solstone services · terms
these terms cover services.solstone.app, the place you sign in, and the solstone services sol pbc runs for you there: private network, encrypted backup, confidential processing, solstone.me, and the part of notifications sol pbc runs. they're between you and sol pbc. the short version comes first; the details follow.
the short version
- nothing here is required. solstone runs on devices you own, and your journal lives on one of them. three services take money today: private network, encrypted backup, and solstone.me. each has a way to do the same thing with sol pbc out of the path. confidential processing is available to approved scouts, and notifications to your phone are off until you turn them on. these terms cover your sign-in, the portal, and the parts sol pbc runs for you when you turn them on.
- your journal is always private, only yours, and nothing sol pbc runs reads a word of it except where a section below says so. private network carries encrypted bytes it can't read. encrypted backup holds encrypted blocks we have no key to. solstone.me is the one that lets an agent you choose read from it, and that agent is never us: it gives your journal an address so that agent can read the part of it you allow, over a connection our relay passes along and cannot read. with confidential processing, our own model reads what you send, in the clear, only while it answers you, and verifiably keeps none of it; while it's on, your speech goes for transcription too, unless you turn that switch off. each service's section says what sol pbc, and the provider whose hardware it runs on, can see.
- you can always turn a service off, and what sol pbc runs for you is nearly all that changes. two things to know, and the first is the one exception: media you offload into encrypted backup lives only there, so letting backup go takes that media with it (section 12); and closing your sign-in ends a paid subscription and deletes the operated backup copy with it, with no 30 days (section 7). apart from offloaded media, nothing on your devices changes.
- if you pay, it renews until you cancel, and canceling is as easy as subscribing. turning a service off doesn't cancel its subscription; the billing portal does (section 3). you keep what you paid for through the end of the period. for 14 days after you buy a subscription, you can withdraw for a full refund, wherever you live (section 3). if we ever charge you by mistake, we refund it.
- if you stop paying for encrypted backup, we keep the encrypted copy for 30 days after your paid period or your access ends, then delete it for good. if you offloaded media into it, that copy is the only one.
- what we hold is small, named, and mostly yours to see, export, and delete, and you can close your whole sign-in yourself. the privacy policy lists all of it, service by service, and names the few things that outlast a deletion.
- we never sell, license, sublicense, or lease your data, and we never use it for targeted advertising or behavioral profiling. that isn't a policy. it's Article 8 of sol pbc's articles of incorporation, and it can't be amended without the founder's personal signature; after him, the language can only get stronger. you can read it at solpbc.org/articles.
- if something goes wrong, whether the claim is about a service, the portal, your sign-in, or scout, the most we owe you is what you paid us for that service in the past year, or $100, whichever is more, except where the law says we can't limit it, and except for the covenants in section 6, our promise never to train a model on what you send us, section 13's promise that nothing you send is kept, and section 14's promise that we hold no readable record of what your agents asked, were shown, or were refused, none of which are capped at all. encrypted backup has one rule of its own: keeping your copy available while you pay (or have it as a scout), and keeping it for the 30 days after, is on us; what was inside a lost copy, which we can't read or rebuild, is not, unless our own failure to keep it available is what lost it (section 12).
- if these terms change in a way that matters, we tell you first, and you can walk away.
how to read these terms
the short version is a summary. the sections below carry the specifics: how paying and canceling work, what each service handles and keeps, closing your sign-in and what outlasts it, and the legal limits. if the two ever seem to disagree, the detailed section governs; tell us at support@solstone.app and we'll fix the summary.
two other documents go with these terms. the privacy policy at solpbc.org/privacy is part of this agreement, and it is the one home for what sol pbc holds: what each service handles and keeps, who processes it, how long it lasts, how to see, export and delete it, and what outlasts a deletion. these terms are the one home for what each service does, and for paying, canceling, refunds and the legal limits. where one document needs the other's facts it points there rather than repeating them. and when you turn on a service, the page you turn it on from tells you what that particular service does.
part one · what applies to everything
1. who these terms are between, and how you agree
these terms are a contract between you and sol pbc, a Colorado public benefit corporation. they cover:
- services.solstone.app, the services portal, where you sign in to turn services on and off, see what we hold about you, and manage billing;
- the solstone services sol pbc runs for you: private network, the operated tier of encrypted backup, confidential processing, solstone.me, and the hop that carries notifications to an iphone (section 15). "operated" means sol pbc runs that part; each service's section names a way to do the same thing with sol pbc out of the path, except that hop, which section 15 explains;
- the scout program.
they don't cover the solstone software itself, which is open source under its own license, or anything you run on your own devices, your own network, or your own storage. sol pbc isn't in the path for any of that, and these terms don't reach it.
you agree to these terms the first time you do any of these: sign in to services.solstone.app, turn on a service, or subscribe to one at checkout. each of those pages says so and links here, so you can read them first. if you already have a sign-in, signing in, renewing, or keeping a service on is how you agree to this version; if you don't agree, turn the service off or cancel. section 9 says what happens if you reject a later material change. if you're new and don't agree, don't sign in and don't turn anything on; solstone keeps working without us.
you need to be at least 13 to sign in, and at least 18 (or the age of majority where you live) to subscribe to a paid service. our services aren't directed to children under 13, and if we learn a sign-in belongs to someone under 13, we delete it.
