In short
We care about your privacy, so we have kept the scope of what we collect small enough to describe honestly. We collect personal data where you give us your consent, or where we need it to provide our services (the "Services") or to run and improve our website at sioma.ai, app.sioma.ai and any other site we operate (the "Website"). We do not sell your personal information. Nothing loads from an analytics or advertising vendor until you have said yes.
Sioma is not yet an incorporated company: it is operated by Sagi Gleizer as an individual trading as Sioma. In this policy "we", "our" and "us" mean that operator, who is the data controller for the information described below.
You are not legally required to give us any personal data, but without some of it we cannot give you an account, reply to you, or offer the full experience of the Services. Please take the time to read this policy so you understand what we hold. We will not use your personal data in any way that contradicts it.
Reach us about anything on this page at privacy@sioma.ai.
1. Data scope
How we collect information depends on why you came. Some technical data is generated by everyone who loads the Website; the rest you give us deliberately. Where information could identify a specific person, or is linked to data that could, we treat it as "Personal Data".
1.1 Everyone who visits
When you browse the Website or email us, we and our service providers (section 5) collect or generate technical data: your IP address, non-identifying details of your device, operating system, browser version, locale and language, the cookies stored on that device, and the pages, clicks and other interactions you make. Some of this arrives through cookies and similar technologies, which section 3 covers. We also record how you reached us — the campaign or link, and the page you landed on — so we know which of our marketing is worth continuing; that reaches no third party, and it is recorded whether or not you accepted analytics.
We do not use this data to learn your identity. We use it to understand how the Website and Services are actually used, to keep them secure, and to comply with the law.
1.2 When you ask for a demo or contact us
Our forms require an email address or a phone number, and record which form you used. Some also accept a name, a role, a subject and a short message. We use this to reply, to track the conversation, and we keep our own notes on it. We ask for a work email but accept any address.
1.3 When you register an account
An account needs an email address and either a password or a Google or Microsoft sign-in. Passwords are hashed; we never see them. We also store your name if you give one, and which workspace you belong to. Authentication runs on our own servers — no third-party identity provider holds your account. We send transactional email (verification, password resets, invitations) because the account does not work without it.
1.4 Data your organisation sends through Sioma
This policy covers visitors to our Website, people who ask us for a demo, and account holders. It does not cover the data a customer's own systems send through Sioma when their agents run: for that the customer is the controller, we act only on their instructions, and a separate agreement governs it.
Where you connect a third-party service to Sioma, you are also bound by that service's own terms and privacy notice — please read them first. We never receive or store your passwords for those services, and the same is true of Google and Microsoft sign-in.
2. Data uses
We use your Personal Data as necessary to perform the Services; to comply with applicable law; and on the basis of our legitimate interests in maintaining and improving the Services, understanding how they are used, supporting our users, and protecting and securing them, ourselves and the Services. Where we rely on consent — analytics and advertising measurement — nothing runs until you accept, and you may withdraw at any time.
We use pseudonymised Personal Data:
- to facilitate, operate and provide the Services and the Website;
- to give our users support, assistance and technical help; and
- to develop, customise and improve the Services and your experience of them.
We use Personal Data:
- to contact you with service-related messages, such as verification, invitations, or notice of maintenance (see section 6);
- to contact you with promotional messages, where you have not opted out (see section 6);
- to support and enhance our security, including preventing and mitigating fraud, error, and illegal or prohibited activity — we use your IP address to rate-limit and block abuse, and record it against API-key events so an account owner can audit their own keys;
- to create aggregated statistics and anonymised or pseudonymised data, which is no longer personal and which we may use freely; and
- to comply with applicable laws and regulations.
3. Cookies, tracking and other uses
The Website and some of our service providers use cookies, anonymous identifiers and similar technologies to provide and improve the Services, personalise your experience, and measure how our activities perform.
Until you consent we set no analytics or advertising cookie, and the site works fully without them. Our cookie policy lists every cookie and browser storage key we set, what each does, and who sets it. You can change or withdraw your choice at any time from the cookie settings, or block cookies in your browser — nothing breaks, though you will need to sign in again.
4. Storage and retention
Our service providers process your information in the United States, so using Sioma from elsewhere means your information is transferred outside your own country. Where the law requires a safeguard we rely on the European Commission's Standard Contractual Clauses; analytics and advertising transfers also rest on your consent. Privacy law varies between jurisdictions, and we have taken reasonable steps to ensure our service providers treat your Personal Data securely and lawfully in line with common industry practice, whatever the lesser requirements of their own jurisdiction might allow.
We retain your Personal Data for as long as you keep an active account with us, in order to maintain our relationship and provide the Services — in other words, for as long as you remain our user and have not told us otherwise. We also retain Personal Data for legal and accounting purposes, and to have evidence of our relationship should any legal issue arise after you stop using the Services. Where records exist so that you can audit your own history — security and API-key events — we keep them for the life of the account for that reason.
