Privacy Policy
This Privacy Policy explains what Soga collects, why it is used, when it is shared, how long it is kept, and the choices and rights available to you when you use soga.gg and related Soga services.
Effective and last updated September 4, 2026
1. Scope and who is responsible
Soga (“Soga,” “we,” “us,” or “our”) operates the service and determines the purposes and means of processing described in this policy. This policy applies to Soga’s website, accounts, interactive stories, creator tools, generated media, and support communications. It does not govern a third party’s own website or independent processing.
Soga is the service operator and data controller for the processing described here. For privacy questions or requests, contact info@soga.gg.
2. Information you provide and account records
Account information: your email address and, if you use Google sign-in, your Google account identifier, verified-email status, display name, and profile photo. If profile features are enabled, we may also store the username and profile details you choose. Account records also include the member or admin access role assigned to the account, the most recently recorded successful sign-in time, and a two-letter signup-country code inferred from the network location of the account’s earliest recorded successful sign-in.
Story and creator content: story premises, titles, styles, cast selections, character names and descriptions, choices, custom actions, player names, story state, relationship state, progress, and settings. Creator draft contents are stored in your browser. For signed-in accounts, limited creation metadata—title, style, visibility, character count, and timestamps—is synchronized to Soga; premises, cast names and descriptions, draft images, and draft text are not included in that server index.
Images: an optional selfie or other adult reference image you choose to submit, plus scenes generated from it. The original selfie is normally kept in your browser and transmitted to the image-generation provider as an identity reference only when you request a scene containing your character. Soga stores generated scenes but does not ordinarily store your original selfie.
Communications: information you send when you request support, report content, exercise a right, or otherwise contact us. Soga does not currently offer paid plans and does not collect payment-card information.
3. Information collected automatically
Soga and its infrastructure receive technical data such as IP address, approximate country, request date and time, requested URL, browser and device information, referral information, error data, and security signals. Soga hashes an IP address to apply short-lived rate limits. For signed-in speculative story generation and story-image generation, the rate-limit hash also includes an internal account identifier so one household does not share the same generation allowance. The rate-limit record contains neither the raw IP address nor the raw account identifier and is kept for about one hour. Soga stores only the two-letter country code associated with initial account creation; existing account codes may be backfilled from the earliest successful sign-in event already held in PostHog. When a requested story reply fails after the available model attempts, Soga stores a short-lived operational incident linked to the internal account, story, and scene IDs, along with fixed failure categories, model-selection ID, attempt counts, HTTP status, and rounded duration. The incident never contains the prompt, custom action, transcript, generated prose, raw provider response, or image URL.
The app creates a random browser identifier to synchronize story progress and generated media. When you are signed in and a story save is written, Soga also associates that save with your verified account and stores the number of choices in its choice log so account activity can be summarized; anonymous and older unassigned saves remain browser-keyed and are not guessed onto an account. We also collect limited product events, such as page views, sign-in method, story starts, choice-selection metadata, coarse story-model selection IDs, stable story-info profile IDs and whether the layout is metered or contextual, coarse use of composer formatting tools, completion, creator use, visibility selection, whether an AI story response successfully included structured narrative formatting, whether the background story planner or image-prompt fallback was used, fixed response-contract and validation-mode labels, coarse custom-route confidence and whether a free-form message stayed in place or explicitly advanced the scene, the coarse generation path, number of model attempts and provider failures, streamed chunk count, and rounded provider, response-header, first-content, validation, and total timings, aggregate counts of the memory events, characters, and open plot threads supplied to story orchestration, aggregate preset-branch prefetch counts, outcomes, timings, and cache-use states, and aggregate counts and rounded time to first visible assistant text. We do not put story text, character names, info-panel contents, memory contents, plot-thread text, generation prompts, cache keys, or the text of a custom choice into analytics.
4. How we use information
We use information to authenticate you; send requested sign-in links; provide profiles; administer accounts and access; load and save progress; create stories, characters, and scenes; carry your choices into later scenes; speculatively prepare text for a small number of preset branches so the next scene can load faster; remember settings; provide support; and otherwise perform the features you request.
We also use information to secure Soga, rate-limit abusive traffic, diagnose failures, moderate content, enforce the Terms, protect users and rights, measure feature performance, develop and improve the service, comply with law, and establish or defend legal claims.
Soga uses AI to generate entertainment content and route story choices. It does not use automated processing to make decisions that produce legal or similarly significant effects about you.