2. your sign-in
- how it works. you sign in with your email (we send you a code) or with a passkey (a sign-in key your own device holds, so there's no password to make up or lose). a session lasts up to two weeks unless you sign out sooner, and you can end any session from the portal.
- what we hold for a sign-in. the privacy policy lists each record and how long it's kept (your sign-in), and services.solstone.app/transparency shows each kind of record your download carries except support requests, with your most recent records of each. if you open a support request, you can see your history at services.solstone.app/support.
- it's yours to keep safe. a sign-in is for one person. keep your passkeys and your email in your own hands: anyone who can read your email or use your passkey can sign in as you and manage your services. if you think that's happened, sign out everywhere from the portal and tell us. the privacy policy says when one of our operators can open a session on your sign-in, and how you see and end it.
- the solstone app has no sign-in of its own. the portal is where you sign in, and only to manage what sol pbc runs for you. your journal and your devices work without it.
3. paying, renewing, and canceling
this section applies to any service you subscribe to: today, private network, the operated tier of encrypted backup, and solstone.me. prices are in the services portal and at checkout. if you have two journals, that's two subscriptions.
- everything is shown before you pay. each service has a flat price, tax included, per journal, not per device: one subscription covers one journal and every device you've paired with it (connected to it as one of yours). the price, the billing interval, that it renews automatically, and how to cancel are all shown to you at checkout, before we take any billing details, and you agree to it there before any charge. after you subscribe we send you a written confirmation you can keep, with those renewal terms, our cancellation policy, and how to cancel. Colorado's automatic renewal law requires each of these (C.R.S. § 6-1-732(2)). checkout and that confirmation also tell you how to withdraw (below), and the confirmation carries the withdrawal form.
- your subscription renews automatically at the end of each term, once a year on the annual plan or once a month on the monthly plan, at your plan's then-current price, using the payment method on file, until you cancel. nothing renews while your sign-in is closing (section 7).
- a renewal is never a surprise. on an annual plan we email you 25 to 40 days before each renewal to say that it will renew and how to cancel. on a monthly plan we send the same email once a year, 25 to 40 days before the renewal that carries you past each full year. that is the notice C.R.S. § 6-1-732(4) requires.
- we tell you before a price changes. a price change is a material change (section 9): we notify you first, and it applies only from a renewal, so you can cancel before it does.
- cancel anytime, with no more steps than it took to subscribe. the billing portal (a page Stripe hosts for us, linked from your services) cancels your subscription. no phone call, no email, no retention maze. the prorated mid-term exit in section 9 is the one exception: that one you ask for by email.
- you can withdraw within 14 days, for a full refund, wherever you live. until the end of the 14th day after the day you buy a subscription, you can withdraw from it, even if you've already started using the service. use withdraw from contract here on that service's page or at services.solstone.app/billing, and confirm; or email support@solstone.app saying you withdraw, with or without the form below. a withdrawal you send within the 14 days counts, even if it reaches us later. withdrawing ends the service that day, as if its paid period had ended, and each service's section says what that means for it. we refund everything you paid for that subscription within 14 days, the same way you paid. if you withdraw on the page, we email you a record of your withdrawal right away; if you email us, we reply to confirm it. you get these 14 days once for each subscription, counted from when you bought it: a renewal doesn't start a new 14 days. we start a service as soon as you pay, so the page you subscribe from asks you to confirm that's what you want; confirming doesn't change any of this. the laws of some places, including the EU and the UK, give you a right to withdraw too, and this doesn't take it away.
- you keep what you paid for. when you cancel, the service keeps working until the end of the period you've already paid for, then stops. we don't prorate a cancellation you make on your own, and we don't claw back; a withdrawal within 14 days (above) refunds everything, and sections 9 and 14 name the other times we refund unused time. for confidential processing, what a plan includes within a period is part of the plan terms shown at checkout (section 13).
- nothing on your devices is lost when a service stops, with one exception. your journal, your devices, and your device pairings are untouched. the exception is media you offloaded into encrypted backup, which lives only there. what happens to a copy or a credential sol pbc held is in that service's section, and if you've turned on media offload, section 12 is the one to read before you let backup lapse. re-subscribe anytime to turn a service back on.
