sozy LLC (“sozy,” “we,” or “us”) builds tools that help real estate professionals turn listings into editorial social-media content. This policy explains what we collect, how we use it, and the rights you have over your data. Plain English; no dark patterns.
1. What we collect
Account information
- Your email address and (optionally) your name, used to sign you in and contact you about your account.
- Authentication state managed by Supabase. We never see or store passwords directly.
Content you create
- Listing URLs you paste (e.g., Zillow, MLS) and the public listing data we fetch from them.
- Photos you upload and the carousels, captions, and hashtags sozy generates from them.
- Brand-profile information you enter (e.g., name, location, voice).
Connected social accounts
- When you authorize sozy to publish to Instagram, TikTok, or LinkedIn, we receive the minimum information required to post on your behalf: your account ID, username or display name, and an OAuth access token (and refresh token where applicable). We request only the publishing scopes; we do not request access to your DMs, follower lists, or any private data we don't need.
Payment information
- Subscriptions are processed by Stripe. Stripe receives and stores your payment-card details directly. sozy only receives a customer reference, subscription status, and the last four digits of your card for receipts.
Usage data
- Standard server logs (IP address, user agent, page accessed, timestamp) for security and operations. Aggregated, anonymized usage metrics for product improvement.
2. How we use your information
- To provide sozy: generate content from your listings, store your renders in your library, and publish to your connected social accounts when you tell us to.
- To bill you for your subscription and send transactional emails (receipts, account notices).
- To detect abuse, debug issues, and keep the service running.
- To send occasional product updates. You can unsubscribe at any time; transactional account emails are not optional while you have an active subscription.
3. Third-party services we use
sozy depends on a small set of third-party providers. Each one only receives the information needed to do its job:
- Supabase — authentication, database, file storage.
- OpenAI — generates captions, hashtags, and creative copy from your listing data and brand profile. OpenAI does not train on API content per its API policy.
- Firecrawl — fetches public listing data from URLs you paste.
- Stripe — processes subscription payments.
- Upload-Post — used during early access to publish to social platforms; will be retired once sozy's direct integrations are approved.
- Vercel — hosting and content delivery.
- Meta (Instagram), TikTok, LinkedIn — receive your post content and access tokens at the moment you authorize publishing.
4. Social platform tokens
When you connect Instagram, TikTok, or LinkedIn, sozy stores the access token issued by that platform so we can publish on your behalf when you tap “post.” We use these tokens only to publish content you have created in sozy. We do not read messages, scrape followers, post anything you have not authorized, or share tokens with third parties. You can revoke access at any time from your account settings or directly from the platform.
5. How we store and protect your data
- Data is encrypted in transit (HTTPS) and at rest by our hosting providers.
- Access tokens are stored in our database with row-level security so only your account can read them.
- Database backups are retained by Supabase for operational continuity.
6. How long we keep it
- Account, listings, and renders are kept while your account is active and deleted within 30 days of account closure or deletion request.
- Social access tokens are deleted immediately when you disconnect a platform.
- Billing records are retained for up to 7 years to comply with tax and accounting law.
7. Your rights
You have the right to:
- Access the data we hold about you.
- Correct information that is wrong or incomplete.
- Delete your account and associated data.
- Export your generated content.
- Withdraw consent and disconnect social platforms.
To exercise any of these, see our data deletion page or email hello@sozy.app. We respond within 30 days.
8. Cookies and local storage
sozy uses cookies and browser storage strictly for session management (keeping you signed in) and a temporary anonymous identifier so you can preview a render before creating an account. We do not use third-party advertising or tracking cookies.
9. Children
sozy is not directed at children under 13. We do not knowingly collect data from anyone under 13. If you believe we have, contact us and we will delete it.
10. International transfers
Our providers process data in the United States. By using sozy, you consent to your information being transferred to and processed in the U.S.
11. Changes to this policy
We may update this policy as the product evolves. Material changes will be announced by email and reflected in the effective date at the top of this page. Continued use after a change means you accept the updated policy.
12. Contact
Questions, requests, or concerns? hello@sozy.app.