Skip to content

Solid Privacy Policy

Effective Date: September 23, 2026

This Privacy Policy explains how Codapt Inc. (“Codapt,” “we,” “us,” or “our”) collects, uses, discloses, and retains personal information in connection with Solid, solid.tech, and related software, websites, applications, systems, projects, and services (collectively, the “Services”).

Solid is an AI-powered managed service. Projects may be performed using artificial intelligence and other automated systems, Codapt employees and personnel, independent contractors, subcontractors, and third-party resources, in any combination. Human personnel may directly participate in fulfilling user requests and may access information, including credentials and sensitive information, when connected to a Project or the Services.

A “Project” is a task, goal, or other request submitted to Solid. “Project Data” includes prompts, conversations, files, code, credentials, outputs, and other information supplied, accessed, observed, or generated in carrying out a Project. Where applicable law requires consent for a particular use of information, we request it separately.

1. Scope and Our Role

This Privacy Policy applies when Codapt determines why and how personal information is processed in connection with the Services, including for account administration, authentication, billing, Project performance, security, support, analytics, development, improvement, and marketing.

A business customer may also use Solid to process information about its own customers, users, employees, contractors, or other people. In some circumstances, Codapt processes that information on the business customer’s behalf. The business customer is responsible for its own privacy notices, legal bases, instructions, and compliance. If your information was submitted to Solid by a Solid customer or collected through an application controlled by that customer, you may need to contact that customer to exercise your rights.

This Privacy Policy does not govern the independent privacy practices of third-party websites, applications, accounts, services, or organizations with which Solid or a user interacts.

2. Information We Collect

The information we collect depends on how you use the Services, what you ask Solid to do, what information a Project encounters, and which people, systems, and resources are involved.

2.1 Account, Identity, and Contact Information

We may collect:

  • name, email address, profile information, account identifiers, and authentication information received from a sign-in provider;
  • phone number and phone-verification information;
  • organization, role, and business information;
  • account preferences, plan information, and account status; and
  • communications addresses and identifiers.

2.2 Billing, Subscription, and Credit Information

We may collect:

  • billing name and address;
  • subscription, purchase, invoice, payment-status, refund, dispute, and transaction information;
  • Credit balances, expiration dates, Project Charges, usage, and related records; and
  • limited payment-method information made available by a payment processor, such as card type, last four digits, and expiration information.

Payment information may be processed directly by a payment processor rather than stored by Codapt in full.

2.3 User Content and Project Information

We may collect and process any information submitted, uploaded, entered, connected, made available, or encountered in connection with a Project, including:

  • prompts, goals, instructions, conversations, messages, and feedback;
  • files, images, audio, video, documents, designs, databases, repositories, and source code;
  • business information, customer information, product information, plans, and records;
  • generated code, content, applications, configurations, and outputs;
  • information contained in websites, applications, accounts, systems, and services that Solid accesses; and
  • information about users and non-users that appears in Project materials or is encountered while performing a Project.

2.4 Credentials and Sensitive Information

Projects may involve credentials and sensitive information, including:

  • usernames, passwords, authentication codes, security questions, session information, cookies, tokens, certificates, and API keys;
  • financial, payment, account, transaction, and tax information;
  • private communications and confidential business information;
  • precise or approximate location information;
  • government identifiers;
  • health, employment, education, demographic, biometric, or other sensitive information; and
  • information that may reveal racial or ethnic origin, religious or philosophical beliefs, political opinions, trade-union membership, sexual orientation, immigration status, or other legally protected characteristics.

You should provide only information that is reasonably necessary for your Project and that you are authorized to provide. Depending on how a Project is performed, credentials and sensitive information may be accessible to automated systems, Codapt personnel, contractors, and third parties.

2.5 Agent, Browser, Tool, and Action Information

We may collect information generated, observed, or recorded while Solid performs a Project, including:

  • websites and pages visited;
  • browser content, form fields, page elements, and interactions;
  • screenshots, recordings, images, and visual information;
  • network requests and responses;
  • tool calls, tool results, commands, action histories, task state, and execution traces;
  • communications sent or received;
  • accounts, services, and resources created or accessed;
  • code changes, deployments, database activity, and system events;
  • errors, failures, retries, performance data, and diagnostic information; and
  • information inferred from Project activity.

