All legal documents

Privacy Policy

Privacy Policy

Document version: vPRIV-2.0 · Effective date: 2026-07-29 · Last updated: 2026-07-29

This Privacy Policy explains how Sorxi LLC, a Wyoming limited liability company ("Sorxi," "we," "us," or "our"), collects, uses, shares, and protects personal information when you use the Sorxi One platform, the website at sorxi.com, and the Sorxi application (together, the "Service"). It is a single, consolidated policy: it includes our cookie disclosures (Section 7), the list of the third-party service providers we use (Section 9), and your privacy rights (Section 12). Read it together with the Terms of Use and the No-PHI and Confidentiality Policy. Capitalized terms have the meanings given in the shared glossary.

By using the Service, you agree to the collection and use of information as described in this Policy.


1. Who this Policy applies to

This Policy applies to individuals in the United States who use the Service, including nurses and other healthcare professionals, students, healthcare educators, healthcare leaders, and the individual contacts of a Client or Organization that provisions the Service. The Service is offered from the United States and is directed to United States residents. It is not intended for anyone under 18. The Service is US-only at launch and is not directed to individuals outside the United States.

Where an Organization provisions the Service for its people, this Policy governs how Sorxi handles personal information as part of operating the Service. Your Organization may have its own privacy practices that also apply to you; those are the Organization's responsibility, not Sorxi's.

2. Information we collect

Account information. Your name, email address, and professional credentials (which may include your specialty, unit, organization, and role). We do not use or store passwords; authentication uses a magic link sent to your email or Google sign-in.

Usage data. The questions you ask the Workbench, the Outputs you receive, the tools you use (Prep, Process, and Build), and your saves, exports, and other engagement. Some usage data is stored as structured signals that record how the Service was used without keeping a copy of the underlying question or answer text (see Section 10).

Technical data. Your IP address, device type, and browser, collected automatically.

Subscription and entitlement data. Your plan, entitlements, and whether you are on the Free Tier or a paid Subscription. Payment card processing is handled by Stripe; Sorxi never receives or stores full payment card numbers.

Nursing license information. If you take a Sorxi continuing education activity, we collect your registered-nurse license number and your licensing state. These are saved to your profile so you do not have to enter them again for a later activity, and you can view or change them there.

Continuing-education purchase and completion records. For each activity, we record which activity you took, the date you completed it, the contact hours awarded, and your name, license number and licensing state. California requires an approved continuing-education provider to keep these records, so they are retained differently from the rest of your account information — see Section 10.

A summary of the categories of personal information we collect and the purposes for which we use them, provided as a notice at collection for U.S. state-privacy purposes, appears in Section 12.

3. Protected Health Information (PHI)

Sorxi does not collect or store PHI at launch, and you must not enter PHI into the Service.

Not entering PHI is your responsibility. Sorxi does not machine-screen your content for PHI. Sorxi is not HIPAA-compliant, and no Business Associate Agreement (BAA) is in effect. Support tickets and the Get Backup / Expert channel likewise rely on the no-PHI rule.

Sorxi is designed at launch not to receive, process, or store PHI, and it does not offer a HIPAA-covered PHI workflow. Sorxi will handle PHI only under a written covered-data arrangement, including a signed Business Associate Agreement (BAA), for an Organization. The Service is not HIPAA-compliant at launch, and you must not use it as a system of record for any patient information.

Future PHI pathway. Any future capability that would allow PHI to be handled is gated behind a control that is not active at launch. Before that pathway can be turned on, Sorxi must have in place, among other requirements, signed BAAs with each relevant Subprocessor, a zero-retention data-processing agreement with the embeddings provider, healthcare-attorney review, errors-and-omissions insurance, lawyer-reviewed consent copy, and point-in-time-recovery backups. See the No-PHI and Confidentiality Policy.

Process tool and de-identified learnings. The Process tool lets you debrief a moment involving AI. It stores only a de-identified learning. Sorxi is designed not to store patient-specific or incident-specific records, or a registry of AI errors or near-misses. Where the Service records that a professional acted safely (for example, that an escalation was raised, a refusal was given, or a check was completed), that record is about the professional's own action and is not tied to a patient or a specific event.

4. How we use information

We use personal information to:

  • operate, maintain, and personalize the Service;
  • generate Outputs in response to your use of the Workbench;
  • improve our tools and Content using de-identified data;
  • provide support and respond to your requests;
  • protect the security and integrity of the Service, including detecting and preventing abuse and fraud; and
  • comply with legal obligations and enforce the Terms of Use.

