SoleCo

Privacy

Last updated September 18, 2026

What SoleCo collects, why, and what it will never hold.

Pre-launch draft. The operating entity, the privacy contact, and whether SoleCo needs a UK or EU representative are being settled before SoleCo takes payment.

What SoleCo never stores

SoleCo never stores passwords, API keys, recovery codes, or seed phrases. It records which accounts each company uses and whose login controls them, never the passwords themselves. If you paste something that looks like a key, SoleCo refuses to save it. There are no file uploads, so password exports can’t be uploaded either.

What SoleCo stores

Only what the score and reminders need:

  • Your email address and, if you add it, your name.
  • Company names, entity type, state, and one line on what each company does.
  • Account names and whose login each one is (for example “GitHub organization acme-robotics, company login”), with renewal dates and links you add.
  • Scan answers, checklist progress, the dates you recorded emergency access being used, and when you downloaded documents.
  • Payment status from Stripe. Card details go to Stripe and never reach SoleCo.

What stays in your browser

The people in your step-in guide, their phone numbers and email addresses, and your wishes in your own words are typed, stored, and printed in your browser. SoleCo’s servers never receive them, so SoleCo can’t lose them in a breach, and can’t recover them for you either. The scan doesn’t ask for names, bank names, or which password manager you use.

The free scan

If you run the scan without signing in, your answers stay in your browser’s local storage. They’re sent to SoleCo only to calculate the score and aren’t saved on the server unless you sign in and choose to save them.

Who else sees it

  • Service providers that run SoleCo: hosting (Vercel), database (Neon or Supabase), email delivery (Resend), and payments (Stripe).
  • Nobody else. SoleCo doesn’t send your documents to lawyers or anyone else, sell data, or use it for advertising.

Your choices

  • Change or remove anything in your workspace at any time.
  • Delete your account in Settings. This removes everything SoleCo stores. Step-in guide details in your browser stay until you clear them on the guide page, and printed copies are yours to shred.
  • Questions: [privacy contact, to be added before launch].

How long SoleCo keeps it

  • Your workspace, which means your companies, accounts, scan history, and checklist progress, for as long as your account exists. Deleting your account removes it.
  • Database backups hold copies for a short window set by the provider, after which they expire.
  • Sign-in links expire 15 minutes after you ask for one, and work once. A signed-in session lasts 30 days.
  • Payment records, for as long as tax rules require them. Stripe holds the card details, not SoleCo.
  • A free scan you haven’t saved, and your step-in guide details, stay in your browser until you clear them. They aren’t on SoleCo’s servers at all.

If you’re in the UK or the EU

The UK GDPR and the EU GDPR apply to you. SoleCo is built so that the most sensitive part of your plan, the people in it and what you want to happen, never reaches its servers, so there is less to ask about than usual.

Who is responsible: [Operating entity] is the controller for what SoleCo stores. Contact: [privacy contact, to be added before launch].

Why SoleCo is allowed to hold it:

  • To provide what you asked for (a contract with you): your email address, your companies and accounts, your score, and your checklist progress.
  • Legitimate interests: keeping the service working and preventing abuse, which is why sign-in attempts are rate limited and sessions are recorded.
  • Consent: the quarterly check-in email, which you turn on and can turn off at any time.
  • A legal obligation: payment and tax records.

Your rights: you can ask for a copy of what SoleCo holds about you, correct it, delete it, receive it in a portable form, object to or restrict a use, and withdraw consent. Settings already does the two most common ones: see your workspace, and delete it. For anything else, write to the contact above, and SoleCo will answer within a month.

Complaints: if you think SoleCo has it wrong, you can complain to your national data protection authority, or to the Information Commissioner’s Office in the UK. Telling SoleCo first is welcome but not required.

Where it’s processed: SoleCo runs on US providers (Vercel, Neon or Supabase, Resend, Stripe). Data is transferred outside the UK and the EEA under the standard contractual clauses in those providers’ terms. [To confirm before launch: the signed data processing terms with each provider, and whether SoleCo needs a UK or EU representative.]

No profiling, no advertising, and no automated decisions about you. The SoleCo Score is a calculation from answers you gave, shown to you with every row of its working. Nothing decides anything about you, and nothing is used to target advertising.

Staying safe

SoleCo never asks for a password, a two-factor code, a recovery code, or a key. Not by email, not by phone, not on this site. If someone claiming to be SoleCo asks, it isn't us. How SoleCo handles security

Cookies

One cookie keeps you signed in. No advertising or cross-site tracking cookies.