Privacy Policy

Last updated: October 2026


Soda LLC ("Soda", "we", "us") builds the memory layer for customer-facing teams. This policy explains what personal data we collect, why we collect it, who we share it with, how long we keep it, and what rights you have.

We have tried to write this in plain language. If anything is unclear, email privacy@getsoda.app.

This policy covers the Soda macOS application, the Soda web application, and getsoda.app. It does not cover the third party tools you connect to Soda, which are governed by their own policies.

Who we are

Soda LLC is a limited liability company registered in Wyoming, United States.

For individual accounts, Soda is the data controller for the personal data described in this policy.

For business and team accounts, the organisation that provides your Soda account is the controller and Soda acts as a processor on its behalf. In that case, the organisation's own privacy notice governs how your data is handled, and requests to access or delete data should go to them first.

What Soda does

Soda is the memory layer for customer-facing teams. It runs quietly on macOS and builds a living profile of every customer, prospect and partner, so that context from calls, email and conversations stays available to you and your team without anyone stopping to write it down.

To do that, Soda needs to understand what you are working on. That means taking in context from your calls, your calendar and your email, and turning it into knowledge that can be searched and surfaced later.

You choose what Soda pays attention to. You can pause listening during a call, choose which meeting apps Soda listens to, turn email reading off for each mailbox, and exclude people and domains. What Soda captures is private to you by default. If you share knowledge with your team, or your account is part of a team workspace, see "Teams and shared knowledge" below.

Personal data we collect

From the Mac application

Call audio and transcription. When Soda is listening during a call, it transcribes the audio on your Mac. We never upload audio. Audio is held in an encrypted buffer on your Mac only until it is transcribed, then deleted. The transcript is sent to our servers. See "Calls and the people you speak to" below for your responsibilities when using this feature.

Who is on the call. Soda reads the names of participants in the meeting window (using the macOS Accessibility permission), the window title, and the addresses of open browser tabs to spot a meeting link. If reading the names fails, the text of the meeting window is sent to our servers and to OpenAI to pick out the names. Soda reads no other screen content, never records video, and does not save screenshots.

Calendar data. When you connect your Google, Microsoft or Apple calendar, Soda fetches your calendar events, including titles, attendees, dates and meeting URLs, directly from the provider to your Mac. For Google and Microsoft calendars, our servers keep the connection: an encrypted token, your account email and your calendar list. Apple Calendar is read on your Mac only. When Soda matches a call to an event, your Mac sends that event's title and attendees (names and email addresses) to our servers with the call, so the call lands on the right profiles.

Email. If you connect a Gmail or Outlook mailbox, see "Gmail and Outlook" below.

Account information. Your name, email address, and authentication credentials. You can sign in with Google or Microsoft. When you do, we receive your name, email and profile picture from the provider via OAuth. We do not receive or store your Google or Microsoft password.

Support communications. If we are helping you with a problem, we may ask the app to send us its diagnostic log. We only do this after you agree in writing. The log can include page titles and web addresses the app saw, but never your passwords or keys, and never email content. It is sent over an encrypted connection to private storage, kept no longer than 30 days, then deleted.


On-device models. Soda also uses Apple's on-device models for some processing. Nothing leaves your Mac for that.

Gmail and Outlook

You can connect a Gmail mailbox or a Microsoft Outlook mailbox. Outlook works with work and school accounts only.

What we ask for. For Gmail, we ask to read your mail and to create drafts (gmail.readonly and gmail.compose). For Outlook, we ask to read your mail (Mail.Read). Soda never sends email. Drafts are for you to review and send yourself.

What we read. We read your conversations with people. We skip newsletters, marketing, automated notifications, no-reply senders, calendar invites, and people and domains you have excluded. We never download attachments. We keep only an attachment's file name, type and size. Your first mailbox syncs the last 30 days, up to 600 conversations. Later mailboxes sync from the moment you connect them.

What we store. While a mailbox is connected, we store message text and a search index of it, subject lines, thread summaries, the facts we learn with a short quoted excerpt for each, sender signature details, and encrypted connection tokens.

Voice Profile and drafts. To make drafts sound like you, we learn your writing style from a sample of mail you have sent, and keep cleaned copies of that sample as style examples. We also store the subject, body and recipients of drafts Soda writes for you. Drafts you never use may be deleted after 90 days.

