Legal

Privacy Policy.

Effective 27 June 2026

We know that your privacy is important, and we're committed to protecting it. This Privacy Policy explains, in a clear and simple way, how we collect, use, and protect your personal data when you use our generative AI services ("Services").

Sorena AB (559573-7338) is a Swedish company based in Stockholm ("We", "Us" or "Sorena AI"). Sorena started operations in February 2024 and was officially registered in February 2025.

If you install or use Sorena through a GitHub App or a GitHub Marketplace listing, this Privacy Policy also explains how we handle GitHub account, organization, repository, installation, support, and billing-related personal data that is shared with us directly by you, by your workspace administrators, or through GitHub's APIs and webhook events.

Our public website uses privacy-by-default, cookieless analytics for limited website measurement unless you accept analytics cookies. We cannot and will not use this default cookieless measurement to identify users, and we do not sell personal data. By continuing to use our website or Services, you acknowledge this Privacy Policy and our basic cookieless measurement. Non-essential analytics cookies, advertising cookies, and personalization cookies are used only if you choose to allow them in the cookie banner.

All data is encrypted at rest and in transit. None of the cloud providers we partner with have access to the data, as per our enterprise agreements.

Who collects your data?

Sorena AI as data controller

Sorena AI is the data controller. This means that Sorena AI is the entity that decides how and why your personal data is collected and used.

Sorena AI as data processor

If you use our Services to process personal data on behalf of your business, you are the data controller, and Sorena AI is the data processor. This means that you decide how and why the personal data is processed, and we process such data on your behalf and according to your instructions to provide you with the Services. This Privacy Policy only covers the processing activities we carry out as a data controller. It does not apply to the processing activities we carry out as a data processor on your behalf, which are governed by our Data Processing Agreement.

What data do we collect?

Data you provide directly to us

Identity, account and contact data when you create your account on our platform or subscribe to our newsletter. We also collect any Feedback (screenshots and comments) you choose to provide. Our Services are intended for users who can lawfully enter into the relevant service relationship or provide any required consent in their jurisdiction.

Personal data generated by your use of our Services

When you use the Services, we automatically collect security logs, technical information through cookies, and Output (content generated by the Services based on your Input). If you include personal data in your Input, then such personal data may be included in the Output.

Personal data that is indirectly provided to us

Data publicly available on the Internet: Our models are trained on data that is publicly available on the Internet, which may contain personal data, even if we use good practices to filter out such personal data.

GitHub App and Marketplace data

If you connect Sorena to GitHub, we may receive GitHub account and organization identifiers, usernames, display names, email addresses where GitHub shares them with us, repository metadata, installation identifiers, repository access selections, webhook event metadata, and GitHub Marketplace purchase or subscription data such as plan, seat, billing-cycle, and effective-date information. We use this data only to provision, secure, support, bill, and operate the GitHub integration and the related Sorena service.

Why do we use your data?

Service Provision & Improvement

We use your data to provide the Services and generate aggregated and anonymized statistics to enhance functionality and performance.

General Administration

For security management, sending important non-marketing communications about service updates or account information, and managing technically required cookies.

Model Development

We do not use your Input and Output to train our models.

Marketing Operations

For sending newsletters (with consent), lead development, event invitations, and managing our business relationship with you. We do not use GitHub App or GitHub Marketplace personal data for third-party advertising, data sale, or unrelated marketing without a separate lawful basis and, where required, your consent.

Commercial Management

For contract administration, invoicing, and payment processing.

Dispute Resolution

To investigate and resolve disputes, enforce our contract, and protect our legal rights.

Data Subject Requests

To respond to your requests regarding your personal data rights.

GitHub integration operations

To verify GitHub App installations, associate an installation with the correct Sorena workspace, honor repository access choices, process Marketplace purchases and plan changes, detect misuse, respond to support requests, investigate security incidents, and maintain audit trails for the GitHub integration.

