Skip to content
SOLSTERA™LABS
Company Suite Products Principles Contact Account
Account

Privacy Policy

General company and account privacy information, with product-specific disclosures kept explicit.

Effective date: August 11, 2026

Solstera Labs LLC ("Solstera Labs," "we," "us," or "our") provides software for AI-assisted operations, blueprint walkthroughs, communication and unified-inbox workflows, attorney-supervised legal workflows, market research, and metadata-first account operations. This Privacy Policy explains how we handle information collected through this website, Solstera Atlas™, Space-Reveal, Solstera Market Intelligence™, Trusted Entry, Solstera Inbox One, early-access requests, and related product communications.

Information we collect

We collect information you choose to provide, including name, business name, email address, phone number, website, team size, selected product lane, desired timing, and message text submitted through contact or early-access forms.

If you create a Space-Reveal account, we collect account information such as email address, password authentication data, email verification status, password reset tokens, session records, admin role status where applicable, and account activity needed to operate the service.

Space-Reveal project data may include uploaded blueprint or design PDFs, room names, dimensions, plan calibration choices, generated or edited model geometry, materials, finish images, screenshots, measurement notes, review sessions, review invite metadata, and related project settings. You should not upload Social Security numbers, payment card numbers, medical information, legal client data, or other highly sensitive information unless a separate written agreement specifically covers that use.

The site and app also process technical information needed to operate securely, such as IP-derived rate-limit data, browser/device information available through ordinary web requests, server logs, cookies, local browser storage, and error or health-check information.

How we use information

We use information to respond to inquiries, evaluate product fit, schedule demos, provide and secure accounts, sync saved projects across devices, generate Space-Reveal review sessions, send verification and password reset emails, support users, maintain service reliability, enforce usage limits, improve product quality, and comply with legal or security obligations.

We do not use customer blueprint files, project materials, or account content for public marketing without permission. We also do not sell personal information.

Space-Reveal storage

Space-Reveal is local-first. When you are not signed in, saved project metadata may be stored in your browser's localStorage and uploaded PDFs or material images may be stored in your browser's IndexedDB. That local browser data stays on your device unless you clear it, use browser controls, or sign in and sync selected project data to the server.

When you are signed in, project JSON and uploaded PDF, design-layer, material, or finish image files may sync to the Space-Reveal server. Server-side project data and asset bytes are encrypted at rest. Account-backed Quest review links publish a sanitized, read-only review package and expire automatically. Recipient invite records store intended recipient email/label metadata and hashed invite tokens so owners can track and revoke access.

Space-Reveal is not intended to be the only archive of your construction drawings, design records, customer records, legal records, or professional work product. Keep independent copies of source files and records you need to preserve.

Cookies and local storage

Space-Reveal uses cookies for account sessions and CSRF protection. The app also uses localStorage and IndexedDB so projects can reopen quickly and so large PDF/image files do not have to be placed in localStorage. At launch, Solstera Labs does not use third-party advertising pixels on the website.

Trusted Entry

If you create a Trusted Entry account, we collect account information and the account metadata you choose to keep in your workspace: account names, domains, launch URLs, usernames, ownership and review status, discovery and import history, and workspace, device, and sync metadata. Discovery runs through the Trusted Entry browser companion and the guided imports you approve. Trusted Entry is designed never to collect or store passwords, passkeys, cookies, TOTP seeds, recovery codes, or session tokens.

Trusted Entry is not yet publicly available. If billing launches, Zoho will process payment details under its own privacy policy; Solstera Labs will store only customer, subscription, and entitlement references needed to operate access, never card or bank account numbers.

Solstera Atlas™

Solstera Atlas™ is the AI assistant platform provided by Solstera Labs LLC. Atlas may process workspace configuration, tasks, instructions, prompts, generated outputs, durable memory, model and connector configuration, credential references, guardrail decisions, held-action reviews, and execution or audit evidence inside a customer-isolated stack.

Customers choose and authorize their own AI-model and connector providers. Content needed to perform a requested task may be sent to those providers under the customer’s provider account, terms, privacy policy, and usage arrangement. Atlas does not bundle customer AI usage or use a shared funded model account as a fallback.

