Privacy Policy
1. Introduction
SOSUITE LLC (“Sorcrr,” “we,” “us”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and share information when you use sorcrr.com, app.sorcrr.com, market.sorcrr.com, our mobile applications, and related services (collectively, the “Platform”).
By using the Platform, you consent to the practices described in this policy. If you do not agree, please do not use our services.
2. Information We Collect
Information You Provide
- Account data: Name, email address, phone number, password, profile photo
- Profile information: Work experience, skills, education, bio, video introductions
- Company data: Company name, address, industry, logo, team members (for employer accounts)
- Service listings: Offering details, pricing, availability, bounty settings (for Market providers)
- Job postings: Job descriptions, salary ranges, requirements, bounty amounts (for employers)
- Communications: Messages, chat content, support tickets, feedback
- Video content: Profile videos and application videos you choose to upload
- Payment information: Processed by Stripe—we do not store credit card numbers (see Section 7)
Information Collected Automatically
- Usage data: Pages visited, features used, clicks, time spent, search queries
- Device information: IP address, browser type, operating system, device identifiers
- Location data: Approximate location based on IP address, city/region or radius-based location shown in product filters, and precise GPS/home-address signals only when you choose to use verification or location features that require them
- Referral data: Share chain interactions, referral link clicks, conversion events
Information from Third Parties
- OAuth providers: Name, email, and profile photo from Google or Apple when you sign in
- Stripe: Payout status and account verification status (not payment card details)
- Calendar providers: Availability time slots from Google Calendar or Apple Calendar (see Section 5)
3. How We Use Your Information
| Purpose | Data Used |
|---|---|
| Provide and operate the Platform | Account data, profile, listings, bookings |
| Match candidates with jobs | Profile, skills, experience, AI matching scores |
| Match buyers with providers | Search queries, location, preferences, availability |
| Process payments and bounties | Transaction data, Stripe account status |
| Track and distribute referral bounties | Share chain data, referral links, conversion events |
| Power AI features (SAI, matching, analysis) | Profile data, job data, interaction history |
| Send notifications and communications | Email, phone, push notification tokens |
| Prevent fraud and enforce Terms | Usage patterns, device info, IP address |
| Improve the Platform | Aggregated usage analytics, feedback |
4. Contact Import & Address Book
With your explicit, opt-in permission, Sorcrr may access your device’s address book to help you discover people you know on the Platform.
Key commitment: Contact import is optional. When you choose to import contacts, phone numbers and email addresses are transmitted securely, normalized, and matched against existing Sorcrr users. Sorcrr may store hashed contact identifiers, contact names, match status, and import timestamps to support matching, invite tracking, contact-joined notifications, and referral recommendations. We do not sell your contact list.
- You can revoke address book access at any time through your device settings
- We do not message or contact people from your address book without their independent consent
- The “Invite Friends” feature sends invitations only when you explicitly choose to invite specific contacts
- You can request deletion of imported-contact data through the app where available or by contacting privacy@sorcrr.com
5. Calendar Integration
Sorcrr Market allows providers to connect Google Calendar or Apple Calendar for availability management.
- Calendar access is authorized via OAuth 2.0—you grant and revoke access through Google or Apple directly
- We read event times only to determine busy/free slots—we do not access event titles, descriptions, attendees, or other details
- We create calendar events for confirmed bookings with only the information necessary (time, service name, booking reference)
- Calendar data is not shared with other users, third parties, or used for advertising
- You can disconnect your calendar at any time from Commerce > Calendar Settings
6. Decision-Support & AI Data Processing
Sorcrr provides two different kinds of assistive technology: deterministic decision-support tools, including Career Rank Score (“CRS”) and Open Algorithm, and the SAI artificial-intelligence assistant. The distinction matters because deterministic tools follow published rules, while model-assisted features may generate or interpret content probabilistically.
