Draft of 8 September 2026 · version 0-draft
This policy is a draft and has not been reviewed by a lawyer.
It describes what Somara actually does with your data today, so you can decide with your eyes open. If you create an account now you are agreeing to this interim policy, and we will ask you to review and accept the final version once it is published.
Somara is accounting software. You connect bank accounts, import records, and keep a general ledger. This policy covers the data you put into Somara and the data we collect to run it.
We use these sub-processors. Each one sees only what its job requires.
Somara does not call a language model and does not train anything on your data. Somara is built to be driven BY an agent rather than to contain one: if you connect Claude, ChatGPT, or your own software, that agent runs under your control and reads your books through a credential you issue and can revoke. The data it sees goes to the provider you chose, under their terms, not ours.
You decide what each credential may do. Access is scoped per resource and per level, and you can change or revoke it at any time from the dashboard without re-issuing the credential.
We do not sell personal data, and we do not share it for advertising. We disclose it only to the sub-processors above, to someone you have invited to your organization, or where the law requires it.
While your subscription is active, we keep your books so you can use them. That is the point of an accounting system.
If you cancel, we keep your data for 30 days and then clear it. We email you when you cancel and again seven days before the deadline, so you have time to export or come back. Deletion is not automatic and unattended: a person triggers it, which is also why it may happen slightly after day 30 rather than exactly on it.
You can ask us to delete your data sooner. Write to privacy@somara.ai.
Backups are the honest caveat. Deleting data from the application does not immediately remove it from encrypted database backups, which roll off on their own schedule. The exact backup retention window is still being confirmed and this paragraph must state it before this policy is published.
Somara's database and application are hosted in the United States. If you use Somara from elsewhere, your data is transferred there.
/api/export.Access to your books is enforced in the database itself, per organization. Bank access tokens are encrypted at rest and held apart from your ledger. Agent credentials are stored hashed and are shown to you once, at creation.
If you believe you have found a security problem, write to security@somara.ai.
Questions, access requests and deletion requests: privacy@somara.ai.