Legal
Privacy Policy
Last updated: August 25, 2026
Solomo is an independent research tool, not a broker or a SEBI-registered adviser, and nothing on it is investment advice. This policy is written to describe what the product actually does; it has not been reviewed by counsel, and should be before any large-scale launch.
1. What we collect
You can use every part of Solomo — screener, company research, portfolios, and the AI chat — without an account. Nothing is hidden behind a sign-in.
- On your device only — theme, experience mode, exchange and notification preferences, plus your watchlist and any portfolio you have not synced, live in your browser's local storage. Clearing your browser removes them.
- If you create an account — your email address, and (if you sign in with Google) the name and profile picture Google returns. Passwords are never visible to us: they are hashed by our authentication provider and we cannot read them.
- If you sync a portfolio — the ticker symbol, quantity, average cost, sector and optional purchase date of each holding. Nothing that identifies you to a broker: no account number, no PAN, no bank or demat details. We never ask for them and cannot accept them.
- Server logs — our host records standard access logs (IP address, user agent, pages requested) for security and performance, and we keep a short application log described in section 4.
- How Solomo is used — which pages are opened and a small set of named actions, tied to a random per-browser identifier so we can tell a returning visitor from a new one. This is our own analytics, kept on our own server, never shared. It never records what you type. Section 5 sets out exactly what it does and does not store, and how to switch it off.
2. Accounts and where your data lives
Accounts and portfolio sync are provided through Supabase, which hosts our authentication and database. We chose the Mumbai (ap-south-1) region, so account data for Indian users is stored in India rather than being sent abroad.
- Only you can read your rows. The database enforces row-level security: every query is restricted to the signed-in account's own records, at the database itself rather than by application code. One user cannot read another's portfolio even if our front-end had a bug.
- The key that ships in your browser is a public one by design, and is useless without a valid session for the account it belongs to.
- Supabase processes this data on our instructions as our processor. Their handling is governed by the Supabase privacy policy.
3. What we don't do
- We do not sell or rent personal information, ever.
- We do not run advertising, ad networks, or cross-site tracking pixels.
- We do not connect to your broker, hold your money, or place trades. We cannot see your real holdings unless you type or import them yourself.
- We do not require an account, and we do not put research content behind one.
4. AI features
The "Ask Solomo" chat and the portfolio page's "Ask about your portfolio" chat generate answers with a third-party large-language-model provider, the Google Gemini API, used on Google's free (unpaid) tier.
- What is sent: the question you type, the recent turns of that same conversation, and — on the portfolio page only — a summary of the holdings you have entered (ticker symbols, quantities, values and derived ratios). Your name, email and account identifier are never sent.
- How Google may use it: under the Gemini API terms for unpaid services, Google may use inputs and outputs to provide, improve and develop its products, and human reviewers may read them. Please do not type personal details into the chat.
- What we log: we do not store your questions or the answers in full, and never the answer text at all. Our application log records which company an answer was grounded in, which model replied, and token counts. It also records a shortened, redacted outline of the question: capped at twelve words, with email addresses, phone numbers, web links, recognised company names, dates, money amounts and every number replaced by placeholders such as <co> and <n>. Nothing identifying you — no name, account, or IP address — is stored beside it.
- Why we keep that outline: a question Solomo could not answer is the most useful signal we get, and it is the only way to learn what the product is missing. If we logged only the successes we would never see the gap.
- The limit of that redaction: it is automatic and imperfect. It removes a company name only when our system recognised the company, so an unusual spelling or a name we do not carry can survive into the log. Please treat the chat as you would any public search box and do not type anything private into it.
- Daily limits: to keep a shared free quota available to everyone, we count AI answers against a rolling daily allowance. Those counters are stored under a hashed form of your IP address; the stored record itself contains only a number and a timestamp.
5. Cookies, local storage and analytics
We set no advertising cookies. Local storage holds your preferences and any unsynced portfolio data, and clearing it removes everything Solomo has saved on your device.
Our landing page includes Cloudflare Web Analytics, which counts page views without cookies and without building a profile of you across sites. It is the only third-party analytics on Solomo.
We also run our own product analytics, on our own server. Nothing is shared with anyone. It records which pages are opened and a short list of named actions — opening a chart, running a screen, asking the AI, hitting a daily limit — so we can tell which parts of Solomo are useful and where people get stuck. Each browser is given a random identifier, stored in local storage, that lets us count a returning visitor as one person rather than two. It is not linked to your name or email, and it is not shared with or bought from anybody.
What this deliberately never records: the text of anything you type, the values in any form, the contents of a page, your full browser user-agent, or your IP address. Web addresses are stored without their query strings, and where you arrived from is reduced to the site name alone. Your IP address is used only to produce a short scrambled code that changes every day, so that we can spot one machine pretending to be hundreds; because the scrambling changes daily, that code cannot be used to follow you from one day to the next.
Opting out. If your browser sends a Global Privacy Control or Do Not Track signal, Solomo sends no product analytics at all — the data is never collected rather than collected and discarded. Most privacy-focused browsers and extensions can turn this on for you.
6. Data security
The site is served over HTTPS with HSTS, a restrictive Content Security Policy and frame protections. Credentials and keys are held outside the public web root, passwords are hashed by our authentication provider, and database access is restricted per account as described in section 2. No system is perfectly secure, and we will not claim otherwise.
7. How long we keep things
- Account and synced portfolio data — kept while your account exists. Delete your account and it is removed.
- Server access logs — retained by our host on their standard schedule, typically a few weeks.
- AI usage counters — reset on a rolling 24-hour window.
- Product analytics events — kept for 90 days on our own server, then deleted automatically. The daily scrambling code used to spot abuse is discarded after 3 days.
- Application log (the AI capacity and question-outline log in section 4) — kept on our own server and cleared periodically. It is never shared and never leaves that machine.
- Local browser data — until you clear it.
8. Your rights
Under India's Digital Personal Data Protection Act, 2023, and comparable laws elsewhere, you may:
- Access a summary of the personal data we hold about you and how it is processed.
- Correct data that is inaccurate, or complete data that is incomplete.
- Erase your data — deleting your account removes your email and every synced holding.
- Withdraw consent at any time, by deleting your account or simply by not using the AI features.
- Raise a grievance about how we have handled your data, using the contact below.
If you never create an account, we hold no personal data about you beyond ordinary server logs, so there is nothing for us to return or delete.
9. Contact
Questions, requests, or grievances about this policy or your data: privacy@solomo.ai. We aim to respond within 30 days.