Human-decision commitment: CRS, Open Algorithm, SAI, matching, summaries, and other Platform signals do not make autonomous hiring, firing, booking, financial, or professional decisions. Authorized people remain responsible for reviewing relevant evidence, correcting errors, providing required notices or alternatives, and making consequential decisions.
Career Rank Score (CRS)
CRS is a viewer-independent score from 0 to 1000 calculated by a versioned, deterministic formula. The current formula uses eligible submitted four-dimensional reviews, dated work experience, completed education, and skills or certificates. Missing components are renormalized rather than silently treated as zero. CRS does not use age, account age, salary, referral counts, or employer or institution prestige.
To calculate, explain, and audit CRS, Sorcrr may process and retain:
- Eligible review dimensions and review status, without converting the absence of a review into a negative rating
- Dated work, completed education (including degree level and normalized GPA when a supported grading scale is usable), skills, certificates, and verification status associated with those records
- The current score, component breakdown, formula version, confidence, verification coverage, availability or freshness state, calculation timestamps, and historical score snapshots
- Authorized ranking-policy versions and result receipts needed to show which filters, thresholds, weights, and sort metric a viewer applied
Verification coverage is shown separately and is not a hidden multiplier. Current and historical CRS records are retained while an account is active to support reproducibility, correction, disputes, safety, and audit. They are removed or anonymized under Section 11 when the underlying account or data is deleted, unless a narrower record must be retained for legal, fraud, security, or dispute purposes.
Open Algorithm / Viewer-Owned Ranking
Open Algorithm (also described as “build your own algorithm”) is a deterministic filter and sorting policy. It can use authorized evidence scope, CRS or confidence thresholds, verification coverage, verified work years, explicit component or dimension weights, and derived metrics such as score per verified year. It does not rewrite a person’s canonical CRS. Sorcrr returns the original score beside any derived value, policy version, confidence, and explanation.
Ranking policies may be stored for a personal, company, or job scope. Access controls determine who can create, view, or change each policy. Sorcrr prohibits using protected characteristics as filters or weights and does not provide a Platform function that automatically rejects or selects a person solely from CRS or a ranking lens. Learn more at How CRS Works.
SAI: A Permissioned AI Assistant
SAI is clearly presented as an AI assistant. It routes a request through the current user’s authorized context and the narrowest suitable tool. Some routes are deterministic and do not invoke a generative model. Other routes use a model for drafting, summarization, retrieval assistance, or interpretation and may consume AI credits.
Depending on the feature you invoke and your permissions, SAI may process:
- Message text, timestamps, sender metadata, and attachments in conversations you participate in
- Internal briefs or Internal Remarks that your hiring role is authorized to access; employer-only intelligence is not disclosed to candidates
- Profile, job, application, company, provider, offering, booking, customer, or finance-support context relevant to the request
- Files you select and approved personal, team, company, or customer-facing knowledge sources
- When enabled for the applicable workflow, user-scoped preferences, conversation continuity, diary or timeline summaries, compacted memory, and derived retrieval indexes or graph relationships used to find relevant authorized context
- When separately enabled, real-time interview transcripts and interviewer-only assistive output. Interview AI is not assumed to be active in every interview, and Sorcrr does not retain an interview audio or video recording through this feature.
SAI can produce drafts, summaries, explanations, navigation help, retrieval results, and assistive recommendations. Output is returned within the authorized account, conversation, or workflow that requested it. Customer-facing SAI uses approved company knowledge and permitted customer context, not an owner’s personal memory. Company users can review or take over supported customer workflows.
Personalization & Controls
Where the user profile-context control is available, you can disable use of eligible profile data for SAI personalization. That preference does not disable required account or safety operations, deterministic tools, or a model-assisted feature that you separately choose to invoke with selected content. You can also choose not to submit optional files or prompts to SAI. Important external, financial, account, and hiring actions retain their normal authorization and confirmation requirements.