Some of this information may not be directly visible to you in the Solid interface.

2.6 Generated Applications and End-User Information

If Solid creates, hosts, operates, connects to, or supports an application, website, database, or service, we may process information submitted by or about that application’s users, visitors, customers, employees, or other individuals. This may include contact information, account information, content, usage information, transactions, communications, and any other information the application is configured to collect or process.

The Solid customer responsible for that application must provide appropriate notices and obtain required rights and consents.

2.7 Device, Usage, and Technical Information

We may automatically collect:

  • IP address, device identifiers, browser type, operating system, language, and approximate location;
  • login, session, authentication, and security events;
  • pages, features, buttons, and functions used;
  • timestamps, referring pages, URLs, and navigation information;
  • cookies, local storage, and similar technologies;
  • logs, telemetry, performance, crash, error, fraud, and diagnostic information; and
  • information about how you interact with messages and the Services.

2.8 Communications, Support, and Feedback

We may collect communications with Codapt, support requests, surveys, interviews, feedback, feature requests, and records of calls or meetings where legally permitted.

2.9 Information From Other Sources

We may receive information from:

  • sign-in, authentication, phone-verification, and payment services;
  • people or organizations that invite, refer, communicate with, or provide information about you;
  • third-party websites, applications, accounts, services, databases, and public sources encountered in connection with a Project;
  • security, fraud-prevention, and abuse-prevention sources; and
  • corporate transactions, advisers, authorities, and other lawful sources.

2.10 Derived and Deidentified Information

We may create summaries, inferences, classifications, embeddings, evaluations, and statistics as part of performing Projects and operating the Services. We may also aggregate or deidentify information for the purposes described in this Policy. These activities do not expand the uses permitted by Section 3.4.

3. How We Use Information

We may use information for the following purposes:

3.1 Provide and Fulfill the Services

We use information to:

  • create and administer accounts;
  • authenticate users and verify phone numbers;
  • receive, interpret, plan, perform, monitor, and complete Projects;
  • enable Solid and human personnel to act on user instructions;
  • access, create, configure, operate, deploy, modify, connect, support, suspend, or discontinue accounts, software, applications, infrastructure, communications, and other resources;
  • communicate and interact with users and third parties in connection with Projects;
  • process subscriptions, Credits, Project Charges, and payments;
  • provide generated results, applications, deployments, and related functionality; and
  • personalize Project execution and user experiences.

3.2 Human Participation

Codapt employees, contractors, and other personnel may access and use information to directly perform or assist with Projects, communicate with users or third parties, operate tools, handle credentials, review work, resolve obstacles, and otherwise fulfill user requests.

3.3 Operate, Support, and Secure the Services

We use information to:

  • provide support and respond to requests;
  • troubleshoot, debug, test, monitor, maintain, and improve reliability;
  • authenticate users and protect accounts;
  • prevent, detect, investigate, and respond to fraud, abuse, security incidents, policy violations, and harmful activity;
  • maintain logs, backups, continuity, and internal records; and
  • enforce our agreements and protect Codapt, users, and third parties.

3.4 Service Improvement and AI Processing

We may use Project Data and operational information to troubleshoot issues, evaluate service quality, test functionality, improve workflows and software, and maintain reliability and safety. This may involve human review and processing by existing AI systems.

Codapt does not use information collected through the Services to train or fine-tune AI or machine-learning models for Codapt, and does not commission third parties to do so on Codapt's behalf. Sending information to an existing model to carry out a request, or reviewing service performance, is distinct from model training.

To provide the Services, we may transmit Project Data, including credentials or sensitive information when involved in a Project, to third-party providers. Depending on the provider, service, configuration, and applicable agreement, a provider may retain inputs, outputs, or related information and use it to improve its own services or train its own models. Codapt's position above is not a representation that every third-party provider applies a no-training or zero-retention policy.

