SVRGN Inc.

Privacy policy

Last updated 2026-08-31

Who we are

SVRGN Inc. (“Sovereign”, “we”) builds and operates software that small businesses use to run their own operations. Sovereign exists to provide real time business intelligence. This policy explains what information we collect, why, who we share it with, and how to have it deleted.

For any question about this policy, or to exercise any right described in it, write to hello@svrgninc.com.

The two kinds of information we hold

It matters which of these applies to you, because the answers differ.

First, information about the people we do business with: a prospective or current customer’s name, email address, company, and the answers they give during onboarding, along with the agreements they sign. We collect it because we cannot open an account or send an invitation without it.

Second, information from the business systems a customer connects to us — their advertising accounts, their social media Pages, their commerce and email platforms. A customer grants us access to their own accounts so that our software can do the work they hired it to do. We act on that data on the customer’s instructions and for no other purpose.

Facebook and Instagram data

When a business chooses to work with us on Facebook or Instagram, it adds SVRGN Inc. as a partner to its own Meta Business Portfolio and shares specific assets with us — typically a Facebook Page, an Instagram business account, and an advertising account. We never ask for a customer’s Facebook or Instagram password, and we never log in as them. The business grants the access, and the business can withdraw it at any time from its own Meta Business settings, without involving us.

We request only the permissions listed below, and we use each one only for the purpose stated. We do not sell this data, we do not use it for advertising to anyone other than the business that owns it, we do not use it to build profiles of individuals, and we do not combine one business’s Meta data with another’s.

Permission we requestWhat it gives us access toHow long we keep it
pages_show_listThe names and IDs of the Facebook Pages a business has shared with us.Held while the business is a client; removed when they end the partnership.
pages_read_engagementPosts, comments and engagement counts on those Pages.Read on demand to prepare drafts and reports. Aggregate figures are kept; comment text is not stored.
pages_manage_postsThe content we publish on the business's behalf, after the business approves it.The approved draft and the publication record are kept as the business's audit trail.
instagram_business_basicThe username and ID of the connected Instagram business account.Held while the business is a client.
instagram_business_content_publishThe media and captions we publish on the business's behalf, after approval.The approved draft and the publication record are kept as the business's audit trail.
business_managementThe structure of the assets a business has shared with us — which Page, which ad account.Held while the business is a client.
ads_readCampaign structure and performance figures for the ad accounts shared with us.Performance figures are kept to report on results over time.
ads_managementCampaigns, budgets and adjustments we make from plans the business approved.The approved plan and the change record are kept as the business's audit trail.
read_insightsAggregate Page and Instagram insights — reach, impressions, follower counts.Aggregate figures are kept to report on results over time.

Deleting Facebook and Instagram data

There are two routes, and they do different things.

If you are a business working with us, removing SVRGN Inc. as a partner in your Meta Business settings ends our access immediately. To have the data we already hold deleted as well, write to hello@svrgninc.com and we will delete it and confirm in writing.

If you are an individual Facebook or Instagram user, you can send us a deletion request through Meta by removing the Sovereign app from your Facebook settings, which sends the request to us automatically. You can also request deletion directly at https://os.svrgninc.com/api/meta/data-deletion. Either way we act on the request, then give you a confirmation code and a status page that explains, in plain language, what we searched and what we found.

We should be straightforward about the likely answer: Sovereign works with businesses rather than with individual account holders, so in almost every case we hold no personal data about an individual Facebook or Instagram user, and the status page will say exactly that. The request is still recorded and answered.

Who else processes this data

We use service providers to run Sovereign. Each one processes data only to provide its service to us, and we remain responsible for what they do with it.

These process data for every customer:

  • Railway — hosting for the Sovereign application and for each customer’s own deployed system, including the encrypted storage of the credentials a customer has connected. This is the most sensitive provider on this list.
  • Upstash — the database holding account records, onboarding records and our audit log.
  • Anthropic — the AI models that draft content and answer questions inside the product. Prompts may contain business data a customer has connected. This data is not used to train the models.
  • GitHub — source-code hosting for each customer’s deployed system.
  • Hostinger — outbound email and our public website.
  • DocuSign — signing of customer agreements.
  • Stripe — payment processing for our fees. Stripe receives the billing contact and plan details; card numbers go to Stripe directly and we never hold them.
  • Cloudflare — secure network transit, where used.
  • Sentry — error and performance monitoring. Configured to exclude personal identifiers by default.
  • Vercel — a legacy host that now only redirects old links to our current address.