We do not use your personal information to make legally or similarly significant decisions about you through solely automated means without a lawful basis and appropriate safeguards.

5. Artificial-intelligence processing

Outputs are generated by Anthropic's Claude models, which Sorxi uses on a prompt-only basis. Sorxi does not fine-tune models on your data. When you use the Workbench, the prompt is sent to Anthropic for processing under a data-processing agreement that requires zero data retention and prohibits using Sorxi data to train models. Because PHI must not be entered by you (Section 3), prompts should not contain PHI.

6. How we share information

We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We share information only as follows:

  • Service providers (Subprocessors). With the providers that operate the Service on our behalf, each under a data-processing agreement and permitted to use the information only to provide services to us. They are listed in Section 9.
  • De-identified, cohort-level aggregate data. We may create and use de-identified, cohort-level aggregate data (grouped by attributes such as specialty, unit type, region, or organization-size band, never Organization-identified at launch, with a suppression threshold so any surfaced insight reflects a cohort of at least five). This data does not identify you. We share it with third parties only where you have consented (Section 8).
  • Legal and protective disclosures. Where required by law or legal process, or where we believe in good faith that disclosure is necessary to protect the rights, property, or safety of Sorxi, our Users, or the public, or to investigate fraud or a security incident.
  • Business transfers. In connection with a merger, acquisition, financing, or sale of assets, subject to this Policy or a successor policy with comparable protections.

7. Cookies and tracking

Sorxi uses a small number of cookies and similar technologies:

  • Strictly necessary — for authentication (your magic-link or Google session) and core functionality. These cannot be disabled without breaking the Service.
  • Preferences — to remember settings you choose.
  • First-party analytics — a minimal, privacy-preserving measure of usage on the marketing website.

We do not use third-party advertising trackers, and we do not run third-party analytics on authenticated application routes. We honor Global Privacy Control (GPC) and similar browser opt-out signals, and we do not sell personal information through cookies. We do not respond to Do Not Track (DNT) browser signals, which lack a settled standard; GPC is the signal we honor. You can control cookies through your browser settings; disabling strictly necessary cookies will prevent sign-in.

8. Consent model

For sharing of de-identified product-improvement data and for the email digest, Sorxi uses an opt-out model: both are on by default and can be turned off at any time in Manage Account. We capture your consent through a click-wrap agreement presented during your first authenticated session, and we record the version of the billing terms you accepted at that time. When this Policy or the Terms of Use change materially, we re-prompt you before you continue using the Service.

9. Service providers (Subprocessors)

We use the following third-party service providers to operate the Service. Each processes only the data needed for its function, under data-processing terms with that provider. Business Associate Agreements will be in place with the relevant providers before any PHI handling is enabled (not active at launch).

Where an additional provider supports the Service's infrastructure — for example identity sign-in, key management, or code and content hosting — Sorxi applies the same data-processing requirements and lists it here once its terms and processing locations are confirmed. The notice commitments below apply to those providers as well.

ProviderFunctionData processedTerms
AnthropicAI generation of OutputsPrompt inputs and generated OutputData-processing agreement requiring zero retention; not used to train models
SupabaseDatabase, authentication, file storageAccount data, usage records, artifacts, uploadsDPA now; BAA before any PHI
VercelApplication hosting and serverless functionsRequest and runtime dataDPA now; BAA before any PHI
CloudflareDomain routing and proxying, bot protection on sign-in, edge processing, and video delivery for continuing-education activitiesRequest and connection data, including IP address; bot-check tokens; video playback requestsDPA now; BAA before any PHI
ResendTransactional email (magic links, receipts, alerts, continuing-education certificates)Email address and message content, including certificate attachments (name, license number, activity, hours)DPA now; BAA before any PHI
StripePayment processing and subscription billingPayment method and transaction data (no full card numbers to Sorxi)Stripe DPA; PCI-DSS
Embeddings provider (not yet selected)Vector indexing of documents when document features are enabledDocument text and chunksZero-retention DPA; BAA if PHI; not active at launch
SentryApplication error monitoringError diagnosticsNo PHI

We will update this list when it changes. Before a new Subprocessor begins processing, we will notify Organizations and Users at least 30 days in advance where the change is material, and affected Organizations may object under their agreement.