SAI Memory & Context Management
SAI context is not one undifferentiated record. Sorcrr separates live conversation or workflow context, user-scoped memory such as preferences and diary or timeline summaries, approved personal or organizational knowledge, and derived retrieval data such as embeddings, compacted summaries, or graph relationships. Each source keeps its own user, team, company, job, customer, or platform access boundary. A model-assisted request receives only the relevant context assembled for that authorized request, not unrestricted access to an account or organization.
Supported AI settings let you inspect a unified memory inventory and source breakdown, open source-specific views, configure retention preferences, preview compaction, and preview eligible cleanup before deletion. You may also end or delete supported conversations and request export or deletion under Sections 11 and 12. Cleanup coverage varies by source: deleting a derived vector or index does not necessarily delete its canonical source record, and some sources must be corrected or deleted in the product surface that owns them. The confirmation flow identifies affected sources and known preserved sources where supported. Security, fraud, billing, dispute, backup, and legal-retention duties can limit or delay deletion.
AI Providers & Training
Depending on the selected capability, Sorcrr may use Google Cloud services, including Speech-to-Text and Vertex AI, and approved model families made available through Vertex AI or another configured enterprise provider. Current providers and model availability can change as we improve reliability, safety, price, and regional support.
- Sorcrr does not authorize service providers to use your prompts, files, chat content, or outputs to train shared foundation models unless we first obtain your permission or clearly disclose a different arrangement.
- Provider features may temporarily retain or cache data for abuse prevention, safety, service operation, or a feature you select. Sorcrr uses enterprise data controls where available and limits provider access to the requested processing.
- Google Cloud processing is governed by its enterprise Data Processing Addendum. International transfers use the safeguards described in Sections 13 and 15.
Retention of SAI Data
- SAI-generated outputs (summaries, recommendations, drafts) are retained for the lifetime of the authorized chat, document, workflow, or account that contains them and are deleted or anonymized under Section 11.
- SAI processing logs used for debugging, billing, audit, and abuse prevention are retained for 90 days, then automatically purged unless a specific security, fraud, dispute, or legal hold requires narrower retention.
- Vector embeddings derived from authorized profile or content sources are retained while the applicable account or source is active and removed or anonymized according to Section 11.
- User-scoped memory tiers may have configurable auto-deletion periods where that setting is supported and enabled. The underlying source record follows the retention rule for the product surface that owns it.
AI Credits
Model-assisted features may require purchased, granted, or company-funded credits. A deterministic CRS calculation or Open Algorithm ranking route does not consume generative-AI credits. Usage tracking may include model, provider, token, tool, file, company, job, and workflow metadata needed for billing, abuse prevention, support, and audit logs.
If a company funds your AI credits or approves a top-up request, company admins may see request reason, requested amount, approval status, allocation amount, expiration, and company-scoped usage metadata. Your personal paid credits remain personal and are not exposed as a company balance. Learn more at How SAI Works.
7. Payment Data & Stripe
All payment processing is handled by Stripe, Inc. Sorcrr does not store, process, or have access to your full credit card numbers.
- What Stripe stores: Payment method details, transaction history, bank account information for payouts
- What Sorcrr stores: Transaction amounts, timestamps, booking/job references, payout status, Stripe customer and account IDs
- Stripe Connect: If you receive payouts, Stripe collects identity verification data (name, date of birth, government ID) as required by financial regulations. This data is stored by Stripe, not Sorcrr.
Stripe’s handling of your data is governed by the Stripe Privacy Policy.
8. Cookies & Analytics
Cookies
Sorcrr uses essential cookies for authentication and session management. We do not use third-party advertising cookies or cross-site tracking cookies.
Google Analytics (GA4)
We use Google Analytics 4 (measurement ID: G-9XZBXVWHXS) to understand how users interact with the Platform. GA4 collects:
- Page views, session duration, and navigation paths
- Approximate geographic location (country/city level)
- Device type, browser, and operating system
- Referral sources (how you found Sorcrr)
GA4 data is used to improve the Platform and understand launch funnels. Where a public consent control is available or legally required, your choice applies to non-essential analytics on that surface. You can also opt out of Google Analytics through browser controls or the Google Analytics Opt-out Browser Add-on. Signed-in app analytics choices are managed in app privacy settings where available.
