Privacy Notice
1. Overview
SofiaStage AI services include the SofiaStage GPT and the public, read-only SofiaStage MCP server. They provide information about cultural events by querying the public SofiaStage data service. This Privacy Notice explains what data is processed when you use these services.
2. Data Processed
2.1 User Messages
When you interact with SofiaStage GPT:
- Your messages are processed by OpenAI in order to generate responses.
- Messages may be temporarily processed and stored according to OpenAI's platform policies.
- SofiaStage (the operator) does not receive, store, or directly access your full conversation unless explicitly shared outside the ChatGPT platform.
For details about how OpenAI processes data, refer to: https://openai.com/policies/privacy-policy
2.2 API and MCP Requests to SofiaStage
When an AI client calls the SofiaStage API or MCP server:
- The request contains only structured parameters needed to fetch event data (for example date filters, venue name, time filters, or a public event ID).
- No personal identifiers (name, email, account data) are sent to the SofiaStage API.
- The SofiaStage API may log:
- Timestamp, protocol path, status and request duration
- MCP tool name and success/failure state, without raw tool arguments
- A one-way hash used for rate limiting; the application does not log the raw network address
- Technical delivery and security metadata processed by Cloudflare
These logs are used solely for:
- Service reliability
- Abuse prevention
- Performance monitoring
Logs are not used for profiling or advertising.
3. Data Collected by SofiaStage
SofiaStage GPT and the MCP server do not:
- Require user accounts
- Collect names, emails, or contact details
- Track user identities
- Use cookies
- Perform behavioral tracking
- Sell or share personal data
The GPT provides read-only access to publicly available event information.
4. Third-Party Services
SofiaStage GPT operates within the ChatGPT platform provided by OpenAI, and the MCP server can be connected from OpenAI or other compatible clients. Conversation processing occurs under the selected client's infrastructure and policies. SofiaStage receives only the structured public-data request sent to its API or MCP endpoint, not the full conversation.
5. Data Retention
SofiaStage API server logs are retained only as long as necessary for:
- Operational monitoring
- Security
- Abuse prevention
No user conversation histories or raw MCP tool arguments are stored in SofiaStage application logs.
6. Security
Reasonable technical safeguards are implemented to protect the SofiaStage API from unauthorized access, abuse, and data misuse. Since the API is read-only and does not process personal user accounts, data exposure risk is minimal.
7. Children's Privacy
SofiaStage GPT is not directed toward children under 13. No intentional collection of children's personal information occurs.
8. Changes to This Notice
This Privacy Notice may be updated from time to time. The latest version will be available at: https://api.sofiastage.com/privacy
9. Contact
For privacy-related questions:
Email: privacy@sofiastage.com
Website: https://sofiastage.com