GitHub App and Marketplace disclosures

Relationship to GitHub

When you install Sorena through GitHub, GitHub remains an independent provider of the GitHub platform and Marketplace. Sorena is responsible for how Sorena collects and uses personal data inside the Sorena product and for the GitHub integration data we receive to provide our service.

Purpose limitation

We use GitHub-derived personal data only to establish and facilitate the relationship between Sorena and the end user or customer, to provide the GitHub-connected service, to secure and support the integration, and to fulfill related billing and compliance obligations. We do not sell GitHub-derived personal data and do not use it to advertise third-party goods or services.

AI interaction notice

Sorena includes generative AI features. When GitHub content or metadata is processed through those features, the resulting outputs may be generated or assisted by AI systems. We provide product notices, workflow context, and support channels so users can understand when they are interacting with AI-generated or AI-assisted content, report issues, and apply human review where appropriate.

How long do we keep your data?

Service & Account Data

Account data is kept while you're registered plus 1 year after termination. Input and Output data is kept for 30 days for abuse monitoring. Fine-tuning data is kept until you delete it or your account. For technical support, we keep data until request processing plus 5 years for records.

Security & Technical Data

Security logs are kept for 1 rolling year. Cookies are kept as long as you consent to their use.

Commercial & Legal Records

Contracts are kept for contract duration plus 7 years. Invoices are kept for 7 years from year-end. For disputes, data is kept until appeal periods end, with possible archival extension.

Marketing & Business Data

Newsletter contact data until unsubscribe, leads for 3 years from collection, B2B customer data for contract duration plus 3 years. Privacy requests are kept for 6 years after processing.

GitHub App and Marketplace data

GitHub installation, repository-access, billing, and webhook audit records are kept for as long as the integration or customer relationship is active and for a reasonable period afterward to handle security, billing, audit, tax, legal, and dispute requirements. When the data is no longer needed for those purposes, we delete it or de-identify it unless a longer retention period is required by law.

Who do we share your data with?

Internal Access

Authorized team members who need access to perform their jobs.

Financial & Legal

Banks and financial organizations, regulatory authorities like the Swedish data protection authority (Integritetsskyddsmyndigheten), courts, mediators, accountants, auditors, lawyers, bailiffs, and debt collection agencies when appropriate.

International Transfers

We prioritize EU providers compliant with GDPR. For non-EU providers, we ensure adequate safeguards under Article 46 of GDPR and include the latest European Commission's Standard Contractual Clauses.

Third-party service providers and subprocessors

How we use providers

We use selected third-party service providers to host, secure, support, analyze, and improve our services. Depending on the service and processing context, these providers may act as subprocessors or independent service providers. Provider access is limited to the data necessary for the relevant service, and where required we use data processing agreements and international-transfer safeguards such as Standard Contractual Clauses or equivalent mechanisms.

GitHub, Inc.

GitHub is one of our listed third-party service providers. We may use GitHub for source code hosting, development workflows, CI/CD, security tooling, and where applicable GitHub App and GitHub Marketplace platform services connected to Sorena integrations.

Infrastructure, AI, and analytics providers

Our main providers may include Cloudflare, Inc (Security, content delivery, cloud services, and selected AI or search-related platform services), Amazon.com, Inc (Cloud Services and AI-related infrastructure), Microsoft Corporation (Cloud Services, AI Services, and Microsoft Clarity for website behavior analytics), OpenAI, Inc (AI Services), Anthropic PBC (AI Services), Google LLC (Website Analytics, including Google Analytics and related gtag-based measurement where enabled), PostHog Cloud EU (Website and Product Analytics, including anonymous cookieless website measurement when analytics cookies are not accepted, hosted in the European Union), Hetzner Online GmbH (Cloud Services), and Bahnhof AB (Cloud Services).

Sales, CRM, billing, and finance providers

Where used in our operations, additional providers may include HubSpot Ireland Limited (lead handling, CRM, contact forms, lifecycle emails, and sales operations in Europe), Stripe Payments Europe, Limited (payment processing, invoices, subscriptions, and card or billing workflows in Europe), and Fortnox AB (customer, contact, invoice, accounting, and related finance operations in Sweden).