Firebase Analytics
Our mobile applications use Firebase Analytics for app usage data (screen views, feature usage, crash reports). Firebase is operated by Google and governed by Google’s privacy policies.
9. Data Sharing
We do not sell your personal data. We share information only in these circumstances:
- With other users: Your public profile, listings, and reviews are visible to other Platform users as necessary for the service to function
- With service providers: Stripe (payments), Google Cloud and Vertex AI (infrastructure, storage, AI), Firebase (authentication and phone verification, hosting, notifications, analytics), Resend (email), and Google Analytics (web analytics)
- For referral chains: When you participate in a referral, your name may be visible to other chain participants (not your contact details)
- For legal compliance: When required by law, regulation, legal process, or government request
- For safety: To protect the rights, property, or safety of Sorcrr, our users, or the public
- In business transfers: In connection with a merger, acquisition, or sale of assets (with notice to users)
10. Data Security
We implement robust security measures to protect your data:
- Encryption in transit: All data transmitted between your device and our servers uses TLS/HTTPS
- Encryption at rest: Sensitive data is encrypted in our databases (Google Cloud SQL)
- Authentication: RS256 JWT tokens with JWKS validation, two-tier defense-in-depth architecture
- Access control: IAM-locked Cloud Run services, no direct public access to backend services
- Secret management: All credentials stored in Google Cloud Secret Manager (no hardcoded secrets)
- Monitoring: Security headers, scanner-path blocking, abuse monitoring, audit logging, and service-level access controls
No system is 100% secure. While we take extensive measures to protect your data, we cannot guarantee absolute security. If we discover a data breach that affects your personal information, we will notify you in accordance with applicable law.
11. Data Retention & Account Deletion
How to Delete Your Account
You can request deletion or anonymization of your Sorcrr account and the personal data we hold for you through these paths:
- Inside the app: Open Settings > Personal Data > Delete Account. After you confirm the dialog, your account is immediately deactivated, you are signed out, the account stops appearing in normal search and listing surfaces, and deletion or anonymization begins.
- Web form (no sign-in required): Submit a request at sorcrr.com/account-deletion. This form is intended for users who have uninstalled the app or cannot sign in. You only need your email address and optional account ID.
- Email: Write to privacy@sorcrr.com from the email address on your account.
What the Deletion Flow Looks Like
- You submit a deletion request via app, web form, or email
- We send an acknowledgement email to the address on file
- We verify the request is coming from the account owner (via the email we already have on file, or a simple confirmation link)
- We deactivate the account, anonymize core account identifiers, and remove or anonymize supported personal data from active product systems within 30 days after verification, subject to the retention rules below
- We send a confirmation email when the request has been processed or explain any retained categories required by law or platform safety
If you change your mind within 30 days of your request, reply to the confirmation email or contact privacy@sorcrr.com and we can cancel the deletion.
What Is Removed Or Anonymized From Active Product Systems
- Profile (name, photo, bio, work experience, skills, education)
- Uploaded videos, thumbnails, and documents (resumes, cover letters, portfolios)
- Chat messages, internal remarks, and internal briefs authored by you
- SAI conversation history and SAI-generated outputs tied to your account
- Current and historical CRS records, component breakdowns, and personal ranking policies tied to your account, subject to any narrow dispute, security, fraud, or legal hold
- Vector embeddings derived from your content
- Job postings, applications, service listings, and bookings you created
- Notifications, notification preferences, device tokens
- Referral links you own (chain attribution is retained in anonymized form for accounting)
- SAI processing logs older than 90 days are already purged; the remainder is purged with your account
What Is Retained for Up to 7 Years
To comply with US and international tax, accounting, and anti-fraud obligations, we retain the following for up to 7 years after account closure:
- Transaction records: invoices, payment receipts, payout records, refund records
- Bounty payout history (amounts, counterparties, dates)
- Tax and 1099 reporting data
- Anti-fraud and abuse records where we have a reasonable belief of a policy violation
These records are minimized — we keep only what financial and legal regulations require, and they are not used for any product or marketing purpose.
