the short version
sol pbc makes open source software, and operates three optional hosted services. private network is a relay sol pbc runs that lets you reach your own journal from your phone. the operated tier of encrypted backup is storage sol pbc runs so an encrypted copy of your journal can live off your own machine. confidential processing is an AI model sol pbc runs on confidential GPU hardware, for when your journal needs more capacity to think with than the machine it's on. we don't sell your data, and we never will.
the first two are built so sol pbc can't read your journal. the relay is blind by construction: it passes encrypted bytes between your devices and can't read what's inside. the operated backup holds encrypted blocks we have no key to. the contents, file names, and folder structure are all encrypted on your device before anything leaves it.
confidential processing is different, and the difference matters. it is off until you turn it on. while it is on, what you send is encrypted over the network but visible in running memory only while it is being processed by sol pbc's own engine. we are not going to tell you we never see it. what we can tell you is that the service runs zero data retention (ZDR): no content is kept, not even in logs, no human reviews it, and nothing is used to train anything. the cloud host whose hardware it runs on is excluded from all of it by that hardware, which your journal checks cryptographically before it sends. the full account is below.
the billing system is not blind. to run your subscription we knowingly hold a small, named set of data (your email, your subscription status, and a reference to your sign-in), which you can see, export, or delete anytime. nothing readable from your journal reaches any of them. the no-sale promise isn't just a promise: it's a binding legal covenant in our articles of incorporation, enforceable against the company forever.
most of what sol pbc makes runs on your hardware and never reaches us, and our hosted services either can't see what flows through them (the relay) or hold only encrypted blocks they have no key to (the operated backup). this policy discloses in full what our services see and how they're processed.
who we are
sol pbc is a Colorado public benefit corporation. our benefit purpose, as filed with the Colorado Secretary of State, is to advance digital self-determination by providing open-source, privacy-respecting tools and services that enable individuals to directly collect and gain insight from their personal data.
sol pbc has one director: jeremie miller, the founder. the company can only be acquired by a successor that is legally bound to preserve a substantially equivalent benefit purpose and that assumes covenants no less protective than Article 8. acquisition by an entity that wouldn't honor these protections is not permitted. these constraints are in the articles of incorporation and cannot be weakened. see the amendment lock below.
contact: contact us. for the hosted services specifically, support@solstone.app.
what sol pbc makes
sol pbc develops two open source projects:
- solstone: sol keeps a journal of what you see and hear. an open source, local-first memory the agents you use can work from. it processes your screen and audio locally with AI and builds a searchable knowledge graph of your digital life. it runs on your hardware. your data stays on your device.
- vit: a developer capability network built on AT Protocol. developers and AI agents discover, share, and remix software capabilities through a decentralized social network.
sol pbc also operates three optional hosted services:
- private network: a relay sol pbc runs so you can reach your own journal from your phone (or any of your devices) without running your own relay. it's a convenience, never a requirement: the free paths (connecting directly on your own network, bringing your own transport, or self-hosting the open-source relay) are always available and are private by the same construction. the relay is blind: it moves encrypted bytes between your devices and can't read them.
- encrypted backup, operated tier: storage sol pbc runs so an encrypted copy of your journal can live somewhere other than your own machine, without you having to set up and manage your own bucket. it's a convenience, never a requirement: the free path, pointing solstone's backup at your own object-storage bucket (Backblaze B2, Amazon S3, Cloudflare R2, any S3-compatible provider), is always available and uses the same engine, the same encryption, and the same recovery model. the operated tier is encrypted by construction: before anything leaves your machine, solstone encrypts the contents, the file names, and the folder structure, and sol pbc stores only those encrypted blocks. we hold no key, no password, and no way to read them.
