← Back to home

Privacy Policy

How SoWhatify handles your data — in the Chrome extension, on this website, and through Claude.

Last updated: 14 August 2026

SoWhatify turns web page content into personal implications using a profile you build. There are three ways to use it, and they do not all store data in the same place:

  • the Chrome extension, which reads the page you are on and calls the AI provider you configured;
  • this website, where you build lenses and personas, edit your profile, and read your history;
  • Claude or another MCP client, which runs your lenses in a conversation.

Signed out, the extension keeps everything on your device. Signing in is the line that matters: an account is what lets all three see one profile, one lens library and one history, and that sharing only works because the account holds that data on our server. The sections below say exactly what crosses that line.

Data SoWhatify handles

Data Where it is stored When it leaves your device
Profile (display name, year of birth, country, role, industries, topics, companies, holdings, real estate, family context, watchlists, and similar fields you enter) Your browser (chrome.storage.local) on this device. Once you sign in, also on our server — that copy is what the website and Claude read. Sent to whichever model runs an analysis; synced to our server while you are signed in with a verified email (see Account sync below)
Preferences (language, tone, reading time, excluded topics, model choice) Same as profile Same as profile
API keys (OpenAI, Anthropic, Gemini, OpenCode) Your browser on this device — plus our server only for a key you delegate to a Dropbox Never sent to our servers, unless you deliberately delegate a key to a Dropbox you create (see below). Otherwise used only to call the provider you configured, and never included in cloud sync.
PDF files you choose to analyze Read in your browser on this device. The file itself is not uploaded. No — the text is extracted on your device, and only that text is sent to the AI provider you chose, like any other page content. If you switch PDF reading to our server in the options, the file is uploaded to extract the text and then deleted immediately, never stored, indexed, or reused.
Page content you analyze (article text, the text you select, or clipboard text when you choose the clipboard source) Held in memory for the analysis. The result, and an excerpt of the source it was based on, are saved to your history — see the next row for where that lives. Sent to whichever model runs that analysis: the provider you configured in the extension, or Claude when you run a lens from an MCP client. If you use Chrome AI (on-device Gemini Nano), it does not leave your device.
Analysis history (your past results) Your browser on this device (most recent 100). While you are signed in, also on our server, so the extension, this website and Claude show one history. Signed out, it stays on this device. Signed in, each entry is uploaded: the result text, an excerpt of the source, the page address, and which lens and model ran it. Anything you run from Claude is created on our server to begin with.
MCP access token (the personal URL you paste into Claude or Cursor) In your Claude or Cursor configuration. We store only a SHA-256 hash of it, so the URL cannot be recovered from our server — that is why a regenerated URL is shown once. Sent by your MCP client on every request, to identify the account
Account & marketplace data (email for sign-in, lenses/chains/personas you create or publish) Our server, when you sign in or publish Created intentionally by you when you sign in, sync, or publish

AI providers

When you run an analysis with a cloud model, the page content, your selection or clipboard text, and relevant profile context are sent to the provider you selected — OpenAI, Anthropic, Google (Gemini), or OpenCode — using your own API key. Their handling of that data is governed by their privacy policies. Choosing Chrome AI keeps the analysis fully on your device.

Running a lens from Claude works differently — there is no API key and we call no provider. See Claude and other MCP clients below.

PDF analysis

PDFs are read on your device, in the extension itself, using Mozilla's pdf.js. The file is never uploaded. Only the extracted text leaves your browser, and only to the AI provider you selected — exactly like any other page content.

The extension options offer a server setting for PDF reading, useful when a document will not read correctly on your device. Choose it and the file is uploaded to our server (sowhatify.com) to extract the text, then deleted as soon as extraction finishes — success or failure. We do not store, index, back up, or reuse it, and we do not read its contents beyond extracting the text returned to your browser. The default setting also falls back to the server if reading on your device fails unexpectedly; set PDF reading to On this device only if you want that never to happen.

Dropboxes

A Dropbox is a page you create and share, so that someone without a SoWhatify account — a client, a customer — can submit a document and have it read through one of your lenses. It is the one part of SoWhatify where we run the AI model ourselves, because the person submitting has no account and no key of their own, and you are not there when they submit.

The provider key you attach. It is encrypted before storage and tied to that one Dropbox, and nothing reads it back out — not the page, not our API, not your account export. Changing it means replacing it. You can forget it at any time from the Dropbox's page, which also switches the Dropbox off. We recommend attaching a dedicated key with a spending cap rather than your main account key, and the form says so.

What is kept, and for how long. A submission — the extracted text, the analysis, and any answers to questions you asked on the form — is kept for the retention window the Dropbox's owner set, from one day up to a year (three months by default). When that window passes, the visitor's result link stops working and the record is removed automatically; you can also delete a submission yourself at any time before then. Uploaded files themselves are deleted as soon as the text is extracted, exactly as described under PDF analysis. Deleting the Dropbox deletes its submissions with it, and deleting your account deletes both.

If you run a Dropbox, the documents people send you are your responsibility. They are being handled on your behalf, under your provider key, and it is you who decides how long to keep them. The person submitting is shown a link to their own result which expires on a schedule you set, and which stops working the moment the submission is deleted.

Dropbox pages are not indexed by search engines and are excluded in our robots.txt. The address is unlisted, and you can additionally require an access code.