5. Legal bases for processing
Where EEA, UK, or similar law requires a legal basis, we process account information, story state, prompts, and requested generations as necessary to provide the service and perform our agreement with you. We process security, fraud prevention, service analytics, troubleshooting, product improvement, and rights protection for our legitimate interests, balanced against your rights.
We rely on consent when we specifically ask for it, such as when you choose to submit an optional image where consent is the appropriate basis. You may withdraw consent prospectively. We also process information when necessary to comply with law or protect vital interests. If required information is not provided, the related feature may not work.
6. Where information is stored
Cloudflare hosts Soga. Account and authentication records—including the two-letter signup-country code—browser-keyed and account-linked story saves, generated-media records, short-lived generation-incident records, and security records may be stored in Cloudflare D1. Generated scene images may be stored in Cloudflare R2. Cloudflare also processes network and security logs needed to deliver and protect the site.
Your browser stores creator drafts, your Soga persona name and original local photo, local story saves, theme, a random client identifier, and a pseudonymous PostHog analytics identifier. Browser data remains on that browser until you clear it, reset the relevant feature, or the app replaces it.
Generated scene images are stored at public media URLs so they can appear in stories; anyone with the exact URL may be able to view them. Your original selfie is not published as a generated-media URL. Do not submit images or story details that require absolute confidentiality.
7. Service providers and disclosures
Cloudflare provides hosting, database, object storage, content delivery, logging, and security. Google processes Google sign-in and supplies the account details you authorize. Twilio SendGrid receives your email address and one-time link to deliver a requested sign-in email; open and click tracking are disabled for those messages.
PostHog provides product analytics. Soga also stores aggregate story-message submission and first-visible-reply timing totals without message or story content. API Mart receives a bounded planning request for the background story planner, including the selected choice or custom action, its authored effect, the destination scene outline, story events already public to the active characters, open plot-thread IDs and titles, and a fictional responder name. Inception Labs receives the limited story state, player name, choices, and custom action needed to continue a story with Mercury 2. For signed-in players, Soga may also send up to three preset branch requests in advance to reduce the wait after a choice; custom actions are not generated in advance. API Mart and Inception Labs do not need your account email or selfie. Runware receives the scene-generation prompt, your optional selfie when your character is present, the relevant fictional cast portraits, and a story-style reference; it does not need your account email. Those providers may receive ordinary request metadata such as IP address as part of delivering their service.
We may also disclose information when you direct us to make content public or unlisted; to professional advisers bound by confidentiality; to comply with law, legal process, or enforceable government requests; to protect people, rights, and service security; or in connection with a merger, financing, reorganization, or sale, subject to appropriate protections and notice where required.
8. Product analytics
Soga sends page paths, a pseudonymous browser identifier, and limited manual product events to PostHog’s United States cloud. PostHog enriches events with approximate country information from request metadata. After sign-in, we also send your server-issued account UUID, email address, display name, username if set, and signed-in status so activity is attached to your account profile. Soga may copy the two-letter country code from an account’s earliest successful sign-in event into its protected account record for administrative reporting. Story-model analytics record only the selected model’s stable internal ID, coarse generation path, fixed response-contract and validation-mode labels, attempt and provider-failure counts, streamed chunk count, whether an availability fallback was used, and rounded provider, header, first-content, validation, and total timings. Custom-route analytics add only a coarse strong, weak, or continuity label. Story-info analytics record only stable internal story/profile IDs and whether the free-form layout is metered or contextual, never the panel contents. Composer analytics record only whether a preset was loaded for editing or action markers were inserted, never the text. Reply-latency analytics contain only stable story/scene IDs, fixed interaction and delivery labels, and a rounded duration to first visible assistant text; the separate product metric stores only aggregate submission counts and rounded first-visible durations. Branch-prefetch analytics contain only stable IDs, aggregate counts, outcomes, and rounded timings. Admin directory, story, user-overview, and generation-incident analytics contain only coarse entry and request outcomes, aggregate result counts, fixed data-availability, filter, or resolution labels, and rounded timings; country codes displayed in the directory are not repeated on those admin analytics events, dynamic admin account and story paths are normalized before analytics are sent, and the events do not contain an incident ID, rejection detail, selected or listed user’s account fields, admin search text, message or story contents, or payment details. We do not send PostHog your Google profile photo, story premise or title, branch or choice text, character descriptions, custom-choice text, info-panel contents, cache keys, selfie, generated image, generation prompt, or the contents of support messages.
