Last updated: July 13, 2026
This policy describes how Solace AGI ("Solace", "we") handles data. It is written to match how the product actually works. Because Solace operates a managed technology department, we do process your data on your behalf — this policy is honest about where it goes and how it is protected.
The Solace runtime that executes work routes all network activity through a single controlled egress at solaceagi.com. The runtime does not hold third-party API keys and does not reach external services on its own. This means:
Each customer runs in its own tenant scope. Cross-tenant access to your data is a prohibited state in the architecture, not a configuration setting. WorldData (public/licensed) is kept separate from the private customer records you provide.
To operate the service we use infrastructure and model providers (for example, cloud hosting and language-model providers) reached only through our controlled backend. We contract these providers to protect your data and to process it only to deliver the service. A current subprocessor list is available on request.
We retain your data for as long as needed to operate your service and to maintain the evidence trail you rely on. On termination you may export your data, and you may request deletion consistent with the Ownership Covenant and any legal retention obligations.
Depending on your jurisdiction you may have rights to access, correct, export, or delete personal data we process. For data we process as a processor on a customer's behalf, we act on that customer's instructions. Contact us to exercise these rights.
Security controls are described on the Trust page, where each control is labeled as implemented, a design goal, or a contractual option. We do not claim certifications we have not completed.
We may update this policy; material changes will be notified. This page supersedes any earlier "Solace City" privacy statement. Questions: phuc@phuc.net.