Privacy Policy
What personal data Soli.So processes, why, who else receives it, how long it is kept and what you can do about it.
Last updated: 21 September 2026.
Who is responsible
Soli.So is the controller of the personal data described here. Write to us about anything on this page at info@soli.so; the formal company details are at the foot of this page.
What we process, and why
Your account. Your email address; your password, stored only as a hash and never as the password itself; your time zone and language preference; whether your address is confirmed; the devices you chose to remember for sign-in; a link to your Google or Facebook account if you sign in that way (never a password held there); and a profile picture, if you add one.
Your work. The brands, campaigns and content cards you create; the text the service drafts and the text you write; the pictures, videos and documents you upload; your notes on a card; your conversation with the assistant; and speech — audio you dictate, or a video's soundtrack, which a speech-to-text provider returns as text.
Your connected social accounts. Which networks you connected, each account's display name, the identifiers our publishing provider uses for them, and the performance figures read back for posts published through the service. We never receive or store a social-network password.
Your People list. The names and network handles you enter for mentions — other people's data, entered by you; see The people you enter below.
AI work and its cost. For every AI call: which part of the app made it, which model answered, the token counts, the cost and the card it belonged to — your token balance and the per-card cost in Statistics come from it.
Billing. Your customer and subscription identifiers at our payment provider, the seats and token packs you hold, your period dates and your status. Card numbers and payment credentials are entered with Stripe and held by Stripe. They never reach this application: we do not see them and we do not store them.
Information from elsewhere, and technical records. A web page you ask the assistant to read (we keep what it says about your brand) and the queries a campaign's research runs through a search provider. Plus ordinary technical records — failed actions, server and application errors — kept for fault-finding and security; they record what happened, never what you wrote.
Why we are allowed to process it
- To perform our contract with you — your account, your work, publishing, statistics and billing.
- Our legitimate interest — keeping the service secure, working and affordable to run: the technical and AI-cost records, rate limits, backups and fault-finding. We keep these narrow, and we build no profiles of you from them.
- Your consent — where something is genuinely optional and we ask for it, such as connecting a social account. You can withdraw it at any time, which does not affect what was done before.
- A legal obligation — invoices and accounting records.
Who else receives it
We do not sell personal data, and we do not share it for advertising. Each provider below receives only what its job needs:
- OpenAI — the AI models: your instruction, the brand and campaign description, the post it applies to, and any picture or video frame it is asked to read.
- Zernio — publishing: a post's content, links to its media and the identifiers of the social account it goes to; it returns the result and the statistics.
- Stripe — payments, invoices and the billing portal: your email address, the subscription, and the billing name, address and tax number you enter there; card data stays with Stripe, under its own privacy notice.
- Cloudflare R2 — storage for your uploads and for the encrypted nightly database backup, both in Cloudflare's EU jurisdiction.
- Resend — transactional email (sign-in codes, password resets, address confirmation, service notices): your email address and the message.
- Soniox — speech to text: the audio of a dictation, or a video's soundtrack.
- DataForSEO — web search when the assistant researches a campaign: the search query, not your content. It is an EU processor.
Each processes it only on our instructions, and a new provider is named here before it receives your data; we also use ordinary hosting and infrastructure providers. Inside Soli.So, access is limited to the few people who run the service, and beyond that we disclose personal data only where the law requires it.
Where the data is
Your uploaded files, your documents and the encrypted database backups are stored in Cloudflare's EU jurisdiction. Some of the providers listed above are established outside the European Economic Area, principally in the United States. Where personal data reaches them, the transfer is covered by the European Commission's standard contractual clauses in that provider's own terms.
The people you enter
The mention list holds other people's names and network handles, entered by you — so you should have a legitimate reason to keep them. We use them only to write mentions into your posts and to resolve a handle with the network when a post is published, and they are deleted with the entry, the brand or your account. If one of those people asks us about their data, we will tell them who put it there.
Cookies, and what we do not do
There is no third-party analytics, advertising or tracking on these public pages. Nothing here profiles you, no data about your visit goes to anyone else, and there is therefore no consent banner to click.