Other Retention Rules
- Active accounts: Your data is retained as long as your account is active
- Contact import data: Optional imported-contact data may include hashed contact identifiers, contact names, match status, and import timestamps; it is deleted or anonymized when you request deletion of imported-contact data or close your account, subject to abuse, safety, and legal retention needs
- SAI processing logs: 90 days, then auto-purged (see Section 6)
- SAI memory and context: User-configured retention applies to supported memory tiers when enabled; conversations, knowledge, source records, and derived indexes otherwise follow their owning surface, account, and Section 6 rules
- CRS score history and ranking receipts: Retained while the relevant account or authorized scope is active, then removed or anonymized under this section unless narrower legal, fraud, security, or dispute retention applies
- Analytics data: Aggregated and anonymized analytics are retained indefinitely. Individual-level analytics are retained for 26 months (GA4 default)
- Backups: Encrypted backups are purged according to our backup retention schedule, typically within 35 days of account deletion
12. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you
- Correction: Request correction of inaccurate or incomplete data
- Deletion: Request deletion of your personal data (subject to the financial-records retention described in Section 11). You can delete your account inside the app at Settings > Personal Data > Delete Account, via our web deletion form (no sign-in required), or by emailing privacy@sorcrr.com.
- Portability: Request your data in a machine-readable format
- Objection: Object to processing of your data for certain purposes
- Withdraw consent: Withdraw consent for optional data processing (e.g., contact import, calendar access)
To exercise any of these rights, contact us at privacy@sorcrr.com. We will respond within 30 days.
13. GDPR & European Privacy Rights
If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, the following additional rights and disclosures apply under the General Data Protection Regulation (GDPR).
Lawful Basis for Processing:
- Contract Performance — Processing necessary to provide Sorcrr’s core services (account management, job matching, payments)
- Legitimate Interest — Processing for security, fraud prevention, and platform improvement
- Consent — Contact import, calendar access, analytics where consent is required, personalization, and marketing communications (you may withdraw app-level consent via Settings > Privacy where available; public-web analytics choices are controlled through public consent controls where available, browser controls, or by contacting privacy@sorcrr.com)
Additional Rights:
- Right to lodge a complaint with your local data protection supervisory authority
- Right to request restriction of processing
- Right not to be subject to solely automated decision-making with legal or similarly significant effects where applicable; Sorcrr’s CRS, Open Algorithm, and SAI features are assistive and keep consequential decisions with human users
International Data Transfers: Your data is transferred to the United States for processing. We rely on Google Cloud’s Data Processing Agreement and Standard Contractual Clauses (SCCs) approved by the European Commission to ensure adequate protection of your data during international transfers. Stripe uses similar mechanisms for payment data.
14. Children’s Privacy
Sorcrr is not intended for users under the age of 16. We do not knowingly collect personal information from children. If we learn that we have collected data from a child under 16, we will delete it promptly. If you believe a child has provided us with personal information, please contact us at privacy@sorcrr.com.
15. International Data Transfers
Sorcrr operates primarily in the United States. If you access the Platform from outside the US, your data may be transferred to and processed in the United States. We rely on Google Cloud’s Data Processing Agreement and Standard Contractual Clauses (SCCs) to ensure adequate data protection for international transfers. Stripe uses similar mechanisms for payment data.
16. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated effective date. For material changes, we will provide notice through the Platform or via email. Your continued use of Sorcrr after changes take effect constitutes acceptance.
17. Contact
For questions, concerns, or requests regarding your privacy:
- Privacy inquiries: privacy@sorcrr.com
- General support: privacy@sorcrr.com
- Legal: legal@sorcrr.com
- Company: SOSUITE LLC, 312 W 2nd St, Unit #A448, Casper, WY 82601