Last updated: June 2026 · Plain words on purpose.
Sotto is built on a simple idea: your conversations are a private room. This policy explains what we collect, why, who touches it, and what your choices are — in plain language. If anything here is unclear, write to us and we'll explain it like a person.
We do not sell your data. We do not show ads. Your conversations are not used to train AI models.
Sotto runs on a small set of service providers, each receiving only what's needed for their job:
Sotto accounts are individual. There are no shared workspaces, organization dashboards, or admin views — your threads are not visible to your employer or anyone else through the product. Our team does not browse user conversations; limited technical access exists only for security, debugging at your request, or where the law requires it.
Your account and threads are kept for as long as you have an account, because memory across time is the product. Delete your account and we delete your conversations and threads from production systems within 30 days, with routine backups expiring on their own schedule after that.
Data is encrypted in transit and at rest. Sign-in uses one-time magic links rather than passwords, so there's no Sotto password to leak. No system is perfectly secure, but we build as if your conversations were ours.
Sotto is for working professionals and isn't intended for anyone under 18.
Sotto is operated from Singapore and handles personal data in line with Singapore's Personal Data Protection Act (PDPA). If you use Sotto from elsewhere, your data is processed where our providers operate.
If this policy changes in a way that matters, we'll tell you in the product or by email — not bury it.
Questions, deletions, exports: privacy@[yourdomain].