Privacy Policy
Last updated: March 4, 2026
Soketify ("we," "us," or "our") operates the Soketify managed WebSocket infrastructure service, accessible at soketify.com. This Privacy Policy explains what information we collect, how we use it, with whom we share it, and your rights regarding that information. By using Soketify you agree to this policy.
1. Information We Collect
Account & Identity
When you create an account via Google or GitHub OAuth, we receive your name, email address, and profile picture from the OAuth provider. We store your name and email; the profile picture is used only during your session and is not persisted.
Usage & Technical Data
We collect data about how you use the service: WebSocket apps you create, connection counts, message volumes per billing period, peak concurrent connections, and hourly and daily usage snapshots. We also collect standard server logs (IP address, request timestamps, HTTP status codes) for security and operational purposes.
Billing & Payment
We collect subscription plan information, billing cycle dates, and payment event history (transaction IDs, amounts, plan at time of payment). Credit card and banking details are processed directly by Wompi and are never stored by Soketify.
Cookies & Local Storage
We use session cookies necessary to keep you logged in. We do not use tracking, advertising, or analytics cookies. You may disable cookies, but the service will not function without session cookies.
2. Google API User Data
This section specifically addresses our use of data received from Google APIs, in compliance with the Google API Services User Data Policy.
What we access
When you sign in with Google, we request access only to your basic openid, profile, email. We do not request access to Gmail, Drive, Calendar, or any other Google product.
How we use it
Google API data is used exclusively to create and authenticate your Soketify account. We do not use Google API user data to serve advertisements, build advertising profiles, or train machine learning models.
Sharing
We do not share, sell, or transfer Google API user data to third parties, except to our infrastructure providers (Cloudflare, Hetzner) solely to operate the authentication service. We do not allow humans at Soketify to read your Google API data without your explicit consent, except as required for support you specifically request.
Retention & deletion
Your name and email received from Google are retained for as long as your Soketify account exists. When you delete your account, all Google API user data we hold is permanently deleted within 30 days. You may also revoke Soketify's access to your Google account at any time via Google Account Permissions. Revoking access does not delete your Soketify account; it only prevents future Google sign-in.
3. How We Use Your Information
- To create and manage your account and authenticate you
- To provide, operate, and improve the Soketify service
- To calculate usage, enforce plan limits, and process billing
- To send transactional emails (usage alerts, payment receipts, service notices)
- To respond to support requests and troubleshoot issues
- To detect and prevent fraud, abuse, and security incidents
- To analyze aggregate, anonymized usage patterns to improve the service
- To use your company name and/or logo as a commercial reference (e.g., on our website or in sales materials), subject to your right to opt out at any time by contacting us
- To feature anonymized or aggregated usage data in public benchmarks, demos, or marketing materials
4. Information Sharing and Disclosure
We do not sell your personal information. We share information only in the following circumstances:
Service Providers
We share data with the following third-party providers who process it on our behalf under confidentiality obligations:
- Cloudflare — Application hosting, edge network, and database (D1). Data processed in the United States.
- Hetzner — Virtual private servers hosting WebSocket infrastructure. Data processed in the United States (us-east, us-west regions).
- Wompi — Payment processing for subscribers. Your billing information is subject to Wompi's privacy policy.
- Resend — Transactional email delivery (usage alerts, payment receipts).
- Google — OAuth authentication (as described in Section 2).
- GitHub — OAuth authentication. We receive your name, email, and GitHub username.
Business Transfers
In the event of a merger, acquisition, or sale of all or substantially all assets, user information may be transferred as part of the transaction. We will notify you via email before your information is subject to a materially different privacy policy.
Legal Requirements
We may disclose information if required by law, regulation, legal process, or governmental request, or to protect the rights, property, or safety of Soketify, our users, or the public.
With Your Consent
We may share information for purposes not described in this policy when we have your explicit consent.
5. International Data Transfers
Soketify is operated from and its primary infrastructure is located in the United States (Cloudflare edge, Hetzner US data centers in us-east and us-west regions). If you are accessing the service from Central America or any other region, your information will be transferred to and processed in the United States. By using Soketify you explicitly consent to this transfer. We implement appropriate technical and organizational safeguards to protect your data during transfer and storage.
6. Data Retention
- Account data — Retained until you delete your account. Deleted within 30 days of account deletion.
- Usage data (hourly/daily snapshots) — Retained for 24 months, then automatically purged.
- Payment records — Retained for 7 years to comply with financial record-keeping regulations.
- Server logs — Retained for 90 days for security and debugging purposes.
- Email logs — Retained for the duration of your current billing period for deduplication, then purged.
7. Security
We implement industry-standard security measures including TLS 1.3 encryption for all data in transit, HMAC-SHA256 for API authentication, secure session management, and access controls limiting data access to authorized personnel. No transmission over the internet or method of electronic storage is 100% secure. We will notify affected users without undue delay in the event of a data breach affecting your personal information.
8. Your Rights
Depending on your location, you may have the following rights:
- Access — Request a copy of the personal data we hold about you.
- Correction — Request correction of inaccurate personal data.
- Deletion — Request deletion of your personal data. You may also delete your account directly from the dashboard.
- Portability — Request your data in a portable format.
- Opt-out of commercial references — Request that we remove your company name/logo from any marketing materials.
California residents (CCPA): You have the right to know what personal information we collect, to opt out of any sale of personal information (we do not sell personal information), and to non-discrimination for exercising your rights. To exercise your CCPA rights, contact us at the address below.
To exercise any of these rights, email privacy@soketify.com us. We will respond within 30 days.
9. Children's Privacy
Soketify is not directed to children under 16. We do not knowingly collect personal information from children under 16. If we learn that we have collected personal information from a child under 16, we will delete it promptly. If you believe we have collected information from a child under 16, please contact us at privacy@soketify.com.
10. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email (at the address associated with your account) and by updating the "Last updated" date at the top of this page at least 14 days before the change takes effect. Continued use of Soketify after the effective date constitutes acceptance of the updated policy.
11. Contact
For questions, data requests, or concerns about this Privacy Policy, contact us at:
Soketify