When you disconnect a mailbox. Our access ends at once and the connection token is removed. A nightly job then deletes the stored message text and its search index, usually within a day. We keep your memories, the facts and their excerpts, your Voice Profile (including its sample emails) and your drafts. Sender signature details are deleted. If a conversation is also in a mailbox you still have connected, we keep its text until you disconnect that one too.

Managing your email data. Our help centre explains how to disconnect a mailbox, what is deleted and what is kept, and how to delete your account: getsoda.app/docs/integrations/gmail-and-outlook and getsoda.app/docs/memory/delete-your-data.

Inactivity. Our policy is that after 12 months with no sign-in and no sync, we disconnect your mailboxes and delete the stored message text, after we email you a warning. We do not apply this automatically yet.

Knowledge Soda derives

Soda creates new records from the raw context above, including summaries, extracted facts, relationship profiles, and vector embeddings used for search. These derived records are personal data in their own right, both about you and about the people you work with, and are covered by this policy.

From the website and analytics

Website. When you visit getsoda.app we collect standard server logs, including IP address, browser type and pages visited. If you fill in a form on getsoda.app, what you enter is sent to our team's Slack and we may reply by email.

Product analytics. We use PostHog, hosted in the EU (Frankfurt), to collect usage events from the desktop app and the web app. Events are tied to your account. Desktop events can include the questions you type into Soda's search, short fragments of a call transcript, the names of the people on a call, meeting links, the title and attendee email addresses of the calendar event a call was matched to, and device and usage details. They do not include email content, email addresses from your mail, page text or window titles. We do not record your sessions. PostHog also records an approximate location (city level) derived from your IP address.

Error reports. We use Sentry, in its EU region, for error and crash reports. We remove email content and secrets from them.

Cookies. The web app sets only the cookies needed to keep you signed in. Product analytics in the web app use your browser's local storage, not a cookie.

Personal data about other people

Soda is built to hold context about the customers, prospects and colleagues you work with. That means we process personal data about people who are not Soda users, including names, job titles, contact details, what was discussed, what was agreed, and details those people shared during conversations.

Where you use Soda for individual purposes, you are responsible for having a lawful basis to record and retain information about the people you work with. Where your organisation provides your account, your organisation is the controller for that data.

Soda is not designed to capture special category data such as health information, political opinions, religious beliefs, or trade union membership. We ask that you do not use Soda to build records of that kind, and you can exclude people and domains and turn off listening for a meeting app.

Calls and the people you speak to

Recording and transcribing conversations is regulated differently in different places. Some countries and US states require the consent of every participant. You are responsible for telling the people on your calls that the conversation is being transcribed and for obtaining consent where the law requires it. Soda lets you pause listening during a call.

Why we use your data, and our legal basis

We rely on performance of our contract with you to provide Soda's core functionality, meaning understanding context, building profiles and making knowledge searchable. The same basis covers communicating with you about your account and material changes to the service.

We rely on your consent to listen to your calls and read your email. You give that consent when you grant Soda the Mac permissions it asks for and when you connect a mailbox, and you can withdraw it at any time.

We rely on our legitimate interests to keep Soda secure, prevent abuse and investigate incidents, and to improve performance, reliability and features using usage data.

We rely on consent, or our legitimate interests in marketing to existing customers, to send you product updates and marketing. You can opt out in any message.

We rely on compliance with a legal obligation to meet our legal, tax and regulatory requirements.

We do not sell your personal data. We do not share it for cross-context behavioural advertising. We do not use your data, or data derived from it, to train our own AI models or those of our providers. We do not serve advertising.

Soda does not make decisions about you that produce legal or similarly significant effects without human involvement.

Teams and shared knowledge

Soda is designed so that knowledge can be shared across a team. Being in a workspace shares nothing by itself. Where you are part of a team workspace:

  • Knowledge you choose to share, and profiles designated as shared, are visible to other members of that workspace

  • Workspace administrators can manage members, approve join requests and set a workspace-only sharing policy. They cannot see your memories unless you share them.

  • If you leave or are removed, you keep your own memory. Shares others gave you are revoked. Shares you gave to others stay with them.

Anything not shared stays private to your account.

