Skip to content
SOSEI
Get Started

Privacy Policy

Effective date: June 17, 2026

SOSEI (β€œwe”, β€œus”) respects your privacy. This Privacy Policy explains what personal data we collect when you use sosei.site and the SOSEI platform, how we use it, and the rights you have under the EU General Data Protection Regulation (GDPR) and comparable laws.

1. Data Controller

The data controller for personal data processed about you as an account holder is the operator of SOSEI, a company registered in Estonia (registered office: Narva mnt 7, 10117 Tallinn, Estonia). Its full registered name and commercial-register code are set out in our Terms of Service or available on request. Contact: [email protected].

Where a website we host for you collects personal data from its own visitors (for example, through the built-in contact form), you are the controller of that visitor data and SOSEI acts as your processor under Article 28 GDPR β€” processing it only to provide the Service and on your instructions. A data-processing agreement is available on request; see our Terms of Service, Section 14.

2. Data We Collect

  • Account data β€” email address, authentication metadata, password hash.
  • Project data β€” the source URLs you submit, scraped content, generated site content, hosting slugs.
  • Contact-form submissions on your hosted sites β€” stored so you can reply to your visitors.
  • Billing data β€” minimal information forwarded to our payment processor; we do not store full card numbers.
  • Technical data β€” IP address, browser user-agent, and request logs, used for security and abuse prevention.

3. Legal Bases (GDPR Art. 6)

  • Contract β€” to provide the Service you requested.
  • Legitimate interest β€” to operate, secure, and improve the platform.
  • Consent β€” for optional analytics or marketing where required. You can withdraw consent at any time.
  • Legal obligation β€” to comply with tax, accounting, and lawful requests.

4. How We Use Data

  • Rebuilding, hosting, and maintaining your site.
  • Account management, billing, support.
  • Security, fraud prevention, and abuse mitigation.
  • Aggregated, non-identifying analytics to improve the product.

We do not sell personal data. We do not use your content to train third-party AI models.

5. Sharing & Sub-processors

We share data with trusted vendors who process it on our behalf under a data-processing agreement, including:

  • Supabase (authentication + PostgreSQL database hosting)
  • DigitalOcean (application hosting and custom-domain certificates)
  • Cloudflare, Inc. (bot protection on our sign-up, login and contact forms β€” the challenge sends the visitor's IP address and browser signals to Cloudflare; and TLS termination for customer domains connected through Cloudflare)
  • Anthropic PBC (AI models that generate and edit website content, translations and support-chat answers β€” receives the content of the site being rebuilt and the instructions you give the editor)
  • Google LLC (Gemini AI models for image and video generation and for AI-visibility checks; Google Places for the business-rating badge you confirm; and, on the product website only and only after you consent to marketing cookies, Google Analytics 4 and Google Ads conversion tracking β€” see our Cookie Policy)
  • OpenAI (image generation requested from the editor β€” receives the prompt and any image you supply) and fal.ai (image upscaling β€” receives the image being enlarged)
  • Perplexity AI (queries about your business used for the AI-visibility report β€” brand and site names, no visitor data)
  • Firecrawl (page fetching for some source websites during a rebuild β€” receives the public URLs being crawled)
  • Resend (transactional email β€” receives recipient addresses and the message content of account, contact-form and report emails)
  • Stripe, Inc. (payments and invoicing when you subscribe)
  • ipapi.co (country lookup of a visitor's IP address for regional abuse limits β€” only when we have that lookup switched on; no other data is sent)
  • Meta Platforms, Inc. (advertising-conversion measurement via the Meta Pixel and Conversions API β€” only on the product website, and only after you consent to marketing cookies; see our Cookie Policy)
  • Google LLC (advertising-conversion tracking and remarketing via Google Ads β€” only on the product website, and only after you consent to marketing cookies; see our Cookie Policy)

International transfers rely on Standard Contractual Clauses or equivalent safeguards as required by GDPR.

6. Retention

We retain account and project data for the life of your subscription. If your subscription ends or lapses, your hosted site is taken offline and we keep the generated site and its data for a grace period (currently 30 days) so you can reactivate it by resuming payment; after that we may permanently delete the generated site, its version history, and its backups, subject to any legal retention obligations. Logs are retained for a limited period for security and debugging. You can request earlier deletion at any time.

7. Your Rights

Under GDPR (and similar regimes) you have the right to:

  • access the personal data we hold about you,
  • rectify inaccurate data,
  • request erasure (β€œright to be forgotten”),
  • restrict or object to processing,
  • receive a portable copy of your data,
  • lodge a complaint with your local supervisory authority.

To exercise these rights, write to [email protected].

8. Security

We use TLS in transit, row-level security at the database layer, least-privilege service credentials, and infrastructure isolation. No method is 100% secure, but we work continuously to meet modern best-practice standards.

9. Children

SOSEI is not directed to children under 16 and we do not knowingly collect their data.

10. Changes

We may update this Privacy Policy. Material changes will be announced on this page with a revised effective date.

11. Contact

Privacy questions or requests: [email protected].