sokkosai
We host it Your agent on our server — live in minutes Install package We install on a device or VPS you provide Dedicated hosting Managed single-tenant hosting — by quote Custom project Anything irregular — brief me, quote in 24h Care & maintenance We watch it, fix it, add skills on request For business Larger and B2B engagements
More from SoKKoS
Plotmosa ↗ Sketch → render for landscapers
How it works Examples Pricing FAQ
English EN Nederlands NL Polski PL Français FR Deutsch DE Español ES Italiano IT Русский RU Українська UK
Sign in Start free Open your agent →
Open your agent Overview Billing Settings Change password ⚙ Admin
Solutions
We host itInstall packageDedicated hostingCustom projectCare & maintenanceFor business
How it works Examples Pricing FAQ Sign in Start free
More from SoKKoS
Plotmosa ↗
Legal · GDPR · last updated 2026-07-19

Privacy Policy

What we collect, what we never collect, and who else touches your data. We deliberately keep the surface small — phone numbers and analytics aren't on this list because we don't collect them, and passwords are only ever stored as a one-way hash.

On this page
1. Who we are2. What we collect2a. Privacy-first measurement3. What we never collect4. Sub-processors5. Cookies6. Your rights (GDPR)7. Retention periods8. International transfers9. Security10. Children11. Contact

1. Who we are

SoKKoS AI — eenmanszaak (sole proprietorship in the Netherlands), KvK 42029374, BTW-id NL005441743B74, Beuningen, Gelderland, NL. Contact: [email protected]. We're the data controller for everything described below.

2. What we collect

The smallest amount that lets us run an agent for you and send you a receipt.

  • Email address — required for authentication (magic-link, email + password, or Google OAuth) and billing notifications. Stored in Azure Table Storage (West Europe).
  • Password — only if you set one. If you choose email + password sign-in, we store your password solely as a salted bcrypt one-way hash (cost factor 12). Your plaintext password travels over TLS each time you set, change, reset or sign in with it, is processed in memory only to hash or verify, and is never stored or logged; we can't recover it — a reset issues a new single-use link. Magic-link and Google sign-in remain available if you prefer no password at all.
  • Telegram chat / user ID and bot token — only if you link Telegram (e.g. to reach support via @sokkosai_bot or to run your agent's own Telegram bot). If you connect your own bot, its bot token is stored encrypted at rest (shown to you only as “set”, never displayed again) so your agent can send on your behalf. Used to route messages. Clearing the token removes it from storage; a running agent may keep using its current token until its next restart, when the disconnect takes effect.
  • Google profile basics (name, picture) — only if you choose “Sign in with Google”. Used to greet you in the dashboard. Disconnect any time and we delete the cached copy.
  • LinkedIn publisher data — operator account only. Our internal admin publisher stores the LinkedIn member/Page identifier, granted scopes, token expiry and OAuth access/refresh tokens needed to publish SoKKoS posts. Tokens are encrypted before storage and never shown in the browser or logs. This integration is not offered to customer accounts; disconnecting it deletes the stored authorization.
  • IP address — logged for rate-limiting and fraud prevention. Rate-limit counters are keyed to short time windows and are not used once their window passes; the IP recorded at signup stays with your account record and is deleted with your account.
  • Payment metadata — transaction IDs, amount, currency, method (SEPA / iDEAL / card / PayPal). Processed by Mollie B.V. in Amsterdam. We never see your card number or bank credentials — only the receipt.
  • Server logs — request paths, response codes, timing. No request bodies. Retained 30 days for debugging, then rotated.
  • “Report a problem” submissions — only if you use the bug-report button: your description, the page URL, and the most recent browser console logs (with API keys and tokens automatically masked) so we can debug the issue.
  • Chat messages that show contact intent — the site assistant does not store your conversation, but if a message shows you want a human to follow up (you include an email or phone number, or ask about pricing / setup) we forward that message to our operator over Telegram so we can reply. Nothing is sent for ordinary questions.

2a. Privacy-first measurement

We measure how the site is doing — which pages people open, when a buy button is clicked — with a small, first-party setup that stays entirely on our own infrastructure: no Google Analytics, no Hotjar, no third-party tracking script running by default (see §3 and §5). The one exception is the Meta Pixel, which loads only after you explicitly opt in via the cookie banner — see the third item below.

