Privacy Policy

Last updated: September 23, 2026

This Privacy Policy explains what information Sophia collects, how it is used, and the choices you have. It applies to the Sophia mobile app and the Sophia website.

Who we are

Sophia is a personal-learning app that builds private, AI-generated courses on topics you choose. Sophia is operated by Dulaj Disanayaka, an independent developer based in the Netherlands, who is the controller of your personal data. You can reach us at hello@bytexy.com for any privacy or support question.

Information we collect

We collect only what we need to run the service:

  • Account identity. When you sign in, a third-party authentication service gives us your email address, your name and, if you use a social provider such as Google, the basic profile information that provider returns. Whether your email is verified, and the user ID your sign-in provider assigns you, are recorded so we can grant one-time free credits fairly.
  • Waitlist email (website). If you join the waitlist on our website, we store the email address you enter and use it only to tell you about Sophia's launch. No account is involved. To leave the waitlist, email hello@bytexy.com and we will remove your address.
  • Course content you create. The topics, prompts, links, files, and preferences you submit to build a course, and the curriculum and lessons Sophia generates for you.
  • Learning schedule and notifications. Your daily-session settings and, while daily reminders are on, the push-notification token for your device.
  • Interests (optional). The interests you type under Settings and, if you leave “Learn from my courses” on, the topics of your own courses, so Explore can put the courses you would pick first.
  • Purchase and subscription state. When you buy a subscription or credits, a third-party subscription-management platform and the app stores tell us your app user ID and your transaction history (which product, when, and whether it is active, refunded, or cancelled). We never receive or store your card number. Payments are processed entirely by Apple or Google.
  • Credits and usage. Your credit ledger, the credits reserved and consumed by previews and generations, and records of what was generated.
  • Inbound email (if you use it). If you use the email-to-course feature, we receive the email you send to our intake address, including its sender address, subject, content, and attachments, so we can build the requested course and associate it with your account. This is processed through a third-party email delivery service.
  • Feedback and support. If you report a bug, send feedback, or request a feature in the app, we store your message, its category, your account ID, and technical context such as the device model, app and update versions, and the route where you opened the form. We also store any images or files you choose to attach. We use this information to respond to problems and improve Sophia.
  • Shared courses and reports. If you share a course to Explore, we publish its text and its card. The card carries the first name on your account when you shared it, and we count how many members save the course. If you report a shared course, we store your account ID, the reason, and any details you give, together with how we resolved it. If you hide an author, we store which author you hid.
  • Diagnostics. If a crash or error occurs, limited technical diagnostic data may be sent to a crash reporting service to help us fix it. Bug reports you choose to submit are also sent there with the message and technical context described above. Files attached to the report stay in Sophia's feedback queue and are not sent to that service.

How your content is used to generate courses

To build a course, Sophia sends the topic, prompt, and any sources you provide to third-party AI model providers that generate the curriculum, lessons, and illustrations. Some handle text and research, while a third-party image-generation service creates imagery. When you ground a course in a link or the open web, the relevant content and web search queries are processed by these providers to produce your course. We also request a brand icon for a course from a third-party logo/image service based on the course topic. The AI provider that writes your courses does not use your content to train its models under our paid agreement. Your content is used to produce your course; it is not sold or used to advertise to you.

Why we are allowed to use your data

The GDPR requires a legal basis for every use of personal data. These are ours.

  • To provide the service you signed up for. Running your account, building and storing your courses, the tutor chat, daily sessions, the email-to-course feature, sharing courses to Explore and saving courses from it, the interests you type under Settings, and recording your purchases and credits.
  • With your consent. Daily reminders, which you allow through your device's notification permission and can turn off under Settings or in your device settings at any time. When you turn reminders off we delete the notification token for every device on your account; when you turn notifications off for Sophia in your device settings, that device's token goes the next time you open Sophia. The website waitlist, which you leave by emailing us. Withdrawing consent does not affect what happened before.
  • For our legitimate interests, where the interest is clear and does not override your rights:
    • preventing fraud and abuse: keeping one free-credit grant per person, and carrying an unpaid store-refund balance to a new account opened by the same person;
    • auditing refunds and the cost of what we generate, using your credit ledger and usage records;
    • keeping Explore safe: handling reports about shared courses and the authors you hide;
    • support and product improvement: reading the feedback you send, and diagnosing crashes and errors;
    • counting how many people use Sophia each day and month;
    • suggesting Explore courses from what your own courses are about, which you can turn off under Settings → Interests;
    • keeping a record that an account was deleted, so a request already in flight cannot recreate its data.

    You can object to any processing on this basis; see “Your rights”.

  • To meet a legal obligation. Keeping records of purchases and payments for as long as tax and accounting law requires.

Where your data is processed and how transfers are protected

Your account and course data are stored with a cloud database and hosting provider in the United States. The other providers described below may also process data outside the European Economic Area, mostly in the United States. We protect each of these transfers in one of two ways:

  • Adequacy decision. Our authentication, email delivery, app update and push notification, crash reporting, and web hosting and file storage providers hold active certifications under the EU-US Data Privacy Framework, which the European Commission has found gives an adequate level of protection.
  • Standard contractual clauses. Our database and hosting provider, our AI model providers, and our subscription-management platform process your data under the standard contractual clauses approved by the European Commission.

