Privacy Policy for Sophia AI
MoboDevs ("we", "our", or "us"), operating under mobodevs.net, values the privacy of every user who downloads, installs, or interacts with the Sophia AI Voice Assistant Windows desktop application ("Sophia", "Software").
This Privacy Policy describes what information is collected, how it is used, how it is safeguarded, and how we strictly adhere to Google API Services User Data Policies regarding Google OAuth 2.0 authentication.
1. Purpose of Sophia AI
Sophia AI is a desktop-based voice assistant for Microsoft Windows designed to execute local OS tasks (volume adjustment, window management, application launching), web research, and voice-assisted productivity through LiveKit WebRTC and AI language models.
2. Google OAuth 2.0 Authentication & User Data
Sophia AI integrates Google OAuth 2.0 ("Sign in with Google") to verify the user's identity during initial setup.
When you choose to authenticate via Google, we request access only to non-sensitive, standard OpenID profile information:
- Google Account ID: A unique numerical identifier to verify account uniqueness.
- Full Name: Used to personalize voice responses and display within the app.
- Email Address: Used to associate your authorized software license with your account.
- Profile Picture URL: Used to render your avatar icon in the desktop settings modal.
No Sensitive Scopes Requested: Sophia AI does not request access to Google Drive, Gmail, Google Calendar, Contacts, location tracking, or any other sensitive or restricted Google APIs.
3. How Your Data is Stored & Processed (Local-First)
Sophia is architected as a local-first desktop application:
- All authentication tokens, profile details, and user settings are stored locally on your physical computer under
%APPDATA%\Sophia\data. - We do not operate remote tracking servers that log your voice conversations or system interactions.
- Voice audio is streamed directly to your configured LiveKit server endpoint in real-time and is not stored or shared for advertising.
4. Data Sharing & Third-Party Disclosure
We hold a strict zero-data-monetization policy:
- We NEVER sell, rent, lease, or trade your personal information or Google user data to third parties.
- We do not share user data with advertising networks, data brokers, or marketing platforms.
- We do not use Google user data to train generalized AI models.
5. Google API Services User Data Policy Compliance
Sophia AI's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
6. How to Revoke Access or Delete Data
You retain full control over your Google credentials at all times:
- In the Desktop App: Open Sophia Settings and click "Sign out". This immediately clears your local session credentials.
- Via Google Account: You can revoke Sophia AI's access at any time by visiting your Google Security Dashboard at https://myaccount.google.com/permissions.
- Data Deletion: Deleting the
%APPDATA%\Sophiadirectory permanently removes all locally stored data, memories, and tokens from your machine.
7. Security Safeguards
We employ robust industry-standard safeguards including HTTPS/TLS 1.3 encryption for OAuth token exchanges, Content Security Policies (CSP) to block unauthorized remote script injections, and Windows DPAPI encryption for local credential storage.
8. Contact Information
If you have any questions, feedback, or data privacy requests concerning Sophia AI or this Privacy Policy, please contact:
- Developer: MoboDevs
- Email: git.mobodevs@gmail.com
- Support Email: support@mobodevs.net
- Website: https://mobodevs.net