Soroyi
/Privacy Policy
Psychological Safety & Data Minimization

Soroyi Privacy Policy

Last Updated: August 15, 2026 · Effective Immediately

Soroyi is built from the ground up on the principle of psychological safety. We believe people speak more freely and thoughtfully when they have complete control over how their voice, questions, and identity are shared. This policy explains what information we collect, how it is used, and how it is permanently deleted.

1Participant Privacy & Invisible Authentication

When participants join a Soroyi session through a link or room code:

  • No accounts or passwords: Participants are never asked to create an account, provide an email address, or link a social profile.
  • Anonymous identity: We generate an invisible, cryptographically random anonymous session token so that row-level database security can protect your contributions without tracking your personal identity.
  • Display names & pseudonyms: You provide only a display name or permitted pseudonym for each session.

2Contribution Options & Visibility Controls

Soroyi allows you to contribute via Voice Notes, Typed Text, or requests to Speak Live. For every contribution, you explicitly select one of three visibility levels:

🔒 Host Only

Only the host and co-moderators see your question and name in their private queue.

🎭 Shared Anonymously

The audience sees your question attributed to “Someone” without revealing your name.

🏷️ Shared with Name

Your question and chosen display name are visible to the host and fellow participants.


3Voice Recordings & AI Transcription

When you record a voice note in Soroyi:

  • Pre-submission review: We automatically transcribe your audio using OpenAI Whisper so you can review, edit, or re-record the text before deciding to join the queue.
  • Private storage: Audio recordings are stored in private cloud storage buckets protected by Row-Level Security (RLS) policies. They are accessible exclusively via short-lived, encrypted signed URLs.
  • No model training: Your voice recordings and transcripts are not used to train public AI models.

4Data Retention & Permanent Deletion

Soroyi implements strict automated retention windows configured by the host upon session creation:

24 HoursStrict Privacy: Recordings and queue data are automatically and permanently purged 24 hours after the session concludes.
7 DaysStandard Follow-up: Data is retained for 7 days to allow hosts to complete follow-ups before automatic deletion.
30 DaysExtended Window: Data is retained for up to 30 days.

Immediate manual purge: Hosts can permanently delete all audio recordings immediately after a session from the session summary report, or delete the entire session and all contributions at any time.


5Moderator & Host Accounts

For session organizers (hosts and invited co-moderators):

  • We collect your email address, name, and authentication credentials (via secure Supabase Auth or Google OAuth) to manage session ownership and access controls.
  • We never sell, rent, or monetize your contact information or session data.

6Your Rights (GDPR / CCPA) & Contact

You have the right to request access to, correction of, or permanent erasure of any personal data stored by Soroyi. If you have questions regarding this Privacy Policy or wish to exercise your data rights, please contact our team at privacy@soroyi.com.