Privacy Policy
Last updated: July 13, 2026
This policy describes how Solace AGI ("Solace", "we") handles data. It is written to match how the product actually works. Because Solace operates a managed technology department, we do process your data on your behalf — this policy is honest about where it goes and how it is protected.
1. How data flows
The Solace runtime that executes work routes all network activity through a single controlled egress at solaceagi.com. The runtime does not hold third-party API keys and does not reach external services on its own. This means:
- Data needed to perform your workflows (for example, content sent to a language model, or an action taken on a platform you authorized) passes through Solace's controlled backend.
- We do not sell your data, and we do not use your private customer records to train shared models.
- Earlier statements that "data never leaves the premises" or that "Solace does not collect your files or source code" applied to an older architecture and are superseded by this policy.
2. What we process
- Account data — the details needed to create and manage your subscription.
- Customer data you supply — records, documents, media, and, where you engage us to build software, the relevant code and configuration.
- Operational data — the inputs, actions, approvals, and outputs of your workflows, recorded to your evidence trail.
- WorldData — public and licensed market data, maintained separately from your private records.
3. Tenant isolation and separation
Each customer has its own tenant scope, and keeping one customer out of another's data is a design commitment, not a configuration setting. Enforcement is still in progress: access checks already cover customer data such as CRM records, messages, files and e-sign, and the remaining routes are being brought under the same check. We treat any cross-tenant access as a defect to fix, never as a setting. The current status is published on our Trust page. WorldData (public/licensed) is kept separate from the private customer records you provide.
4. Subprocessors
To operate the service we use infrastructure and model providers (for example, cloud hosting and language-model providers) reached only through our controlled backend. We contract these providers to protect your data and to process it only to deliver the service. A current subprocessor list is available on request.
5. Retention and deletion
We retain your data for as long as needed to operate your service and to maintain the evidence trail you rely on. On termination you may export your data, and you may request deletion consistent with the Ownership Covenant and any legal retention obligations.
6. Your rights
Depending on your jurisdiction you may have rights to access, correct, export, or delete personal data we process. For data we process as a processor on a customer's behalf, we act on that customer's instructions. Contact us to exercise these rights.
7. Security
Security controls are described on the Trust page, where each control is labeled as implemented, a design goal, or a contractual option. We do not claim certifications we have not completed.
8. Mobile numbers and text messages (SMS)
Where a customer business uses our messaging features, we process the mobile phone numbers their own end users provide — for example a parent enrolling a child at a tutoring centre — solely to deliver the messages that end user consented to receive.
No mobile information is sold, rented, or shared with third parties or affiliates for marketing or promotional purposes. Mobile numbers and SMS consent are never shared with third parties for their own marketing.
Numbers are disclosed only to the telecommunications provider that carries the message on our behalf, strictly for delivery, and to no one else. Text messaging originator opt-in data and consent are not shared with any third party.
Consent is collected on the enrolment and booking forms where the number is entered, is affirmative (never pre-checked), and is recorded with a timestamp and the exact wording shown. Consent is never a condition of enrolment or purchase.
Message frequency varies. Message and data rates may apply. Reply STOP to any message to opt out at any time, or HELP for assistance. Opt-out is honoured immediately and enforced on every subsequent send. Full programme details are on our SMS Policy page.
9. Changes and contact
We may update this policy; material changes will be notified. This page supersedes any earlier "Solace City" privacy statement. Questions: phuc@phuc.net.