Credential material is kept within the customer’s isolated Atlas boundary and is exposed only through the constrained product mechanisms needed to use an authorized provider. External sends, payments, filings, calendar changes, and provider writes are default-off or held behind explicit controls unless an authorized customer enables and releases them.

Solstera Inbox One

Solstera Inbox One is a unified inbox that connects the email, calendar, and messaging accounts you choose to link — currently Google (Gmail and Google Calendar), Microsoft (Outlook mail and calendar), and Slack — and helps you triage, draft, and reply with AI assistance. Inbox One is in beta. You connect accounts by signing in with each provider's own sign-in page (OAuth); Inbox One never sees or stores your provider password.

When you link an account, the provider shows you a consent screen listing exactly what Inbox One is requesting. Inbox One requests:

  • Google (Gmail and Google Calendar). Your basic profile (name, email address); read access to your Gmail messages and labels; the ability to modify Gmail labels and message state (for example marking a thread read, archiving, or moving it) and to manage drafts; the ability to create drafts and send email from your address when you tell it to; read access to your Google Calendar; and the ability to create and update calendar events when you ask Inbox One to schedule something. (OAuth scopes: openid, email, profile, gmail.readonly, gmail.modify, gmail.compose, calendar.readonly, calendar.events.)
  • Microsoft (Outlook / Microsoft 365). Your basic profile; read and write access to your mail (read messages and folders, update message state, manage drafts); the ability to send mail as you when you tell it to; and read and write access to your calendars. (Microsoft Graph delegated scopes: openid, profile, offline_access, User.Read, Mail.Read, Mail.ReadWrite, Mail.Send, Calendars.Read, Calendars.ReadWrite.)
  • Slack. Read access to your direct messages, group direct messages, and the public and private channels you are a member of; basic member directory information so names resolve correctly; and the ability to send messages as you when you tell it to. (Slack user-token scopes: im:history, im:read, mpim:history, mpim:read, channels:history, channels:read, groups:history, groups:read, users:read, chat:write.)
  • Microsoft Teams (not yet available). When the Teams connector launches, it will additionally request read access to your Teams chats and the ability to send chat messages as you (Chat.Read, ChatMessage.Send). We will update this policy when Teams goes live.

Inbox One acts only on the account you linked, only with the permissions above, and mail is sent or calendar events are created only as a result of actions you (or workspace members you authorize) take in the product.

How Inbox One stores this data. Synced content — message headers, message bodies, thread and folder metadata, attachment metadata (file names, types, and sizes — not the attachment files themselves), calendar events, and contact display information — is stored in a PostgreSQL database on Solstera Labs-operated server infrastructure in the United States. OAuth access and refresh tokens are encrypted at rest with AES-256-GCM using a dedicated key before they are written to the database. Each customer organization's data is isolated by organization and workspace identifiers enforced on every query.

Google user data — Limited Use. Inbox One's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In plain terms: we use Google user data only to provide and improve Inbox One's user-facing features (your unified inbox, summaries, drafts, and scheduling). We do not sell Google user data; we do not use it for advertising; we do not transfer it to data brokers or information resellers; we do not use it to build profiles for any purpose other than the features you see; humans at Solstera Labs do not read your messages except with your explicit permission (for example, a support request you initiate), for security investigation and abuse prevention, or where required by law; and we do not use Google user data to develop, improve, or train generalized artificial-intelligence or machine-learning models.

AI processing. Inbox One's AI features — thread summaries, reply drafts, proofreading, attachment overviews, and meeting-time suggestions — are powered by the OpenAI API. When you use one of these features, the relevant conversation content (for example, the thread you asked to summarize, plus attachment file names, types, and sizes) is sent to OpenAI to generate the result and returned to you. This processing is used solely to deliver the user-facing feature you invoked. Content sent through the OpenAI API is not used by OpenAI to train its models, and Inbox One disables response storage on its API requests. Solstera Labs does not use your content to train any model of its own, and no human at Solstera Labs or OpenAI reviews your content as part of normal AI-feature operation. AI usage is metered per workspace with configurable daily limits.

