Privacy

Last updated September 2, 2026

Sosai Studio reads what you and your clients submit in order to build a design brief. This page says exactly what that means: what is stored, what leaves our servers, and what never does.

Who is responsible

House of Goods GmbH
Zürcherstrasse 39d, 8952 Schlieren, Switzerland
VAT CHE-226.355.701 MWST
Managing director: Hendrik van Dyck

For any privacy question, including access, correction and deletion requests, write to hello@sosai.studio.

Which law applies

We are established in Switzerland, so the revised Swiss Federal Act on Data Protection (revFADP / revDSG) applies. Because we also serve customers in the European Union, the GDPR applies to their data in addition. Where the two differ, we follow the stricter rule rather than the more convenient one.

What we store

  • Your account: email address, name if you provide one, and the studio it belongs to. Sign-in runs over a one-time email link or Google.
  • Briefing content: the text you or your client write, the URLs you submit, and the files you upload. We keep the raw text, OpenGraph metadata, a full-page screenshot of each crawled URL, and a compressed preview of each image.
  • Derived facts: colour palettes measured from those images, style tags, and the structured briefing built from your answers.
  • Billing: a customer reference and the subscription or payment identifiers. Card details never touch our servers.

What we send to third parties

  • AI models (via OpenRouter): excerpts of your briefing text and the images you submitted, so a model can judge style and fill gaps. Before any text is sent, contact details in it are stripped and replaced with placeholders. Colour values are measured by us, never generated by a model.
  • Stripe: your email and the amount, to take payment and issue a receipt.
  • Email delivery: your email address, to send sign-in links and account notices.
  • Customer relationship (Mautic):your email address, your first name if you gave one, and a short label for where you are in the product, such as having signed up, finished a first briefing, started the Pro trial, used up a month's analyses or cancelled. This is what account and onboarding email is based on. It holds no briefing content and nothing about your clients. People who fill in a briefing through a client link are not added here at all: they answered the studio that invited them, not us.
  • Product analytics (Matomo): page views and funnel steps, measured without cookies and without a cross-site identifier. This runs on our own analytics instance and is not shared with advertising networks.
  • Advertising measurement (Meta): only after you agree in the cookie banner. Any personal identifier in a conversion event is hashed (SHA-256) before it leaves our server. Decline and no Meta script is loaded at all.

We never send briefing content, client names or uploaded files to analytics or advertising services, and aggregate reporting carries no personal data at all.

Public share links

A briefing becomes readable without a login only when you publish it. The link contains an unguessable token, is marked not to be indexed by search engines, and shows the briefing read-only. You can withdraw it at any time from your briefings list, after which the link stops working. Anyone who already opened it may still hold a copy of what they saw.

How long we keep it

Briefings and their sources stay until you delete them or close your account; deleting a briefing removes its analysis, answers and uploads. Billing records are kept as long as tax and accounting law requires.

Cookies

Sosai Studio sets one cookie to keep you signed in, and one to remember your choice in the cookie banner. Neither is used for advertising. Product analytics runs cookie-free. Advertising cookies are set only if you agree, and you can change your mind at any time from the link in the footer.

Your rights

You can ask for a copy of your data, have it corrected, or have it erased. Write to hello@sosai.studio and we will answer within 30 days.