10. Data retention

We keep personal information for as long as needed to provide the Service and for the purposes in this Policy, then delete or de-identify it, subject to the following:

  • Raw message text is kept under tight access controls and purged on a short time-to-live basis of 90 days.
  • Structured usage signals are append-only and retained; they contain no copy of the question or answer text.
  • Generated artifacts you save are retained as your library asset while your account is active or until you delete them.
  • Uploads are owner-scoped and can be hard-deleted by the owner.
  • Dormant accounts have their personal data and any uploads purged; we may retain a limited business-contact record.
  • Continuing-education records are kept for four years after the activity concludes. California requires an approved continuing-education provider to retain the participant's name, license number, the activity, its date, and the hours awarded (16 CCR §1454(f)). These records are kept even if you delete your account, because retaining them is a legal obligation rather than a choice.

Your license number and licensing state exist in two places, and deletion treats them differently. The copy on your profile — the one saved so you need not retype it — is deleted with your account, like the rest of your profile. The copy inside each completed continuing-education record is retained for the four years the regulation requires; we remove the link between those records and your account and keep only the fields the regulation requires. This is the one category a deletion request does not remove; everything else in this Section and in Section 12 continues to apply. The participant-facing terms are in the Continuing Education Participant Policy.

11. Security

We use administrative, technical, and physical safeguards designed to protect personal information, including encryption in transit and at rest, database row-level isolation between tenants, least-privilege access controls, magic-link and Google authentication with no stored passwords, security monitoring, and error logging through Sentry. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

12. Your U.S. privacy rights

Depending on your state of residence, you may have some or all of the following rights: to access or know the personal information we have collected; to correct inaccurate personal information; to delete your personal information; to obtain a portable copy (a self-service export is planned); to opt out of the sale or sharing of personal information (as noted in Section 6, we do not sell or share for cross-context behavioral advertising); to opt out of targeted advertising; and to opt out of certain profiling with legal or similarly significant effects. The rights available to you vary by your state of residence.

Notice at collection. We collect the categories described in Section 2 (identifiers such as name and email; professional and employment-related information, which includes your registered-nurse license number and licensing state where you take a continuing education activity; usage data, including the questions you ask the Workbench, the Outputs you receive, and your saves and exports; internet and device activity; and commercial and subscription information). We use them for the purposes in Section 4, retain them as described in Section 10, and do not sell them or share them for cross-context behavioral advertising. Completed continuing-education records are subject to a four-year legal retention requirement and are not removed by a deletion request, though the copy of your license information held on your profile is — see Section 10.

How to submit a request. Contact help@sorxi.com. We will take reasonable steps to verify your identity before acting, which may include confirming information associated with your account, and you may use an authorized agent where permitted by law. If we decline your request, you may appeal by replying to our response or contacting help@sorxi.com. We will not discriminate or retaliate against you for exercising your privacy rights. Our internal handling of these requests is described in the Privacy-Rights Request SOP.

California residents (CPRA). You have the rights above under the California Consumer Privacy Act, as amended by the California Privacy Rights Act. Certain professional credentials may be treated as sensitive personal information; we use such information only to provide and improve the Service and for the other purposes in this Policy, and not to infer characteristics about you. Your registered-nurse license number is not treated as sensitive personal information: it is a professional license that the California Board of Registered Nursing itself publishes in its public license-verification lookup. The continuing-education record it forms part of — which activity you purchased, when, and that you completed it — is not public, and we treat that record as personal information. Under California's "Shine the Light" law, you may request information about disclosures of personal information to third parties for their direct-marketing purposes; Sorxi makes no such disclosures. We honor GPC opt-out signals.

13. Children

The Service is not directed to, and is not intended for, anyone under 18. We do not knowingly collect personal information from anyone under 18, and we will delete it if we learn we have.

14. Data-breach notification

Sorxi maintains an internal procedure for responding to security incidents and personal-data breaches. If a breach affecting your personal information occurs, we will notify affected individuals and applicable authorities as required by, and within the timelines set by, applicable law.

15. Changes to this Policy

We may update this Policy from time to time. When we make a material change, we will update the "Last updated" date and the document version shown at the top of this Policy, and, where required, re-prompt you (Section 8). Your continued use of the Service after an update means you accept the updated Policy.

16. Contact

Questions about this document: help@sorxi.com.

  • Sorxi LLC
  • Email: help@sorxi.com
  • Phone: (201) 687-9261
  • Mailing address: 30 N Gould St #41294, Sheridan, WY 82801