Privacy Policy

    Effective date: 9 July 2026

    This Privacy Policy explains how SOMA A.I PTE. LTD. (“SOMA”, “we”, “us”) collects, uses, discloses, and protects personal data in connection with the SOMA A.I platform and website (the “Service”). It is designed to be consistent with the Singapore Personal Data Protection Act (PDPA), and, where applicable, the EU/UK General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA/CPRA).

    For the data you upload and process through the Service, you are generally the controller and SOMA acts as your processor. For your account and our website, SOMA is the controller.

    1. Information We Collect

    1.1 Information you provide

    • Account and profile data: name, email address, organization name, role, and login credentials.
    • Billing data: subscription plan and transaction records. Payment card details are collected and processed directly by our payment processor — we do not store full card numbers.
    • Communications: messages, support requests, and feedback you send us.

    1.2 Data you upload or generate (“User Content”)

    • Advertising and campaign data, brand information, files, and other content you upload or connect, and the AI-generated Insights produced from it. This may incidentally contain personal data if you choose to include it.

    1.3 Public and third-party data

    • Publicly available information about your brand and competitors you specify — such as public social media profiles, public marketplace listings, and public customer reviews — collected to produce competitive and reputation insights. We apply reasonable measures to minimize personal data (for example, anonymizing individual reviewer identities).

    1.4 Information we collect automatically

    • Usage data: feature usage, actions taken, and Credits consumed.
    • Device and log data: IP address, browser type, device identifiers, and timestamps.
    • Cookies and similar technologies: used for authentication, preferences, security, and analytics (see Section 7).

    2. How We Use Information

    We use personal data to:

    • provide, operate, maintain, and secure the Service;
    • generate the Insights you request;
    • authenticate users and manage Organizations and team access;
    • process payments, manage subscriptions, and administer Credits and the referral programme;
    • provide customer support and respond to inquiries;
    • monitor, analyze, and improve the performance and security of the Service (using operational and usage data — not by training AI models on your User Content);
    • detect, prevent, and address fraud, abuse, and security incidents;
    • comply with legal obligations and enforce our Terms.

    3. Legal Bases for Processing (GDPR)

    Where GDPR applies, we rely on: performance of a contract (to provide the Service); legitimate interests (to secure and improve the Service, prevent fraud); consent (where required, e.g., certain cookies or marketing); and legal obligation (to comply with law). You may withdraw consent at any time where processing is based on consent.

    4. Artificial Intelligence and Your Data

    4.1 SOMA uses third-party AI providers to generate Insights. Our AI processing runs on Anthropic’s Claude models. Under Anthropic’s commercial API terms, your inputs and outputs are not used to train Anthropic’s models.

    4.2 We never use your User Content to train, fine-tune, or improve any AI model — ours or any third party’s. Your data is processed only to generate the insights you ask for.

    5. How We Share Information

    We do not sell or rent personal data. We share it only as follows:

    5.1 Sub-processors / service providers. We use trusted third parties to operate the Service. Each is bound by confidentiality and data-protection obligations and may process personal data only on our instructions. Our current sub-processors include:

    ProviderPurposeLocation
    AnthropicAI processing (insight generation; no training on your data)United States
    SupabaseDatabase, authentication, and storageSingapore
    VercelApplication hosting and deliveryUnited States
    ApifyCollection of public third-party data (social / reviews)United States
    StripePayment processingUnited States

    5.2 Within your Organization.User Content and activity are visible to members of your Organization as configured by your administrators. Your data is never shared with other customers or tenants — every Organization’s data is isolated and access-controlled at the database level.

    5.3 Legal and safety. We may disclose data where required by law, legal process, or governmental request, or to protect the rights, safety, and property of SOMA, our users, or the public. Where permitted, we will notify you.

    5.4 Business transfers. In connection with a merger, acquisition, or sale of assets, data may be transferred subject to this Policy.

    6. Multi-Tenancy and Access Controls

    SOMA is multi-tenant by design. Each Organization’s data is isolated and enforced at the database level through row-level security. Access is limited to (a) the members you invite to your Organization, and (b) a small number of SOMA personnel strictly on a need-to-know basis to operate and support the Service, under confidentiality obligations. Where our staff access an Organization for support, such access is controlled and auditable.

    7. Cookies and Tracking

    We use cookies and similar technologies for authentication, security, remembering preferences, and understanding usage. Strictly necessary cookies are required to operate the Service. Where required by law, we will request consent for non-essential cookies. You can control cookies through your browser settings; disabling some may affect functionality.

    8. Data Retention

    We retain personal data for as long as your Account is active and as needed to provide the Service, and thereafter as necessary to comply with legal obligations, resolve disputes, and enforce our agreements. When you delete data or close your Account, we remove it from our active systems within a reasonable period, subject to legal retention requirements and routine backup cycles.

    9. Data Security

    We implement technical and organizational measures to protect personal data, including encryption in transit and at rest, access controls, and least-privilege access for staff. No system is completely secure; we cannot guarantee absolute security, but we work to protect your data and will notify you of qualifying data breaches as required by law.

    10. International Data Transfers

    We and our sub-processors may process data in countries other than yours. Where we transfer personal data across borders, we implement appropriate safeguards required by applicable law (for example, Standard Contractual Clauses under GDPR, or comparable measures under the PDPA).

    11. Your Rights

    Depending on your location, you may have rights to:

    • access the personal data we hold about you;
    • correct inaccurate data;
    • delete your data;
    • export / port your data in a portable format;
    • object to or restrict certain processing;
    • withdraw consent where processing is based on consent.

    You can export or delete your data at any time through the Service or by contacting us. Where SOMA acts as a processor for User Content, we will assist the relevant Organization (controller) in responding to such requests, or direct you to it.

    To exercise your rights, contact privacy@soma-ai.co. We will respond within the timeframe required by applicable law. You also have the right to lodge a complaint with your local data protection authority (in Singapore, the PDPC).

    California residents (CCPA/CPRA):we do not sell or “share” personal information for cross-context behavioral advertising. You have the right to know, delete, correct, and be free from discrimination for exercising your rights.

    12. Children’s Privacy

    The Service is not directed to individuals under 18, and we do not knowingly collect their personal data. If you believe a minor has provided us data, contact us and we will delete it.

    13. Third-Party Links

    The Service and Insights may reference or link to third-party websites and platforms. We are not responsible for their privacy practices; review their policies.

    14. Changes to This Policy

    We may update this Policy from time to time. Material changes will be notified via the Service or email, and the “Effective date” above will be updated. Continued use after changes take effect constitutes acceptance.

    15. Contact Us

    Data Protection / Privacy inquiries: privacy@soma-ai.co

    SOMA A.I PTE. LTD. · 44 Brockhampton Drive, Serangoon Garden Estate, Singapore 559092