Privacy Policy
Last updated: December 2025
1. Introduction
Socratic ONE ("we", "our", "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your information when you use our service.
2. Information We Collect
2.1 Account Information
- Email address (required for account creation)
- Display name (optional)
- Encrypted password hash
2.2 API Keys
- Your AI provider API keys are encrypted using industry-standard encryption (Fernet/AES)
- Keys are stored encrypted at rest and only decrypted momentarily during API calls
- We never log or store your decrypted API keys
2.3 Discussion Data
- Research topics you submit
- AI responses generated during discussions (Pro users only, for history feature)
- Free tier users' discussions are not permanently stored
2.4 Usage Data
- Topic and query counts for billing purposes
- Subscription status
3. How We Use Your Information
- To provide and maintain our service
- To process your AI research requests
- To manage your subscription and billing
- To send service-related emails (verification, password reset)
- To enforce usage limits based on your plan
4. Third-Party Services
4.1 AI Providers
When you use our service, your research topics are sent to the AI providers you select (xAI, Anthropic, Perplexity, OpenAI). Each provider has their own privacy policy. You use your own API keys, establishing a direct relationship with these providers.
4.2 Payment Processing
We use Stripe for payment processing. Stripe collects and processes your payment information according to their privacy policy. We do not store your credit card details.
4.3 Email Delivery
We use SendGrid to send transactional emails. Only your email address is shared for delivery purposes.
5. Data Security
- All data is transmitted over HTTPS
- API keys are encrypted using Fernet symmetric encryption
- Passwords are hashed using bcrypt
- Database access is restricted and monitored
6. Your Rights
You have the right to:
- Access: Request a copy of your data via account settings
- Correction: Update your profile information anytime
- Deletion: Delete your account and all associated data
- Export: Download your data in a portable format
7. Data Retention
- Account data is retained until you delete your account
- Discussion history (Pro) is retained until deletion or account closure
- Billing records are retained as required by law
8. Cookies
We use essential cookies for authentication and session management. We do not use tracking cookies or third-party analytics that identify individual users.
9. Children's Privacy
Our service is not intended for users under 18. We do not knowingly collect information from children.
10. Changes to This Policy
We may update this policy periodically. We will notify you of significant changes via email or service notification.
11. Contact Us
For privacy questions or to exercise your rights, contact us at: privacy@example.com