Back to Sologang

Privacy Policy

Last updated: [[PUBLICATION DATE]]

This policy describes how Sologang processes the personal data of its users, in accordance with Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 (LOPDGDD).

Data controller

  • Controller: [[Alfredo Omaña]] (brand "Sologang")
  • Tax ID (NIF): [[21495245C]]
  • Address: [[Santo Isidra 31, 28041, Madrid, Spain]]
  • Privacy contact: privacy@sologang.io

What data we process

Registration and identification

  • Email address (for registration and magic-link sign-in).
  • A system-generated user identifier.

API keys (BYOK, "bring your own key")

If you connect keys from language-model providers, they are encrypted on your own device (device-bound AES-GCM) and stored only in encrypted form. The plaintext key is never transmitted to or stored on our servers. You keep control of your keys at all times.

Product usage

  • Conversations and messages you exchange with the platform's roles.
  • Missions, roadmap and deliverables you generate.
  • Your project profile (idea, sector, stage, country, product URL) that you provide.
  • Usage records (tokens and cost) for spend control and billing.
  • Actions prepared or executed in connected tools.
  • Your plan or subscription tier.

Third-party connections (when you authorize them)

If you connect services such as GitHub or Slack, the access tokens needed to execute the actions you authorize are stored. You can revoke these connections at any time.

Purpose and legal basis

  • Providing the service (performance of a contract, Art. 6.1.b GDPR).
  • Spend control and billing (contract / legal obligation).
  • Security and abuse prevention (legitimate interest, Art. 6.1.f GDPR).
  • Service communications (contract or consent, as applicable).

Processors and providers

We use providers acting as data processors, with appropriate safeguards:

  • Supabase (authentication and database).
  • Vercel (hosting and infrastructure).
  • Language-model providers to which you connect your own key (BYOK): processing takes place with your key and under your account with that provider.
  • GitHub, Slack or other tools you connect voluntarily.

Some providers may process data outside the European Economic Area, in which case the safeguards required by the GDPR apply (for example, standard contractual clauses). [[REVIEW with an advisor the specific server location of your Supabase/Vercel setup and adjust this paragraph.]]

Retention

We keep your data while your account is active. When you delete conversations or your account, the associated data is removed within the corresponding technical timeframes, except where legal retention obligations apply (for example, billing records).

Your rights

You may exercise your rights of access, rectification, erasure, objection, restriction and portability by writing to privacy@sologang.io. You may also lodge a complaint with the Spanish Data Protection Agency (www.aepd.es).

Minors

The service is intended for adults or persons with legal capacity to enter into contracts.

Sologang · hello@sologang.io · privacy@sologang.io