Privacy Policy
Last updated 9 September 2026
Soravya is software that event organizers use to run their events. If you are attending an event, the organizer invited you and holds your details; we hold them on that organizer’s behalf. This page describes what we do with data across the whole platform.
Who is responsible for your data
For anything to do with an event you were invited to, the organizer is the data controller and Soravya is their processor. They decided to collect your details and they decide how long to keep their own copy. We act on their instructions, within the limits set out here.
For the account you sign in with, and for the running of the platform itself, Soravya is the controller.
Signing in, and what we get from Google
Sign-in is handled by Firebase Authentication, a Google service. You can sign in with an email address and a password, or with your Google account.
If you choose Continue with Google, we request three scopes — openid, email and profile — and from them we use only your email address. We use it to find the person the organizer invited and to sign you in as them. We do not read your Gmail, your contacts, your calendar, your Drive, or anything else in your Google account, and we ask for no permission that would let us.
Your Google password is never seen by us. Signing in with Google does not, by itself, grant access to any event: you can only reach an event whose organizer has already added your address.
Data received from Google is used and transferred in accordance with the Google API Services User Data Policy, including its Limited Use requirements.
What we store
- Your identity. Your email address, your name if you gave one, and an identifier linking you to your Firebase sign-in account.
- What the organizer registered. The name, address and any details they imported, plus anything you add to your own profile — a photo, a short bio, your role, industry or country, and who you would like to meet.
- What you do in a workspace. The sessions you save to your agenda, meeting requests you send or accept, and announcements delivered to you.
- Sign-in records.For each session: when it began and expires, the IP address it was created from, and your browser’s user-agent string. These exist so you can be signed out everywhere if an account is compromised.
- An audit trail. Administrative actions — who changed what, and when — because an event platform without one cannot answer a question about its own behaviour.
Product analytics are recorded against a one-way hash of your membership rather than your identity, so they cannot be read back as a list of what any one person looked at.
What we never do
- We do not sell your data, and we do not share it with advertisers.
- We do not use it to train AI models — neither ours nor anyone else’s.
- We do not show your email address to other attendees unless you have both agreed to share it.
- We do not tell an organizer what any individual read. They see counts and totals.
Who else touches it
We use a small number of processors, each for one job: Google Cloud and Firebase (hosting and sign-in), Neon (the database), and Postmark (sending email). Attendee data is stored in the European Union, in Frankfurt.
How long it is kept
- The details an organizer registered you with are theirs, and they keep them. That is the same list they held before the event, including for telling you about the next one.
- What we observed about you — the sessions you saved, who you asked to meet, what was delivered to you — is deleted 90 days after the event ends.
- Audit records are kept longer, because their purpose is to remain answerable after the fact.
Your rights
You can ask for a copy of your data, ask us to correct it, or ask us to delete it sooner than the schedule above. Where the organizer is the controller we will pass your request to them and tell you we have. Write to the address below and we will answer within 30 days.
Children
Soravya is for professional events and is not intended for anyone under 16. We do not knowingly collect their data.
Changes
If this policy changes, the date at the top changes with it. The privacy notice you agreed to for a specific event carries its own version, and we do not alter the wording of a notice somebody has already consented to.