Privacy Policy

Last updated: September 8, 2026

This is an English translation provided for reference. The Korean version prevails in the event of any discrepancy.

1. Purposes of Processing Personal Information

Soha AI (the "Company") processes personal information for the purposes set out below. Personal information under processing is not used for any purpose other than these, and where the purpose of use changes, the Company takes the necessary measures, including obtaining separate consent.

  • Account registration and management (identity verification, conclusion, maintenance and termination of the service agreement)
  • Service delivery (AI brand visibility analysis, competitor monitoring, report generation)
  • Providing AI assistant referral analysis based on the Google Analytics property the user has connected (see Section 9)
  • Handling customer inquiries and complaints
  • Statistical analysis for service improvement and new service development

2. Personal Information We Collect and How We Collect It

Information we collect

  • Required: email address, password (stored encrypted), service usage records, access logs, cookies
  • Social login (Google): email address, profile name, profile image URL
  • Information generated while using the service: registered site domains, analysis results, prompt settings
  • Payment and subscription information: billing email, customer name, subscription plan, payment and subscription identifiers, payment status, payment amount and currency
  • Google Analytics integration (optional): the email address of the connected Google account, the identifier and display name of the selected Google Analytics 4 property, the connection and last synchronization timestamps, and the encrypted refresh token. See Section 9 for details.

How we collect information: direct entry by the user at sign-up, Google OAuth integration, integration with our payment processor, and automatic collection in the course of service use.

The Company does not itself store full payment instrument details such as credit card numbers. Payment instrument details are handled on the secure payment pages provided by our payment processor.

3. Retention and Use Periods

The Company processes and retains personal information within the retention and use period required by applicable law, or within the retention and use period consented to by the user at the time of collection.

  • Account information: until the user withdraws membership (destroyed immediately upon withdrawal, except where applicable law requires retention for a specified period)
  • Service usage records: 3 years (Act on Consumer Protection in Electronic Commerce, etc.)
  • Records of payments and supply of goods: 5 years (Act on Consumer Protection in Electronic Commerce, etc.)
  • Google Analytics integration data (including the encrypted refresh token): until the user disconnects the integration or withdraws membership (destroyed immediately upon disconnection)

4. Provision of Personal Information to Third Parties

As a rule, the Company does not provide users' personal information to third parties. The following are exceptions.

  • Where the user has given prior consent
  • Where required under the provisions of applicable law, or where an investigative authority makes a request for investigative purposes in accordance with the procedures and methods prescribed by law

5. Third-Party Processors

The Company entrusts the processing of personal information to the following processors in order to deliver the service.

ProcessorEntrusted work
Supabase Inc.Database and authentication service operation
Vercel Inc.Web service hosting
Google LLCSocial login authentication, AI analysis API, Google Analytics data retrieval (where the user has connected an account)
Polar Software, Inc.Paid plan payments, subscription management, receipt issuance and refund handling

6. Your Rights and How to Exercise Them

As a data subject, you may exercise the following rights at any time.

  • Request access to how your personal information is processed
  • Request correction of any errors
  • Request deletion
  • Request suspension of processing

You can exercise these rights by emailing support@soha-ai.com, and the Company will respond within 10 days.

7. Use of Cookies

The Company uses cookies to analyze service usage and improve the user experience. You may refuse cookie storage through your browser settings; however, doing so may limit your use of the service.

8. Security Measures

The Company takes the following measures to keep personal information secure.

  • Encrypted storage of passwords and authentication credentials (including Supabase Auth)
  • Encryption of data in transit via HTTPS/TLS
  • Least-privilege access control and periodic review of access rights
  • Data isolation through Row Level Security (RLS)

9. Google Analytics Integration and Handling of Google User Data

Only where the user explicitly chooses to connect Google Analytics within the service does the Company access Google user data, with the user's consent obtained through Google OAuth 2.0, as described below. The integration is optional, and the rest of the service remains fully usable without it.

Google user data we access

  • Aggregated report data from the Google Analytics 4 property selected by the user: sessions, active users, new users, engaged sessions and engagement rate, average session duration, page views, key events (conversions) and total revenue, broken down by date, session default channel group, session source/medium and landing page path
  • The email address of the connected Google account and the display names of the Google Analytics accounts and properties it can access (used to show which account is connected and to let the user select the property to analyze)

The Company accesses this data on a read-only basis only, and does not create, modify or delete any of your Google Analytics settings or data. We retrieve metrics that Google Analytics has already aggregated, not raw event-level data that could identify individual visitors.

Purpose of use: the data is used solely to identify and analyze visits that arrived at the user's website through AI assistants (such as ChatGPT, Gemini and Claude) and to present that analysis in dashboards and reports.

Scopes requested: we request only the minimum scopes required to provide the feature.

  • https://www.googleapis.com/auth/analytics.readonly — read-only access to Google Analytics data
  • openid, email — to obtain the email address of the connected Google account so that it can be displayed in the interface

Storage and deletion: the refresh token issued by Google is encrypted with AES-256-GCM before storage and is never stored in plaintext. Access tokens are not stored at all; they are re-issued whenever they are needed. Report data we retrieve is cached temporarily for up to 30 minutes to keep dashboards responsive and to manage Google API quota consumption, and is not persisted to our database. When a user disconnects the integration, we delete the stored token and connection record and also revoke the grant on Google's side.

No sale, no advertising, no human access: the Company does not sell data retrieved from Google Analytics to third parties, and does not use it for advertising purposes or provide it to advertising providers. Humans do not read this data, except with the user's explicit consent, where necessary for security purposes (such as investigating abuse or incidents) or to comply with applicable law, or where the data has been aggregated and anonymized so that individuals cannot be identified and is used for internal operations.

Compliance with Limited Use requirements: Soha AI's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

How to disconnect: you can disconnect at any time from the "Google Analytics connection" screen in your site settings within the service. You can also revoke access directly from your Google Account security settings at myaccount.google.com/permissions.

10. Data Protection Officer

The Company has designated the following data protection officer, who has overall responsibility for personal information processing and for handling user complaints and providing redress in relation to personal information.

Name: Soha AI Privacy Team

Email: privacy@soha-ai.com

Reports of, or consultations regarding, personal information infringement can be directed to the Korea Internet & Security Agency's Personal Information Infringement Report Center (privacy.kisa.or.kr, 118 within Korea).

Privacy Policy