Sayo Privacy Policy
This Policy describes how Sayo handles personal information across released features. A feature remains unavailable unless its required data flow, contract, retention, and security facts are verified.
1. Scope
This Privacy Policy explains how [UNRESOLVED:operator.legal_name] handles personal information through Sayo websites, accounts, AI-assisted research features, support, and paid services. It applies only to processing for which the operator acts as controller or business; a linked third party's separate policy governs its independent processing.
2. Categories and storage
The release must replace every unresolved entry below with a reviewed public fact.
| Processing area | Data categories and required/optional status | Collection source | Data subjects | Storage location |
|---|---|---|---|---|
| account | [UNRESOLVED:data.account.categories] | [UNRESOLVED:data.account.sources] | [UNRESOLVED:data.account.subjects] | [UNRESOLVED:data.account.storage_locations] |
| authentication | [UNRESOLVED:data.authentication.categories] | [UNRESOLVED:data.authentication.sources] | [UNRESOLVED:data.authentication.subjects] | [UNRESOLVED:data.authentication.storage_locations] |
| conversation | [UNRESOLVED:data.conversation.categories] | [UNRESOLVED:data.conversation.sources] | [UNRESOLVED:data.conversation.subjects] | [UNRESOLVED:data.conversation.storage_locations] |
| billing | [UNRESOLVED:data.billing.categories] | [UNRESOLVED:data.billing.sources] | [UNRESOLVED:data.billing.subjects] | [UNRESOLVED:data.billing.storage_locations] |
| security | [UNRESOLVED:data.security.categories] | [UNRESOLVED:data.security.sources] | [UNRESOLVED:data.security.subjects] | [UNRESOLVED:data.security.storage_locations] |
| analytics | [UNRESOLVED:data.analytics.categories] | [UNRESOLVED:data.analytics.sources] | [UNRESOLVED:data.analytics.subjects] | [UNRESOLVED:data.analytics.storage_locations] |
Conversation content includes chats, prompts, responses, notes, attachments, tool inputs and outputs, cited extracts, and derived content only when the relevant feature actually processes them. The reviewed account and security inventories must also identify signup intents, consent records, support and privacy-rights requests, feedback submitted through a separately labeled channel, and associated audit records rather than hiding them under a generic label.
3. Purposes and legal bases
We limit each processing activity to its disclosed purpose and applicable legal basis.
| Processing area | Purposes | Legal bases |
|---|---|---|
| account | [UNRESOLVED:data.account.purposes] | [UNRESOLVED:data.account.legal_bases] |
| authentication | [UNRESOLVED:data.authentication.purposes] | [UNRESOLVED:data.authentication.legal_bases] |
| conversation | [UNRESOLVED:data.conversation.purposes] | [UNRESOLVED:data.conversation.legal_bases] |
| billing | [UNRESOLVED:data.billing.purposes] | [UNRESOLVED:data.billing.legal_bases] |
| security | [UNRESOLVED:data.security.purposes] | [UNRESOLVED:data.security.legal_bases] |
| analytics | [UNRESOLVED:data.analytics.purposes] | [UNRESOLVED:data.analytics.legal_bases] |
We do not repurpose user content for model training, general product improvement, advertising, or unrelated evaluation. Provider no-training evidence is [UNRESOLVED:ai.provider.no_training_evidence].
4. Required and optional information
The category table identifies required and optional elements for each processing area. The signup or transaction screen repeats what is required to create an account, secure access, answer a request, or complete a purchase. Optional information is labeled separately, and refusing optional information does not block unrelated core functions. Optional analytics requires a separate opt-in.
