Soma 0.1 — Privacy & Data Policy

Effective: 2026-08-21

What we process

Prompts and generated outputs are processed to serve each request, including execution of candidate code inside an isolated sandbox for verification.

What we log

Operational metadata only: timestamps, token counts, model id, status codes, latency, and a hashed API-key identifier — used for metering, billing, rate limiting, abuse prevention, and reliability. Raw prompt text is not written to server logs.

Retention

Response bodies may be retained up to 72 hours solely to support idempotent replay (Idempotency-Key) and background-job delivery, then deleted. Optional conversation memory (only when you send a conversation_id) is retained until it expires or you delete it. Verified problem–solution pairs (a prompt plus code that passed verification) may be retained in Soma's internal solution corpus to improve future answer quality.

Training

We do not train foundation models on your data. The solution corpus above is a retrieval store of execution-verified code, not model training. If you need zero data retention (no corpus, no memory, no replay cache), contact us for a ZDR key.

Subprocessors

Requests may be processed transiently by vetted third-party inference infrastructure under contractual terms that prohibit training on your content. Verification, certification, signing, and storage run on Soma-operated infrastructure in US datacenters.

Compliance

Zero-data-retention by default: no (see Retention). HIPAA: not supported. Do not send PHI or regulated data.

Contact

centrum.arvind@gmail.com