SophusX Chrome Extension Privacy Policy
The SophusX Chrome extension uses customer data only to help authenticated SophusX users create, validate, and work with network optimization models, and to maintain and improve that service.
Sophus does not sell extension data or use it for advertising, lending, or creditworthiness decisions.
1. Scope and responsible company
This policy applies specifically to the SophusX Chrome extension and its supporting service, which runs in two regions: agent.sophusx.com (United States) and eu.agent.sophusx.com (Europe). The user chooses the region in the extension before logging in.
Choosing the Europe region means the supporting service and the files it stores are hosted in Europe. It is not, at present, a guarantee that all processing stays in Europe: the AI providers listed in section 5 may process submitted content in other regions.
Sophus Technology Inc. ("Sophus", "we", "us") is responsible for the processing described here.
2. The extension's single purpose
The extension helps authenticated SophusX users create and work with network optimization models from spreadsheet data and written business requirements.
3. Information handled
- Account information: SophusX username and identifiers
- Authentication information: existing SophusX session token (password not collected)
- User-provided content: spreadsheets, file names, business requirements
- Model information: SophusX project and model identifiers, model data needed for requested operations, generated workbooks, validation results, and solver results
- Communications: chat messages, feedback, support information
- Service activity: build status, timestamps, versions, errors, journey records
- Request information: IP address, request path, time, technical error details
4. How information is used
Information is used to:
- recognize and authenticate the user's SophusX session
- process selected inputs and create, validate, import, solve, display, or update SophusX models
- provide model-specific chat and preserve the user's extension workflow
- provide customer-requested support and investigate errors or security incidents
- measure and improve the quality, reliability, safety, and usability of the SophusX extension
5. Service providers and data transfers
Service providers include:
- DigitalOcean - hosts the SophusX agent service and the SophusX platform
- Anthropic - Claude services support model building
- OpenAI - AI services support the model-specific chat, including scenario planning
Customer data is not used by Sophus to train general-purpose AI models.
Sophus does not transfer extension data outside these service needs except for security, legal compliance, or a corporate transaction governed by applicable law.
6. Storage and retention
- Browser storage: the authentication token and username remain until logout, removal through browser controls, or extension uninstall. Recent-model references, local chat history and a short record of recent builds remain until removal through browser controls or extension uninstall; from extension version 0.2.6 they are also removed at logout. Settings that are not personal data (such as the chosen region) remain until removal through browser controls or extension uninstall
- Uploaded files and build artifacts: retained on the agent service for no more than 30 days
- Server-side chat, feedback, and journey records: retained for no more than 90 days
- Request information in server logs (IP address, request path, time): retained for no more than 90 days
- Operational AI chat session files: normally deleted after 7 days
- SophusX models: retained in the SophusX platform until deleted by the customer
7. Human access
Access is restricted to authorized Sophus personnel who need it for customer-requested support, security investigation, legal compliance, or service-quality improvement.
Identifiable customer content may be reviewed for quality improvement only with the customer's consent; otherwise quality review uses aggregated or anonymized information.
8. Security
Sophus uses HTTPS for data in transit, access controls, restricted production access, redaction of fields that hold passwords or tokens in service records, and retention controls. Free text that a user types, such as a chat message, is stored as typed.
No method of storage or transmission is completely risk-free, but Sophus applies safeguards appropriate to the data and service.
9. Sale, advertising, lending, and AI training
Sophus does not:
- sell extension user data;
- use or transfer extension user data for advertising or purposes unrelated to the extension's single purpose;
- use or transfer extension user data to determine creditworthiness or for lending;
- use extension customer data to train general-purpose AI models.
10. Chrome Web Store Limited Use
Sophus's use and transfer of information received through Chrome APIs complies with the Chrome Web Store User Data Policy, including its Limited Use requirements.
Information is used only to provide or improve the extension's user-facing purpose, for permitted security or legal needs, or in aggregated or anonymized form for internal operations.
11. Access, correction, and deletion
Users or customer administrators may request access, correction, or deletion of extension-related personal data by emailing privacy@sophus.ai.
Sophus will verify the requester and complete valid deletion requests within 30 days, except where retention is required by law.
The session token can also be removed by logging out. All local extension data, including chat history, is removed by clearing the extension's browser storage or uninstalling the extension. From extension version 0.2.6, logging out also removes local chat history, recent-model references and the record of recent builds.
12. Changes
We may update this policy when the extension or applicable requirements change. Material changes to extension data practices will be disclosed before the changed practices take effect.
Contact
Questions: privacy@sophus.ai
Company: Sophus Technology Inc.
Website: sophus.ai