Sophon 2.0 is here

Privacy Policy

Last updated: September 20, 2026

1. Introduction

Buildersoft LLC ("we," "our," or "Buildersoft") operates Sophon, an AI personal assistant platform. This Privacy Policy explains how we handle information in connection with the Sophon software, the Sophon website (sophon.buildersoft.io), and related services.

Core principle: Sophon is a self-hosted platform. When you run Sophon on your own infrastructure, your data stays on your infrastructure. We do not collect, access, store, or process your conversations, memory, documents, credentials, or any runtime data.

2. What We Do Not Collect

When you self-host Sophon, the following data remains entirely on your servers and is never transmitted to Buildersoft:

  • Conversations and chat history
  • Agent memory (short-term and long-term)
  • Uploaded documents and processed content
  • API keys, OAuth tokens, and credentials
  • Channel configurations and message content
  • Workflow definitions and execution data
  • User profiles and authentication data

Sophon contains no usage analytics, tracking pixels, or behavioural telemetry, and license validation is entirely offline. Three marketplace features do make outbound requests, and all three can be turned off:

  • A marketplace update check, every 24 hours by default, set by Sophon:Marketplace:UpdateCheckInterval. It asks the registry which versions exist for the packages you have installed.
  • Anonymous install reporting — an instance identifier (hashed at rest by the registry), plus the package name, version, and whether it was an install or an uninstall. Set Sophon:Marketplace:ReportInstalls to false to opt out.
  • Automatic marketplace updates — new in Sophon 2.0 and off by default. An administrator turns them on with Sophon:Marketplace:AutoUpdate, or in the Dashboard under Settings → Marketplace → Automatic updates. While they are on, the same 24-hour sweep also downloads the new package versions it finds and installs them through the regular verified path — checksum verified, rolled back if an update fails. Left off, Sophon only tells you an update exists and never downloads one on its own.

Browsing or installing from the Marketplace by hand downloads packages over the same route, whether or not automatic updates are on. Setting Sophon:Marketplace:Enabled to false disables all of it, along with the marketplace UI and endpoints — the right configuration for air-gapped deployments. No conversation, memory, document, or credential data is included in any of these requests.

3. What We May Collect

3.1 Website

When you visit our website, we may collect standard web server logs (IP address, browser type, pages visited) for security and operational purposes. We do not use third-party analytics or advertising trackers.

3.2 Contact Forms

If you contact us through our website, we collect the information you voluntarily provide (name, email, message content) to respond to your inquiry.

3.3 License Verification

Nothing. Pro and Enterprise license keys are signed certificates that your own installation verifies locally — tier, seat count, feature flags, and expiry are read straight out of the key. No license key, hardware fingerprint, or activation call is transmitted to us, and Sophon does not phone home to stay licensed. It keeps working on a disconnected network.

3.4 Marketplace

If you use the Sophon Marketplace to browse or install skills, requests are made to the Marketplace API. These requests include your Sophon instance version and the package being requested, and installing or updating a package downloads it from the registry. No conversation data, memory, or credentials are transmitted.

4. Third-Party Services

Sophon connects to third-party services only when you explicitly configure them:

  • LLM Providers (Anthropic, OpenAI, Google, Ollama, etc.) — conversation content is sent to your chosen provider according to their privacy policy.
  • Channel Platforms (Telegram, WhatsApp, Slack, etc.) — messages are exchanged with these platforms according to their respective policies.
  • Integration Services (GitHub, Jira, Google Calendar, etc.) — data is exchanged only when you install and configure the corresponding skill.

You choose which providers and services to connect. Sophon ships with zero pre-configured external connections.

5. Data Storage & Security

All Sophon runtime data is stored in the ~/.sophon directory on your host. Credentials are encrypted at rest. On Windows the encryption key is bound to your operating-system account through DPAPI; on macOS and Linux the default local backend uses AES-256-CBC under a key file kept in the same data directory, so for production deployments off Windows we recommend configuring an external vault. Enterprise deployments can integrate with HashiCorp Vault, AWS Secrets Manager, or Azure Key Vault.

6. Children's Privacy

Sophon is not directed at children under 13. We do not knowingly collect personal information from children.

7. Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated revision date. Material changes will be communicated through the Sophon changelog.

8. Contact Us

If you have questions about this Privacy Policy, please contact us at privacy@buildersoft.io.