- refunds. a withdrawal within 14 days refunds everything you paid for that subscription (above). otherwise we don't run refund math on cancellation, because you keep the service through the end of what you paid for. if you're charged in error, whether a duplicate charge, a charge after you canceled, or a billing mistake, email support@solstone.app or use the billing portal and we'll refund the incorrect amount. nothing here affects any chargeback or refund right you have through your card issuer or under the law where you live.
withdrawal form (fill this in and send it only if you want to withdraw):
to: sol pbc, 16095 East 109th Place, Commerce City, CO 80022, United States · support@solstone.app
I hereby give notice that I withdraw from my contract for the provision of the following service: ______
ordered on: ______
name: ______
address: ______
signature (only if you send this on paper): ______
date: ______
4. payment is handled by Stripe
- sol pbc doesn't take or store your card. payments run through Stripe, our payment processor. paying by card is your choice, and choosing it is what sends your card, the name on it and your billing address to Stripe, which handles them under its own terms and privacy policy. Stripe may offer you its own Link wallet at our checkout; it's Stripe's product under Stripe's terms, it's optional, and using it changes nothing about what we keep.
- what we send Stripe, what we keep from what it sends back, and what we can see at Stripe are in the privacy policy (billing). sol pbc never sends Stripe anything from your journal.
- Stripe runs the fraud and anti-money-laundering checks a payment company has to run; those are Stripe's checks, not ours, and we never direct Stripe to profile you. the privacy policy names the one other use Stripe's own terms allow (who processes data for us).
5. fair use
the services are for you, your own journal, and your own devices. don't use them to attack, overload, or interfere with a service or anyone else's systems. don't route other people's traffic or store other people's content through them, and don't use them at a scale that degrades a service for everyone else. each service's section names anything specific to it.
what suspension can touch, and what it never can. sustained abuse can suspend your access to a service. it can never suspend your journal, your devices, or any path of your own: those are yours and don't run through us. if we suspend access we tell you why and what it would take to restore it, and you can reply at support@solstone.app.
6. how your data is used, and the covenants behind it
what a service handles to do its job is in its section in part two, and none of it is read by us except where a section says so in as many words. your sign-in and billing details are used only to run your sign-in and your subscriptions, and to keep our books. none of it is ever sold, licensed, shared for anyone else's purposes, profiled, used for advertising, or used to train any model.
the covenants. sol pbc's articles of incorporation carry a Customer Privacy Covenant (Article 8) that legally binds the company, and these terms make its covenants promises to you under this agreement:
- never to sell, license, sublicense, or lease your data, in any form;
- never to use it for targeted advertising or behavioral profiling, and never to let anyone else do that on our behalf;
- never to hand it outside sol pbc except through the three narrow doors Article 8 allows: a service provider bound by written agreement to protections no weaker than these covenants, and only as far as strictly necessary to provide, maintain, secure, or support the service you asked for; your own specific and informed direction; or compulsion of law, which we resist;
- and to carry all of this through any sale, merger, or change of control.
the privacy policy sets out each of these in full: its citation, the three doors, the conditions a successor must meet, and what Article 8 means by Customer Data, which is what these terms call your data (what sol pbc will never do). the articles are the authority, and you can read them at solpbc.org/articles. these covenants can't be amended without the founder's personal written consent, and after he stops serving, the language can only get stronger, never weaker, except to the minimum a law strictly requires.
who processes data for us. Cloudflare, Microsoft Azure and Stripe process data for these services, and Google runs the mailbox where mail to support@solstone.app lands. none of them is given a readable byte of your journal. the privacy policy names what each one handles and what it can see, and carries every change to that list (who processes data for us).
7. how long we keep it, closing your sign-in, and your rights
the privacy policy is the home for all of this, and it is part of this agreement: what we keep, service by service, and for how long, and how to see it, download it, and delete it yourself, how long a deletion takes, what outlasts a deletion, and your privacy rights and how to appeal. these terms don't repeat it. what belongs here is what closing your sign-in does to your services, to what you've paid for, and to the only copy of anything:
- it stops the services on your sign-in as soon as you confirm. none of them starts anything new for you from then on. what's already under way can finish, and two things can take a while: a backup or restore already running, and a solstone.me address, which can keep working until the short-lived pass your journal already holds for it runs out (section 14).
- you have 72 hours to change your mind. keep your sign-in before they're up, and your services come back on, as your subscriptions and scout access allow. nothing renews while your sign-in is closing. if a subscription was due to renew in that time, keeping your sign-in charges that renewal then, and its new period starts that day. the time your services were stopped isn't refunded or added on.
- when the 72 hours are up, it ends your subscriptions. every subscription on your sign-in ends, with no refund of the unused period, unless you withdraw within your 14 days (section 3). if you'd rather use what you paid for, cancel from the billing portal instead and let the period run out.
- after the 72 hours, sol pbc deletes the operated backup copy, with no 30-day lapse window. if you've turned on media offload, that copy is the only copy of that media, and it goes too, so restore that media to your devices before you confirm.
