Security.
What we do with your data, stated plainly. Every line below is something we can point to, not a promise.
Your conversations are not used to train models
Sotto sends transcript text to a commercial language-model provider to generate advice, under that provider's own API terms — which is a service contract, not a training relationship. Your negotiation is not training data for anyone's model.
Encrypted in transit
Every connection to Sotto is TLS, terminated at the edge before any request reaches the application.
Documents you upload are encrypted at rest
Contract and BATNA documents you upload are stored as ciphertext, not plaintext. This is specific to uploaded documents — it is not yet a blanket claim about every kind of data this product stores, and we would rather say that precisely than round it up.
Deletion and retention are yours to control
A deal, a call, or a recording is yours to delete. Recordings you do not delete yourself are removed automatically after a retention window your operator sets — never kept indefinitely by default.
Jurisdiction is the operator's, not ours to assume
The consent text every counterparty sees does not name a country's law — it says the organising party is responsible for the law that applies where the call takes place, and that is deliberate: retention windows, consent wording and residency are set per deployment, never hardcoded to one jurisdiction. Ask your operator which regime theirs runs under.