Privacy Policy
1. Introduction
Sophon Consulting ("SOPHON," "we," "us," or "our") respects your privacy and is committed to protecting your personal data. This page explains how we handle information when you visit sophon.consulting, what rights you may have, and how to contact us.
2. Data We Collect
We may collect Identity Data, Contact Data, Technical Data, and Usage Data.
- Identity Data: first name, last name, username, or a similar identifier.
- Contact Data: email address and telephone number.
- Technical Data: IP address, browser, operating system, platform, and device details.
- Usage Data: information about how you use our website and services.
3. How We Use Your Data
We use personal data only when the law allows us to, including to perform contracts, pursue legitimate interests, and comply with legal obligations.
4. Cookies and Analytics
We use cookies, local storage, and similar client-side technologies only when they are necessary for the website to function or when you explicitly allow analytics. Browser analytics are off by default and only turn on after you click Accept analytics.
Vercel Web Analytics measures aggregate page traffic outside the consent boundary. It is cookie-free and does not use browser local storage to identify you. We use its anonymous, aggregate reporting to understand broad site traffic.
If you accept analytics, we also use PostHog for deliberately bounded page and funnel events, session replay, and JavaScript error capture. PostHog uses anonymous local-storage persistence on this domain only; we do not enable cross-domain identity. We retain PostHog data for 12 months.
For recognized AI-agent and command-line-tool requests to our machine-facing Agent Skills endpoints, we record aggregate operational events containing only the endpoint path, HTTP method, and a coarse client classification. We do not send cookies, raw user-agent strings, requester IP addresses, or entered content with these events; we disable person profiles and location enrichment. This limited telemetry helps us assess whether published discovery resources are being used.
The AI Opportunity Triage interface and our WebMCP tools (opportunity triage and readiness assessment) calculate locally in your browser. We do not receive the text you enter — workflow or organization details, evidence, use cases, or generated artifacts — through WebMCP tools, and WebMCP invocations do not send analytics. If you accept browser analytics and use the visible triage interface, we record only the result band, recommendation, total score, and export format where applicable — not the text you enter or the generated artifact.
The complete visible AI Opportunity Triage surface is excluded from session replay. Inputs, evidence, follow-up questions, rendered results, and generated artifacts are replaced with a redacted block before replay data leaves your browser.
Our hosted MCP server at /api/mcp works differently from the in-browser tools: tool inputs are sent to our server, where they are processed transiently to compute the deterministic response. We do not store them, use them for training, or share them, and server-side telemetry for MCP requests records metadata only — the tool name, the resulting verdict or band, numeric scores, and a coarse user-agent class — never the text you submit or the generated artifact.
You can withdraw consent at any time by opening Privacy Settings in the footer. When you decline analytics, we stop analytics capture for future activity and clear the analytics persistence we control in your browser.
We deliberately disable PostHog autocapture, page-leave events, surveys, feature flags, heatmaps, dead-click and rage-click detection, product experiments, and web-vitals or network-performance capture. Session replay and JavaScript error capture remain inside the explicit-consent boundary.
5. Data Security
We use reasonable security measures to help prevent personal data from being lost, misused, accessed without authorization, altered, or disclosed.
6. Data Retention
We retain personal data only for as long as reasonably necessary for the purposes for which it was collected, including legal, regulatory, tax, accounting, and reporting requirements.
7. Your Legal Rights
Depending on applicable law, you may have rights to access, correct, erase, object to processing, restrict processing, or request transfer of your personal data. Contact us if you want to exercise those rights.
8. Contact Us
If you have any questions about this privacy policy or our privacy practices, contact us at hello@sophon.consulting.