- some things outlast it, and the privacy policy names them all: among them the no-name reservation of your solstone.me address and its public certificate records (section 14), and the services portal's request trace, until it expires. where a service's section says its records are deleted with your sign-in, what the privacy policy says outlasts a deletion still applies.
- it never touches your journal on your devices, your devices themselves, or a bucket you control.
you have the privacy rights your state or country gives you, and we extend them to everyone, wherever you live. exercise any of them at support@solstone.app.
8. the services are provided as-is
we work to keep every service up, but we don't guarantee uninterrupted service. a service can go down for maintenance or for reasons outside our control, and your journal won't use confidential processing when it can't verify it. a path of your own is always your fallback, and your journal on your devices is never on the line.
to the fullest extent permitted by law, each service is provided "as is" and "as available," and sol pbc disclaims all implied warranties, including merchantability and fitness for a particular purpose. sol pbc is not liable for indirect, incidental, or consequential damages, and sol pbc's total liability to you under these terms, whatever the claim is about (a service, the portal, your sign-in, or the scout program), is limited to the greater of $100 or the fees you paid us in the 12 months before the claim for the service the claim is about. nothing in these terms limits liability that cannot be limited by law, including for fraud, gross negligence, willful misconduct, or personal injury, or any statutory right you have as a consumer. that cap doesn't apply to the covenants in section 6, to our promise never to train a model on what you send us, to section 13's promise that nothing you send is kept, or to section 14's promise that we hold no readable record of what your agents asked, were shown, or were refused. the first isn't ours to cap by agreement; the rest we will not. two services carry a specific limit of their own, stated in their sections: the operated backup, on what was inside a lost copy, and confidential processing, on what the model produces.
9. changes to these terms
we may update these terms. if a change is material, we'll notify you before it takes effect, in a form you can keep, with how to cancel (C.R.S. § 6-1-732(3)). for a change that takes effect at your next renewal, you can cancel before then if you don't agree. if a material change has to take effect mid-term, the notice says how to cancel for a prorated refund of the unused period (today: write to support@solstone.app before the date). if you keep using a service after a change takes effect, that's how you accept it; if you don't want to, turn the service off or close your sign-in before then.
when we add a service, we add its section here. if we ever retire a service you've paid for, we refund the time you paid for past the date it stops. if sol pbc ever winds down, Article 8 still governs where your data can go: anyone it goes to must take on covenants no less protective (section 6). we keep the current version posted here with the date it took effect.
no change to these terms can weaken the covenants in section 6. those change only the way Article 8 allows, and a change to a terms page isn't one of them.
10. the legal details
- these terms are between you and sol pbc, a Colorado public benefit corporation, and they're governed by Colorado law.
- these terms, the privacy policy, the disclosure you're shown when you turn on a service or a feature of one, the plan terms you're shown at checkout, and, if you're a scout, the program disclosure you acknowledged, are the whole agreement between us about the services. if these terms ever conflict with sol pbc's articles of incorporation, the articles govern.
- when a section says we email you, we use the primary address on your sign-in; keep it current.
- if a court finds part of these terms unenforceable, the rest still applies. if we don't enforce something once, we can still enforce it later. sections 6, 7, 8, and 10, every refund promise in these terms (sections 3, 9, and 14, including a withdrawal within 14 days), the promises section 8 says aren't capped, what sections 11, 12, 13, and 14 say happens after a service stops, and the specific limits in sections 12 and 13, keep applying after a subscription or a sign-in ends, for as long as they're relevant.
- sol pbc can hand these terms, or your data, to another company only in the way Article 8 allows (section 6).
- questions: support@solstone.app.
part two · each service, one at a time
each section below covers one service sol pbc runs, and only the part sol pbc runs. for private network, encrypted backup, confidential processing, and solstone.me, the way to do the same thing with sol pbc out of the path is named first, because it's always there.
11. private network (the relay)
what it is. a relay sol pbc runs so your devices can reach your journal from anywhere, without you running a relay of your own.
you never have to pay us. the same private connection is always available for free. on the same network, your devices connect to your journal directly. or point solstone at your own VPN, Tailscale, or tunnel. or run the open-source relay yourself. all three are private by the same construction as the relay we run, because your devices encrypt to each other whatever path they take. the relay is convenience, never a privacy upgrade.
blind by construction. the relay passes encrypted bytes between your devices. it has no key to read them and keeps no copy of what flows through. sol pbc operates the relay and cannot read what it carries.
what the relay handles, and what we keep. to move your bytes, the relay and Cloudflare, whose network it runs on, necessarily handle connection metadata, and pairing a device issues that device a credential, which the device holds. the relay keeps no list of your devices, and no connection log of its own. what we keep is a record of your journal, and two access records at services.solstone.app. the privacy policy lists each one, what it holds, and how long (private network). the records we keep are Customer Data under our covenants, used only to operate and secure the relay, and deleted with your sign-in, apart from what section 7 says outlasts a deletion. the relay never reads, stores, or analyzes what's inside your traffic. your traffic passes through and is gone.
when it stops. cancel, or let it lapse, and the relay keeps working until the end of the period you paid for, then stops. withdraw within 14 days (section 3), and it stops that day. closing your sign-in stops it as soon as you confirm (section 7). your journal, your data, and your device pairings are untouched. the free paths keep working, and you're never locked out of your own journal by a billing state. re-subscribe anytime.
