Your context stays yours.
This Privacy Policy explains what personal data Solum collects, why we process it, who we share it with, how long we keep it, how we protect it, and the rights and choices you have. It is written to be read, not just filed. Please read it alongside our Terms of Use, into which this policy is incorporated.
Effective July 2, 2026. Last updated July 2, 2026.
Who we are
Solum (“Solum,” “we,” “us”) is a personal context vault for AI. It keeps one private, authoritative copy of the context you choose to save and hands the specific slice you’ve granted to whichever AI assistant you connect. We operate the website at usesolum.co and the associated application, browser extension, desktop application, and connected-AI interfaces (together, the “Service”).
For the purposes of the EU and UK General Data Protection Regulation (GDPR), Solum is the controller of the personal data described here. You can reach us about any privacy matter, including exercising your rights, at solumverif@gmail.com. We have not appointed a statutory Data Protection Officer; privacy requests go to that same address.
The short version
- We store the context you choose to save so we can serve it back to you and to the AIs you explicitly connect. That’s the whole job.
- We do not train AI models on your content, and we do not sell, rent, or share it for advertising.
- We run no third-party analytics, ad trackers, or behavioral profiling. The only cookies we set are the ones needed to keep you signed in.
- Your captured conversations and snippets are encrypted at rest. You can additionally lock high-sensitivity entries so that even we can’t read them (see How we protect your data).
- You can view, edit, export, and delete your data, and revoke any connected AI, at any time.
This summary is for orientation only; the sections below are the operative terms.
1. Personal data we collect
We collect only what the Service needs to function. The categories below describe what we may hold, depending on which features you use.
Account and identity data
- Email address and basic profile. When you sign up with Google, we receive your email address and basic Google profile (such as your name). When you sign up with an email and password, we collect your email address.
- Authentication credentials. Password-based accounts are authenticated through our infrastructure provider, which stores a hashed password (we never see it in plaintext). If you enroll a passkey, we store the public-key credential and related WebAuthn metadata; if you set up a recovery passphrase or recovery codes, we store only hashed or wrapped forms.
- Profile details you provide. Fields you choose to fill in during onboarding or later, such as your name, pronouns, location, role, current life or work context, and preferred communication style.
Context you save (your content)
- Facts, preferences, projects, relationships, and behavioral rules you record or that are extracted from what you capture.
- Conversations and snippets you capture from AI tools and elsewhere, including their text and metadata about their source (for example, which platform or tool they came from).
- Files and attachments you upload (such as PDFs, images, and documents) and text extracted from them.
- Messages you send in the “Talk to Solum” chat, which are stored only transiently (see How long we keep your data).
Connection and activity data
- Connected AIs.Which assistants you connect over the Model Context Protocol, the access tokens issued to them, and the scopes or Spaces you’ve granted each one.
- Activity and audit log. A record of changes to your vault — edits, imports, promotions, connections, deletions — so you can review history and roll changes back.
- Team or organization data. If you join a business account, we store your membership, role, and status, and the email address an administrator used to invite you.
Technical and support data
- Operational connection data. Our hosting and database providers (Vercel and Supabase) process technical data such as IP address and browser or device information to deliver the Service, keep it secure, and detect abuse. We do not use this data to build advertising or behavioral profiles.
- Support and waitlist. If you email us or join a waitlist, we keep your message and email address. Our public business-waitlist form additionally records your browser user-agent string and a hashed form of your IP address to prevent spam.
Sensitive information. Because Solum lets you store free-form personal content, what you save may reveal sensitive details (for example, about health, beliefs, or relationships). We do not ask for sensitive data, and you decide what to save. You can mark entries as high-sensitivity and lock them so that only you can decrypt them.
2. Where your data comes from
Most data comes directly from you — what you type, save, upload, or capture. We also receive your email address and basic profile from Google when you choose to sign in with Google. If you enable an optional connector, we receive data from that service on your instruction (see Google user data).
3. Why we use your data, and our legal bases
We process your personal data for the purposes below. For users in the EU, UK, and other regions that require a legal basis, the applicable GDPR basis is noted in brackets.
- To provide the Service— storing your context, running the memory pipeline that organizes it, and serving the slices you’ve granted to connected AIs. [Performance of a contract with you.]
- To run AI-assisted features — summarizing, classifying, extracting, editing, and enhancing your content when you use those features. [Performance of a contract; your consent where you initiate a specific action.]
- To connect AIs and optional services — sharing context with an assistant, or reading from a connector, only after you explicitly connect and grant it. [Your consent, which you can withdraw at any time.]
