Effective 27 June 2026
We know that your privacy is important, and we're committed to protecting it. This Privacy Policy explains, in a clear and simple way, how we collect, use, and protect your personal data when you use our generative AI services ("Services").
Sorena AB (559573-7338) is a Swedish company based in Stockholm ("We", "Us" or "Sorena AI"). Sorena started operations in February 2024 and was officially registered in February 2025.
If you install or use Sorena through a GitHub App or a GitHub Marketplace listing, this Privacy Policy also explains how we handle GitHub account, organization, repository, installation, support, and billing-related personal data that is shared with us directly by you, by your workspace administrators, or through GitHub's APIs and webhook events.
Our public website uses privacy-by-default, cookieless analytics for limited website measurement unless you accept analytics cookies. We cannot and will not use this default cookieless measurement to identify users, and we do not sell personal data. By continuing to use our website or Services, you acknowledge this Privacy Policy and our basic cookieless measurement. Non-essential analytics cookies, advertising cookies, and personalization cookies are used only if you choose to allow them in the cookie banner.
All data is encrypted at rest and in transit. None of the cloud providers we partner with have access to the data, as per our enterprise agreements.
Sorena AI is the data controller. This means that Sorena AI is the entity that decides how and why your personal data is collected and used.
If you use our Services to process personal data on behalf of your business, you are the data controller, and Sorena AI is the data processor. This means that you decide how and why the personal data is processed, and we process such data on your behalf and according to your instructions to provide you with the Services. This Privacy Policy only covers the processing activities we carry out as a data controller. It does not apply to the processing activities we carry out as a data processor on your behalf, which are governed by our Data Processing Agreement.
Identity, account and contact data when you create your account on our platform or subscribe to our newsletter. We also collect any Feedback (screenshots and comments) you choose to provide. Our Services are intended for users who can lawfully enter into the relevant service relationship or provide any required consent in their jurisdiction.
When you use the Services, we automatically collect security logs, technical information through cookies, and Output (content generated by the Services based on your Input). If you include personal data in your Input, then such personal data may be included in the Output.
Data publicly available on the Internet: Our models are trained on data that is publicly available on the Internet, which may contain personal data, even if we use good practices to filter out such personal data.
If you connect Sorena to GitHub, we may receive GitHub account and organization identifiers, usernames, display names, email addresses where GitHub shares them with us, repository metadata, installation identifiers, repository access selections, webhook event metadata, and GitHub Marketplace purchase or subscription data such as plan, seat, billing-cycle, and effective-date information. We use this data only to provision, secure, support, bill, and operate the GitHub integration and the related Sorena service.
We use your data to provide the Services and generate aggregated and anonymized statistics to enhance functionality and performance.
For security management, sending important non-marketing communications about service updates or account information, and managing technically required cookies.
We do not use your Input and Output to train our models.
For sending newsletters (with consent), lead development, event invitations, and managing our business relationship with you. We do not use GitHub App or GitHub Marketplace personal data for third-party advertising, data sale, or unrelated marketing without a separate lawful basis and, where required, your consent.
For contract administration, invoicing, and payment processing.
To investigate and resolve disputes, enforce our contract, and protect our legal rights.
To respond to your requests regarding your personal data rights.
To verify GitHub App installations, associate an installation with the correct Sorena workspace, honor repository access choices, process Marketplace purchases and plan changes, detect misuse, respond to support requests, investigate security incidents, and maintain audit trails for the GitHub integration.
When you install Sorena through GitHub, GitHub remains an independent provider of the GitHub platform and Marketplace. Sorena is responsible for how Sorena collects and uses personal data inside the Sorena product and for the GitHub integration data we receive to provide our service.
We use GitHub-derived personal data only to establish and facilitate the relationship between Sorena and the end user or customer, to provide the GitHub-connected service, to secure and support the integration, and to fulfill related billing and compliance obligations. We do not sell GitHub-derived personal data and do not use it to advertise third-party goods or services.
Sorena includes generative AI features. When GitHub content or metadata is processed through those features, the resulting outputs may be generated or assisted by AI systems. We provide product notices, workflow context, and support channels so users can understand when they are interacting with AI-generated or AI-assisted content, report issues, and apply human review where appropriate.