- confidential processing: an AI model sol pbc runs on confidential GPU hardware, so your journal can think with more capacity than your own machine has. it's a convenience, never a requirement: the free paths are always available, and on them sol pbc is not in the path at all. you can run a model locally on your own hardware, or bring your own provider key or your own endpoint. what makes this one confidential is that sol pbc runs the model itself inside a hardware boundary that excludes the cloud host from what is being processed, and your journal verifies that boundary before it sends anything. because it is the one service where content is processed rather than carried or stored, it gets its own section below.
what data does sol pbc collect?
from local use of solstone and vit: nothing
solstone and vit are open source software that runs on your hardware. sol pbc receives no data merely from your local use of these products: no telemetry, no analytics, no crash reports, no usage data. the software works entirely offline from sol pbc. if you apply for or receive Scout status, we receive the Scout records described below; if you enable a paid hosted service, we receive the records described in that service's section.
the source code is public. you can verify this yourself.
from applying for or receiving Scout status: application and status history, never your journal
Scout is a status on an owner sign-in. approval enables complimentary access to eligible services; paid access is independent. if you apply for or receive Scout status, we keep the application text you submit, the fact and time you acknowledged the disclosure, the current status and its timestamps, and a forward-only history of real status changes.
each lifecycle-history event says what administrative action occurred; the internal owner-sign-in identifier; the prior and new status; a standard reason; whether the action came from the owner, a named operator, or an authenticated automated service; and the time, order, and reference identifier. events are append-only: we do not edit or selectively delete them. the history begins when this feature launches. we do not invent old events from prior timestamps. it contains no journal content, application text, customer email, credential or token, network address, browser details, billing identifier, or key material. an operator email may appear only to identify that authenticated operator; an automated service is never presented as identifying a human.
we use lifecycle history only to administer and secure Scout status, provide it to you on an access or export request, and resolve operational problems with your status. it is never used for analytics, aggregate reporting, advertising, profiling, behavioral measurement, or model training. history remains while the owner sign-in exists and is deleted with it. request your retained Scout history, correction of the current status, or owner-sign-in deletion at support@solstone.app. this history never contains or deletes the journal on your own devices.
from the hosted relay (private network): connection metadata, never content
when you use the hosted relay, your devices open an encrypted tunnel to each other and the relay passes the encrypted bytes between them. the encryption is end-to-end between your own devices. the relay holds no key to it and keeps no copy of what flows through. sol pbc cannot read your journal or anything inside the tunnel.
to move your bytes, the relay and Cloudflare (whose network the relay runs on) necessarily handle connection metadata about your devices: their network (IP) addresses, connection timing, and how much data moved. pairing a device also enrolls it: the relay issues that device a credential and we keep the record saying which of your devices may reach which of your homes, until you unpair it or the credential expires. all of this is Customer Data under our covenants (the Article 8 term, defined in what sol pbc will never do below): we use it only to operate, secure, and bill the relay, and we never sell it, profile you with it, or use it for advertising. it can reveal that your devices connected, never what they said. Cloudflare's handling of the edge data it sees is described in the Cloudflare privacy policy.
if someone served sol pbc a subpoena over the relay, the only things we could produce are that connection metadata and those enrollment records: that your devices connected, when, how much data moved, and which of them may reach which of your homes. never the contents, because there is no key and no plaintext to give. we resist such demands to the maximum the law allows and notify you when we legally can.
from the operated tier of encrypted backup: encrypted blocks + storage metadata, never content
when you use the operated tier, solstone encrypts your journal on your own device, so the contents, the file names, and the folder structure all become unreadable ciphertext, and then uploads those encrypted blocks to storage sol pbc runs for you. sol pbc stores the blocks and cannot read them: we hold no key, no password, and no way to decrypt them. nothing readable from your journal reaches us, our storage provider, or anyone we could be compelled to disclose to. what we and Cloudflare hold are encrypted blocks plus the operational and connection metadata described below, never your content.
to operate and bill the storage, we keep a small amount of operational information about your stored blocks: how many encrypted objects there are, how much space they take, and when they last changed. we use it only to run and bill the service, never to profile you or for any other purpose, and it never includes the contents of your journal.