The public site sets one cookie, and only when you use the language switcher: your language choice, so the page stays in the language you picked; it lasts a year. Signed in, the app uses a session cookie and a cross-site-request-forgery token — both strictly necessary — plus, if you chose to remember the device, one that lets it skip the email code; signing out of all devices revokes it.
The technical records above are our own, are never shared, and are never used for advertising.
How long we keep it
Your account and the brands you use stay for as long as you use the service. Within that, things expire on their own:
- Content cards and their media — 90 days after their scheduled date.
- Uploaded pictures, videos and documents — 90 days, used or not.
- A card's revert history — the ten newest versions, for 7 days.
- Campaigns, and brand and campaign edit history — 12 months (a campaign, from the day it ends).
- A brand — after 12 months of no use, and only when no social account is connected to it.
- Statistics, AI-usage records and technical records — 12 months.
- Your conversation with the assistant — the newest 30 messages stay; older ones go once they are more than 14 days old.
- Encrypted database backups — 14 days.
A lapsed subscription deletes nothing by itself: the service is closed off, connected social accounts are disconnected after 30 days so they are not held open unpaid, and the periods above run their course. Deleting your account erases everything at once.
Deleting your account yourself
Your profile page has a real deletion, not a request form. You confirm with your password — or, if you sign in through Google or Facebook and have none, with a code emailed to you — and in one step every connected social account is disconnected from our publishing provider, your subscription is cancelled immediately, and everything belonging to your account is erased: brands, campaigns, content cards, uploads, documents, conversations, your People list, and your technical and AI-usage records.
Two things survive, and you should know about them before you press it. Posts already published remain on the social networks — nothing we do can take them down — and our payment provider keeps your invoice history for the period accounting law requires.
Your rights
Under the General Data Protection Regulation you can ask us for a copy of your personal data (access), to correct it (rectification), to delete it (erasure), to restrict or object to a particular use, and to receive what you provided in a portable form (portability). Where we rely on your consent, you can withdraw it at any time.
Much of this you can do yourself in the app: edit or delete a brand, campaign, card or upload, disconnect a social account, or delete the whole account as described above. For anything else write to info@soli.so — we answer within one month. If you are not satisfied, you can complain to the data-protection supervisory authority where you live or work.
We make no decisions about you by automated means alone, and we build no profiles of you for advertising or for automated decisions. The service uses AI to write and illustrate your content — it is a draft you review, and nothing is published until you approve it. It does adapt to you: from your own edits to your own posts it learns how you write, so that it writes more like you. That stays with your brand, is never used for anyone else, and no model is trained on it.
How we protect it
- Your password is stored only as a hash, never as the password itself, and signing in also requires a code sent to your email address.
- Everything travels over HTTPS, and uploaded files are private — never served from a public address.
- The nightly database backup is encrypted before it leaves the server, into a locked EU bucket.
- Access inside Soli.So is least-privilege, and rate limits and usage ceilings guard what could be abused.
No system is perfectly safe. If a breach ever affects your personal data, we will tell the supervisory authority and, where the law requires it, you.
Children
The service is for professional use by adults and is not directed at children. We do not knowingly process a child's personal data. If you believe a child has created an account, write to info@soli.so and we will remove it.
Changes to this policy
We may update this policy — most often when a provider or a retention period changes. The current version, with the date it last changed, is always on this page; please look at it from time to time. If we ever want to use your personal data for a genuinely new purpose, we will tell you before we do.
Company details
The formal details of the company that acts as controller:
- Controller — Soliso MB, a small partnership (mažoji bendrija) registered in the Republic of Lithuania
- Registered address — Tiltų g. 19, LT-91249 Klaipėda, Lithuania
- Company registration number — 308006691
- Data-protection contact — info@soli.so
- Supervisory authority — the State Data Protection Inspectorate of the Republic of Lithuania (Valstybinė duomenų apsaugos inspekcija), or the authority of the EU country you live in