Sotto Get Started

Privacy Policy.

Last updated: June 2026 · Plain words on purpose.

Sotto is built on a simple idea: your conversations are a private room. This policy explains what we collect, why, who touches it, and what your choices are — in plain language. If anything here is unclear, write to us and we'll explain it like a person.

What we collect

  • Account information. Your email address (used for magic-link sign-in), and the name and role you optionally provide so Sotto can address you naturally.
  • Your conversations and threads. The messages you exchange with Sotto and the situation context Sotto keeps for you — people you mention, plans, open loops, outcomes. This is the product working, and it exists so Sotto can remember your situation across weeks.
  • Payment information (paid plans only). Handled by Stripe; we never see or store your card details.
  • Basic usage data. Technical logs (device type, errors, timestamps) needed to keep the service running and fix what breaks.

How we use it

  • To provide Sotto: generating responses, remembering your threads, following up on your situations.
  • To run the service: sign-in, billing, support, debugging.
  • To improve Sotto in aggregate — measuring things like how often threads reach resolution. Not by reading your conversations for curiosity.

We do not sell your data. We do not show ads. Your conversations are not used to train AI models.

Who processes your data

Sotto runs on a small set of service providers, each receiving only what's needed for their job:

  • Anthropic — the AI provider that powers Sotto's responses. Your messages are sent to Anthropic's API to generate replies. Under Anthropic's commercial API terms, these are not used to train their models.
  • Supabase — our database and authentication provider, where your account and threads are stored encrypted at rest.
  • Stripe — payment processing for paid plans.
  • Hosting and infrastructure providers — used to serve the application.

Who can see your conversations

Sotto accounts are individual. There are no shared workspaces, organization dashboards, or admin views — your threads are not visible to your employer or anyone else through the product. Our team does not browse user conversations; limited technical access exists only for security, debugging at your request, or where the law requires it.

How long we keep it

Your account and threads are kept for as long as you have an account, because memory across time is the product. Delete your account and we delete your conversations and threads from production systems within 30 days, with routine backups expiring on their own schedule after that.

Your choices

  • Access or correct your account information at any time.
  • Delete your account and data — email us from your account address and we'll handle it.
  • Export — ask and we'll send you your threads in a readable format.

Security

Data is encrypted in transit and at rest. Sign-in uses one-time magic links rather than passwords, so there's no Sotto password to leak. No system is perfectly secure, but we build as if your conversations were ours.

Age

Sotto is for working professionals and isn't intended for anyone under 18.

Where we operate

Sotto is operated from Singapore and handles personal data in line with Singapore's Personal Data Protection Act (PDPA). If you use Sotto from elsewhere, your data is processed where our providers operate.

Changes

If this policy changes in a way that matters, we'll tell you in the product or by email — not bury it.

Contact

Questions, deletions, exports: privacy@[yourdomain].

Sotto
FAQPrivacyTermsGet started

Sotto is a thinking partner, not a therapist, a lawyer, or a substitute for the people in your life. When something is beyond its lane, it says so and points you to real support.

Edit with