to move your encrypted blocks, the storage (running on Cloudflare, in Cloudflare R2) and Cloudflare itself necessarily handle connection metadata about your device's upload sessions: its network (IP) address, connection timing, and how much data moved. this metadata is Customer Data under our covenants: we use it only to operate, secure, and bill the storage, and we never sell it, profile you with it, or use it for advertising. Cloudflare sees only those encrypted blocks, that operational information, and this connection metadata, never your content. its handling of the data it sees is described in the Cloudflare privacy policy.
what happens to your backup after you stop paying. while your subscription is active, we keep your encrypted backup available. when your subscription lapses, whether you cancel or a renewal fails, the operated storage keeps running through the end of the period you've already paid for, then stops, and we keep your encrypted blocks for 30 days after that, then permanently delete them. within that 30-day window, re-subscribing turns the operated tier back on against your existing backup, with nothing lost; after 30 days the operated copy is gone for good. this only ever affects the copy in our storage. your journal on your own devices, and any backup in your own bucket, are never touched. because the backup is encrypted with a key only you hold, once it's deleted we cannot recover it.
if someone served sol pbc a subpoena over the operated backup, the only thing we could produce is encrypted blocks we can't read, that operational information, and the connection metadata of your upload sessions. never the contents, because there is no key and no plaintext to give. we resist such demands to the maximum the law allows and notify you when we legally can.
from confidential processing: what you send the model, retained by nobody
confidential processing is off until you turn it on, and turning it off puts everything back on your own machine. what follows describes what happens while it is on.
what leaves your device. the text and images your journal needs a model to work through, and, if the audio switch is on, your audio for transcription. that switch is on by default while confidential processing is in use, and it is yours to change: turn it off and speech becomes text on your own device instead, taking effect on the next thing you say. your journal itself never leaves.
sol pbc runs the model. the engine is ours: our own model weights and our own serving stack, on confidential GPU hardware sol pbc operates. no third-party AI provider is in the path and nothing you send is handed to one. we would rather be precise here than sound better than we are: what you send is encrypted over the network, and visible in running memory only while it is being processed. that is what confidential means here, and it is not the sealed arrangement the relay and the operated backup have. we do not claim it is. what we do claim is what becomes of it: the service runs zero data retention (ZDR). no content is kept, not even in logs. no human reviews it. nothing is used to train anything.
the hardware is Microsoft Azure's, and Azure is excluded from what runs on it. the machine is a confidential GPU instance in Microsoft Azure: an AMD SEV-SNP confidential virtual machine with an NVIDIA H100 running in confidential-compute mode. that boundary is enforced by the hardware, not by configuration or by promise, and it keeps the host out of what is being processed, memory included. Microsoft hosts the machine. it is not a party to your content.
your journal checks the hardware itself, every time, before sending anything. this is the part you do not have to take on trust. before a channel is used, your journal cryptographically verifies the machine: the AMD attestation chain up to AMD's own signing keys, the GPU's own evidence, the binding of that evidence to the encrypted connection, and a fingerprint of exactly which software booted on that machine. that fingerprint is pinned in solstone's open source code, so it is public, version-controlled, and cannot be quietly repointed at different software without a release anyone can see. if any of it fails to verify, nothing is sent. your journal waits, tells you plainly that it could not verify, and never silently falls back to some other service. you can turn the whole lane off and process locally at any time.
what we keep. nothing from what you send: that is what zero data retention means, and it includes logs. to run the service and keep it healthy we count fleet-wide totals, which are counts rather than content and are not associated with you, your journal, or your account. we do not profile you with any of it, and none of it is ever used for advertising.
if we're compelled. there is no retained content to compel, because none is kept once a request is answered. what a demand could reach is the account and billing record described above, on the same terms as any other service, and the fleet-wide totals, which are not about you. never the contents of what you sent, because they are not there to give. we resist such demands to the maximum the law allows and notify you when we legally can.
