Privacy Policy

Last updated: 7 September 2026

No tracking
Encrypted at rest
Plain English
EU hosted

This policy explains what Solorva does with your information, in the plainest language we can manage. It describes how the product actually works today, not how we might like it to sound.

Who we are

Solorva is an AI brand and content platform operated by Antypas Ventures. When you use Solorva, we decide how and why your personal data is processed, which makes us the data controller for that information.

You can reach us about anything in this policy at privacy@solorva.com.

What we collect

We collect only what the product needs to work:

  • Account details — your name, email address, and a password. Passwords are stored only as a bcrypt hash; we never hold the password itself and cannot recover it for you.
  • Brand and business information — the website addresses you submit, the brand profile extracted from them (voice, palette, typography, positioning), product details you import, and any assets you upload.
  • Content you create — generated posts, articles, images, research reports, and anything saved to your library.
  • Usage records for billing — a ledger of what each generation cost, so credits and spending limits can be enforced. This records the operation and its cost, not the content of what you generated.
  • Support correspondence — anything you send us by email.

What we do not collect

We do not run analytics, advertising, or tracking software of any kind. There is no Google Analytics, no advertising pixel, no session recording, and no third-party script watching what you do on the site.

We do not sell personal data, and we do not share it for advertising.

Cookies

Solorva sets one cookie, and it remembers whether you left the sidebar open or closed. It is strictly functional and carries no identifier that can be used to track you.

Your sign-in session is held in your browser's local storage rather than a cookie, and is sent only to our own API.

Why we process your data

Where the UK GDPR or EU GDPR applies to you, our lawful bases are:

  • Performance of a contract — to run your account and produce the content you ask for.
  • Legitimate interests — to keep the service secure, prevent abuse, enforce spending limits, and diagnose faults.
  • Legal obligation — to keep records we are required to keep, such as those relating to payments.

Who we share it with

Solorva is built on other companies' services. These are the ones that may receive your data, and what each of them gets:

  • OpenRouter — receives the prompts and brand context needed to generate your content, and routes them to model providers including Anthropic, OpenAI and Google. United States.
  • Perplexity — receives the research queries built from your brand and business details when you run a research report. United States.
  • Image model providers — Google, Black Forest Labs, Sourceful and OpenAI, reached through OpenRouter, receive the image prompts derived from your brief.
  • DigitalOcean — hosts the application and the database. Our servers and your data are in Amsterdam, in the European Union.
  • Resend — delivers transactional email, such as password resets. Your email address and the message are processed to send it.
  • UploadThing — stores files you upload, where that feature is used.
  • Outstand — connects your social accounts and publishes to them on your behalf. When you connect an account you approve it on the network itself; Outstand holds that permission, and we never see or store your social password or access token. When a post goes out, the caption and the image links for that post are sent to them.
  • Payment providers — when payments are enabled, card and billing details are handled by the provider directly and never reach our servers.

We share the minimum each service needs. We do not give any of them your data for their own marketing.

Connecting a social account

This is the part of the product where you give something away, so it is worth setting out in full. The short version is on the Connected Accounts screen; this is the whole of it.

  • Connections are handled by Outstand, a specialist publishing service we have partnered with. They run the approved applications that LinkedIn, Instagram, Facebook, Threads, TikTok, YouTube, Pinterest and Bluesky require, which is why you do not have to create developer accounts of your own.
  • When you press Connect you are taken to Outstand, and then to the network itself, where you approve the access. You type your password on the network's own site. We never see it, never receive it, and never store it.
  • Outstand holds the permission that lets Solorva post on your behalf. We store only an opaque identifier for the connection, plus the account name and picture so you can tell your accounts apart. There is no credential of yours in our database that could post as you if it leaked.
  • When a scheduled post goes out, its text and the links to its images are sent to Outstand, who deliver it to the network you chose. Nothing else about your account is sent with it.
  • Disconnecting takes effect immediately. The connection is removed rather than kept for thirty days like other things you delete, because withdrawing permission should take effect when you withdraw it. Reconnecting means approving again.
  • You can also revoke Solorva's access from the network's own settings at any time, without involving us at all.

AI provider keys

Generation is included in your subscription. You do not supply an AI provider key and we do not store one for you. Until 7 September 2026 you could supply your own OpenRouter key; that option has been removed, and any key supplied before then has been erased from our database.

Sending data outside the UK and EU

Our servers and database are in the European Union. Some of the AI providers listed above are in the United States, so when you generate content, the prompt and the brand context it needs travel there.

Those transfers rely on the providers' own transfer safeguards, including Standard Contractual Clauses where they apply.

How long we keep it

We keep your account, brand profiles, and generated content for as long as your account exists, because that content is the thing you came for and deleting it on a timer would be unhelpful.

You can delete a business and its content yourself at any time. To delete your whole account, email privacy@solorva.com and we will remove it and its content.

Backups are retained on a rolling basis by our hosting provider, so deleted data can persist in a backup for a short period before it ages out.

How we protect it

  • All traffic is encrypted in transit with TLS.
  • Passwords are stored as bcrypt hashes, and API keys you supply are encrypted at rest.
  • The database is not reachable from the public internet — only our application servers can connect to it.
  • Sessions expire, and changing your password invalidates any session issued before the change.
  • No security is absolute, and we will tell you promptly if a breach affects your personal data.

Your rights

You can ask us to:

  • Give you a copy of the personal data we hold about you.
  • Correct anything that is wrong.
  • Delete your account and its data.
  • Restrict or object to how we process it.
  • Provide your data in a portable form.

Email privacy@solorva.com and we will respond within one month. If you are in the UK or EU and you think we have handled your data badly, you can also complain to your national data protection authority — in the UK, that is the Information Commissioner's Office.

Children

Solorva is not intended for anyone under 18, and we do not knowingly collect data from children. If you believe a child has given us personal data, email privacy@solorva.com and we will delete it.

Changes to this policy

If we change this policy in a way that materially affects you, we will update the date at the top of this page and, where the change is significant, tell you by email.

Contact us

Questions about this policy, or a request about your data, go to privacy@solorva.com.