PostHog automatic interaction capture, heatmaps, performance capture, exception capture, surveys, and session replay are disabled. Analytics is not used for advertising. Soga respects browser Do Not Track signals; you can also prevent future local analytics storage by blocking site storage or using browser controls, although clearing all site storage also removes local drafts and progress.
9. Cookies and local storage
Soga uses HttpOnly, SameSite cookies to protect Google and email sign-in attempts and to keep you signed in. Google sign-in nonces expire after 10 minutes, email links expire after 15 minutes, and the normal sign-in session expires after 30 days unless you sign out sooner.
Local storage is used for story continuity, creator drafts, character settings, theme, the random browser identifier, and analytics. Unlike a cookie, local storage is controlled by your browser and is not automatically sent with every request. Blocking essential cookies prevents account sign-in; clearing local storage can permanently remove drafts or progress that exist only on that device.
10. No sale or targeted advertising
Soga does not sell personal information, rent it, or share it for cross-context behavioral advertising, and it does not use story content or images to target ads. Because Soga does not sell or share personal information for targeted advertising, a Global Privacy Control signal does not change that practice. We do honor Do Not Track for PostHog analytics.
11. Retention and deletion
Account and identity records are kept while your account is active and afterward only as reasonably needed for deletion processing, security, dispute resolution, or legal obligations. Your assigned access role and most recently recorded successful sign-in time are account records kept under this same schedule; pruning individual sessions does not remove them. Expired Google nonces, email links, sessions, and rate-limit records are pruned on a rolling basis. Story-generation incident records are automatically pruned after about 30 days. Signing out deletes the current server-side session token.
Local drafts and saves remain until you reset them or clear the browser. Cloud story progress, its account association when present, and its stored message count remain until you reset the story or request deletion. Generated scenes and previously created character references may remain until you request deletion or we determine they are no longer needed to provide the service. Resetting a story does not necessarily remove every generated image. Cached copies and provider backups or security logs may persist for a limited period after deletion.
We keep support, legal, and abuse records only as long as reasonably needed for the purpose, and analytics for as long as needed to understand product performance under the PostHog project’s retention settings. We may retain de-identified or aggregated information that can no longer reasonably identify you.
12. International processing
Soga and its providers may process information in the United States and other countries whose privacy laws differ from yours. Where law requires safeguards for an international transfer, we use the provider’s contractual transfer terms or another lawful transfer mechanism. Contact info@soga.gg for more information about safeguards relevant to your data.
13. Security
Soga uses safeguards appropriate to the service, including encrypted transport, hashed session and one-time tokens, HttpOnly sign-in cookies, input limits, rate limiting, access controls, and server-verified account linkage for signed-in story saves. Anonymous story saves remain pseudonymous. No online service can guarantee perfect security, and unlisted or public media URLs are not confidential storage.
If you believe your account or information is at risk, sign out, secure your email or Google account, and contact info@soga.gg.
14. Your privacy rights
Depending on where you live and subject to legal exceptions, you may have rights to know or access personal information; correct it; delete it; receive a portable copy; restrict or object to processing; withdraw consent; and appeal a denied request. You may also have the right not to be discriminated against for exercising a privacy right and to complain to your local data-protection authority.
California residents may request the categories, sources, purposes, recipients, and specific pieces of personal information covered by applicable law, and may request correction or deletion. Soga does not sell or share personal information for targeted advertising and does not use or disclose sensitive personal information to infer characteristics about you.
Send requests to info@soga.gg from the email associated with your account when possible. Describe the right you want to exercise and the relevant account, browser, story, or media URL. We may verify your identity and authority before acting. An authorized agent may submit a request where permitted by law. We will respond within the period required by applicable law.
15. Children
Soga is for adults aged 18 and older and is not directed to children. Do not create an account for a child or submit a child’s image or personal information. If we learn that we collected personal information from someone under 18 in violation of this policy, we will take reasonable steps to delete it. Report suspected child data to info@soga.gg.
16. Changes and contact
We may update this policy as Soga, its providers, or applicable requirements change. We will post the revised policy and update the effective date; if a change materially affects how we use previously collected information, we will provide additional notice or request consent where required.
For privacy questions, access, correction, portability, or deletion requests, email info@soga.gg. For the fastest response, include “Privacy Request” in the subject line.