  • Anonymous funnel events. When you open the “payment opening soon” popup or click a buy / register button, your browser sends us a tiny event — the event name, the package it referred to, and the page path. We store these in our own Azure database. No IP address, no email, no name, no cookie, and no raw browser fingerprint are attached — we keep only a coarse, one-way hash of the browser type so we can tell humans from bots in aggregate.
  • Advertising click-ids. If you reach us from an online ad, the link may carry a Google click identifier (gclid) or a Meta click identifier (fbclid) and campaign tags (utm_*). We keep these in your browser's local storage (first-party, up to 90 days) so that, if you later sign up or send a brief, we can tell which ad worked. We do not share this data with third parties for their own purposes; we only use it ourselves, and — if you convert — may upload the click-id back to the ad platform it came from (Google Ads or Meta) to mark that one conversion (“offline / enhanced conversions”). You can clear it any time by clearing site data in your browser.
  • Meta Pixel — opt-in only. To measure how well our ads on Meta platforms (Facebook / Instagram) perform and to build ad audiences, the site may load the Meta Pixel, a measurement script from Meta Platforms Ireland Ltd. It loads strictly after you click “Accept” in the cookie banner. If you decline — or simply ignore the banner — no pixel code runs and no request to Meta is made. You can withdraw consent at any time via the “Cookie preferences” link in the footer; the pixel then stops loading from your next page view. How Meta handles this data: facebook.com/privacy/policy.

The first-party measurement needs no cookie banner: the funnel events are anonymous and the click-id is stored only when you arrived from an ad you already clicked. The Meta Pixel is exactly why the banner exists — it never runs unless you've agreed. If you prefer not to be measured at all, decline the banner and browse with local storage disabled — the site works exactly the same.

3. What we never collect

  • Plaintext passwords. If you set a password we keep only a salted bcrypt hash (see §2); the plaintext is never stored, logged or recoverable. You can also sign in with a magic link or Google and set no password at all.
  • Your AI API keys in plaintext. Your model-provider keys (Google Gemini, OpenAI, Anthropic, OpenRouter, Groq and others) are encrypted before they are stored (EU Azure storage) and decrypted server-side only to inject into your container's environment (at launch, and when you apply or rotate keys). They are never logged, never shared with third parties, and deleted with your account.
  • Voice recordings beyond live processing. If you use the voice agent, audio is streamed to the model provider in real time and discarded immediately after the response. We do not persist recordings.
  • Tracking / analytics cookies — none without consent. No Google Analytics, no Hotjar, no analytics cookie of our own. The only third-party measurement script we use at all is the Meta Pixel, and it loads strictly after you opt in via the cookie banner (§2a) — decline or ignore the banner and nothing fires. Our baseline measurement is the first-party, cookieless setup described in §2a. See §5.
  • Phone numbers. Support is asynchronous; we have no phone field.

4. Sub-processors

To run the service we rely on a small set of named processors. Each has its own privacy policy you can read.

  • Google LLC — Sign in with Google (OAuth) & Gemini API. policies.google.com/privacy
  • LinkedIn Corporation — operator-only OAuth and publication of SoKKoS posts to our personal profile and company Page. LinkedIn receives only the post and destination chosen by the operator. linkedin.com/legal/privacy-policy
  • Your chosen model provider(s) — when you connect a BYO API key (e.g. OpenAI, Anthropic, OpenRouter, Groq, NVIDIA, DeepSeek, or a custom OpenAI-compatible endpoint), your agent sends prompts directly to that provider under your own account and the provider's terms. You choose this processor; disconnect its key to stop the flow.
  • Mollie B.V. (Amsterdam, NL) — payment processing. mollie.com/privacy
  • Resend — transactional email (magic-link, billing receipts). resend.com/legal/privacy-policy
  • Microsoft Azure — hosting for the public site and customer database (region: West Europe / Sweden Central).
  • Cloudflare, Inc. — DNS, edge proxy, DDoS mitigation.
  • Hetzner Online GmbH — per-customer VPS hosting (region: Germany or Finland, your choice or auto-selected by proximity).
  • Telegram FZ-LLC — only if you link Telegram: support chat via @sokkosai_bot and/or your agent's own Telegram bot. telegram.org/privacy

If we add or change a sub-processor that materially affects what data is processed, we'll update this page and notify active customers by email at least 30 days before the change takes effect (see Terms §10).

5. Cookies

Consent-free, we set two first-party cookies — both functional (Art. 5(3) ePrivacy exemption: strictly necessary, or explicitly requested by you):

  • sokkosai_session (HttpOnly, Secure, SameSite=None, Domain=.sokkosai.com so it works across our subdomains) — keeps you signed in. Lifetime: 90 days, sliding window.
  • lang — remembers the site language you pick in the language switcher. Lifetime: 1 year.

With your consent only: if you click “Accept” in the cookie banner, the Meta Pixel (§2a) may set its own cookies (such as _fbp) for ad measurement. If you decline or ignore the banner, no Meta cookie is ever set. You can withdraw consent at any time via the “Cookie preferences” link in the footer.