from subscribing (billing): the minimum to bill you
if you subscribe to a hosted service, we collect and keep the minimum needed to run your subscription: your email address, your subscription status and renewal dates, and a reference that ties the subscription to your sign-in. payments are handled by Stripe, our payment processor. your card and payment details go directly to Stripe and are governed by Stripe's terms and privacy policy. sol pbc never sees or stores your card. we send Stripe only what's needed to charge you for the service, and we never send Stripe anything from your journal.
we use your billing details only to run your subscription. we do not sell them, share them for anyone else's purposes, or use them for advertising, profiling, or any other purpose. (see what sol pbc will never do.) we keep your billing details for as long as you have a subscription, plus the period that tax and financial-records law requires us to retain transaction records afterward (generally up to seven years); when neither applies anymore, we delete them.
from solpbc.org: almost nothing
when you visit solpbc.org, our hosting provider, Cloudflare, collects standard edge server logs (IP address, pages visited, browser type, timestamp). this is inherent in how the web works. Cloudflare's collection and handling of these logs is described in the Cloudflare privacy policy under "end users."
sol pbc does not access these logs for analytics or any other purpose. we don't use Google Analytics, tracking pixels, cookies, or any other tracking technology on solpbc.org.
from email: what you send us
if you email us, we receive your email. we use it to respond to you. we don't add you to mailing lists, share your email with anyone, or use it for marketing.
what sol pbc will never do
these aren't policies. they're binding covenants in our articles of incorporation and bylaws. while the founder serves as a director, any amendment requires his personal written consent (a right that cannot be delegated). after he ceases to serve, amendments are permitted only to strengthen these protections or to comply with mandatory law to the minimum extent strictly required. weakening amendments are foreclosed forever. (Articles of Incorporation, Article 8, Section 8.6.)
throughout this section, user data refers to what is legally defined in Article 8 as Customer Data: any data, information, content, record, output, or inference concerning a user or derived from such data, including de-identified, anonymized, aggregated, pseudonymized, or encrypted forms.
- never sell, license, sublicense, or lease user data, including anonymized, aggregated, or de-identified data. most privacy laws allow companies to share "de-identified" data freely. Article 8 closes that gap entirely. (Articles of Incorporation, Article 8, Section 8.3(a)(1))
- never use data for advertising, profiling, or behavioral targeting. user data can only be used to provide the service to the person who generated it, including through service providers strictly necessary to provide, secure, or support that service. no analytics vendors, no tracking pixels, no behavioral profiles. no exceptions. (Articles, Section 8.3(b))
- never weaken these protections, even if acquired. any merger, acquisition, or transfer of control is conditional: the successor must be legally bound to preserve a substantially equivalent benefit purpose and must assume covenants no less protective than Article 8. shareholders and former shareholders are third-party beneficiaries with direct enforcement rights that survive the transaction. (Articles, Section 8.5)
- always pursue the strongest practical encryption and access controls: encryption in transit and at rest, least-privilege access, and ongoing design toward end-to-end encryption, customer-held keys, secure enclaves, and confidential computing, all of which minimize and, where reasonably practicable, eliminate operator access to plaintext data. (Bylaws, Article III, Section 3.1)
- always resist government data demands: resist disclosure to the maximum extent permitted by law, notify the affected user if legally allowed, and pursue architectures that make compelled disclosure technically infeasible. (Bylaws, Article III, Section 3.2)
these covenants bind the company, the founder, and any successor. they apply in full to the hosted services. the relay's blind-by-construction design, and the operated backup holding encrypted blocks we have no key to, are these covenants made concrete.
the narrow exceptions. your data leaves sol pbc only in the three narrow ways the covenant allows: (1) to the named processors below, strictly to run the service you asked for; (2) when you direct it, for example by choosing to pay Stripe by card; or (3) when we're compelled by law, in which case we resist to the maximum the law allows, disclose the minimum required, and notify you when we legally can. we never sell, license, or trade your data, and we never share it for anyone else's purposes. (Articles, Section 8.3(a)(2).)
