Privacy Policy
Last updated: July 25, 2026. The short version: your journal is yours. We don't read it, mine it, profile you, train AI on it, or sell it — ever. With end-to-end encryption on, we can't read it even if we wanted to.
Who we are
Solous ("Solous", "we", "us", "our") is a private life-journaling service. For
the purposes of the EU/UK General Data Protection Regulation (GDPR), Solous is the
data controller of the personal data described here.
Data-protection contact: contact@solous.live.
We aim to answer any privacy request within 30 days.
What we collect
- Account data: your email address and authentication
credentials (a one-way hash of your password, passkey public keys, and
authenticator/2FA setup). For end-to-end-encrypted accounts we also store
wrapped (encrypted) key material that only your passphrase or
recovery key can open — we cannot use it.
- Your content: the entries, replies, tags, locations, edit
history, and media (photos, audio, video) you choose to save. This exists
solely so the Service can show it back to you.
- Technical logs: standard web-server and security logs
(IP address, timestamps, requested pages, error traces) kept briefly for
security, abuse prevention, and debugging.
- Essential cookies: a session cookie and a CSRF-protection
token, required to keep you logged in securely. Nothing else.
We collect nothing else. No analytics scripts, no advertising pixels,
no third-party trackers, no device fingerprinting, no data brokers.
Server logs. Our own web server records each request so
we can tell whether the site is working and spot abuse. We deliberately keep
the least that is still useful: your IP address is masked
before it is written down (the last part is replaced with zeroes, so it
identifies a rough network rather than you), anything you typed into
a URL is dropped entirely — searching your own journal never reaches
a log file — and cookies are never recorded, so a log can't be used to sign
in as anyone. These logs are deleted after 14 days. They are
never used to build a profile, and they are never shared.
One exception, stated plainly because it is a third party: the
sign-up and password-reset pages load a bot check from Cloudflare
(Turnstile). It exists to stop automated scripts from creating accounts and
making us send email to people who never asked for it. Cloudflare sees your IP
address and some browser characteristics in order to decide whether you're a
robot. It is not an analytics or advertising product, it sets no tracking
cookies, and it appears nowhere inside your journal — only on those
two pages, before you have an account.
Why we process it, and our legal bases
We only process your data to run the Service for you. Under the GDPR, our
lawful bases are:
- Performance of a contract (GDPR Art. 6(1)(b)) — creating
and operating your account and storing/serving your content are what you
signed up for.
- Legitimate interests (Art. 6(1)(f)) — keeping the Service
secure and reliable (brief logs, abuse prevention, debugging), balanced
against your rights.
- Legal obligation (Art. 6(1)(c)) — where we are legally
required to retain or disclose specific information.
- Consent (Art. 6(1)(a)) — for anything optional we might
add in future; you can withdraw consent at any time.
We do not use your data for advertising, profiling, automated
decision-making with legal effect, or AI training.
How your content is protected
- Encrypted in transit (HTTPS/TLS with HSTS) and
encrypted at rest (AES-256).
- Two-factor authentication is mandatory on every account.
- Media is kept in a private store and served only through short-lived signed
links.
- End-to-end encryption (optional, per account): when you
turn it on, your entries, replies, locations, edit history, and media are
encrypted on your device with a key derived from your passphrase. We store
only ciphertext and key material we cannot open. In that mode we
cannot read your content — and we cannot recover it if you lose your
passphrase and recovery key. This is the point.
- Honesty note: for accounts without end-to-end
encryption, "encrypted at rest" does not stop our systems from technically
accessing stored content. We do not access it except where strictly
required to operate the Service, to prevent imminent harm, or where legally
compelled.
How long we keep it
- Your content and account data: for as long as your account
exists. You can delete any of it, or your whole account, at any time.
- After deletion: content is removed from live systems
promptly and expires from encrypted infrastructure backups within about
7 days.
- Technical/security logs: retained for a short period
(generally up to 90 days) then discarded.
Who processes your data on our behalf
We keep our vendors to a minimum. Your data is hosted on
Amazon Web Services (AWS) in the United States, which stores and
processes it strictly on our instructions as a data processor (compute, database,
media storage, and transactional email delivery). We have no advertising or
data-sharing partnerships of any kind, and we do not sell or rent your data.
We disclose data to authorities only when compelled by valid
legal process, and only the minimum required. For end-to-end-encrypted content,
what we can produce is ciphertext we cannot decrypt.
International data transfers
If you use Solous from outside the United States (including the EU/UK), your
data is transferred to and processed in the US. Where required, such transfers
rely on appropriate safeguards such as the Standard Contractual Clauses offered
by our infrastructure provider.
Your rights
Depending on where you live (including under the GDPR and the California CCPA/CPRA),
you have some or all of these rights:
- Access / know — get a copy of the personal data we hold.
You can also export your complete journal at any time from
the Export page.
- Rectification / correction — fix inaccurate data (you can
edit your content directly).
- Erasure / deletion — delete your content or your whole
account at any time.
- Restriction and objection — ask us to limit or stop certain
processing.
- Portability — receive your data in a portable, machine-readable
format (that's exactly what the export is).
- Withdraw consent — where processing relies on consent.
- Non-discrimination — we will never penalize you for
exercising these rights.
California residents: we do not sell or share
your personal information (as those terms are defined by the CCPA/CPRA), and we do
not use it for cross-context behavioral advertising.
To exercise any right, email
contact@solous.live. If you are in the
EU/UK and believe we have mishandled your data, you also have the right to lodge a
complaint with your local data-protection supervisory authority.
Children
Solous is not directed to children. You must be at least 16 years old (or the
minimum age of digital consent in your country, if higher) to create an account.
We do not knowingly collect data from children under that age; if you believe a
child has signed up, contact us and we will delete the account.
Data breaches
If a personal-data breach occurs that is likely to put your rights at risk, we
will notify affected users and, where legally required, the relevant supervisory
authority without undue delay.
Changes to this policy
We may update this policy; the "Last updated" date above always reflects the
current version, and we will announce material changes in the Service.
Contact
Privacy questions or requests: contact@solous.live.
See also our Terms of Service.