No analytics cookies of our own. No advertising cookies without opt-in. The first-party ad click-id from §2a lives in your browser's local storage, not a cookie. The cookie banner exists for exactly one thing — the opt-in Meta Pixel; everything else on this site works without it.

6. Your rights (GDPR Articles 15–22)

If you're in the EU/EEA, you have the right to:

  • Access — ask what data we hold about you.
  • Rectify — correct anything that's wrong.
  • Erase (“right to be forgotten”) — delete your account and associated data.
  • Restrict — pause processing while a question is unresolved.
  • Port — receive a machine-readable copy of your data.
  • Object — object to processing based on legitimate interest.

Most of these are self-service in your dashboard. For anything that isn't, email [email protected] and we'll respond within 30 days. See the GDPR rights page for the exact request format and how each right maps to a self-service action.

7. Retention periods

  • Account record — until you delete your account.
  • Session cookie — 90 days, sliding (resets on each visit).
  • Magic-link & password-reset tokens — single-use, and rejected once used or after 15 minutes.
  • LinkedIn OAuth tokens — until the operator disconnects or replaces the authorization. Expired tokens remain encrypted only so the console can report connection status and cannot be used without reauthorization; publisher drafts and delivery receipts remain in the internal queue until administratively removed.
  • Payment records — 7 years (mandatory under Dutch tax law, Art. 52 AWR).
  • Server logs — 30 days raw, then aggregated.
  • IP addresses — the signup IP is kept with the account record and deleted with the account; rate-limit counters only serve their short time window.
  • Anonymous funnel events & ad click-ids (§2a) — up to 12 months, then deleted or aggregated. The click-id (gclid / fbclid) in your browser's local storage expires after 90 days.
  • Cookie-consent choice (§5) — kept in your browser's local storage until you change it via “Cookie preferences” or clear site data.
  • VPS container after cancellation — 14 days grace, then destroyed (see Terms §7).

8. International transfers

Your SoKKoS-hosted data — your agent's environment, config, logs, integrations and key management — stays inside the EU/EEA: Azure (West Europe / Sweden Central), Hetzner (Germany / Finland), Mollie (Amsterdam). The AI model you connect is your own choice and is covered separately below.

Some processors may transfer data outside the EU under Standard Contractual Clauses (SCCs) approved by the European Commission, or their own published safeguards:

  • Google (OAuth login + the Gemini API you choose to use) — the prompts and context needed to generate a response are processed by Google under its terms; some processing may occur in the US.
  • LinkedIn (operator-only publishing) — OAuth identifiers and the posts we deliberately publish are processed on LinkedIn's global infrastructure and may be transferred outside the EU under LinkedIn's published safeguards.
  • Cloudflare — edge proxy with global PoPs; traffic may transit US infrastructure even though your origin is in the EU.
  • Telegram (only if you link it) — the messages, chat/user IDs and bot API calls you route through Telegram are processed on its global infrastructure and may leave the EU under its own terms. Don't link Telegram if you need to keep this flow inside the EU.

These processors publish their cross-border safeguards. You can opt out of Google by using magic-link sign-in and bringing an EU-region API key from another provider.

9. Security

  • TLS 1.3 for everything in transit (Cloudflare-terminated, modern cipher suites).
  • HttpOnly + Secure + SameSite=None cookies; not readable by JavaScript.
  • Encryption at rest on Azure Storage (AES-256) and on Hetzner volumes (LUKS).
  • No plaintext passwords stored anywhere — when you set a password we keep only a salted bcrypt hash (cost 12).
  • Secrets in a KV store, not in code repositories.
  • Least-privilege access — a single admin account; destructive admin actions require an explicit type-to-confirm step. Hardware-key step-up (WebAuthn) for admin is on the roadmap.

If you find a security issue, please email [email protected] with “security” in the subject. We acknowledge within 48h.

10. Children

The service is not directed at people under 16. We don't knowingly collect data from minors. If you believe a minor has signed up, email us and we'll delete the account.

11. Contact & complaints

Data-protection questions — [email protected]. We respond within 30 days.

You can also lodge a complaint with the Dutch supervisory authority: Autoriteit Persoonsgegevens.

SoKKoS AI
KvK 42029374 · BTW NL005441743B74
Beuningen, Gelderland, NL
Last updated 2026-07-19

↑ Back to top

sokkosai
No run limits. Bring your own keys. Export anytime. Hosted by me — or installed in your environment.
Product How it works Examples Pricing
Account Sign in Dashboard Billing Export your data Sign out
Legal Privacy Terms GDPR Cookie preferences
Contact [email protected] Telegram WhatsApp no calls — async only Enterprise work
More from SoKKoS Plotmosa ↗
© 2026 SoKKoS AI · Beuningen, NL · Imprint & legal

We use the Meta Pixel for ad measurement — only if you agree. Privacy policy

Report a problem