How AI processes your data

To turn your calls and email into facts, summaries, search answers and drafts, Soda sends text to AI services. We send only the text needed for the task.

Various open-weight AI models, through OpenRouter. We use several open-weight AI models, one whose weights are published so any provider can run it. Hosting providers based in the United States run it for us: DeepInfra, Fireworks AI and CoreWeave. We reach them through OpenRouter, a routing service based in the United States, and every request is restricted to those hosts with data collection denied and zero data retention required. OpenRouter keeps no prompts or outputs, and all three hosts are on its public zero-data-retention list, so they must not store your text after they reply. This model extracts facts, writes summaries and profiles, drafts follow-ups and answers your searches.

OpenAI (United States).OpenAI creates embeddings (a numeric index) of email passages, call transcripts, facts and your search queries; writes contact and company summaries, briefings and graph summaries; reconciles action items and checks whether a new fact replaces an older one; extracts fields when you run a recipe; helps read participant names from a meeting window; and is our backup if OpenRouter fails. OpenAI does not store our chat requests. It keeps inputs for up to 30 days to watch for abuse, then deletes them. We have asked for zero data retention and will update this page if it is approved.

None of these services may train AI models on your data, and we do not train models on it either.

Who we share data with

We share personal data with the service providers below, each under written terms that restrict what they can do with it.

AI providers. OpenAI (US), OpenRouter (US), and the hosting providers based in the United States that run an open-weight AI model for us, as described above. We use API access that does not permit these providers to use your data to train their models.

Infrastructure and operations:

  • Supabase, for authentication, database and storage, on AWS in Ohio, United States

  • Vercel (US), for our application servers

  • PostHog (EU hosted), for product analytics

  • Sentry (EU region), for error monitoring and crash reporting

  • Resend (US), for account emails only, including sign-up decisions and replies to forms on getsoda.app. It receives no email or call content.

  • Slack (US), for internal team communication and notifications. 

  • Downloads. The Mac app fetches its updates from GitHub and its speech-to-text model from Hugging Face, and the sign-in page loads a font from jsDelivr. These services see your IP address and nothing else.

  • Google (US) and Microsoft (US), for calendar, email and identity integrations accessed via OAuth 2.0

  • Framer and Cloudflare, which host and serve getsoda.app, and Mintlify, which hosts our help centre

  • Anthropic (US), whose Claude models our team uses as an engineering and operations assistant.

A current list of our sub-processors is available at privacy@getsoda.app.

We may also disclose personal data:

  • Where we are required to by law, court order, or a valid request from a public authority. We will notify you where we are permitted to do so

  • To our professional advisers, such as lawyers and auditors, where necessary

  • In connection with a merger, acquisition or sale of assets, in which case we will notify you before your data becomes subject to a different privacy policy

We do not otherwise disclose your data to third parties.

OAuth tokens for connected services are stored encrypted with per-user encryption keys.

Google API disclosure

The use of information received from Google Workspace scopes will adhere to the Google User Data Policy, including the Limited Use requirements.

When you connect your Google account, Soda accesses your data solely to provide its core functionality to you. Specifically:

Gmail (gmail.readonly, gmail.compose). Soda reads your conversations to build facts about the people and companies you work with, to let you search them, and to show the relevant thread beside a contact's profile. It reads sent mail to learn your writing style, and creates follow-up drafts for you to review and send yourself. See "Gmail and Outlook" above for what we store and for how long.

Google Calendar (calendar.readonly). Soda fetches your calendar events directly to your Mac to show upcoming meetings and surface relevant context. When a call is matched to an event, the event's title and attendees are sent to our servers with the call.

How we use and share Google user data.

  • We use it only to provide the user-facing features described in this policy.

  • We transfer it only to the companies named in this policy, and only as needed to provide those features.

  • We do not sell it or use it for advertising.

  • No one at Soda reads the content of your Google data, except with your agreement, when needed for security or abuse, or when the law requires it. The one other case is feedback you send on a follow-up draft, which shares a copy of that draft with the Soda team for review. In those same cases, the operations assistant named above may read it too.

  • We do not use it to train, retrain or improve general AI models.

Retention. Mailbox data follows the rules in "Gmail and Outlook" above. If you delete your Soda account, we delete all Google-derived data from our live systems within 30 days. You can request deletion at any time at support@getsoda.app.