12. encrypted backup, operated tier
what it is. storage sol pbc runs so an encrypted copy of your journal can live somewhere other than your own machine, without you setting up a bucket (a bucket is what cloud storage calls a folder you rent).
you never have to pay us. point solstone at your own bucket (Backblaze B2, Amazon S3, Cloudflare R2, any S3-compatible provider), pay that provider directly, and sol pbc is never contacted and never holds your data. the bring-your-own path and the operated tier use the same engine, the same encryption, and the same recovery model; the only difference is whose bucket the encrypted blocks land in. the operated tier is convenience, never a privacy upgrade.
encrypted by construction: only you can read it. before anything leaves your device, solstone encrypts it, so the contents, the file names, and the folder structure all become unreadable ciphertext. sol pbc stores those encrypted blocks and cannot read them: we hold no key, no password, and no way to decrypt your backup.
what the storage handles, and what we keep. the encrypted blocks; a small amount of operational information about them (how many, how much space, when they last changed); the connection metadata of your upload sessions, which the storage (Cloudflare R2) necessarily handles; and a few access and credential records at services.solstone.app. none of it says anything about your content. the privacy policy lists each record, what it holds, and how long (encrypted backup). the encrypted blocks and the records we keep are Customer Data under our covenants, used only to operate and secure the service, and deleted when your sign-in is, apart from what section 7 says outlasts a deletion.
your recovery key is the only key. solstone gave you a recovery key when you set up backup. a backup is restored only with it, and we don't have it. keep it safe. if you lose it, the backup can't be restored, by you or by us.
a second copy, unless you choose otherwise. an encrypted backup is a second copy of a journal that lives on your own devices, not a substitute for it. there is one exception, and it's your choice: media offload is off unless you turn it on, and if you do, your journal removes media from your device once the backup holds it, and for that media the backup is the only copy. everything in this section, including what happens after a lapse, applies to that media too. if we ever lost that copy, that media would be gone, and section 8's limit is what we'd owe you; so don't let the backup go while it holds the only copy of something you want.
after your subscription lapses, we keep your encrypted backup for 30 days, then delete it. here is the sequence, whether you cancel, withdraw (section 3), a renewal payment fails, or your scout access ends:
- the operated storage keeps running through the end of the period you paid for, then stops. if a renewal payment fails, the clock below doesn't start until that period has ended. if your scout access ends, you withdraw under section 3, or you stop a service early under section 9, the storage stops that day and the clock starts then; once it has stopped, your journal can't read the backup until you subscribe.
- your encrypted blocks then stay in our storage for 30 days. re-subscribe within those 30 days and the operated tier turns back on against your existing backup with nothing lost.
- after 30 days the operated copy is permanently deleted, and because it's encrypted with a key only you hold, once it's deleted we cannot recover it. this only ever affects the copy in our storage.
you can also delete the operated copy yourself, anytime, from the backup screen in your journal; and closing your sign-in deletes it (section 7), with no 30-day lapse window.
fair use, specifically. the operated tier is for backing up your own journal. don't use it to store or distribute anything else.
a limit specific to this service. the operated copy is encrypted with a key only you hold, so we can't read it, rebuild it, or put a value on what's in it, and for everything except media you offloaded it's a second copy of a journal that lives on your own devices. so sol pbc is not liable for any inability to restore a copy where you have lost your recovery key, or for what was inside a lost operated copy, except where our own failure to keep it available is what lost it. none of this limits our responsibility to keep your backup available while you're paying for it or have it as a scout, and to keep it for the 30 days after that this section promises, and if we fail at that, section 8 says the most we can owe you.
13. confidential processing
what it is. an AI model sol pbc runs on confidential GPU hardware, so your journal can think with more capacity (room to think faster and longer) than the device it lives on. it's off until you turn it on, and you can turn it off from the journal at any time.
you never have to pay us. this is capacity, not a gate. your journal can always think without us: with a model on your own hardware, where nothing leaves your device and sol pbc is not in the path; with your own provider key, where the key stays in your journal and sol pbc is not in the path; or with any endpoint you run or trust. confidential processing is never a privacy upgrade over running locally. if you stop using it, you lose capacity. you don't lose your journal and you don't lose your privacy.
a model sol pbc runs itself. sol pbc's own model weights, served by sol pbc, on confidential GPU hardware sol pbc operates. it's the same model generation your own device runs, with more room to run it: more capacity, never a better model. no third-party AI provider is in the path, and nothing you send is handed to one.