who processes data for us
sol pbc keeps its list of data processors short and names them. each is bound, by contract and by Article 8, never to use what we send it to advertise to you, profile you, or sell your data. like any payment or infrastructure company, each also runs its own fraud-prevention, security, and service operations on the limited technical data it handles, which is exactly why we send each one as little as possible, and never a byte from your journal.
| provider | what they handle | what they can see |
|---|---|---|
| Cloudflare | hosts solpbc.org; operates D1 storage for Scout application/status history and for the relay's device-enrollment records; operates the network the hosted relay runs on; operates the storage (Cloudflare R2) for the operated tier of encrypted backup | for solpbc.org: standard edge logs (it does not analyze them for us). for Scout application/status history: the minimized records described above. for the relay: connection metadata + the encrypted bytes + the enrollment records saying which of your devices may reach which of your homes. for the operated backup: the encrypted blocks + the operational information above (object count, size, last-changed) + connection metadata (network address, timing). never your content |
| Microsoft Azure | hosts the confidential GPU machine that confidential processing runs on | operational facts about the machine itself: that it exists, its size, and when it is running. the hardware boundary excludes Azure from what the machine is processing, memory included, so it sees no content, no prompts, no transcripts, and nothing from your journal |
| Stripe | payment processing for the hosted subscriptions | your card + payment details (which you provide to Stripe directly) and the minimal billing info we send to charge you. never anything from your journal |
if we ever add or change a processor, we'll update this list and the changelog below.
your rights
you have rights over your data, and we extend them to everyone, regardless of where you live:
- access: ask us what personal data we have about you
- correction: ask us to fix inaccuracies
- deletion: ask us to delete your data
- portability: get a copy in a portable format
- opt out: of sale, targeted advertising, or profiling (sol pbc does none of these, for anyone, ever)
you can see your current sign-in details at services.solstone.app/transparency. for access or export (including retained Scout lifecycle history), correction, deletion, or any other right, email support@solstone.app (for the services portal and hosted services) or contact us. some billing transaction records remain for the tax and financial-records period described above even after a deletion request. deleting service records never touches your journal, which lives on your own devices. we'll respond as fast as we can, and within the time the law requires: 45 days under the Colorado Privacy Act, with the extensions the law allows.
if we deny a request, you can appeal by replying to support@solstone.app; we'll respond to the appeal within 45 days. if we deny the appeal, you can raise it with the Colorado Attorney General.
if you're a Colorado resident, you have the specific rights granted by the Colorado Privacy Act; residents of California (CCPA/CPRA) and the EU/UK (GDPR) have the equivalent rights, including, where those laws grant them, the right to restrict or object to processing. sol pbc does not make automated decisions about you and does not profile you. our covenants go further than any of these laws require. exercise any of them through the channels above.
vit and AT Protocol
vit is built on AT Protocol, a decentralized protocol where most data is public by design. when you publish a capability, vouch for a skill, or follow someone on vit, that data flows across the AT Protocol network to relays and indexers operated by many different parties.
sol pbc's privacy commitments apply to data on sol pbc's infrastructure. once data is published to the AT Protocol network, sol pbc cannot delete copies from other servers. this is how decentralized protocols work.
if sol pbc operates a relay or PDS for vit, we collect only what the protocol requires to function. no additional tracking, analytics, or data collection.
solstone and recording laws
when what you share with the solstone app includes audio of a conversation, wiretapping and consent statutes call that recording, the term used in this section, because it is the term used in the laws.
the solstone app takes in what you share with it, including your screen and, when you turn audio recording on, the audio you record. all of it goes into your journal. if you use solstone, you are responsible for complying with recording-consent laws in your jurisdiction. some states and countries require all parties to a conversation to consent to recording.
sol pbc doesn't record anything. you do, on your own hardware. we recommend informing others in advance when audio recording is active during conversations.
the hosted services in detail
sol pbc operates three optional hosted services today. here is exactly what each does with your data.
private network (the relay)
- what we collect and why: to run the relay, the network handles connection metadata (your devices' network addresses, timing, data amounts) and the encrypted bytes themselves. to bill you, we hold your email, your subscription status and renewal dates, and a reference linking the subscription to your sign-in. that's all. nothing from your journal reaches the relay or sol pbc.