- To secure accounts and prevent abuse — authentication, rate-limiting, fraud and abuse detection, and protecting the Service and its users. [Legitimate interests; legal obligation where applicable.]
- To communicate with you — sending account, security, and transactional messages such as email verification and password resets. [Performance of a contract; legitimate interests.]
- To comply with the law — responding to lawful requests and meeting legal obligations. [Legal obligation.]
We do not use your data for advertising, and we do not use it to train AI models. Solum does not make solely automated decisions that produce legal or similarly significant effects about you.
4. AI features and third-party AI models
Several Solum features rely on a third-party large-language-model provider, Anthropic. When you use natural-language editing, the “Talk to Solum” chat, capture summarization and classification, or prompt enhancement, the relevant text is sent to Anthropic’s API to produce the result and then returned to you.
- Under Anthropic’s commercial terms, content sent through their API is not used to train their models.
- We do not train any models on your content, and we do not sell it.
- Because your content can contain sensitive details, you control what you save and what you route through these features; you can keep high-sensitivity entries locked so they are never sent in plaintext.
Separately, when you connect an external AI assistant to your vault (for example, Claude, ChatGPT, or Gemini), that assistant can request the context you’ve granted it. Once context reaches a connected assistant, it is handled under that assistant’s own privacy policy, which we don’t control.
5. When and with whom we share your data
We do not sell your personal data, and we do not share it for cross-context behavioral advertising. We disclose it only in the limited circumstances below.
Service providers (subprocessors)
We rely on a small set of vendors that process data on our behalf, under contract and only to run the Service:
- Supabase — database, authentication, and file storage. Your account and content are stored here (United States region).
- Anthropic — powers the AI-assisted features described above (United States).
- Google — sign-in with Google, and any optional Google connector you enable (see below).
- Vercel — application hosting and delivery (United States).
AIs you connect
An assistant you connect receives only the Spaces or scopes you’ve granted it, and nothing from an assistant you haven’t connected. You can revoke any connection at any time from the Connections page; its access stops immediately.
Business and team accounts
If you use Solum through a business account, your organization’s administrators can see membership information such as your name, role, and status. Administrators cannot read the contents of your personal vault — your captures, facts, and retrievals remain private to you, enforced by row-level security.
Legal, safety, and business transfers
- We may disclose data where required by law, to respond to lawful requests, or to protect the rights, safety, and security of our users, the public, or Solum.
- If Solum is involved in a merger, acquisition, financing, or sale of assets, your data may be transferred as part of that transaction; we’ll require the successor to honor this policy, and we’ll notify you of any material change in control of your data.
6. Google user data
Solum’s use of information received from Google APIs — whether from Sign in with Google or from an optional connector you enable (such as read-only access to Google Drive, Gmail, or Calendar) — adheres to the Google API Services User Data Policy, including its Limited Use requirements. Specifically:
- We only request the minimum Google scopes needed for a feature you turn on, and connectors request read-only access.
- We use Google user data solely to provide and improve the user-facing features you asked for.
- We do not transfer or sell Google user data for advertising, and we do not use it to train generalized AI or machine-learning models.
- We do not allow humans to read Google user data unless you give explicit consent for specific data, it’s necessary for security or to comply with law, or the data has been aggregated and anonymized.
You can disconnect a Google connection at any time from the Connections page, and you can review or revoke Solum’s access from your Google Account permissions.
7. How we protect your data
We use technical and organizational measures designed to protect your data, and we describe them honestly rather than in absolutes.
- Encryption at rest.The conversations and snippets you capture are encrypted at rest using AES-256-GCM. This is encryption at rest, not zero-knowledge: the key is held by the Solum server, and content is decrypted only transiently, in server memory, to serve your reads and run the memory pipeline. We don’t read it for any other purpose.
- Optional zero-knowledge lock. If you enroll a passkey, you can lock high-sensitivity entries with a key derived on your device. Those entries are encrypted so that the Solum server cannot read them; only you can unlock them.
- Searchable fields. To keep the Service usable, some data — such as your structured profile fields and text extracted from files — is stored without at-rest encryption. It remains protected by strict per-user access controls (row-level security).
- Access controls. Every row is scoped to your account and protected by row-level security; connected AIs are limited to the scopes you grant; and data is transmitted over encrypted (HTTPS) connections.
No method of storage or transmission is ever completely secure. We work to protect your data but cannot guarantee absolute security. If we ever learn of a breach affecting your personal data, we’ll notify you and the relevant authorities as required by law.
8. How long we keep your data
We keep personal data only for as long as we need it for the purposes above, then delete it. Specific periods:
- Your saved context — kept until you delete it or delete your account. Deleting an entry or a project removes it immediately.