Providers used only for particular features

These process data only where a customer uses the feature that needs them. If a customer does not use the feature, the provider receives nothing.

  • Deepgram — speech-to-text, for voice interviews and voice front-desk.
  • Twilio, including SendGrid — transactional email, and phone, SMS and call handling.
  • EasyPost — shipping labels, rates and tracking, for fulfilment workflows.
  • Zapier — relaying event notifications to external channels a customer has configured.

One provider that is not ours

Plaid appears in some customers’ bank and supplier-payment workflows. In those cases the customer connects Plaid under their own agreement with Plaid; Plaid is the customer’s provider, not ours, and Plaid’s own privacy notice governs it.

Phone calls and text messages

Some customers use Sovereign to answer their business phone line. If you call or text one of those numbers, you are contacting that business — not us. The business decides what its line does; we run it on their instructions. This section is what happens to that call.

Every call opens by telling you which business you have reached, that you are speaking with an automated assistant, and that the call may be recorded. That announcement is fixed in our software. A business cannot shorten it, switch it off, or ask us to.

Call recording is off unless the business has switched it on. While it is off, nothing is recorded and nothing is transcribed — there is no setting in between the two. Where a business has switched it on, the announcement above has already played before any recording begins; a call on which it did not play is not recorded.

What you say on the call, and the text of the messages you send, is processed by an AI model so that it can understand you and compose a reply, and by a speech-to-text provider where speech is involved. Anthropic and Deepgram are those providers, and they are listed above. That content is not used to train anyone’s models, is not used to advertise to you, and is never combined with another business’s data.

We record that you contacted the business, when, and by which route — a call or a text — because that is the basis on which the business is allowed to reply to you. We do not record it as permission to market to you, and the system cannot send you marketing. If you reply STOP to a text, we record that too, and the business stops texting you.

Sovereign runs a phone number of its own. A call or a message to that number reaches us rather than a customer, is passed on to the person who runs Sovereign, and is not recorded.

Mobile numbers are never sold, and are never shared with anyone for their own marketing or added to a lead list. Where a number reaches a provider — Twilio to carry the message, and the providers named above to process what the message says — it is to do that work for us, and for no purpose of their own.

How often you hear from us by text depends on what you do. A business replies when you contact it; Sovereign’s own line replies when you write to it; and where a business has switched forwarding on, the person who runs it is told when someone has texted the line. There is no recurring message series and no scheduled campaign, so message frequency varies.

Message and data rates may apply. Reply STOP to any text to stop it, and HELP for help.

How long we keep things

Business system data — including anything read from Facebook or Instagram — is kept for as long as the business is our customer, and deleted on request when the relationship ends.

Records of customer agreements, and records of deletion requests we have answered, are kept indefinitely. Both are evidence that we did what we said we would do, and deleting them would destroy the only proof a customer or a regulator could ask us for. A deletion-request record contains a one-way cryptographic digest of the identifier that accompanied the request, never the identifier itself.

Our audit log records that an action happened — which action, when, and under whose authority. It does not record the contents of a customer’s business data.

For customers whose phone line we answer: call recordings, where that business has switched recording on, are kept for 30 days. Transcripts of calls and messages, and the record of who contacted the business and when, are kept for 13 months.

Records of consent — that a person contacted a business, and that they asked it to stop — are kept for five years, and are kept even after that business stops being our customer. They outlive the conversation on purpose: they are the evidence that a message was sent on a lawful basis, and the period in which anyone can raise that question is longer than the conversation itself.

Your rights

You can ask us what we hold about you, ask us to correct it, and ask us to delete it. Write to hello@svrgninc.com. We will respond within 30 days, and we will not charge you for it.

If we ever cannot delete something you have asked us to delete, we will tell you which item and why, rather than declining in general terms.

Security

Access to customer systems is held per customer and stored encrypted. Our own operator access requires a second factor. We keep a tamper-evident record of every consequential action taken inside the product, so that a customer can see what was done on their behalf and when.

We do not claim a security certification we have not obtained. If you need our current security posture in writing for a procurement review, write to hello@svrgninc.com and we will send you what we have.

Children

Sovereign is a product for businesses. It is not directed at children, and we do not knowingly collect information from anyone under 18.

Changes to this policy

When we change this policy we update the date at the top of the page. If a change materially affects what we do with a customer’s data, we tell that customer directly rather than relying on them to notice.

SVRGN Inc. · hello@svrgninc.com · svrgninc.com