5. Processors and subprocessors
No processor is activated until its contracting entity, location, role, data, retention, subprocessors, security and deletion support, and agreement are verified.
| Function | Contracting entity | Country | Purpose | Data | Retention | Subprocessors | Transfer timing | Transfer method | Contract status |
|---|---|---|---|---|---|---|---|---|---|
| ai | [UNRESOLVED:processors.ai.contract_legal_name] | [UNRESOLVED:processors.ai.country] | [UNRESOLVED:processors.ai.purpose] | [UNRESOLVED:processors.ai.data_categories] | [UNRESOLVED:processors.ai.retention] | [UNRESOLVED:processors.ai.subprocessors] | [UNRESOLVED:processors.ai.transfer_timing] | [UNRESOLVED:processors.ai.transfer_method] | [UNRESOLVED:processors.ai.contract_status] |
| authentication | [UNRESOLVED:processors.authentication.contract_legal_name] | [UNRESOLVED:processors.authentication.country] | [UNRESOLVED:processors.authentication.purpose] | [UNRESOLVED:processors.authentication.data_categories] | [UNRESOLVED:processors.authentication.retention] | [UNRESOLVED:processors.authentication.subprocessors] | [UNRESOLVED:processors.authentication.transfer_timing] | [UNRESOLVED:processors.authentication.transfer_method] | [UNRESOLVED:processors.authentication.contract_status] |
| hosting | [UNRESOLVED:processors.hosting.contract_legal_name] | [UNRESOLVED:processors.hosting.country] | [UNRESOLVED:processors.hosting.purpose] | [UNRESOLVED:processors.hosting.data_categories] | [UNRESOLVED:processors.hosting.retention] | [UNRESOLVED:processors.hosting.subprocessors] | [UNRESOLVED:processors.hosting.transfer_timing] | [UNRESOLVED:processors.hosting.transfer_method] | [UNRESOLVED:processors.hosting.contract_status] |
| payments | [UNRESOLVED:processors.payments.contract_legal_name] | [UNRESOLVED:processors.payments.country] | [UNRESOLVED:processors.payments.purpose] | [UNRESOLVED:processors.payments.data_categories] | [UNRESOLVED:processors.payments.retention] | [UNRESOLVED:processors.payments.subprocessors] | [UNRESOLVED:processors.payments.transfer_timing] | [UNRESOLVED:processors.payments.transfer_method] | [UNRESOLVED:processors.payments.contract_status] |
| [UNRESOLVED:processors.email.contract_legal_name] | [UNRESOLVED:processors.email.country] | [UNRESOLVED:processors.email.purpose] | [UNRESOLVED:processors.email.data_categories] | [UNRESOLVED:processors.email.retention] | [UNRESOLVED:processors.email.subprocessors] | [UNRESOLVED:processors.email.transfer_timing] | [UNRESOLVED:processors.email.transfer_method] | [UNRESOLVED:processors.email.contract_status] | |
| analytics | [UNRESOLVED:processors.analytics.contract_legal_name] | [UNRESOLVED:processors.analytics.country] | [UNRESOLVED:processors.analytics.purpose] | [UNRESOLVED:processors.analytics.data_categories] | [UNRESOLVED:processors.analytics.retention] | [UNRESOLVED:processors.analytics.subprocessors] | [UNRESOLVED:processors.analytics.transfer_timing] | [UNRESOLVED:processors.analytics.transfer_method] | [UNRESOLVED:processors.analytics.contract_status] |
A brand name alone is not a verified processor identity.
6. International transfers
Where personal information crosses borders, the verified legal or consent basis is [UNRESOLVED:transfers.cross_border.legal_basis], the user rights method is [UNRESOLVED:transfers.cross_border.rights_method], and the contract verification record is [UNRESOLVED:transfers.cross_border.contract_verified_at]. The processor table must also disclose the destination, timing, method, categories, and retention before the transfer-dependent feature opens.
7. Retention
We use category-specific periods with a number, unit, start event, and explicit exceptions.
| Processing area | Verified retention schedule |
|---|---|
| account | [UNRESOLVED:data.account.retention] |
| authentication | [UNRESOLVED:data.authentication.retention] |
| conversation | [UNRESOLVED:data.conversation.retention] |
| billing | [UNRESOLVED:data.billing.retention] |
| security | [UNRESOLVED:data.security.retention] |
| analytics | [UNRESOLVED:data.analytics.retention] |
Qualitative phrases such as “as long as needed” do not replace these values. A legal hold or statutory record rule is separated from ordinary service data and access is restricted.