- who processes it: Cloudflare (the network the relay runs on) and Stripe (payments). both are named above, bound by contract and Article 8, and able to see only what's described, never your content.
- how it's encrypted: the tunnel is end-to-end encrypted between your own devices. the relay holds no key and keeps no copy; it cannot read what flows through. this isn't a setting you have to trust us to honor. it's how the relay is built.
- how to export and delete: manage, export, or delete your sign-in and subscription data at services.solstone.app/settings/data, or email support@solstone.app. canceling or deleting your subscription stops the relay and never touches your journal.
- what happens when you stop paying: the relay simply stops at the end of the period you've paid for. nothing is lost: your journal, your data, and your device pairings are untouched, and the free paths (direct-on-your-network, bring-your-own-transport, self-host) keep working. you are never locked out of your own journal by a billing state.
- your rights: the access, correction, deletion, portability, and opt-out rights above apply to your hosted-service data, under the Colorado Privacy Act and the equivalent laws of your jurisdiction.
encrypted backup, operated tier
- what we collect and why: to run the storage, we hold the encrypted blocks of your journal (which we can't read), a small amount of operational information about them (object count, ciphertext size, last-changed time), and the connection metadata of your upload sessions (network address, timing, data amounts), all used only to operate, secure, and bill the service. to bill you, we hold your email, your subscription status and renewal dates, and a reference linking the subscription to your sign-in. that's all. nothing readable from your journal reaches the storage or sol pbc.
- who processes it: Cloudflare (Cloudflare R2, the storage the encrypted blocks land in) and Stripe (payments). both are named above, bound by contract and Article 8, and able to see only what's described, never your content.
- how it's encrypted: solstone encrypts everything on your own device before upload: contents, file names, and folder structure. sol pbc stores only the resulting ciphertext and holds no key, no password, and no way to decrypt it. a backup is restored only with your recovery key, which we never have.
- how long we keep it: we keep your encrypted backup while your subscription is active. when your subscription lapses, the operated storage runs through the end of the paid period, then stops, and we keep the encrypted backup for 30 days after that before permanently deleting it. you can also delete it yourself anytime from the backup screen in solstone. deleting it never touches your journal on your own devices.
- how to export and delete: your backup is under your control: you restore it with your recovery key and delete it from the backup screen in solstone. manage, export, or delete your sign-in and subscription data at services.solstone.app/settings/data, or email support@solstone.app.
- what happens when you stop paying: the operated storage keeps working through the end of the period you've paid for, then stops. your encrypted backup is kept for 30 days after that, then permanently deleted (above). nothing else is lost: your journal lives on your own devices, and the free bring-your-own-bucket path keeps working. you are never locked out of your own journal by a billing state.
- your rights: the access, correction, deletion, portability, and opt-out rights above apply to your hosted-service data, under the Colorado Privacy Act and the equivalent laws of your jurisdiction.
confidential processing
- what we collect and why: while the lane is on, your journal sends the model the text and images it needs to work through, plus your audio for transcription if that switch is on. sol pbc's own engine processes it and returns the result. the service runs zero data retention (ZDR): nothing you send is kept once the request is answered, not even in logs. no human reviews it, and nothing is used to train anything. for capacity and health we keep fleet-wide totals not associated with you or your journal. access is either complimentary through the Scout program or by subscription; where you subscribe, the billing data above is what we hold.
- who processes it: sol pbc, which runs the model and the serving stack, and Microsoft Azure, which hosts the confidential GPU machine and is excluded by that machine's hardware from what it is processing. no third-party AI provider is in the path. Stripe handles payment where the access is paid.