Account sync

Signed out, the extension syncs nothing. Signing in with a verified email address turns it on: your profile and preferences are stored on our server (sowhatify.com) so the website, Claude and your other devices see the same thing. Profile sync is on by default once you are signed in — you are asked how to resolve the first sync, and you can switch it off afterwards in the extension options.

Your API keys are never synced. This is enforced on our side, not just promised: the sync endpoint rejects any request whose payload contains an API key, so a future bug in the extension still cannot upload one.

Analysis history is synced separately, and it follows being signed in rather than the profile-sync switch — there is currently no way to keep an account and keep history local. If you want history on this device only, use the extension signed out.

Claude and other MCP clients

Connecting Claude gives it a private endpoint into your SoWhatify library. Three things are worth knowing about where data goes on this path:

  • Claude is the model. We do not call Anthropic for you and we do not hold an Anthropic key on your behalf. Your lens, the profile fields that lens is allowed to read, and the text being analyzed are returned to your own Claude or Cursor client, and what that client does with them is governed by Anthropic's privacy policy (or your MCP client's).
  • Giving Claude a URL means our server fetches that page. When you hand Claude a link rather than pasted text, sowhatify.com requests it and extracts the readable content to use as the seed. That request comes from our server, not your browser, so it carries none of your cookies and cannot reach anything behind your logins.
  • Results are saved on our server. An analysis run through Claude writes to the same account history described above, which is how it also shows up in Chrome and on this website.

Publishing and account deletion are deliberately not available over MCP: lenses and personas created from a conversation are private, making something public takes a deliberate action on this website, and no MCP client can delete your account — see Your controls. You can revoke Claude's access at any time by regenerating your MCP URL on the account page.

Aggregated URL statistics (optional, off by default)

The options page includes a setting to share anonymous statistics about which pages are analyzed, used only to build a public “top pages” list. It is off unless you switch it on.

To be precise about what this records when enabled: the page address including its path, and whether you analyzed the whole page or a selection. Query strings are stripped before storage, so tokens or parameters in a link are not kept, and the stored record contains no account identifier — it cannot be tied back to you. It contains no profile data and no article content. You can disable it in the options at any time.

Website analytics (only if you accept)

The pages of this website can load Google Analytics (GA4). It records which pages are opened, the site you arrived from, your browser and device type, and an approximate location, and it sets cookies (_ga and _ga_…) so that several visits from the same browser count as one visitor rather than several. We use it for one thing: seeing which pages people actually read.

It does not run until you say yes. A short prompt asks on your first visit, and until you accept, nothing is requested from Google at all — not a script, not a cookie, not a background ping. Declining is a real no rather than a quieter yes, and it changes nothing else about how the site works. Your answer is remembered in one cookie of our own (sowhatify_consent, no identifier in it, a year for yes and six months for no), and Cookie settings in the footer reopens the prompt so you can change your mind either way. Advertising signals are switched off in the configuration, so this property cannot feed ad targeting even once you have accepted.

Nothing SoWhatify holds about you goes into it. Analytics sees the page you opened and nothing behind it — not your profile, not your API keys, not your history, and not the content of anything you analyze. We do not pass it your email address or your account identifier, so a visit is not linked to your account. Google derives the approximate location from your IP address and, per its GA4 documentation, does not store the address itself.

This is the website only. The Chrome extension contains no analytics code, and running a lens from Claude does not go through it either. Any content blocker, or your browser's own tracker protection, stops the script from loading — the website works normally without it.

What we do not do

  • We do not sell your personal data.
  • We do not use your data for advertising.
  • We do not transfer your data to third parties except the AI provider you choose, and only to deliver the analysis you request. The one other third party involved is Google Analytics, and it receives website usage only — never your profile, history, keys, or analyses (see Website analytics).
  • We do not read your API keys on our servers — they stay on your device. The single exception is a key you deliberately delegate to a Dropbox you created, which has to be stored so that page can answer people while you are not there (see Dropboxes). Your extension and website keys are unaffected: the sync endpoint refuses to store one at all.

Your controls

  • Edit or clear your profile, preferences, and API keys in the extension options at any time, or edit your profile on this website.
  • Clear your analysis history from the History tab.
  • Use the “Delete user and local data” action in the options to remove all extension data stored on this device.
  • Turn profile sync and aggregated statistics on or off independently.
  • Download everything the account holds — profile, lenses, chains, personas and saved analyses, as one JSON file — from the account page.
  • Delete the account from the same page. It removes the profile, every lens, chain and persona you own (including published ones), your history, and unlinks your Stripe customer record. It cannot be undone, so it asks you to type your email address to confirm (or, for an account with no email address, the word DELETE). Deletion always finishes on this website. The server accepts the request only from a page here, so neither the extension nor Claude nor any script holding a valid token can delete your account — even though they can otherwise act on it. An assistant connected over MCP can start a deletion and hand you a single-use link to the confirmation page, which is how an account created through Claude — one that has no email address to sign in with — can be deleted at all. Opening that link deletes nothing on its own; it expires in 30 minutes, and you still have to confirm here.
  • Revoke Claude's access by regenerating your MCP URL on the account page.

Contact

Questions about this policy or your data? Reach us through the support page.