Please note that except where applicable law requires it, we are not obliged to retain your data for any particular period, and are free to securely delete it for any reason and at any time, with or without notice to you. To ask about retention or deletion, write to privacy@sioma.ai.
5. Data sharing
We may share your data, including Personal Data, with certain third parties — but only as set out here. We do not sell your personal information for money.
Service providers. We engage a small number of companies to perform services complementary to our own. Each sees only what it needs for its purpose, and each is named below with a link to its own privacy policy:
| Provider | What for | Where |
|---|---|---|
| Amazon Web Services | Hosting for the product, accounts, and demo requests | United States |
| Vercel | Hosting for this website | United States |
| Resend | Sending account and transactional email | United States |
| Google Sign-In | Only if you choose to sign in with Google | United States |
| Microsoft Sign-In | Only if you choose to sign in with Microsoft | United States |
| PostHog | Product analytics, with your consent | United States |
| Google Analytics | Website analytics, with your consent | United States |
| Google Ads | Measuring which ads bring people here, with your consent | United States |
| Reddit Ads | Measuring which ads bring people here, with your consent | United States |
Compliance with laws, legal orders and authorities. We may disclose Personal Data, or allow government and law-enforcement access to it, in response to a subpoena, warrant, court order or similar requirement, or in compliance with applicable law. We will tell you first unless we are prohibited from doing so, or unless we have a good-faith belief that disclosure is appropriate to investigate or prevent actual or suspected illegal activity, fraud or other wrongdoing.
Third-party integrations. The Services let you connect certain third-party services, in which case the terms and privacy notices of those services apply to what they hold.
Protecting rights and safety. We may share Personal Data where we believe in good faith that doing so will help protect the rights, property or personal safety of Sioma, our users or the public.
Change of control. If Sioma is ever incorporated or acquired, we will tell you before your information moves under a different policy.
For the avoidance of doubt, we may also share your Personal Data with your explicit approval, where we are legally obliged to, or once we have successfully rendered the data non-personal and anonymous. Non-personal data we may share or use at our discretion.
For California residents: we do not sell your personal information, and we do not share it for cross-context behavioural advertising. Ad personalisation is switched off for every visitor, whatever they answer on the banner, so the advertising cookies you can accept measure which ad brought you here and nothing further — none of them place you in an advertising audience. Because we do neither, there is nothing for a Global Privacy Control (GPC) signal to switch off: the outcome it asks for is already our default for everyone. The banner remains the control, and you can withdraw at any time.
6. Communications
Service communications. We may contact you with important information about the Services — for example verification and password emails, workspace invitations, or notice of changes and maintenance. You cannot opt out of these, because the account does not work without them.
Promotional communications. We may also tell you about new features, events, or anything else we think you will find valuable, through any contact means available to us. If you would rather not receive them, email us at privacy@sioma.ai at any time, or follow the unsubscribe instructions in any promotional message you receive. We will act on either.
7. Data security
To protect the Personal Data held by us and our service providers we use industry-standard physical, procedural and electronic measures. Traffic is encrypted in transit; passwords are hashed; API keys are shown once and then stored hashed. Please be aware that no security measure is absolute: we cannot and do not guarantee the protection of any Personal Data stored with us or with the third parties described in section 5. If a breach affects you, we will tell you.
8. Data subject rights
Wherever you live, you can ask us to see what we hold and get a copy, correct it, delete it (which may mean closing your account), take it elsewhere in a portable format, or object to how we use it and withdraw consent — withdrawal does not undo what came before it.
To exercise any of these rights under applicable law, such as the EU GDPR, write to privacy@sioma.ai. Please note that we may need further information or documents to authenticate your identity before we act, and that we will then retain that information for legal purposes, so we have proof of who made the request. We will respond within 30 days. We will not charge you or degrade the product because you exercised a right. In the EEA, UK or Switzerland you may also complain to your national data protection authority.
9. Children
The Services are built for businesses and are not designed to attract children under the age of 16. We do not knowingly or intentionally collect Personal Data from children and do not wish to. If we learn that a child is using the Website or the Services, we will block that use and make every effort to promptly delete any Personal Data we hold about them. If you believe we might hold such data, contact privacy@sioma.ai.
10. Additional notices
Updates and amendments. We may update and amend this policy from time to time by posting an amended version on the Website; the date at the top always reflects the current version, which takes effect on the date published. If a change materially affects how we use information we already hold about you, we will give advance notice through the Services or any communication means available to us rather than relying on you noticing. After that notice period, amendments are deemed accepted — except where a change requires your opt-in consent, which we will obtain first.
Questions, concerns or complaints. If you have any comment or question about this policy, or any concern about your privacy, write to privacy@sioma.ai. Anything else: hello@sioma.ai.