Privacy Policy

Last updated: May 27, 2026

Short version

Sofro connects to your Microsoft Outlook and Calendar to help you manage your work. We access your email and calendar in real time when you use the product — we never store raw email bodies or full calendar event content. We store AI-synthesised summaries derived from your email and calendar data to power features like briefs and conversation history. Your full email content and raw calendar data is never written to our database. Your OAuth credentials are encrypted at rest using AES-256-GCM. We do not sell your data, train AI models on your data, or share your data with advertisers. Every write action Sofro takes on your behalf requires your explicit approval first. Your daily briefs are generated automatically on a schedule you configure — brief generation reads your email and calendar but never sends, modifies, or deletes anything without your approval.

1. Who We Are

Filip Nikolic, trading as Sofro, Malmö, Sweden. Data controller for sofro.ai. Contact: privacy@sofro.ai

2. What Data We Collect and Why

2.1 Account Data: name, email, timestamp, preferences (brief times, theme, language).

2.2 OAuth Credentials: Microsoft 365. AES-256-GCM encrypted, unique IV per token, never stored in plaintext.

2.3 Email and Calendar Content: Raw email bodies, full message content, and complete calendar event details are never written to our database. Sofro stores AI-synthesised summaries and metadata (such as sender name, subject line, event title, and date) derived from your email and calendar data. This is necessary to power features like conversation history and daily briefs. We do not store full email bodies, message threads, or complete calendar event descriptions.

2.4 Conversation History: messages, responses, approval records, execution confirmations. No raw email bodies.

When Sofro reads your inbox or calendar during a conversation, it may store AI-synthesised metadata (such as sender names, email subjects, and event titles) as part of the conversation record. This allows cards and summaries to reload correctly when you return to a previous conversation. Raw email bodies and full calendar content are never stored.

2.5 Generated Files: deleted 30 days after creation or account closure.

2.6 Morning and Evening Briefs: Your daily briefs are generated and cached so they load instantly. A brief is an AI-synthesised summary derived from your email and calendar data at the time of generation. Synthesised brief content is cached and automatically cleaned up within 48 hours. A secondary brief record used for delivery tracking is retained for up to 7 days. Raw email bodies and full calendar event content used to generate briefs are never stored.

2.7 Usage and Billing: credits, Stripe, no card storage.

2.8 Error Data: Application errors are reported to Sentry. Request bodies and user identifiers (email, username, IP address) are stripped before transmission. No email or calendar content is ever included in error reports.

3. Microsoft API Permissions

PermissionPurpose
Mail.ReadRead Outlook messages when you ask Sofro to check email.
Mail.SendSend email only after you approve the exact message. Sofro never acts autonomously. Exception: brief generation reads your email and calendar automatically on a schedule you configure, but never performs any write action without your explicit approval.
Mail.ReadWriteDraft, reply, or delete email only after explicit approval. Sofro never acts autonomously. Exception: brief generation reads your email and calendar automatically on a schedule you configure, but never performs any write action without your explicit approval.
Calendars.ReadRead calendar events when you ask Sofro to check your schedule or conflicts.
Calendars.ReadWriteCreate, update, or delete calendar events only after approval. Sofro never acts autonomously. Exception: brief generation reads your email and calendar automatically on a schedule you configure, but never performs any write action without your explicit approval.
offline_accessKeep your Microsoft connection working until you disconnect or delete your account.

4. How We Use Your Data

We do not use data to train AI models. We do not sell data.

5. Legal Basis (GDPR)

Account data, OAuth, historyArt 6(1)(b)
Email/calendar content transientArt 6(1)(b)
Brief cacheArt 6(1)(b)
Usage/billingArt 6(1)(b)/(f)
Error dataArt 6(1)(f)

6. Your Rights Under GDPR

You have the right to access, rectification, erasure, restriction, portability, objection, withdrawal of consent, and complaint to a supervisory authority. Use the form below to submit a request — we respond within 30 days as required by GDPR Article 12(3). Complaints may be sent to IMY at imy.se.

We respond within 30 days as required by GDPR Article 12(3). We may verify your identity before processing.

7. Third-Party Processors

ClerkUSASCCs
StripeUSASCCs
NeonEUwithin EEA
DataCrunch Oy (Verda)Finland, EUwithin EEA
SentryUSASCCs
MicrosoftUSASCCs
VercelUSA/EUSCCs
Amazon Web Services (AWS)USASCCs · data stored in EU (Stockholm)

8. Data Retention

Email/calendarRaw email bodies and full calendar event content are never stored. AI-synthesised summaries and metadata (sender names, subjects, event titles) are stored as part of conversation history and brief cache — see sections 2.3, 2.4, and 2.6.
OAuth tokensuntil disconnect or deletion
Account data and conversation historyDeleted immediately upon account deletion request. If your subscription lapses without explicit deletion, data is retained for up to 30 days before cleanup.
Generated files30 days
Brief cache (synthesised summaries)Cleaned up automatically within 48 hours.
Brief delivery recordsCleaned up after 7 days.
Billing records7 years (Swedish law)
Error logs90 days

9. International Transfers

We use SCCs for non-EU processors. Core infrastructure is in the EU.

10. Security

We use AES-256-GCM encryption for OAuth tokens with a unique IV per token, TLS in transit for all connections, a human-in-control architecture where all write actions require explicit approval, tamper-evident audit logging with SHA-256 hash chaining, and security headers (HSTS, CSP, X-Frame-Options) on all responses. Error reports sent to Sentry have request bodies and user identifiers stripped before transmission. We provide 72-hour breach notification to affected users and supervisory authorities where required by GDPR Article 33.

11. Children

Under 16 not permitted.

12. Changes

We provide 14 days notice for material changes.

13. Data Protection Officer

Sofro does not currently meet the thresholds requiring mandatory appointment of a Data Protection Officer under GDPR Article 37. All data protection enquiries are handled directly by the controller at privacy@sofro.ai.

14. Contact

Email: privacy@sofro.ai
Operator: Filip Nikolic, trading as Sofro
Location: Malmö, Sweden
IMY escalation: imy.se