These practices remain subject to applicable law, restrictions governing the source of the information, and any controlling customer or provider agreement. Nothing in this Policy overrides those restrictions or permits a provider to disregard them.

3.5 Personalization, Communications, and Advertising

We may use information to personalize Solid, remember preferences, recommend features or Project approaches, and communicate about Codapt's Services and offerings.

Subject to applicable law and your choices, we may work with advertising and marketing partners to select, deliver, personalize, measure, and improve advertising for Codapt and other businesses. This can include retargeting, conversion measurement, campaign optimization, audience matching, and reaching people with similar interests. Advertising may appear on our Services or on other websites, applications, and services.

Information used for these advertising purposes may include contact and account identifiers, device and cookie identifiers, IP addresses and approximate location, visits to public pages, interactions with our marketing and website, subscription and purchase events, and inferences based on that information. Partners may collect information directly through their technologies or receive permitted information from Codapt, and may combine it with information from other sources to recognize a person or device across services.

These advertising uses concern account, website, marketing, and conversion information, not private Project contents. We do not provide private Project contents or credentials to advertising partners for advertising targeting. Platform-specific restrictions and customer agreements may further limit what information can be used or disclosed.

We may add, remove, or replace advertising partners, campaigns, and technologies over time. Routine changes within the practices described here do not require an amendment to our Terms of Service. We update applicable notices, partner details, and consent or choice mechanisms when required; a new provider or technology is not automatically covered by a consent that does not extend to it.

Advertising disclosures may constitute a “sale,” “sharing,” or “targeted advertising” under applicable privacy law, even without an exchange of money for the information. Sections 7, 11, and 12 describe relevant choices. We obtain consent before processing that requires consent and honor applicable opt-outs.

We may use information to:

  • comply with law, legal process, regulatory requirements, court orders, and governmental requests;
  • establish, exercise, or defend legal claims;
  • protect rights, property, safety, security, and integrity;
  • conduct audits, accounting, tax, compliance, and corporate governance;
  • evaluate or complete a merger, financing, acquisition, reorganization, bankruptcy, sale of assets, or other corporate transaction; and
  • perform other purposes disclosed when information is collected or with your direction or consent.

4. How We Disclose Information

We may disclose information to Codapt personnel, affiliates, contractors, subcontractors, service providers, and other people or organizations that we use, engage, or interact with to perform Projects and provide, operate, support, secure, evaluate, and improve the Services as described in this Policy. Human personnel may directly help fulfill a request and may access credentials and sensitive information when doing so.

We may also disclose information:

  • to people and organizations involved in carrying out your instructions, including recipients of communications or resources created for a Project;
  • to advertising and marketing partners for the purposes and information described in Section 3.5;
  • to other users or the public when a Project publishes, sends, deploys, or shares information;
  • to advisers, auditors, insurers, financing sources, and participants in a corporate transaction, including a successor; and
  • to authorities and other parties where reasonably necessary for legal obligations, claims, compliance, fraud prevention, safety, or protection of rights, or with an appropriate direction or consent.

Providers and other recipients may change. Some process information for Codapt; others determine their own purposes and practices under applicable arrangements. Third-party AI processing is addressed in Section 3.4. Where required, we provide further recipient information, notice, consent, or other choices. Disclosing information does not eliminate Codapt's responsibilities under applicable law or a controlling agreement.

5. Artificial Intelligence, Automated Actions, and Human Review

Solid uses AI and other automated systems to interpret instructions, plan actions, generate content, interact with third parties, and perform Projects. These systems may act without confirmation before each action. Codapt personnel and contractors may directly assist with Projects and access information for the fulfillment, support, security, evaluation, and other permitted purposes described in this Policy.

Solid may generate inferences, predictions, recommendations, or actions based on Project information. The Terms describe the risks of automated and human-assisted execution. Where applicable law gives rights concerning qualifying automated decisions, you may contact us as described in Section 11. Ordinary task automation does not itself determine whether those legal rights apply to a particular decision.

6. Credentials and Sensitive Information

Credentials and sensitive information may be processed as part of a Project and may be accessible to Codapt's systems, authorized personnel, contractors, and relevant providers. The AI-processing practices in Section 3.4 also apply when this information is included in a Project.