- how it's protected: the model runs inside an AMD SEV-SNP confidential virtual machine with an NVIDIA H100 in confidential-compute mode, which keeps the cloud host out of the machine's memory and out of what it is processing. your journal verifies that hardware cryptographically before every use, against a software fingerprint pinned in solstone's open source code, and sends nothing if the check fails. this is not the sealed arrangement the relay and the operated backup have: what you send is encrypted over the network, and visible in running memory only while sol pbc's own engine is processing it. we say so rather than imply otherwise.
- how to export and delete: there is nothing retained here to export or delete. turning the lane off returns processing to your own machine and takes effect immediately; the audio switch does the same for audio alone. your sign-in and subscription data is managed at services.solstone.app/settings/data or through support@solstone.app.
- what happens when you stop paying: processing returns to your own machine at the end of the period you've paid for. nothing is lost, because nothing was stored: your journal is on your own devices and the local and bring-your-own paths keep working. you are never locked out of your own journal by a billing state.
- your rights: the access, correction, deletion, portability, and opt-out rights above apply to your hosted-service data, under the Colorado Privacy Act and the equivalent laws of your jurisdiction.
we will notify owners before launching any new hosted service and publish the updated policy. the covenants above apply to all services. they are structural, not service-specific.
changes to this policy
if we change this policy, we will:
1. update this page with a clear summary of what changed
2. update the changelog below
the covenants in the articles of incorporation and bylaws cannot be weakened through a policy update. see the amendment lock described above.
changelog
| date | change |
|---|---|
| 2026-08-21 | standardized the confidential-processing and recording-laws sections on solstone: the recording-laws section names the app as the solstone app. it now describes what the app takes in as what you share with it, no longer a closed list; attributes the act of recording to you where it describes that intake, not only where it allocates responsibility; and says that what the app takes in goes into your journal. the statutory term recording is unchanged, and so is the you-not-us responsibility allocation. no processor added or removed. the binding covenants are unchanged. |
| 2026-08-01 | added sol pbc's third hosted service, confidential processing, an AI model sol pbc runs on confidential GPU hardware for journals that want more capacity to think with than their own machine has. disclosed in full: that it is off until you turn it on and reversible at any time; that what leaves your device is the text and images the model works through, plus your audio for transcription when that switch is on (it is on by default while the service is in use, and turning it off keeps speech-to-text on your own device); that your journal itself never leaves; that sol pbc runs the model itself, on its own weights and serving stack, with no third-party AI provider in the path; and, stated plainly rather than softened, that what you send is encrypted over the network but visible in running memory only while it is being processed by that engine, which is not the sealed arrangement the relay and the operated backup have, and we do not claim it is. what we do commit to is what becomes of it: the service runs zero data retention (ZDR). no content is kept, not even in logs. no human reviews it. nothing is used to train anything. named Microsoft Azure as a new processor: it hosts the confidential GPU machine (an AMD SEV-SNP confidential virtual machine with an NVIDIA H100 in confidential-compute mode) and the hardware boundary excludes Azure from what that machine is processing, memory included, so it sees no content, no prompts, and no transcripts. disclosed the verification: your journal cryptographically checks the hardware before every use — the AMD attestation chain, the GPU's evidence, the binding to the encrypted connection, and a fingerprint of exactly which software booted, pinned in solstone's open source code so it cannot be quietly repointed — and sends nothing if the check fails, deferring honestly rather than falling back to any other service. usage accounting is fleet-wide totals not associated with any owner. the binding covenants are unchanged. |
| 2026-08-01 | removed the browser-extension disclosure added on 2026-07-26, because there is no longer a browser extension to disclose. sol pbc deleted the delivery route it used; that deletion shipped in solstone 1.0.21, and the extension is not a working part of solstone. it was never announced and never listed, and nothing it took in was ever readable to sol pbc, because it was sealed inside the browser and we held no key. when browser support returns it will be part of a full sol client and covered by that client's disclosures, and this policy will describe it then. the row below records what the 2026-07-26 disclosure said, and stays as written. also updated the recording-laws section to describe what solstone does as experiencing your day along with you, matching the language used elsewhere; the statutory term recording and the you-not-us responsibility allocation are unchanged. no processor added or removed. the binding covenants are unchanged. |