it's protected differently from our other three services. the private network relay and the solstone.me relay can't read what passes through them, and the operated backup holds blocks we have no key to. this one runs inside a confidential container: a machine whose hardware walls off what's in its memory from the company that hosts it. what you send is encrypted over the network and visible in running memory only while it's being processed: our own model reads what you send, in the clear, while it answers you. we can't promise "no key" here, so instead your journal checks a fingerprint of the exact image it booted before it sends anything.
your journal checks before it sends. before anything is sent, your journal verifies the hardware, and a fingerprint of the exact image it booted, against a fingerprint pinned in solstone's open source code. (in full: the AMD attestation chain up to AMD's own signing keys, the GPU's own evidence, the binding of that evidence to the encrypted connection, and the boot fingerprint.) the pin is public and version-controlled, and it ships in the same releases everything else does. we commit that sol pbc will not point you at different software without a release you can read. if the check fails, nothing is sent: your journal waits, tells you plainly that it couldn't verify, and never silently falls back to another service or another provider.
the hardware is Microsoft Azure's, and Azure can't see inside it. the container is an AMD SEV-SNP confidential virtual machine with an NVIDIA H100 in confidential-compute mode, and that boundary is enforced by the hardware, not by configuration or by promise. Microsoft hosts the machine, so it knows the machine exists, its size, and when it's running, and because the channel runs from your journal to that machine directly, Azure's network handles the connection: the address it came from, when, and how much moved. it is not a party to your content.
speech. when the audio switch is on, your journal sends speech for transcription over the same verified channel. it's served with parakeet-tdt-0.6b-v3, created by NVIDIA and used under CC BY 4.0, the same model generation your own device runs. the switch is on by default whenever confidential processing is in use, and the page where you turn confidential processing on says so. turn it off and speech becomes text on your own device instead, once any transcription already under way finishes.
your use is metered, inside the container. the service keeps a count of how much confidential processing it has done for a journal, so it can manage capacity. apart from being down or full for a moment like any service (section 8), it can slow you down or say no when your access has ended, or briefly under fair use, where a no is temporary and clears on its own. your journal keeps thinking on its own either way. being metered is not being suspended: a limit doesn't reach your journal, your local processing, or your own key or endpoint, and the other paths above are always there.
access today, and if paid plans open. access is complimentary while you're an approved scout (section 16). if and when paid plans open and you choose to subscribe, what your plan includes and what happens when you reach it, the price, the billing interval, and the automatic renewal are all shown to you before we take any billing details, and section 3 applies from then on. reaching what your plan includes can slow your processing or make it wait its turn, but it never ends your access before the end of the period you paid for.
turning it off. turn it off from the journal, anytime, and it takes effect for anything your journal starts from then on; work already under way finishes where it started. that needs nothing from us and no billing portal. turning it off stops new processing; it doesn't cancel a subscription, which you cancel from the billing portal as in section 3. nothing is stranded, because none of what you sent was stored: your journal goes back to thinking on your own hardware, or with whatever key or endpoint you point it at. the audio switch is separate and works the same way.
what we keep. running this service involves a few different things, and we keep them apart:
- what you send the model. the text and images your journal needs a model to work through, plus your speech when the audio switch is on. our model processes it and returns the result. the service keeps nothing: no content is kept once your request is answered, not even in logs. no human reviews it. it is never sold, licensed, shared for anyone else's purposes, profiled, or used for advertising.
- nothing you send is used to train anything. not our models, not anyone else's. this is a commitment we make to you, and it's reinforced by the covenants in section 6.
- access records, not content. to run the service and control who can use it, we keep three records about access: that you turned it on and acknowledged the disclosure, each time your journal was issued a credential or refused one, and the short-lived record the turn-on page leaves so your journal can collect its credential. none says how much you used, and none says anything about what you sent. the privacy policy lists what each one holds (confidential processing). all of them are Customer Data under our covenants, and all of them are deleted when your sign-in is, apart from what section 7 says outlasts a deletion.
- inside the container, the service keeps the count of how much confidential processing it has done for a journal, so it can manage capacity, and it notes that a channel was admitted or refused. that count is keyed to your credential, not to your sign-in, and neither it nor those notes record what you sent or where you connected from. metering and abuse handling both run there.
- we keep no connection metadata for this service, beyond the services portal's request trace, which for a credential check names no journal or sign-in. that's still a real difference from the private network and the operated backup. the privacy policy says what that trace holds, and what Azure's network and our providers' short-lived request logs still see.
what the model produces is not advice, and nobody checks it. a model can be confidently wrong. don't rely on what it produces for medical, legal, financial, safety, or any other decision that matters, and check it before you act. as between you and sol pbc, what you send and what comes back are yours. you grant sol pbc a limited license to process what you send, for as long as it takes to answer, solely to run confidential processing and hand the result back to you, and for nothing else. sol pbc claims no ownership of either, and makes no warranty that output is accurate, complete, current, or fit for any purpose.
fair use, specifically. confidential processing is for thinking with your own journal. don't use it to generate or pursue things that are unlawful, that are meant to harm or harass someone, that impersonate a real person in order to deceive, or that attack the service or anyone else's systems.