Retention and deletion for Inbox One. Workspace administrators can configure a data-retention window for synced content (from 30 days up to 10 years; the default is 365 days). Synced provider content older than the retention window is deleted by an automated daily retention process. Disconnecting a linked account immediately deletes that account's synced content — its messages, threads, attachment records, and calendar events — along with its stored OAuth access and refresh tokens, and stops all syncing for that account. You can also revoke Inbox One's access at any time from your provider's own security settings (Google Account → Security → Third-party access; Microsoft account → Privacy → App access; Slack → App management). To request deletion of any remaining information we hold about you, contact us at hello@solsteralabs.com and we will delete it. Backups and logs may persist for a limited period after deletion as part of normal security, disaster recovery, and operations.

Service providers for Inbox One. Inbox One relies on the following providers to operate:

  • OpenAI (OpenAI, L.L.C., US) — AI text generation for the user-facing features described above (API-only; no training on your content; response storage disabled).
  • Resend — delivery of sign-in codes and workspace invitation emails (recipient address and message only; never your synced content).
  • Zoho — bookkeeping and subscription billing, if and when billing is enabled for your account; Zoho processes payment details under its own privacy policy and Solstera Labs never stores card or bank account numbers.
  • Cloudflare — DNS for solsteralabs.com / app.solsteralabs.com.
  • Solstera Labs-operated server infrastructure (US) — application hosting and the PostgreSQL database described above.

Google, Microsoft, and Slack are the services you connect — they act as independent controllers of your accounts under their own terms and privacy policies, not as our sub-processors.

How we share information

We share information with service providers that help us run the business, such as hosting, email delivery, domain/DNS, backup, security, support, and operational tooling providers. We may also disclose information if required by law, to protect rights and security, to investigate abuse, or in connection with a business transfer such as a merger, financing, acquisition, or sale of assets.

Retention and deletion

We keep information for as long as reasonably needed for the purposes described above. Contact requests are kept while we evaluate, respond to, and manage early-access conversations. Space-Reveal account projects and Atlas workspace records are kept until deleted by an authorized user, the account or hosted workspace is terminated, a customer agreement requires deletion, or retention rules require cleanup. Review sessions and one-time auth tokens expire automatically. Backups and logs may persist for a limited period after deletion as part of normal security, disaster recovery, and operations.

Deleting a Space-Reveal account removes saved server projects, active review links, recipient records, and stored blueprint/material files from the server. Local browser copies may still remain on devices where the project was opened until browser storage is cleared.

Security limits

We use technical, administrative, and operational safeguards appropriate for the current product stage, including encrypted server storage for signed-in Space-Reveal project data and assets and separately provisioned customer stacks for Atlas. No internet service, AI provider, connector, local browser storage, email system, or backup process can be guaranteed perfectly secure or always available. You are responsible for choosing what to upload, connect, authorize, and release.

Your choices

You may contact us to request access to, correction of, or deletion of personal information we maintain about you. If you have a Space-Reveal account, some deletion can be performed from the account screen. We may need to verify your identity and may retain information where allowed or required for security, legal, backup, fraud-prevention, or operational reasons.

Depending on where you live, you may have additional privacy rights. We do not currently sell personal information or share it for cross-context behavioral advertising. If those practices change, this policy will be updated before the change takes effect.

Children

Solstera Labs products are intended for business and professional use. We do not knowingly collect personal information from children under 13.

Product integrations

Inbox One's email, calendar, and messaging access is described in the Solstera Inbox One section above and operates only on accounts you explicitly link. Atlas connections operate only through customer-authorized model and connector accounts and the capability boundaries configured for the hosted workspace. Any future access to plans, legal records, document systems, CRM systems, or other customer systems will be governed by the applicable product disclosures, authorization process, and any separate customer agreement. Solstera ProbatePath™ workflows should remain attorney-supervised and should not be treated as consumer legal advice from an automated system.

Updates

We may update this Privacy Policy as the products and business mature. If we make material changes to how we handle personal information, we will provide notice appropriate to the change.

Contact

For privacy questions or requests, contact Solstera Labs at hello@solsteralabs.com.

SOLSTERA™LABS

Independent software for real work.

CompanyAbout Solstera LabsOur approachPrinciples
ProductsConnected suiteAll productsSolstera account
TrustTrust by designPrivacyTerms
ContactStart a conversationhello@solsteralabs.com
© 2026 Solstera Labs LLCThoughtful software, deliberately built.

Atlas™ and Solstera Atlas™ identify the artificial-intelligence software platform provided by Solstera Labs LLC. Other trademarks belong to their respective owners.