Provide only information needed for the Project and that you are authorized to provide. Where practical, use scoped, temporary, or revocable credentials and rotate or revoke them when no longer needed. Security is addressed in Section 9.

7. Cookies, Advertising Technologies, and Choices

We and our partners may use cookies, local storage, pixels, tags, JavaScript, SDKs, and similar technologies to operate the Services, maintain sessions, authenticate users, remember preferences, secure accounts, analyze usage, and support the advertising purposes in Section 3.5. We may also use server-to-server integrations and identifiers for audience matching or conversion measurement. The technologies and providers may vary over time.

These technologies may collect identifiers, browser and device information, IP address, page visits, timestamps, referring information, marketing interactions, and subscription or purchase events. Partner technologies can collect information directly from a browser or device; certain integrations transmit permitted information from our systems. Our advertising uses remain limited to the information described in Section 3.5.

Advertising Choices. Where required by applicable law, we obtain consent before using advertising technologies and provide ways to refuse or withdraw consent and exercise applicable advertising-related opt-out rights. Instructions for exercising these choices are provided with the relevant privacy notice or consent mechanism. We honor legally required opt-out preference signals. You may also contact us at contact@solid.tech with questions or requests concerning your privacy rights. Where required, we provide additional information about technologies, partners, purposes, and durations, and obtain renewed consent when our arrangements change.

You may also manage cookies through your browser or device. Browser controls do not necessarily stop server-side disclosures or account-based advertising uses. For those uses, see the advertising choices above and the request instructions in Section 11. We honor legally required opt-out preference signals, including Global Privacy Control, in accordance with applicable law. Apart from legally recognized opt-out preference signals, we do not separately respond to a browser's generic “Do Not Track” setting. That setting is not treated as consent to tracking.

Choices may need to be repeated on another browser or device or after clearing stored preferences. We apply account-level choices and recognized signals to the extent required by law. Declining optional advertising does not prevent necessary service communications, essential functionality, or all advertising; you may still see contextual or non-personalized advertisements.

8. Retention

We retain personal information for as long as reasonably necessary and proportionate for the purposes described in this Policy or as otherwise required or permitted by law. The period depends on the information's nature and sensitivity, the account or Project lifecycle, the purpose of processing, support and security needs, applicable legal and accounting requirements, dispute periods, and technical considerations such as backups.

Some information may remain after a Project or account ends, including transaction records, security and abuse-prevention records, information needed to resolve disputes or comply with law, and records reasonably needed for permitted service operations and evaluation. We do not retain Project Data for training models for Codapt.

Deletion may take time to propagate through active systems, backups, and relevant providers. We handle valid deletion requests subject to lawful exceptions and restrict retained information to the purposes justifying its retention. Keeping information in a backup, evaluation record, or derived format does not create a general exemption from deletion obligations.

Aggregated or properly deidentified information that no longer identifies an individual may be retained longer for the permitted purposes in this Policy. Where required, we maintain it in deidentified form and do not attempt to reidentify it except as permitted by law. This does not expand the model-training uses permitted by Section 3.4.

9. Security

We use administrative, technical, and organizational measures intended to protect information in light of its nature and the Services provided. No method of transmission, storage, or processing is completely secure, and we cannot guarantee absolute security.

You should secure your own accounts, devices, deployments, credentials, and copies of information, use appropriate access permissions, and maintain backups. This does not remove Codapt's own security obligations.

10. International Processing and Transfers

Codapt is based in the United States. Information may be processed in the United States and other countries where the people, systems, and providers involved in the Services operate. Those countries may have different data-protection laws.

Where applicable law requires safeguards for an international transfer, we use a legally recognized transfer mechanism or another permitted basis applicable to that transfer. Depending on the destination and arrangement, relevant safeguards may include an applicable adequacy decision or approved contractual safeguards with any required supplementary measures. Contact contact@solid.tech to request information about the safeguards applicable to your information and a copy where available under applicable law.

