Somix
Legal

Privacy Policy

Last updated 13 September 2026

In short

Somix is a tool that plans, writes and publishes social media content on your behalf. To do that we need your account details, whatever you tell us about your brand, and permission to post to the social accounts you connect.

We do not sell your data, we do not use it for advertising, and we do not use your content to train AI models. You can export or delete everything at any time by writing to hi@somix.ai.

Who we are

This policy explains how Somix (“Somix”, “we”, “us”) handles personal data when you use the Somix service at somix.ai. It applies to the marketing site and to the product behind sign-in.

Questions, requests and complaints about privacy all go to hi@somix.ai.

What we collect

Account details
Your email address, your display name and — if you sign in with Google — the profile picture Google returns. Used to create your account, sign you in, and address you in the product.
Brand information
Whatever you enter or we learn from a website you ask us to analyse: your brand description, tone of voice, audience, content pillars, colours and logo.
Connected accounts
When you connect Instagram, TikTok, LinkedIn or X, we store the access tokens that platform issues, the account handle, and the permissions you granted. We never receive or store your password for those platforms.
Content you create
Campaigns, posts, captions, documents, images and video you upload or Somix generates for you, plus the publishing results and engagement metrics the platforms report back.
Billing details
Your plan, your credit balance and your payment history. Card details are handled entirely by Stripe — they never reach our servers.
Technical data
Standard server and security logs: IP address, browser type, timestamps and the pages requested. Used to keep the service running and to investigate abuse.

Google user data

If you choose “Continue with Google”, we ask Google only for your basic profile and email address. We use them for one purpose: to create your Somix account and sign you in. We do not read your Gmail, your Drive, your Calendar or your Contacts, and we do not request access to them.

Somix’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not transfer Google user data to third parties except as needed to provide the service, and we never use it for advertising or sell it.

You can withdraw Somix’s access to your Google account at any time at myaccount.google.com/permissions. Doing so removes the sign-in method; write to us if you also want the account deleted.

How we use it

  • To run the service: authenticate you, generate content in your brand's voice, schedule it, and publish it to the accounts you connected.
  • To bill you: track credit usage, process subscriptions, and send receipts.
  • To support you: answer your questions and investigate problems you report.
  • To keep the service safe: detect abuse, spam and unauthorised access.
  • To send service email: invitations, publishing failures, and account notices. Product announcements are opt-out.

We do not use your content or your brand data to train our own models, and we do not sell or rent personal data to anyone.

AI processing

Generating a post means sending the relevant material — your brand description, your campaign brief, the instruction you typed — to an AI model provider. Today those are Anthropic, OpenAI and OpenRouter. We use their business APIs, under terms that prohibit them from using your content to train their models.

Somix generates drafts, not published posts: content is written for your review, and nothing is published to a connected account until it is approved or you have scheduled it for automatic publishing.

Who we share it with

We share data with the service providers that make Somix work, each handling it only on our instructions:

Supabase
Authentication, database and file storage.
Vercel
Hosting for the website and product.
Anthropic, OpenAI, OpenRouter
AI models that generate your content.
Stripe
Subscription and payment processing.
Resend
Transactional email (invitations, notices).
Trigger.dev
Background jobs — scheduled generation and publishing.
Social platforms
Meta (Instagram), TikTok, LinkedIn and X receive the posts you publish and return their metrics. Each has its own privacy policy, which governs what they do with it.

We may also disclose data if the law requires it, or to protect the rights and safety of Somix and its users. If Somix is ever acquired or merged, your data may transfer as part of that — you would be told before it changed hands.

How we protect it

  • Traffic between you and Somix is encrypted with TLS.
  • The access tokens for your connected social accounts are encrypted at rest, separately from the rest of the database.
  • Access to production data is limited to the people who need it to operate the service.

No system is perfectly secure. If a breach ever affects your data, we will tell you and the relevant authorities without undue delay.

How long we keep it

We keep your account data for as long as your account is open. When you delete your account, we delete your brand data, your content and your connection tokens within 30 days, except where we must keep records longer — billing records, for example, which tax rules require us to retain.

Server logs are kept for a short operational window and then discarded.

Your rights

Wherever you live, you can ask us to show you the personal data we hold about you, correct it, export it, or delete it. Depending on where you live you may also have the right to object to or restrict how we use it, and to complain to your local data protection authority.

Write to hi@somix.ai and we will respond within 30 days. We may need to confirm who you are before acting on a request.

Cookies and local storage

Somix stores a session token in your browser so you stay signed in, and remembers small interface preferences locally. That is what the product needs to function — we do not run advertising trackers or third-party analytics cookies on the product.

International transfers

Somix and its service providers operate from a number of countries, so your data may be processed outside the country you live in. Where we transfer personal data across borders, we rely on the safeguards our providers have in place, including the European Commission’s standard contractual clauses.

Children

Somix is a business tool and is not intended for anyone under 16. We do not knowingly collect data from children. If you believe a child has given us personal data, write to hi@somix.ai and we will delete it.

Changes to this policy

We will update this page when our practices change, and revise the date at the top. If a change materially affects how we handle your data, we will tell you by email or in the product before it takes effect.