← Back to Somara

Privacy Policy

Draft of 8 September 2026 · version 0-draft

This policy is a draft and has not been reviewed by a lawyer.

It describes what Somara actually does with your data today, so you can decide with your eyes open. If you create an account now you are agreeing to this interim policy, and we will ask you to review and accept the final version once it is published.

What this covers

Somara is accounting software. You connect bank accounts, import records, and keep a general ledger. This policy covers the data you put into Somara and the data we collect to run it.

What we hold

  • Your account. Email address, and the organizations you belong to. Somara signs you in with a magic link, so we do not store a password.
  • Your books. Everything you enter or import: accounts, journal entries, contacts, invoices, bills, and the documents behind them.
  • Bank data. If you connect a bank, we receive transactions, balances and, if you enable it, investment holdings. We store the access token for that connection encrypted and separately from the rest of your data.
  • Billing. Stripe handles payment. We store your Stripe customer and subscription identifiers and your subscription status. We never see or store your card number.
  • Operational records. An audit log of changes to your books, API request records for rate limiting, and server logs.

Who else processes it

We use these sub-processors. Each one sees only what its job requires.

  • Supabase — database, authentication and file storage.
  • Vercel — application hosting.
  • Plaid — bank connections, if you connect a bank.
  • Stripe — subscription payment.
  • Resend — transactional email, such as sign-in links and invitations.
  • Intuit — only if you choose to import from QuickBooks Online.

We do not send your books to an AI model

Somara does not call a language model and does not train anything on your data. Somara is built to be driven BY an agent rather than to contain one: if you connect Claude, ChatGPT, or your own software, that agent runs under your control and reads your books through a credential you issue and can revoke. The data it sees goes to the provider you chose, under their terms, not ours.

You decide what each credential may do. Access is scoped per resource and per level, and you can change or revoke it at any time from the dashboard without re-issuing the credential.

We do not sell your data

We do not sell personal data, and we do not share it for advertising. We disclose it only to the sub-processors above, to someone you have invited to your organization, or where the law requires it.

How long we keep it

While your subscription is active, we keep your books so you can use them. That is the point of an accounting system.

If you cancel, we keep your data for 30 days and then clear it. We email you when you cancel and again seven days before the deadline, so you have time to export or come back. Deletion is not automatic and unattended: a person triggers it, which is also why it may happen slightly after day 30 rather than exactly on it.

You can ask us to delete your data sooner. Write to privacy@somara.ai.

Backups are the honest caveat. Deleting data from the application does not immediately remove it from encrypted database backups, which roll off on their own schedule. The exact backup retention window is still being confirmed and this paragraph must state it before this policy is published.

Where it is held

Somara's database and application are hosted in the United States. If you use Somara from elsewhere, your data is transferred there.

Your choices

  • Export everything at any time. An owner or admin can download the whole organization — ledger, contacts, transactions, settings and the audit log — as a single file from /api/export.
  • Disconnect a bank at any time; we stop receiving new transactions.
  • Revoke any agent credential at any time.
  • Ask for a copy of what we hold about you, ask us to correct it, or ask us to delete it.

Security

Access to your books is enforced in the database itself, per organization. Bank access tokens are encrypted at rest and held apart from your ledger. Agent credentials are stored hashed and are shown to you once, at creation.

If you believe you have found a security problem, write to security@somara.ai.

Contact

Questions, access requests and deletion requests: privacy@somara.ai.