- “Talk to Solum” chat messages— automatically deleted about 7 days after the conversation’s last activity.
- Activity and audit log — kept for the life of your account so you can roll back changes, and deleted when your account is deleted.
- Extension pairing codes — short-lived; they expire within minutes and are purged shortly after.
- Departing team members — when a business account removes your seat, your associated data is wiped after a short grace period (about 7 days).
Deleting your account.You can delete your account from Settings. This removes your saved context and profile from Solum. Your underlying login identity may persist briefly with our authentication provider and in routine backups; email us and we’ll ensure it is fully removed. We may retain limited records where the law requires it.
9. International data transfers
Solum is operated from, and stores data in, the United States. If you access the Service from the EU, UK, Canada, or elsewhere, your personal data will be transferred to and processed in the United States and other countries where we or our providers operate, which may have different data-protection laws than your own.
Where we transfer personal data out of the EU, UK, or Switzerland, we rely on appropriate safeguards — principally the European Commission’s Standard Contractual Clauses (and the UK International Data Transfer Addendum) — and, where a provider is certified, the EU-U.S. Data Privacy Framework and its UK Extension. You can request more information about these safeguards at solumverif@gmail.com.
10. Your rights and choices
Depending on where you live, you have some or all of the following rights over your personal data:
- Access — ask for a copy of the personal data we hold about you.
- Correction — fix inaccurate or incomplete data.
- Deletion — ask us to erase your data.
- Portability — receive certain data in a portable format.
- Restriction and objection — limit or object to certain processing, including processing based on legitimate interests.
- Withdraw consent — where we rely on consent (for example, a connected AI or a Google connector), withdraw it at any time, without affecting processing already carried out.
- Opt out of “sale” or “sharing” — not applicable in practice, because we do neither.
You can exercise most of these directly in the app: edit or remove any entry from the Memory page, revoke a connected AI from the Connections page, roll back an edit from the Activity log, export your activity history, and delete your account from Settings. For anything else — including a full copy or deletion request — email solumverif@gmail.com. We’ll verify your request and respond within the timeframe the law requires (generally within 30 to 45 days). Using your rights is free, and we won’t discriminate against you for it.
Complaints.If you’re in the EU or UK and think we’ve mishandled your data, you may lodge a complaint with your local supervisory authority (in the UK, the Information Commissioner’s Office). We’d appreciate the chance to address your concern first.
11. U.S. state privacy rights
Residents of California and other U.S. states with comprehensive privacy laws (including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, and Montana) may have rights to access, correct, delete, and obtain a portable copy of their personal data, and to opt out of the sale of personal data, targeted advertising, and certain profiling.
- In the past 12 months we have collected the categories of data described in Section 1 (identifiers, account and profile information, your saved content and files, and technical/usage data), for the business purposes in Section 3.
- We have not sold personal data and have not shared it for cross-context behavioral advertising, and we do not process sensitive data for the purpose of inferring characteristics.
- We disclose data only to the service providers and in the circumstances listed in Section 5.
- Where a state grants a right to appeal a decision on your request, you may appeal by replying to our response or emailing us.
To exercise these rights, use the in-app controls or email solumverif@gmail.com. You may use an authorized agent where the law allows.
12. Cookies, and Do Not Track / Global Privacy Control
We use only the cookies and similar technologies necessary to operate the Service — chiefly to keep you signed in and to secure authentication (for example, session and OAuth/PKCE cookies). We do not use advertising cookies, third-party analytics, or cross-site tracking, so there is no consent banner to click through.
Because we don’t track you across other sites or sell your data, there is nothing to opt out of in that sense. We honor Global Privacy Control (GPC)signals, and because we engage in no cross-site tracking, browser “Do Not Track” signals do not change how the Service works.
13. Children's privacy
Solum is not directed to children. You must be at least 16 years old to use the Service, consistent with our Terms of Use. We do not knowingly collect personal data from anyone under 16. If you believe a child under 16 has provided us with personal data, email solumverif@gmail.com and we’ll delete it.
14. Changes to this policy
We may update this Privacy Policy as the Service evolves. When we do, we’ll change the “Last updated” date above. If a change is material— for example, a new purpose for processing, a new category of recipient, or a change in how you exercise your rights — we’ll actively notify you, such as by email or an in-product notice, rather than relying on you to check this page. Where appropriate, we may ask you to review and accept the updated terms before continuing.
15. Contact us
Questions, requests, or concerns about this policy or your personal data? Email us at solumverif@gmail.com. We read every message.