8. Deletion
You may delete an individual chat; it is removed from active use under the verified conversation schedule [UNRESOLVED:data.conversation.retention]. An account-deletion request immediately blocks new login, AI processing, analytics, and checkout, then starts cancellation, refund, processor-deletion, and erasure steps under [UNRESOLVED:data.account.retention]. We erase account-deletion data as soon as practicable, no later than 30 days from the request in active application databases and no later than 60 days from the request including backup expiration. These are outer technical limits, not routine waiting periods; a shorter verified schedule or legal requirement controls. Required legal records are isolated and used only for the retention exception, and a restored backup is reconciled against the deletion list before ordinary processing resumes.
9. Security
We use risk-appropriate administrative, technical, and organizational measures, including access control, encryption in transit and where appropriate at rest, credential separation, logging, change review, vulnerability response, and processor oversight. No system is perfectly secure; please report suspected compromise promptly and do not send secrets through support.
10. Age limits
Sayo is not directed to children. The minimum age is 18 in the United States and 19 in Korea. We do not knowingly open accounts below the applicable age; if we learn that an ineligible account was created, we block it and review deletion and required notices.
11. Privacy rights and requests
Depending on location and law, you may request access, a copy, correction, deletion, restriction or suspension, portability or transmission, withdrawal of consent, and information about processing. Submit a request to [UNRESOLVED:contacts.privacy.email]. We verify identity proportionately, support authorized agents where required, explain a denial, and do not discriminate for exercising a right.
12. U.S. state privacy rights
Where a U.S. state privacy law applies, residents may have rights to know or access, delete, correct, obtain portable data, opt out of covered sale, sharing, targeted advertising, or profiling, limit certain sensitive-data uses, and appeal a denial. Under the applicable statutory definitions, we do not sell or share personal information and do not use it for targeted or cross-context behavioral advertising. This promise must be checked against every contract, SDK request, and disclosure category before release; if the practice changes, we will add legally required notices and controls before the change.
13. Korean rights and relief
Korean users may exercise rights provided by the Personal Information Protection Act through the contact above and may seek advice or dispute resolution from the competent Korean privacy authorities and relief bodies. The privacy-officer role is [UNRESOLVED:privacy_officer.role] and contact is [UNRESOLVED:privacy_officer.contact]. Domestic-agent applicability is [UNRESOLVED:domestic_agent.applicability]; if required, the verified agent details are [UNRESOLVED:domestic_agent.name], [UNRESOLVED:domestic_agent.address], [UNRESOLVED:domestic_agent.phone], and [UNRESOLVED:domestic_agent.email].
14. AI and automated tools
Sayo uses automated tools to organize information and generate research assistance. Outputs may be wrong and do not by themselves make a legally or similarly significant decision about a user. If a future tool makes or materially supports such a decision, we will assess applicable notice, explanation, opt-out, objection, and human-review rights before release.
15. Security incidents
We investigate suspected incidents, contain affected systems, preserve restricted evidence, determine affected information and jurisdictions, coordinate with processors, and notify users or authorities when and within the time required by law. We do not delay a legally required notice to wait for perfect information.
16. Changes
Every change creates a new immutable policy version and history entry. We give advance notice of material changes and seek renewed consent where law or the changed purpose requires it. A new processor, destination, purpose, category, or longer retention receives review before activation.
17. Contact
Privacy contact: [UNRESOLVED:contacts.privacy.email]. Published response target: [UNRESOLVED:contacts.privacy.response_time]. Operator: [UNRESOLVED:operator.legal_name]. Questions, complaints, and rights requests use the same verified contact shown in the product.