Marketplace and GitHub integration data

For GitHub App and GitHub Marketplace integrations, GitHub-related account, organization, repository, installation, webhook, and subscription data is used only to verify installations, operate the integration, secure the service, support customers, and process billing or subscription events as described in this Privacy Policy.

Data Breach Notification

Notification Timeline

If a personal data breach requires notification under GDPR Article 33, we will notify the relevant supervisory authority without undue delay and, where feasible, within 72 hours after becoming aware of it. If GDPR Article 34 requires communication to affected individuals because the breach is likely to result in a high risk to their rights and freedoms, we will notify those individuals without undue delay.

Notification Content

Our notification will include the nature of the breach, categories of data affected, potential consequences, measures taken to address the breach, and recommendations for you to mitigate potential adverse effects.

Ongoing Communication

We maintain transparent communication throughout the incident response process and provide regular updates on our dedicated security status page.

Prevention Measures

We continuously monitor our systems, conduct regular security assessments, and maintain incident response plans to prevent and quickly address any security incidents.

Your rights

Access

You have the right to know if we process your personal data. You also have the right to request a copy of such personal data and to obtain further information about the way we process your personal data.

Rectification

You have the right to update or correct your personal data.

Deletion

You have the right to delete and/or ask us to delete your personal data.

Objection

You have the right to object to the processing of your personal data. This right does not apply when we have a legal obligation to process your personal data.

Consent Withdrawal

You have the right to withdraw your consent to the processing of your personal data at any time.

Limitation

You have the right to ask us to freeze the processing of your personal data.

Portability

You have the right to obtain and transfer your personal data to another entity.

Post-mortem Rights

You have the right to tell us how you would like us to process your personal data after your death.

Lodge a Complaint

You have the right to lodge a complaint before the competent data protection authority, including the Swedish data protection authority (Integritetsskyddsmyndigheten).

How to Exercise Your Rights

You can exercise these rights by sending us an email at privacy@sorena.io (or contact our DPO at dpo@sorena.io) or by making a request using our Support Center available on your account.

Cookies & Tracking

Essential Technical Cookies

These cookies are strictly necessary for the proper functioning of the website and cannot technically be deactivated from the site. However, you can manage these cookies through your browser settings.

Performance & Analytics Cookies

These cookies help us understand how visitors use our website and improve the experience. We may use Google Analytics, Microsoft Clarity, and PostHog Cloud EU for website and product analytics when you consent to analytics cookies. Microsoft Clarity helps us understand website behavior through analytics such as heatmaps and session insights. If you do not accept analytics cookies, we may still use Google Analytics consent mode, Microsoft Clarity consent mode, and PostHog Cloud EU anonymous cookieless mode for limited website measurement, such as understanding which pages and artifacts are visited, without storing analytics cookies, localStorage, or sessionStorage identifiers in your browser. We cannot and will not use this default cookieless measurement to identify users. This limited cookieless measurement is active by default on the public website; continuing to use the website means you acknowledge this notice, but it is not treated as consent to non-essential cookies. PostHog Cloud EU data is hosted in the European Union. Google Analytics and Microsoft Clarity are not included or allowed inside the internal portal.

Cookie Management

Upon your initial visit, a banner will prompt you to accept or decline non-essential cookies. You can manage preferences through our cookie banner or your browser settings. Continuing to use the website after seeing the banner acknowledges the notice and our basic cookieless measurement, but non-essential cookies still require your banner choice. Note that deleting or blocking cookies may affect your user experience and limit access to certain parts of the site.

Contact Us

If you have any questions about our privacy policy or how we handle your data, please don't hesitate to reach out.

privacy@sorena.io

Data Protection Officer

For specific inquiries about your data protection rights or to report a privacy concern, contact our DPO directly.

dpo@sorena.io