Data Deletion Instructions

Last updated: July 10, 2026

How to Request Deletion

To request deletion of your SOVREN AI account and associated personal data, use one of the following paths:

  1. Email privacy@sovrenai.io from the address on your account, with subject line "Data deletion request"
  2. If available in your portal, use Settings > Account deletion controls (product self-service continues to expand)
  3. Confirm your request when we reply so we can verify account ownership

We process verified deletion requests within 30 days, except where retention is required by law or for narrowly scoped legitimate purposes (for example, fraud prevention, dispute resolution, or demonstrating prior communications consent).

How Deletion Works

SOVREN uses a per-subject cryptographic erasure model for covered account and identity data: sensitive fields are sealed under keys bound to the subscriber; completing erasure destroys the ability to decrypt those fields. Covered stores are processed through a multi-step deletion workflow that records outcomes on a sealed deletion receipt.

Encryption-at-rest and crypto-erase coverage is live for core identity surfaces and is being extended across CRM, voice content, and remaining product tables. Surfaces not yet under per-subject encryption are removed or scrubbed by tracked deletion steps where implemented, or disclosed as residuals below.

What Is Deleted or Made Unrecoverable

  • Account identity and profile fields on covered identity tables
  • Authentication credentials and session material associated with the account
  • Connected mailbox / calendar credential material for the account (where stored)
  • Subscriber configuration bound to the account on covered stores
  • Voice, CRM, and operational content associated with the account — removed, scrubbed, or crypto-erased as each surface's coverage lands (coverage is expanding)
  • Third-party subprocessors receive delete instructions for vendor-held identifiers we track

Disclosed Residuals

Honest deletion means disclosing what may remain after a request completes:

  • Lawful retention. Records we must keep under law or to establish, exercise, or defend legal claims (for example, limited billing or consent evidence).
  • Operational backups. Encrypted or access-controlled backups may retain snapshots for a bounded retention window before natural expiry; post-erasure restores of covered ciphertext cannot re-derive destroyed subject keys.
  • Expanding coverage surfaces. Product tables still moving onto encrypt-at-rest / crypto-erase are scrubbed or deleted by best-effort tracked steps and continue to tighten as cutovers complete.
  • Subprocessors. Telephony, payments, email/calendar connectors, and voice synthesis vendors process limited data under their own retention schedules; we issue deletion instructions for identifiers we control and verify where the integration allows.
  • Aggregated / de-identified analytics. Metrics that cannot reasonably identify you may be retained for product reliability.

Cancellation ends billing and deactivates the service. We do not promise an automatic full data export or an instant infrastructure teardown as part of every cancel click; request export or deletion explicitly if you need either, and we will fulfill through the paths above.

SMS Opt-Out

To stop SMS only (without full account deletion), reply STOP to any SOVREN SMS message. Phone numbers used solely for SMS consent are removed from active messaging lists within 30 days of opt-out, except where retention is required to demonstrate prior consent.

Contact

Privacy requests: privacy@sovrenai.io

Security reports: security@sovrenai.io

Related: Privacy Policy · Security