Privacy Policy
Last updated: April 2026 · Houston AI GmbH, Vienna, Austria
1. Data Controller
Houston AI GmbH
Vienna, Austria
Email: privacy@sovyn.ai
2. Data We Process
Sovyn is an AI-powered productivity and health coaching platform. We process the following categories of personal data:
- Account data: Email address, registration timestamp, authentication tokens
- Usage data: Chat history, tasks, goals, activity logs
- Health and productivity data: Users may voluntarily share health-related information (e.g. sleep, exercise, nutrition) and productivity data (tasks, calendar events) with the AI coach.
- Device data: IP address, device type, operating system, app version
- Payment data: Processed exclusively by our payment provider (Stripe) — we do not store payment information.
3. Purpose of Processing
- Providing and improving Sovyn services
- AI-generated coaching content and recommendations
- Security and abuse prevention
- Compliance with legal obligations
4. AI-Generated Content — Disclaimer
Important notice: Responses and recommendations generated by Sovyn are created using large language models (AI). These outputs do not constitute medical, psychological, legal, or financial advice and do not replace professional consultation. AI systems can make mistakes. Please do not make health- or safety-critical decisions based solely on AI-generated content.
5. Third-Party Providers and Data Transfers
We use the following third-party providers to operate Sovyn:
OpenAI (AI Processing)
To generate AI responses, we use the API of OpenAI, L.L.C. (San Francisco, USA). Conversation content is transmitted to OpenAI and processed in the United States. OpenAI participates in the EU-U.S. Data Privacy Framework and processes data in accordance with its Privacy Policy. Transfers to the USA are based on Standard Contractual Clauses (Art. 46 GDPR).
Supabase (Database & Authentication)
User data, account information, and conversation content are stored in a Supabase database hosted on our own VPS server in the EU (Germany). Supabase Inc. (San Francisco, USA) only provides the open-source software; our data remains on our server.
Stripe (Payment Processing)
Payments are processed via Stripe, Inc. (Ireland/USA). Payment data is transmitted directly to Stripe and is not stored by us.
Sentry (Error Monitoring)
For error tracking we use Sentry (Functional Software Inc., USA). Technical error data (no chat content) may be transmitted.
6. Data Retention and Deletion
Data is retained for as long as an active account exists. You can permanently delete your account at any time via App Settings → Delete Account — this irreversibly removes all personal data. Statutory retention obligations remain unaffected.
7. Your Rights (GDPR)
Under the GDPR you have the following rights:
- Access (Art. 15): You may request information about the data we hold about you at any time.
- Rectification (Art. 16): You have the right to correct inaccurate data.
- Erasure (Art. 17 — “Right to be Forgotten”): You may request deletion of your data. The fastest method: delete your account directly in the app (Settings → Delete Account).
- Data Portability (Art. 20): You may request a machine-readable copy of your data.
- Restriction of Processing (Art. 18): You may request that processing of your data be restricted.
- Objection (Art. 21): You may object to the processing of your data.
- Complaint: You have the right to lodge a complaint with the Austrian Data Protection Authority (dsb.gv.at).
For access requests or data copies, contact: privacy@sovyn.ai
8. Cookies and Tracking
Sovyn uses only technically necessary cookies (authentication tokens, session management). No advertising cookies or third-party tracking tools are used.
9. Changes to This Privacy Policy
For material changes, we will notify registered users by email. The date of the last update is shown at the top of this page.