| 2026-07-26 | disclosed solstone's browser extension in full: that it arrives holding no standing access to any website and reads only the sites you add behind a per-site browser permission grant (and what your browser hands its toolbar popup); that it takes in a page's rendered text and rough layout — including text the page renders out of sight, like screen-reader labels — but never pixels, raw HTML, form-field contents, clicks, scrolling, or keystrokes; that it reads an added site whenever a tab on it is open, background tabs included, and re-reads as the page changes; that the page address is reduced to origin and path inside the page before anything leaves it, with query strings, fragments, and embedded credentials dropped; that message text is included where you add a messaging site, and that outside Gmail and Slack a message you are still typing is taken in with the page; that what it took in waits in your browser's own storage until your journal accepts it, and how to clear it. named both destinations honestly: a journal on your own computer, which sol pbc never touches, or sealed inside the browser to your own home over the existing blind relay — with that relay's connection metadata and device-enrollment records disclosed as Customer Data, added to the relay section, the processor table, and both subpoena paragraphs. no new processor. added sol pbc's affirmative Chrome Web Store Limited Use statement, including that our articles bar selling outright and foreclose reliance on the store policy's merger/acquisition transfer permission. the binding covenants are unchanged. |
| 2026-07-13 | disclosed Scout application/status history, including the forward-only lifecycle audit, its exact minimized contents, operational-only purpose, owner-sign-in-lifetime retention/deletion boundary, and support export channel; named Cloudflare D1 processing; clarified that local use of solstone and vit still sends sol pbc nothing. the lifecycle audit adds no journal content and the binding covenants are unchanged. |
| 2026-06-23 | added sol pbc's second hosted service, the operated tier of encrypted backup (storage sol pbc runs so an encrypted copy of your journal can live off your own machine). disclosed what it collects — encrypted blocks sol pbc has no key to and cannot read, plus minimal storage operational metadata (object count, ciphertext size, last-changed time, used only to operate and bill) — named Cloudflare R2 as the storage processor, and disclosed the retention rule: after the paid period ends, the encrypted backup is kept 30 days, then permanently deleted. Stripe (payments) is unchanged. the binding covenants are unchanged. |
| 2026-06-20 | renamed the hosted service from "solstone hosted — private link" to private network to match sol pbc's v2.1 brand model (the brand lives at the layer; services are named by mechanism). naming-only — no data practice, processor, or covenant changed. |
| 2026-06-16 | updated for sol pbc's first hosted service, solstone hosted — private link (a paid, blind-by-construction relay). added the hosted-relay and billing data-collection disclosures; named Stripe (payments) and Cloudflare (relay network) as processors, with a processor table; described the hosted service in detail (data, processors, encryption, export/delete, graceful cancellation, rights); updated "your rights" with the services.solstone.app self-service + support@solstone.app channels, the CPA appeal mechanism, and the CPA/CCPA/GDPR rights. the binding covenants are unchanged. |
| 2026-05-01 | hosting attribution corrected: solpbc.org is served by Cloudflare Workers only — the prior reference to GitHub Pages reflected an earlier deployment and was no longer accurate. linked to the Cloudflare privacy policy for the edge server logs Cloudflare collects from visitors. |
| 2026-05-01 | updated to reflect the amendment and restatement of Article 8 (CO SOS Doc. 20261537456) and the adoption of restated bylaws. acquisition language updated to reflect that change of control is conditional (mission-aligned successors only, with covenants no less protective). amendment-lock language updated to reflect the new strengthening-only rule outside the founder's stewardship. operational-agent succession references removed; succession now flows through the Successor Designator mechanism in Article 8 §8.4. |
| 2026-03-29 | initial publication |
this privacy policy reflects the binding covenants in sol pbc's articles of incorporation and bylaws. the covenants are the authority — this policy describes them in plain language. if there is ever a conflict between this policy and the articles or bylaws, the articles and bylaws govern.
questions? get in touch.