14. solstone.me
what it is. an address on the internet for your journal, so an agent you already use can read from it: Claude, Codex, goose, or anything else that speaks the Model Context Protocol. you turn it on, you connect an agent, and you choose what that agent may see. your journal makes itself reachable from wherever it is, and enforces that choice on your own device. sol pbc runs the solstone.me relay in between, so your agent can find your journal without you running anything of your own. it's off until you turn it on, and you can turn it off from the journal at any time.
you never have to pay us. your journal doesn't need sol pbc to be reachable. a tunnel that only passes the bytes through works today with nothing of ours in the path, whether you rent one or run your own on a machine you control. one warning: some free tunnels decrypt your traffic in order to move it. whoever runs one of those can read what your agent reads, and can reuse your agent's key to reach your journal as though they were your agent. look for a tunnel that says it only passes the bytes through; if its documentation doesn't say, assume it ends the encryption. the solstone.me relay is convenience, never a privacy upgrade over a tunnel that only passes the bytes through.
blind by construction, and this relay holds no state about you. your own machine holds the private key and ends the encryption, so the solstone.me relay has no key and cannot read a byte of what passes through it. it also keeps nothing: no database and no record of what passes through it. that is how it is built, not a policy we apply to it, and what it does write down about its own health says that something happened, never who it happened to. the machine it runs on is Microsoft Azure's, and Azure is not a party to your content.
your journal's address, and the part of it that is permanent. when you turn this on, services.solstone.app mints an address for your journal: eight random characters with nothing of yours in them, followed by solstone.me. your journal then requests a real certificate for that address itself, the same kind secure websites use, and its key never leaves your machine; that certificate is how your agent can tell it's really your journal at the other end. issuing and renewing a certificate can be delayed, and there is a weekly ceiling on new certificates across everyone we serve, so turning on can land in a waiting state and a renewal can run late; the journal shows you which, and keeps trying. if an address never issues at all, write to support@solstone.app and we refund what you paid. one thing about that address is public, and stays that way. like the certificates behind secure websites, each certificate your journal gets for your address is listed in public certificate logs that nobody can edit, and a new entry is added each time one is issued or renewed. an entry shows that the address exists. none says whose, though an agent you connect knows the address is yours, and so do we until your sign-in is deleted. it stays if you turn this off, cancel, or close your sign-in, and nobody can remove it, including us. the authority your journal asks for the certificate is today Let's Encrypt, and the privacy policy says the same (solstone.me).
your address is never anyone else's. an address, once minted, is never issued to another journal. we keep the reservation that makes that true with no name, sign-in, or journal attached to it, which is why it can outlive your sign-in without saying anything about you (section 7). turning the service off keeps your address, and turning it back on uses the same one, with no new certificate while the one you have is still good, so your agents go on working without being set up again. the same holds if you stop paying: your journal stops being reachable through the solstone.me relay at the end of the period you paid for, your address stays reserved for you, and subscribing again brings back the same one. minting you a second address would add permanent records for that address to those public logs and break every agent you'd connected, and it would take nothing back, because the records for the first address never go away.
what each agent may see is yours to set, and we're not in it. when you connect an agent you choose what it may read: your whole journal, or only the parts of it you choose, and which of transcripts, entities, and facets it may reach within that. transcripts means what was said in your recordings and imports, never the audio or the screen frames themselves; entities means the people, places, and projects your journal knows, and what it has noted about them; facets means facet names and descriptions, and the activities, events, and summaries filed in them. "your whole journal" keeps including what you add later, facets you make later included. a facet you choose grows with its contents, though a facet you make later isn't in that choice unless you add it. it reads; it can't add, change, or delete anything. you can narrow it or disconnect the agent whenever you like, and the change applies on that agent's next request, though what it already read stays with it; a request already in flight finishes under the old choice. it's your journal that checks, every time, not us. there are two ways to connect: pairing in your browser, or a key you create and paste in. a key is a bearer credential: anyone holding it can read what it may see until you revoke it, so keep it as you would a password, and revoke it from the journal if it gets out. sol pbc holds no readable record of what any agent asked your journal for, what it was shown, or what it was refused. your journal keeps that record on your device, for you to read; it can have gaps, which it tells you about rather than hiding. we don't receive it in any form we can read, and we've built this so that it's never sent to us, except that if you use the operated backup, it's inside the encrypted copy of your journal, which we have no key to. changing that would mean rebuilding the service, and we'd have to tell you first under section 9.
