Legal
Privacy Policy
How Suoja collects, uses, and protects your information
⚠ DRAFT — UNDER LEGAL REVIEW

This document reflects our current best understanding of our obligations and your rights, but is not yet final. Final terms will be effective once reviewed by counsel. Last updated: June 1, 2026.

📅   Effective Date: 06/01/2026  ·  Last Updated: 06/01/2026
Overview

About This Policy

This Privacy Policy explains how Suoja Inc. ("Suoja," "we," "us," or "our") collects, uses, and protects information when you use our AI safety platform, including our browser extension and web dashboards.

Suoja is an AI safety platform that monitors AI-generated content in real time to detect and flag harmful outputs including self-harm suggestions, violence encouragement, and psychological manipulation. We apply that same protective philosophy to your personal data — we collect only what is necessary, we do not sell your data, and we are transparent about everything we do.

We operate under five core principles: minimum necessary data · no data selling · purpose limitation · transparency · user control. Data collected for safety scanning is never used for advertising or profiling.
Section 1

Information We Collect

1.1 Account Information

When you create a Suoja account, we collect:

1.2 Incident Data (from the browser extension)

When our extension detects potentially harmful AI-generated content, we log the following:

Data element What it contains Why we collect it
Risk level High, medium, or low To prioritize alerts and reporting
Category Self-harm, violence, or manipulation To categorize incidents for review
Detection summary One-sentence description of what was detected To inform the user and administrator
Platform name e.g., "ChatGPT" or "Character.AI" To identify which AI tool was involved
Timestamp Date and time of detection For incident log and trend analysis
Confidence score 0.0–1.0 numeric score To indicate detection certainty
Important: Suoja does NOT store the full text of AI conversations. We store only the detection metadata listed above — not the content of what you typed or what the AI said. Your conversations remain private.

1.3 Usage Data

We collect basic usage information to improve Suoja:

1.4 Technical Data

Section 2

How We Use Your Information

We use the information we collect for the following purposes:

We do not use your data for: advertising, user profiling, behavioral targeting, selling to third parties, or any purpose unrelated to AI safety protection.
Section 3

Data Sharing

We do not sell your personal data. We share data only in the following limited circumstances:

3.1 Within your organization

If you use Suoja through an organization account (school, hospital, employer), your incident data is visible to the designated administrator of that organization. This is a core feature of the platform — administrators need this data to fulfill their duty of care obligations.

3.2 Service providers

We use the following third-party services to operate Suoja:

Service Purpose Data shared
Anthropic (Claude API) AI-powered harm analysis Text snippets of AI responses — no personal identifiers
Supabase Database hosting Account and incident data — encrypted at rest
Render Backend API hosting API requests — no persistent storage
Netlify Dashboard hosting Static files only — no user data
Google Workspace Email (alerts) Email address and alert content only

3.3 Legal requirements

We may disclose your information if required by law, subpoena, court order, or to protect the safety of any person. We will notify you of such requests where legally permitted.

3.4 Emergency situations

If we detect content that indicates an imminent risk to life, we may share relevant information with emergency services or crisis intervention organizations. This is a rare and last-resort measure taken solely in the interest of user safety.

Section 4

Data Retention

You may request deletion of your data at any time by contacting privacy@suoja.tech.

Section 5

Your Rights

Depending on your location, you may have the following rights regarding your personal data:

To exercise any of these rights, contact us at privacy@suoja.tech. We will respond within 30 days.

Section 6

California Privacy Rights (CCPA / CPRA)

California residents have additional rights under the California Consumer Privacy Act and the California Privacy Rights Act. Suoja does not sell or share personal information for cross-context behavioral advertising as those terms are defined under the CCPA and CPRA. California residents may exercise their rights to access, correct, delete, or limit the use of their personal information by contacting privacy@suoja.tech.

Section 7

Children's Privacy and COPPA Compliance

Suoja is designed to protect minors from harmful AI content. When a parent or legal guardian enrolls a child in Suoja, we collect limited data about that child's AI interactions for the express purpose of detecting harmful content and alerting the guardian.

For children under 13, we operate in compliance with the Children's Online Privacy Protection Act (COPPA):

Schools and organizations deploying Suoja for students under 13 must ensure they have obtained appropriate parental or institutional consents as required by COPPA, FERPA, and applicable state laws.

Children age 13 or older may use Suoja with a guardian account configured by a parent or guardian who maintains visibility over the child's protection settings.

Section 8

Security

We implement industry-standard security measures to protect your data:

No system is 100% secure. If you discover a security vulnerability in Suoja, please report it responsibly to security@suoja.tech.

Section 9

Browser Extension Specifics

9.1 What the extension reads

The extension reads AI-generated text responses on monitored platforms (ChatGPT, Claude, Gemini, etc.) solely for the purpose of harm detection. It does not read:

9.2 What is sent to our servers

When a potential harm is detected, a text snippet of the AI's response is sent to the Anthropic Claude API for analysis. This snippet contains no personal identifiers. If no harm is detected, nothing is sent to our servers.

9.3 Local storage

The extension uses your browser's local storage to save your API key, settings, and a limited incident log. This data stays on your device unless you are logged into a Suoja account, in which case incidents are synced to your account.

The extension only activates on AI platform domains explicitly listed in its manifest. It does not monitor general web browsing.
Section 10

Cookies

Our web dashboards use minimal cookies:

Section 11

Third-Party Services

Suoja integrates with Anthropic's Claude API for AI-powered harm analysis. When text is sent to Claude for analysis, it is subject to Anthropic's privacy policy at anthropic.com/privacy. We configure our API calls to minimize data retention by Anthropic.

Links to third-party websites from our platform are provided for your convenience. We are not responsible for the privacy practices of those websites.

Section 12

International Users

Suoja is currently operated from the United States and intended for use in the United States. If you access Suoja from outside the United States, you do so at your own initiative and are responsible for compliance with local laws. We are working to expand our compliance framework to support international users, including provisions required under the European Union General Data Protection Regulation (GDPR), the United Kingdom Data Protection Act, and other applicable frameworks. Until that expansion is complete, Suoja accounts created outside the United States may be limited in functionality or unavailable.

Section 13

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. When we make material changes, we will:

Continued use of Suoja after the effective date of changes constitutes acceptance of the updated policy.

Privacy Questions or Data Requests?

Contact our team — we will respond within 30 days.

Privacy contact

privacy@suoja.tech

Security reports

security@suoja.tech

Suoja Inc.