Effective: 2026-08-21
Prompts and generated outputs are processed to serve each request, including execution of candidate code inside an isolated sandbox for verification.
Operational metadata only: timestamps, token counts, model id, status codes, latency, and a hashed API-key identifier — used for metering, billing, rate limiting, abuse prevention, and reliability. Raw prompt text is not written to server logs.
Response bodies may be retained up to 72 hours solely to
support idempotent replay (Idempotency-Key) and background-job
delivery, then deleted. Optional conversation memory (only when you send a
conversation_id) is retained until it expires or you delete it.
Verified problem–solution pairs (a prompt plus code that passed
verification) may be retained in Soma's internal solution corpus to improve
future answer quality.
We do not train foundation models on your data. The solution corpus above is a retrieval store of execution-verified code, not model training. If you need zero data retention (no corpus, no memory, no replay cache), contact us for a ZDR key.
Requests may be processed transiently by vetted third-party inference infrastructure under contractual terms that prohibit training on your content. Verification, certification, signing, and storage run on Soma-operated infrastructure in US datacenters.
Zero-data-retention by default: no (see Retention). HIPAA: not supported. Do not send PHI or regulated data.