Soltura Private Beta Privacy Notice

This Notice explains what personal data Soltura uses to run the private beta, why it is used, who helps process it, and how to request access or deletion.

1. Who is responsible

Ray García operates Soltura and is responsible for the personal data described here. Contact privacy@soltura.ai for privacy requests and support@soltura.ai for product support.

2. Data we use

We use account email and authentication information; workspace membership and permissions; project, environment, access, quota, audit, and policy-acceptance records; short-lived connection and credential-operation records; support correspondence; and limited security and service diagnostics.

The data plane receives only fields declared in an approved signal contract. Private-beta users must not put personal data in business-signal fields. Soltura does not receive repository source, coding-agent conversations, plaintext credentials, or raw rejected request bodies.

The incident assistant is disabled for this publication. Soltura does not send incident prompts or context to DeepSeek.

3. Why we use it

We use this data to run the beta, sign users in, control workspace access, secure and diagnose the service, answer requests, recover from failures, and see whether users complete onboarding.

The legal bases are providing the service you request, our legitimate interests in operating and securing a limited beta, and compliance with legal obligations where applicable. Workspace creation is not consent to marketing, and Soltura does not sell personal data or use it for advertising.

4. Providers

Soltura uses Convex for authentication and control-plane storage; Cloudflare for DNS, edge services, email routing, monitoring, and encrypted backup storage; Google for the support and privacy mailbox; and Hetzner for EU-hosted compute and PostgreSQL.

These providers use only the data needed for their role. Convex, Cloudflare, and Google may handle data outside the European Economic Area. When the GDPR applies, their services use recognized safeguards such as adequacy decisions or standard contractual clauses. Their privacy pages are listed below.

5. How long we keep it

We keep account data while the account is in use, and workspace data while the workspace exists. Business-signal detail follows the workspace retention setting. Sign-in, authorization, rate-limit, and operation records use shorter automatic expiry schedules.

Deleting a workspace removes its live data. Encrypted backup copies disappear through the normal backup rotation. We keep a one-way record that the workspace was deleted so a restore cannot bring it back. We keep support and privacy messages only while we need them to answer the request, secure the service, or meet a legal duty.

6. Sharing and security

Data is shared only with authorized members of the same workspace, the providers listed here, or a public authority when legally required. Soltura does not share one workspace's data with another.

We separate workspace access and credential purposes, hash credentials, encrypt traffic and backups, limit service logs, monitor the service, and test deletion and recovery. No online service can guarantee absolute security.

7. Export and deletion

A workspace owner can export or permanently delete the workspace through Soltura Cloud. If deletion stops part-way, Cloud says so and lets the owner retry. It does not report success.

To access, correct, delete, restrict, object to, or receive a copy of personal data linked to your account, email privacy@soltura.ai from its verified address. We may ask you to verify the account.

8. Your rights and changes

Depending on applicable law, you may have rights to access, correct, delete, restrict, object to, or receive a portable copy of your personal data. You may also complain to the Spanish Data Protection Agency or another competent supervisory authority.

This Notice shows its version and effective date. If a later version needs acceptance, Soltura will show it before you continue using Cloud.