Apple and Google collect payment for subscriptions and credits and process your store and payment data under their own privacy terms. We never receive your card details.

Email hello@bytexy.com for a copy of the safeguards that apply to a specific provider, or to ask which providers hold your data.

Third parties we share data with

We share data only with the categories of service providers needed to run the service, and with other members when you choose to share a course. Their roles and contractual terms differ. Apple and Google process store and payment data under their own terms.

  • Authentication service: account identity and sign-in.
  • Cloud database and hosting provider: storing your account and course data (hosted in the United States).
  • Web hosting and file storage provider: serving the website and storing the narration audio of your lessons.
  • AI model providers: generating course text, research, metadata, illustrations, and the spoken narration of lessons from the topics, prompts, and sources you provide, and tagging the interests you type and the topics of your courses for Explore.
  • Logo/image service: brand icons for course topics.
  • Email delivery service: sending and receiving email for the email-to-course feature, and notifying support that new app feedback is waiting.
  • App update and push notification service: delivering app updates and your daily-session reminders. It also uses device information, such as your IP address, in aggregate to analyse and improve its own service, as an independent controller under its own privacy policy.
  • Subscription-management platform: validating and recording purchases and subscription state.
  • Apple and Google: processing payments and running the app stores.
  • Crash reporting service: crash and error diagnostics, and bug reports you submit in the app.
  • Other Sophia members: the text and card of a course you choose to share, under the first name on your account when you shared it. Nothing else about you reaches other members.

We share data only with the categories listed above and never sell your personal data. Sophia shows no advertising.

Deletion and retention

Deleting a course you built permanently removes its lessons, the sources you supplied, the images generated for it, its chat history, and the search index built from it. We delete the stored files themselves, not just the records pointing at them.

Explore holds courses published by Sophia and courses members chose to share. Sharing a course publishes its text and its card under the first name on your account when you shared it; see “Sharing courses” in the Terms of Service for what that means. Unsharing removes the course from Explore straight away. Saving a course from Explore creates an independent frozen copy in your private library. Removing it from your library deletes your copy and its learning data, not the shared course or anyone else’s copy. Your copy stays if the author later unshares the course. If Sophia removes the course, your copy is removed too and shows as removed in your library.

You can delete your account at any time from within the app, under Settings → Account → Delete account. Deleting your account cancels any in-progress generation and permanently removes your content: your courses, learning schedule, preferences, feedback records, and sign-in identity. Courses you shared leave Explore; copies other members saved before that stay in their libraries. Feedback notifications already sent to support and bug reports already sent to the crash-reporting service follow those providers' retention periods.

How long we keep your data

  • Your account, courses, chat, schedule, interests, feedback, and activity records: for as long as your account exists. A course you delete goes at once, with its files. Your device's notification token stays only while daily reminders are on, and goes when you sign out on that device or delete your account. If you sign out while offline, it goes when someone next signs in on that device.
  • Reports about shared courses and their resolution: 12 months after we resolve them.
  • Purchase and subscription records: after account deletion, for as long as tax and accounting law requires us to keep financial records, and while a refund, chargeback, or dispute could still arise. We keep raw purchase notifications from our subscription-management platform for 90 days after we process them; one we cannot process yet is kept until we resolve it.
  • Credit ledger, usage records, and refund cases: after account deletion, for as long as we may need to audit a refund, a chargeback, or the cost of what we generated.
  • Free-credit claim records (your verified email and the user ID your sign-in provider, such as Apple or Google, assigns you): for as long as Sophia offers a one-time free grant, or while an unpaid balance from a refunded purchase is outstanding, so no one can claim the grant twice or escape that balance by opening a new account. A matched new account inherits the balance.
  • Deletion record (your former account ID and the deletion time): after account deletion, so requests already in flight cannot recreate your data. It records nothing beyond the fact that an account with that ID was deleted.
  • Crash and error reports: up to 90 days at the crash reporting service. We remove files attached to feedback you never sent within 24 hours.
  • Waitlist email: until we send the launch notice or you ask us to remove it.

Deleting your Sophia account does not cancel an Apple or Google subscription. Cancel the subscription separately in your App Store or Google Play account settings to stop future billing.

Your rights

Under the GDPR you can ask us for:

  • access to the personal data we hold about you, and a copy of it;
  • rectification of data that is wrong; most of it you can edit in the app;
  • erasure: delete a course in the app, or your whole account under Settings → Account → Delete account, subject to the records listed above;
  • restriction of processing while a dispute about your data is resolved;
  • objection to any processing based on our legitimate interests, including the Explore suggestions drawn from your courses, which you can switch off yourself;
  • portability: a copy of the data you gave us, in a machine-readable format;
  • withdrawal of consent for reminders or the waitlist, at any time.

Email hello@bytexy.com to exercise a right. We answer within one month, as the GDPR requires, and may first ask you to confirm you own the account. Wherever you live, you can use the same options with us.

If you believe we have handled your data unlawfully, you can complain to the Dutch supervisory authority, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl), or to the data protection authority where you live.

Children

Sophia is not directed to children and is intended for use by adults. We do not knowingly collect personal data from children.

Changes to this policy

We may update this policy as the service evolves. When we do, we will revise the “Last updated” date above. Material changes will be reflected here before they take effect.

Contact

Questions about this policy or your data? Email hello@bytexy.com.