How long we keep data

Call audio is never uploaded. It is deleted from your Mac once transcribed.

Transcripts, call write-ups, memories, facts, profiles and embeddings are kept while your account exists, or until you delete the item.

Email message text and its search index are kept while the mailbox is connected. A nightly job deletes them after you disconnect.

Your Voice Profile and follow-up drafts are kept while your account exists.

Raw screen content is not kept.

Account information is kept while your account exists.

Support correspondence is kept for 24 months.

Server logs are kept for a short period, no longer than 30 days.

Product analytics are kept under our analytics provider's plan. Your analytics identity is deleted when your account is deleted.

Error reports are kept for 30 days.

Backups expire after 7 days.

Raw capture is short-lived. The knowledge Soda derives from it is what persists, because that is what makes a profile useful months later.

To delete your account, email support@getsoda.app. We delete your personal data from our live systems within 30 days, except where we must keep it to meet a legal obligation. A deleted item can remain in a backup for up to 7 days.

Storage and security

Data is stored on servers operated by our infrastructure providers, located in the United States. Analytics and error reports go to the EU. We use encryption in transit (TLS 1.2 or above) and encryption at rest.

The Soda app also keeps a copy of your memory on your Mac, in its own application folder, so search and the notepad work instantly. It is protected by your Mac's user account and FileVault, and removed when you sign out of the app.

Our security measures include role-based access control, per-user encryption keys for OAuth tokens, logged and restricted internal access to user data on a need-to-know basis, and regular review of our providers.

No system is completely secure. If a breach affects your personal data and is likely to result in a risk to your rights, we will notify you and the relevant supervisory authority without undue delay, and within 72 hours where required.

Your controls in the product

  • Pause listening during a call

  • Choose which meeting apps Soda listens to

  • Turn email reading off for each mailbox

  • Exclude people and domains

  • Delete a memory, a contact or a company

  • Disconnect a mailbox or calendar

  • Delete your account, by emailing support@getsoda.app

Your rights

Depending on where you live, you may have the right to:

  • Access the personal data we hold about you

  • Correct inaccurate data

  • Request deletion of your data

  • Object to or restrict certain processing

  • Receive a copy of your data in a portable format

  • Withdraw consent at any time, without affecting processing carried out before you withdrew it

  • Not be discriminated against for exercising your rights

To exercise any of these, email support@getsoda.app. We will respond within 30 days. We may need to verify your identity first.

If you are in the UK or EEA and are not satisfied with our response, you can complain to a supervisory authority. In the UK that is the Information Commissioner's Office at ico.org.uk. In the EEA it is the authority in the country where you live or work.

California residents. We do not sell or share personal information as those terms are defined under the CCPA, and we have not done so in the preceding 12 months. You have the right to know, delete, correct, and to limit the use of sensitive personal information. We do not use sensitive personal information for purposes beyond those permitted without a right to limit.

Other US states. Residents of states with comprehensive privacy laws, including Colorado, Connecticut, Virginia, Texas and others, have equivalent rights of access, correction, deletion, portability and appeal. To appeal a decision, reply to our response or email privacy@getsoda.app with "Appeal" in the subject line.

International transfers

We are a United States company. If you use Soda from outside the US, your personal data is transferred to and processed in the United States, and by providers based there including OpenAI, OpenRouter, DeepInfra, Fireworks AI, CoreWeave, Anthropic, Supabase, Vercel, Google, Microsoft, Resend and Slack. PostHog and Sentry process data in the EU.

Where personal data is transferred out of the UK or EEA, we rely on the EU Standard Contractual Clauses together with the UK International Data Transfer Addendum, or on another lawful transfer mechanism where one applies. You can request a copy of the relevant safeguards at privacy@getsoda.app.

Children

Soda is not intended for anyone under 18 and we do not knowingly collect data from children. If you believe a child has provided us with personal data, contact privacy@getsoda.app and we will delete it.

Changes to this policy

We may update this policy. If we make material changes we will notify you by email or in the product at least 14 days before they take effect. The "last updated" date reflects the most recent revision, and previous versions are available on request.

Contact

Soda LLC: privacy@getsoda.app. For account, deletion and data requests, support@getsoda.app.

For general enquiries, hello@getsoda.app.