the agent is yours, and the company behind it isn't ours. the agents you connect are run by other companies, or by you. connecting one means giving it your address, so whoever runs it knows where to find your journal, and can match it to the public certificate records above. and when you let it read your journal, what it reads goes to them, on their terms, and sol pbc is not a party to that and does not see it. these terms don't reach them and we make no promise about what they do, so which agent to trust is your call. the covenants in section 6 bind sol pbc. they don't bind a company you pointed your own journal at.
what this relay and our control plane handle, and what we keep. to carry your traffic, the solstone.me relay and the Azure network it runs on necessarily handle connection metadata. sol pbc sees that, and never what was said, and the relay keeps no record of it. what we do keep is the link between your address and your journal, the record that you confirmed the turn-on screen, and the no-name reservation of the address. we keep no record of the passes your journal asks us for, beyond a trace of each request, which carries nothing that ties it to you and expires on its own. the privacy policy lists each record, what Cloudflare sees when your address is minted and looked up, how long anything lasts, and what sol pbc and Cloudflare, which control the solstone.me name, could do (solstone.me). all of it is Customer Data under our covenants, used only to operate and secure this service. the binding is deleted with your sign-in; what outlasts that is the no-name address reservation above, the public certificate records, and what section 7 says outlasts a deletion.
turning it off, and how quickly that takes effect. turn it off from the agents page in your journal, anytime. your agents stop reaching it on their next request, because the check happens on your own device, not with us. turning it off stops the solstone.me relay carrying your traffic; it doesn't cancel a subscription, which you cancel from the billing portal as in section 3.
a journal that isn't reachable is ordinary. your journal lives on a machine that sleeps, travels, and loses wifi, so an agent will often find it unreachable, and should tell you so rather than hang. that isn't a failure of this service, and section 8 is the general position on availability.
fair use, specifically. this is for your own agents reading your own journal. don't use the address to run a service for other people, to route traffic that isn't yours, or to serve anything other than your journal.
when it stops. cancel, or let it lapse, and the solstone.me relay keeps carrying your traffic until the end of the period you paid for, then stops. withdraw within 14 days (section 3), and it stops that day. closing your sign-in stops it as soon as you confirm, though your address can keep working until the short-lived pass your journal holds runs out (section 7). your address stays reserved throughout. your journal, what's in it, what you've let each agent see, and your record of what they did are all on your devices and are untouched. re-subscribe anytime. one thing on our side, in the cases where we are the one stopping it: because this relay keeps no state, a connection already open through it closes when the short-lived pass runs out rather than at the moment we stop you, which today takes up to fifteen minutes.
15. notifications
what it is. notifications are built into the solstone app: free, turned on by you for each device, no sign-in needed. they give you a short heads-up on your devices when there's something worth a look.
on the device, and on your phone. a heads-up can be a local notification on the device that shows it, and that never leaves the device. notifications from your journal can also reach your phone when you're away from home. those are off until you turn them on, phone by phone, in the solstone app, and your journal locks each one to a key only that phone and your journal hold before it leaves your machine.
the hop, for iphone. reaching an iphone needs a hop, because only an app's own developer can hand a notification to Apple's push service. sol pbc runs that hop on Cloudflare's network. it takes the locked notification and your phone's push token, hands them to Apple with a fixed title and line, and keeps no record of them. android doesn't use it: your journal sends straight to your phone's push service. the privacy policy says what each one sees (notifications).
not a tracking surface. no analytics, no behavioral profiling, and no third party in the path but your phone's push service and, for iphone, Cloudflare, whose network our hop runs on. notifications never become a way to watch you: the profiling half of that is Article 8, and the rest is a promise we make here.
turning it off. turn notifications off on any device, anytime, from the solstone app on that device. on a phone, that also takes it off your journal's list the next time the phone reaches your journal.
16. the scout program
scout is sol pbc's tester program. if you apply and we approve you, you get complimentary access to the services that are open to scouts, and we ask for your feedback. today those services are private network, the operated tier of encrypted backup, confidential processing, and solstone.me.
- complimentary means complimentary. while you're an approved scout, you aren't charged for those services and sections 3 and 4 don't apply to them. everything else does.
- it can end. scout status is ours to grant and ours to end, and we can end it at any time as ordinary management of the program. ending it doesn't close your sign-in: it ends the free access, and anything you pay for separately keeps running; you can always subscribe to a service you were getting as a scout. if encrypted backup was on for you as a scout, section 12's 30-day clock starts the day your access ends. once your access has ended your journal can't read the backup until you subscribe, so if you offloaded media, subscribing within those 30 days is the way to keep it. if solstone.me was on for you as a scout, your journal stops being reachable through the solstone.me relay when your access ends, and your address stays reserved for you on the same terms as section 14 sets out.
- what we keep. your application, your acknowledgment of the program disclosure, your status, and a history of status changes, used only to administer the program and deleted when your sign-in is. the privacy policy describes this record in full, and what outlasts a deletion (scout).