This Privacy Policy explains how GENNIA INTELIGENCIA ARTIFICIAL LTDA, a company registered in Brazil under CNPJ 55.932.239/0001-91 (“Gennia”, “we”, “us”), collects, uses, and protects personal data when you use Sphere (the “Service”). We act as the data controller (controlador) under Brazil's General Data Protection Law (LGPD, Law No. 13.709/2018). Where you use the Service as part of an organization, that organization may also be a controller of its members' data.
1. Data we collect
1.1 Account data
When you sign up, our identity provider (WorkOS) processes your name and email address, and authentication metadata. We store your user and organization identifiers, role, and plan.
1.2 Billing data
Payments are handled by Paddle as Merchant of Record. Paddle collects and processes your payment and billing information under its own privacy policy. We do not receive or store your full card number; we store subscription status, plan, seat count, and related identifiers needed to grant access.
1.3 Content you create or sync
In Solo mode, your documents and workspace data remain primarily on your device. When you use Multiplayer (collaboration) features, the content you choose to share — documents, messages, channels, project data, and attachments — is synced to and stored in our cloud database and object storage so your organization can access it.
1.4 Product analytics & telemetry
We use PostHog to understand how the Service is used (feature events and session replay). Session replay masks password fields and elements tagged as secrets (such as API-key inputs). We associate events with your user id, and send your email and name as identifying traits. Analytics are opt-out— you can disable telemetry in the app's settings, and an opted-out state is honored before any event is sent.
1.5 Crash & error data
We use Sentry to capture crashes and errors (diagnostic and device information) so we can fix problems. This is enabled to keep the Service reliable.
1.6 Voice & dictation
If you use voice dictation or meeting transcription with the cloud engine, the relevant audio is sent to Groq for transcription and returned as text. A local, on-device transcription option is also available and does not send audio off your device.
1.7 Transactional email
We use Resend to send account and billing emails (for example trial reminders and invitations) to your email address.
2. Local agent execution — an important distinction
Sphere's AI agents run on your device. When an agent calls an AI model, the request goes directly from your device to the AI provider you have configured (for example Anthropic or OpenAI) under your own account and that provider's terms and privacy policy. Gennia does not act as an intermediary for, route, or store those model prompts and responses. Content that agents read on your device stays on your device unless you sync it through Multiplayer features or a connected integration.
3. How we use data
- to create and secure your account and authenticate you;
- to provide collaboration, sync, and storage features;
- to process subscriptions and manage seats (via Paddle);
- to send service and transactional communications;
- to improve, debug, and secure the Service (analytics and crash reporting);
- to comply with legal obligations and enforce our Terms.
We do not sell your personal data, and we do not use the content you sync to train our own models.
4. Legal bases for processing (LGPD art. 7)
- Performance of a contract(art. 7, V) — account, billing, sync, and core features;
- Legitimate interest(art. 7, IX) — security, crash reporting, and product improvement, balanced against your rights;
- Consent(art. 7, I) — optional analytics/telemetry and any marketing; you may withdraw consent at any time;
- Legal obligation(art. 7, II) — tax, accounting, and compliance.
5. Subprocessors
We rely on the following processors to run the Service. Each processes personal data only to provide its function, under its own security and privacy commitments.
| Subprocessor | Purpose | Data involved | Region |
|---|---|---|---|
| Paddle | Payments & Merchant of Record | Billing & payment data | UK / EU |
| WorkOS | Authentication & identity | Name, email, auth metadata | USA |
| Neon | Cloud database | Account & synced content | USA |
| Fly.io | Application hosting | All processed data in transit | USA |
| Cloudflare R2 | Object storage | Attachments, avatars, backups | USA / global |
| PostHog | Product analytics & session replay | Usage events, email, name | USA |
| Sentry | Crash & error reporting | Diagnostic & device data | USA |
| Groq | Cloud voice transcription | Audio you dictate (cloud engine) | USA |
| Resend | Transactional email | Email address, message content | USA |
| Composio | Third-party integration broker | Data for integrations you connect | USA |
We keep this list current. Regions are indicative and may change as providers evolve their infrastructure.
6. International transfers
Several subprocessors are located outside Brazil (primarily the United States and the European Union). When we transfer personal data internationally, we do so in accordance with LGPD Chapter V (arts. 33–36), relying on appropriate safeguards such as the providers' contractual data-protection commitments and, where applicable, adequacy or standard contractual clauses.
7. Retention
We retain personal data for as long as your account is active and as needed to provide the Service, then delete or anonymize it within a reasonable period, except where longer retention is required for legal, tax, security, or dispute-resolution purposes. Deleted content may persist in routine backups for a limited time before being overwritten.
8. Your rights (LGPD art. 18)
Subject to legal limits, you may request to:
- confirm whether we process your data, and access it;
- correct incomplete, inaccurate, or outdated data;
- anonymize, block, or delete unnecessary or excessive data;
- obtain portability of your data;
- delete data processed with your consent;
- obtain information about the entities we share data with;
- withdraw consent and opt out of analytics.
To exercise these rights, contact support@usesphere.ai. We will respond within the timeframes required by law. You also have the right to petition the Brazilian data-protection authority (ANPD).
9. Security
We use technical and organizational measures to protect personal data, including encryption in transit, access controls, credential masking in analytics, and hardened cloud infrastructure. No method of transmission or storage is completely secure, but we work to protect your data and to address vulnerabilities promptly.
10. Children
The Service is not directed to children. You must be at least 18, or the age of majority in your jurisdiction, to use it. We do not knowingly collect data from children; if you believe a child has provided us data, contact us and we will delete it.
11. Changes to this Policy
We may update this Policy from time to time. We will update the “Last updated” date and, for material changes, notify you in the app or by email.
12. Contact & Data Protection
For privacy questions or to exercise your rights, contact our data- protection contact at support@usesphere.ai.