider and, where used, our connection-management service providers. Sofia uses the granted authorization to access the data needed for enabled, user-facing features. You can review permissions during authorization and in the provider’s account settings.
Google and Microsoft are independent providers, and their own terms and privacy policies govern their services. This policy describes our handling of information received through those connections.
Sofia’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements, and applicable Google Workspace API User Data and Developer Policy.
We limit connected-service data use to providing or improving the user-facing features you use. We do not sell this data, use it for advertising or advertising profiles, or use it to train general-purpose AI or machine-learning models. Transfers are limited to providing those features, necessary security purposes, compliance with law, or a business transfer where permitted by applicable provider policies and with consent where required.
People do not read Google user data except with your affirmative agreement for specific data, when necessary for security, to comply with applicable law, or for permitted internal operations involving aggregated and anonymized data in accordance with Google’s policies.
05AI processing and service providers
Sofia uses external AI and infrastructure providers. Relevant prompts, conversation context, connected-service content, and tool results may be sent to an AI provider to generate answers or perform the task you request. Processing a request with a model is distinct from training a model. We do not currently train AI models on customer data, including prompts, conversations, or connected-service information, and we do not authorize AI providers to use that data to train general-purpose models. Connected-service content is provided to AI services only to fulfill the user-facing features you request.
We also use providers for hosting, storage, connection management, security, diagnostics, and customer support. They receive information needed to perform their services for us, subject to applicable contractual and provider-policy restrictions. Diagnostic records may include task context and error details, depending on the deployment and enabled monitoring.
Information may be processed in the United States and other countries where we or our providers operate. Where applicable law requires safeguards for international transfers, we use the required safeguards.
07Retention and deletion
We retain information for as long as needed to provide the features you use, maintain authorized connections, meet legal obligations, resolve disputes, and protect the Service. Retention depends on the kind of information and the configuration of your workspace; there is no single fixed retention period for all Sofia data.
- Conversation sessions: the platform’s default cleanup settings archive sessions after 30 days of inactivity and make archived sessions eligible for deletion after 90 days of inactivity. These periods are measured from the session’s last recorded activity, not added together. Workspace settings may differ, and active sessions can remain available longer.
- Saved context and workspace content: information saved outside a conversation, such as memories, files, and task records, can persist separately to support ongoing work. Deleting or expiring a conversation does not necessarily delete these records. You or your administrator can request their removal.
- Operational records: local application logs rotate daily and by default retain seven rotated files. This is not a seven-day limit on all diagnostic, security, hosting, or third-party records, which have separate settings and retention needs.
- Account and connection information: account settings and authorization credentials are maintained as needed for an active account or connection. Disconnecting removes stored connection credentials through the connection-management process; you can also revoke access at the external provider.
- Browser copies: locally saved chat state may remain until cleared, replaced, or removed on sign-out. Browser storage is separate from server-side session cleanup.
To request access to or deletion of your information, including retained connected-service content and derived records, email support@findustries.co. We may verify your identity and coordinate with your administrator for organization-managed information. We handle requests according to applicable law, including any required retention exceptions. Backup and service-provider copies are subject to their applicable deletion cycles; contact us for information about your workspace.
Disconnecting prevents further access through that connection but does not automatically erase previous conversations, saved context, or copies already shared. Request deletion separately if you want those records removed. Information retained in an external service remains subject to that provider’s policies.
08Your choices and rights
You can manage connections in Sofia’s Connections settings and revoke authorization directly with the provider. For Google, visit your Google account connections. For Microsoft, use your Microsoft account or your organization’s application-permission controls; an administrator may need to revoke organization-managed consent.
Depending on where you live, you may have rights to access, correct, delete, or receive a copy of personal information, restrict or object to processing, withdraw consent, or appeal a privacy decision. Contact support@findustries.co to exercise those rights. We respond as required by applicable law and do not discriminate for exercising privacy rights. You may also contact your local data-protection authority.
Where applicable, we process information to deliver the requested service, pursue legitimate interests such as service security and support, comply with legal obligations, or act on your consent. Withdrawing consent does not affect processing that was lawful before withdrawal.
09Cookies and browser storage
This public website does not set application cookies, use analytics scripts, or embed advertising. The Sofia application may use cookies or browser storage to maintain authentication, preferences, and chat state. Where enabled, diagnostic services may collect errors and interaction information. You can clear browser storage through your browser settings; doing so may sign you out or remove locally saved state.
10Security
We use administrative, technical, and organizational measures designed to protect personal information and restrict access. No system is completely secure. Keep your account credentials confidential, review permissions, and contact support@findustries.co if you suspect unauthorized access.
11Children
Sofia is intended for adults and organizational use, not children under 18. We do not knowingly collect personal information from children under 18. If you believe a child has provided personal information, contact us so we can address it.
12Updates and contact
We may update this policy as the Service or legal requirements change. The updated date appears on this page. We provide additional notice of material changes where required, and obtain consent when required before using information for a new purpose.
Privacy and deletion requests: FINdustries, LLC, support@findustries.co.