← Back

Soleora Privacy Policy

Draft v0.1 · Last updated: June 1, 2026

⚠️ Draft — pending legal review. Items marked [TBD] are placeholders to be finalized before launch.

1. Introduction

Soleora is a privacy-first, AI-native browser extension. This policy explains what information the service handles, why, where it is stored, third-party sharing, and your rights. The operator complies with Japan's Act on the Protection of Personal Information and other applicable laws.

Design principle: not collecting data is the best privacy protection. Soleora does not collect your browsing history and keeps the information it does handle to a minimum.

2. Information We Collect

2.1 Stored only on your device (never sent to our servers):

API keys are never sent to our servers; they go directly from your browser to the AI provider you choose.

2.2 Stored in our cloud (sync server):

In Phase 0 the device ID is not tied to a name or email. Name/email collection is planned only when revenue sharing begins (Phase 3), with separate consent.

2.3 Information We Do NOT Collect

2.4 Error Reporting (optional, opt-out)

To diagnose bugs, Soleora may send anonymous technical information (stack traces, extension version, error context) to an error-monitoring service (Sentry) only when a crash occurs. It is on by default, announced on first run, and can be turned off anytime in settings. We never send page URLs, AI prompts, or API keys — all are masked before sending.

3. How We Use Information

4. Third Parties

AI providers (BYOK):Your prompt and your own API key go directly from your browser to the provider you choose (Anthropic, OpenAI, Google). Their handling follows each provider's own policy.

Infrastructure:

Cross-border transfer: Reward-ledger data is stored in Singapore. By using the service you consent to this transfer. [TBD: confirm disclosure method under applicable law]

Revenue sharing / ads (Phase 3+): Amazon (gift codes via the Incentives API) and affiliate networks. Not active in Phase 0.

5. Extension Permissions

PermissionPurpose
storageStore settings, API keys, and the reward ledger on your device
tabsProvide the new-tab page and open the AI answer page
declarativeNetRequestBlock ads and trackers (we never read the traffic)
host: AI provider domainsSend your requests to the AI provider you chose
host: sync server / Sentry ingestSync the reward ledger / send error reports (when enabled)

6. Data Retention & Deletion

7. Your Rights

You may request disclosure, correction, suspension, or deletion of your personal information as provided by applicable law. Contact us via Section 6.

8. Security

We use HTTPS, access control, and least-privilege principles. No method of internet transmission or storage is perfectly secure.

9. Children

The service is not intended for [TBD: target age].

10. Changes to This Policy

We may revise this policy. Material changes will be announced in the store listing or within the service.

11. Contact

[TBD: operator name] · [TBD: contact email]