Account data is kept while you're registered plus 1 year after termination. Input and Output data is kept for 30 days for abuse monitoring. Fine-tuning data is kept until you delete it or your account. For technical support, we keep data until request processing plus 5 years for records.
Security logs are kept for 1 rolling year. Cookies are kept as long as you consent to their use.
Contracts are kept for contract duration plus 7 years. Invoices are kept for 7 years from year-end. For disputes, data is kept until appeal periods end, with possible archival extension.
Newsletter contact data until unsubscribe, leads for 3 years from collection, B2B customer data for contract duration plus 3 years. Privacy requests are kept for 6 years after processing.
GitHub installation, repository-access, billing, and webhook audit records are kept for as long as the integration or customer relationship is active and for a reasonable period afterward to handle security, billing, audit, tax, legal, and dispute requirements. When the data is no longer needed for those purposes, we delete it or de-identify it unless a longer retention period is required by law.
We use selected third-party service providers to host, secure, support, analyze, and improve our services. Depending on the service and processing context, these providers may act as subprocessors or independent service providers. Provider access is limited to the data necessary for the relevant service, and where required we use data processing agreements and international-transfer safeguards such as Standard Contractual Clauses or equivalent mechanisms.
GitHub is one of our listed third-party service providers. We may use GitHub for source code hosting, development workflows, CI/CD, security tooling, and where applicable GitHub App and GitHub Marketplace platform services connected to Sorena integrations.
Our main providers may include Cloudflare, Inc (Security, content delivery, cloud services, and selected AI or search-related platform services), Amazon.com, Inc (Cloud Services and AI-related infrastructure), Microsoft Corporation (Cloud Services, AI Services, and Microsoft Clarity for website behavior analytics), OpenAI, Inc (AI Services), Anthropic PBC (AI Services), Google LLC (Website Analytics, including Google Analytics and related gtag-based measurement where enabled), PostHog Cloud EU (Website and Product Analytics, including anonymous cookieless website measurement when analytics cookies are not accepted, hosted in the European Union), Hetzner Online GmbH (Cloud Services), and Bahnhof AB (Cloud Services).
Where used in our operations, additional providers may include HubSpot Ireland Limited (lead handling, CRM, contact forms, lifecycle emails, and sales operations in Europe), Stripe Payments Europe, Limited (payment processing, invoices, subscriptions, and card or billing workflows in Europe), and Fortnox AB (customer, contact, invoice, accounting, and related finance operations in Sweden).
For GitHub App and GitHub Marketplace integrations, GitHub-related account, organization, repository, installation, webhook, and subscription data is used only to verify installations, operate the integration, secure the service, support customers, and process billing or subscription events as described in this Privacy Policy.
If a personal data breach requires notification under GDPR Article 33, we will notify the relevant supervisory authority without undue delay and, where feasible, within 72 hours after becoming aware of it. If GDPR Article 34 requires communication to affected individuals because the breach is likely to result in a high risk to their rights and freedoms, we will notify those individuals without undue delay.
Our notification will include the nature of the breach, categories of data affected, potential consequences, measures taken to address the breach, and recommendations for you to mitigate potential adverse effects.
We maintain transparent communication throughout the incident response process and provide regular updates on our dedicated security status page.
We continuously monitor our systems, conduct regular security assessments, and maintain incident response plans to prevent and quickly address any security incidents.
You have the right to know if we process your personal data. You also have the right to request a copy of such personal data and to obtain further information about the way we process your personal data.
You have the right to update or correct your personal data.
You have the right to delete and/or ask us to delete your personal data.
You have the right to object to the processing of your personal data. This right does not apply when we have a legal obligation to process your personal data.
You have the right to withdraw your consent to the processing of your personal data at any time.
You have the right to ask us to freeze the processing of your personal data.
You have the right to obtain and transfer your personal data to another entity.
You have the right to tell us how you would like us to process your personal data after your death.
You have the right to lodge a complaint before the competent data protection authority, including the Swedish data protection authority (Integritetsskyddsmyndigheten).
You can exercise these rights by sending us an email at privacy@sorena.io (or contact our DPO at dpo@sorena.io) or by making a request using our Support Center available on your account.
If you have any questions about our privacy policy or how we handle your data, please don't hesitate to reach out.
privacy@sorena.ioFor specific inquiries about your data protection rights or to report a privacy concern, contact our DPO directly.
dpo@sorena.io