Privacy
Your business data, handled with care.
This policy explains what we collect, why, how it's stored, and the rights you have. Plain language, no dark patterns.
Last updated · June 30, 2026
1. Who we are
SoloOS ("we", "us") provides a workspace for solo founders and small teams to manage brand, content, revenue, operations, documents and insights. This policy applies to our website and the SoloOS application.
2. What we collect
- Account data — email, name, business name, password hash, OAuth identifier when you sign in with Google.
- Workspace content — clients, leads, invoices, expenses, content, documents, brand assets, notes and tags you create.
- Uploaded files — invoices, receipts, brand assets, and documents you upload. We may run OCR and AI extraction on these to surface structured data inside your workspace.
- Usage data — pages visited, features used, error reports, device and browser information, IP address (truncated where possible).
- Cookies — see our Cookie Policy.
We do not sell your data, share it with advertisers, or use your workspace content to train third-party AI models.
3. Why we collect it (legal bases)
- Contract — to provide the service you signed up for.
- Legitimate interest — to keep the product secure, debug issues, prevent fraud, and improve features.
- Consent — for optional analytics cookies and marketing communications. You can withdraw consent at any time.
- Legal obligation — to keep invoicing and tax-related records where local law requires.
4. How it's stored and protected
- Hosted in the EU on managed cloud infrastructure.
- Encrypted in transit (TLS) and at rest.
- Workspace isolation enforced at the database layer through row-level security policies.
- File uploads live in private storage buckets, accessible only via short-lived signed URLs.
- Role-based access (owner, admin, editor, viewer). Sensitive surfaces (invites, portal tokens, scheduled reports) are admin-only.
- Activity logs record meaningful changes with actor and timestamp.
5. Documents and OCR
When you upload a document, invoice or receipt, we may extract text and structured fields using OCR and AI to make the content searchable and usable. Extracted data stays in your workspace. We do not use your files to train external models. You can delete a file at any time, which removes both the original and any extracted data.
6. Subprocessors
We use a small number of trusted vendors to run the service: managed cloud hosting and database, AI model providers for in-app assistance and extraction, and email delivery for transactional messages. Each is bound by data-processing terms. A current list is available on request.
7. Retention
- Active workspace data is retained for as long as your account is active.
- Backups are retained for up to 30 days and then rotated out.
- When you delete your account, personal data is removed within 30 days, except records we must keep for legal reasons (e.g. invoices for tax compliance).
8. Your rights
Under GDPR and similar regimes, you can:
- Access the data we hold about you.
- Export your workspace data in a portable format.
- Correct inaccurate data from your account settings.
- Delete your account and personal data.
- Object to or restrict certain processing.
- Withdraw consent for analytics or marketing at any time.
- Complain to your local data-protection authority.
Most of these are self-serve inside the app under Workspace → Privacy & data. For anything else, email privacy@soloos.app.
9. International transfers
Where data is processed outside your region, we rely on Standard Contractual Clauses or equivalent safeguards.
10. Children
SoloOS is not directed at children under 16. We do not knowingly collect data from them.
11. Changes
We'll post material changes on this page and notify active users by email where required.
12. Contact
Privacy questions: privacy@soloos.app