Privacy Policy
This Privacy Policy explains how Sontairo, operated by Sontairo LLC, collects, uses, discloses, and safeguards information when you use the Sontairo website, application, integrations, and related services.
1. Scope
This Privacy Policy applies to information we collect when you access or use Sontairo, including our website, user dashboards, workspaces, AI agents, integrations, APIs, and related support or communications channels (collectively, the "Service").
If you use Sontairo on behalf of a company or workspace, information associated with that workspace may be visible to authorized workspace administrators and members based on the permissions and roles configured in the Service.
2. Information We Collect
Depending on how you use the Service, we may collect the following categories of information:
- account and profile information, such as your name, email address, profile image, password hash, and email verification status;
- workspace, project, and team information, such as workspace names, project names, membership roles, permissions, and related configuration data;
- billing and subscription information, such as plan selection, subscription status, billing period details, and payment-related identifiers from our payment processor;
- prompts, chat messages, instructions, memories, workflow content, tool calls, tool results, approvals, artifacts, and other inputs or outputs you create or generate through the Service;
- connector and integration information, such as connected provider names, scopes, metadata, and encrypted credentials or tokens needed to maintain integrations;
- financial account information, if you choose to connect a bank, card, loan, or investment account through Sontairo Finance, such as institution name, account type and mask, balances, transactions, liabilities, and holdings, together with the encrypted access token Plaid issues for that connection (see Section 5A);
- usage, device, and log data, such as timestamps, IP address where available, session information, security events, audit logs, and operational telemetry needed to run and protect the Service;
- communications and support data, including messages you send to us and, where voice or call-related features are used, call metadata or transcripts processed through those features.
3. How We Use Information
We use information we collect to:
- provide, operate, secure, and maintain the Service;
- authenticate users and manage workspaces, projects, permissions, and subscriptions;
- process prompts, run AI workflows, execute automations, and fulfill your instructions to connected providers and tools;
- prevent fraud, abuse, unauthorized access, and other security issues;
- troubleshoot problems, monitor performance, and improve reliability, safety, and usability;
- communicate with you about your account, billing, product updates, support issues, and legal or policy changes;
- comply with legal obligations, enforce our agreements, and protect our rights, users, and third parties.
4. How We Share Information
We may disclose information in the following circumstances:
- with service providers and subprocessors that help us run the Service, such as authentication, database, hosting, payment, queuing, voice, integration, or infrastructure providers;
- with AI model providers and connector or integration partners when you instruct the Service to send data to them or when that transfer is necessary to complete your request;
- with workspace owners, admins, members, or other authorized users according to your workspace configuration and access controls;
- when required by law, legal process, or a valid governmental request, or when we believe disclosure is necessary to protect rights, safety, property, or security;
- in connection with a merger, financing, acquisition, reorganization, asset sale, or similar corporate transaction, subject to customary confidentiality protections.
We do not disclose your personal information to unrelated third parties for their independent advertising use merely because you use the Service.
5. Providers and Processors Used by the Service
The current Service stack may use third-party providers for hosting, billing, model access, connectors, voice and messaging, email, financial data connectivity, database hosting, and operational infrastructure. These currently include Cloudflare (hosting, network, and storage), Stripe (billing and Sontairo Finance payments), Plaid (financial account connectivity, see Section 5A), OpenRouter and the model providers you configure or we support (AI inference), Composio (tool integrations), Twilio (voice and SMS), Brevo (email), and managed PostgreSQL database hosting.
If you connect your own external services or provide your own API keys, requests and data you send through Sontairo may be transmitted to those providers according to your instructions and their respective terms and privacy policies.
5A. Financial Account Data and Plaid
Sontairo Finance lets you connect business and personal financial accounts so the Service can show balances, transactions, liabilities, and holdings and help you analyze them. We use Plaid Inc. ("Plaid") to connect to your financial institutions. When you link an account, you authenticate directly with your institution inside Plaid Link; Sontairo never sees or stores your banking username or password.
By connecting an account, you grant Sontairo and Plaid the right, power, and authority to act on your behalf to access and transmit your personal and financial information from the relevant financial institution, and you agree to that information being transferred, stored, and processed by Plaid in accordance with the Plaid End User Privacy Policy.
- What we use it for: displaying and organizing your accounts, generating summaries, forecasts, and analysis for you at your request, and powering Finance features you enable. We request only the Plaid products and scopes needed for the features you use.
- What we never do with it: we do not sell financial data, share it for advertising, or use it to train, fine-tune, or evaluate AI models, including Enterprise custom models. The AI reads it at inference time only to answer your own requests.
- How it is protected: Plaid access tokens and financial records are encrypted at rest at the application layer in addition to provider disk encryption, transmitted only over TLS, and restricted to your workspace.
- Disconnecting and deletion: you can disconnect an institution at any time from within Sontairo; doing so removes the connection at Plaid and schedules deletion of the stored financial data for that connection. You may also ask us to delete financial data by emailing legal@sontairo.com, and we will honor the request within 30 days subject only to legal retention obligations. You can additionally manage connections Plaid holds for you through Plaid Portal at my.plaid.com.
- Personal accounts: personal finance accounts are kept in a separate scope from any business entities on your account and are visible only to you unless you choose to share them.
6. Cookies, Sessions, and Similar Technologies
We use cookies, session mechanisms, and similar local storage technologies to keep you signed in, maintain security, remember workspace or interface preferences, and support product functionality. If you disable cookies or similar storage, some features may not function properly.
7. Data Retention
We retain information for as long as reasonably necessary to provide the Service, maintain account history, support operations, comply with legal obligations, resolve disputes, enforce agreements, and protect against fraud or abuse. Different categories of data may be retained for different periods depending on their purpose and legal or operational requirements.
Even after deletion requests or account closure, we may keep limited information in backups, logs, or archival systems for a reasonable period where required for security, fraud prevention, compliance, or legitimate operational needs.
8. Security
We use administrative, technical, and organizational measures designed to protect information we process, described in our Security Overview. For example, all traffic is encrypted in transit with TLS, and secrets, connector credentials, provider tokens, and financial account tokens are encrypted at rest at the application layer (AES-256) in addition to provider storage encryption. However, no method of transmission over the internet or method of storage is completely secure, and we cannot guarantee absolute security.
9. Your Choices
You may be able to update certain account information directly in the Service. You may also disconnect integrations, remove team members, or close workspaces according to the features available in your account.
If you need assistance with access, correction, deletion, or other privacy-related requests, contact us at legal@sontairo.com. We may need to verify your identity and evaluate the request in light of applicable law, technical limitations, security obligations, and the rights of other users or workspace owners.
10. International Use
Sontairo may be accessed from jurisdictions outside the United States, and data may be processed in the United States or other countries where we or our providers operate. By using the Service, you understand that data protection laws in those jurisdictions may differ from those in your own location.
11. Children's Privacy
The Service is not directed to children, and we do not knowingly collect personal information from children in a manner intended to be covered by child-specific privacy laws. If you believe a child has provided us personal information inappropriately, contact us and we will review the request.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in the Service, our practices, legal requirements, or provider relationships. When we do, we will update the "Last updated" date above, and we may provide additional notice where appropriate.
13. Contact
If you have questions about this Privacy Policy or our privacy practices, contact Sontairo LLC at legal@sontairo.com.