11. Your Privacy Rights and Choices

Depending on your location and applicable law, you may have rights to access, correct, delete, or obtain a portable copy of personal information; restrict or object to processing; opt out of a sale, sharing, targeted advertising, or qualifying profiling; limit particular uses of sensitive information; withdraw consent; and appeal a denied request. These rights are subject to applicable conditions and exceptions.

To make a request, email contact@solid.tech with the subject “Privacy Request.” Explain the right you wish to exercise and identify the relevant account or information. For advertising and tracking choices, see Section 7 and any instructions provided with the relevant privacy notice or consent mechanism. You do not need an account to exercise an applicable opt-out right.

We may verify identity or authority for requests that require verification, such as access to or deletion of account information. We do not require verified identity to honor an opt-out where the law prohibits that requirement, although we may need information sufficient to locate and apply the choice. Authorized agents may make requests where permitted, subject to appropriate proof of authority.

We respond within the time required by applicable law and explain a denial where required. To appeal a denial where an appeal right applies, reply to our response or email contact@solid.tech with “Privacy Appeal” in the subject. You may also complain to your relevant privacy regulator or, where applicable, state attorney general.

We do not unlawfully discriminate against people for exercising privacy rights. Some information is exempt from deletion or must be retained for legal purposes, and fulfilling a request may prevent us from continuing a requested feature or Project. Where we act only on a customer's instructions, we may refer a request to that customer or assist it with the request as required.

You may unsubscribe from marketing email through the message's instructions. Necessary account, billing, security, and service communications may continue. Withdrawing consent does not affect processing lawfully performed before withdrawal. Recognized opt-out signals and advertising preferences are handled as described in Section 7.

12. Additional Information for U.S. Residents

The categories described in Section 2 may include identifiers and contact information; account and customer records; commercial and transaction information; internet, network, and device activity; location information; electronic, visual, or audio information; professional or education information; protected characteristics included in Project materials; inferences; and sensitive personal information such as credentials, private communications, financial information, or sensitive records supplied for a Project. Not every category is collected about every person, and sensitive information may be encountered because of a Project rather than requested at registration.

Sources, purposes, recipients, and retention are described in Sections 2 through 4 and 8. Categories actually collected or disclosed depend on the person's interactions and the Projects involved.

Our advertising arrangements may involve a sale, sharing, or targeted advertising as defined by applicable law. The categories involved are contact and account identifiers, device and cookie identifiers, IP addresses and approximate location, website and marketing interactions, subscription and transaction events, and related inferences, disclosed to advertising and marketing partners as described in Section 3.5. Private Project contents and credentials are not included in those advertising disclosures. These disclosures may occur for advertising services or other nonmonetary benefits rather than payment for data.

Where these rights apply, you may exercise them by following the instructions provided with the relevant privacy notice or consent mechanism, submitting a legally recognized opt-out preference signal, or contacting contact@solid.tech. We provide any additional opt-out links or methods required by applicable law. We do not require payment or an account to exercise these rights. We honor applicable rights to limit particular uses or disclosures of sensitive personal information and do not knowingly sell or share personal information of individuals under 16 for advertising.

Section 11 explains requests, verification where appropriate, authorized agents, and appeals. This Policy describes Codapt's practices generally; particular state-law duties and rights apply when the relevant law covers Codapt and the processing involved.

13. Additional Information for the EEA and United Kingdom

Codapt is generally a controller for its own account administration, authentication, billing, security, support, service operations, evaluation, analytics, and marketing. Where it processes personal information solely under a business customer's documented instructions, it acts as a processor for that processing. Applicable processing agreements and mandatory legal requirements govern that role.

Where EEA or UK data-protection law applies, the legal basis depends on the processing:

  • Contract: administering an individual customer's account, providing requested Services, and handling payment where processing is objectively necessary to perform that contract or take requested pre-contract steps.
  • Legitimate interests: operating and securing the business, supporting business-customer relationships, detecting fraud, evaluating and improving service performance without model training by Codapt, maintaining appropriate records, and establishing or defending claims, where those interests are not overridden by the affected person's rights. This may also cover permitted marketing that does not require consent.
  • Consent: optional advertising and tracking where consent is required, and other processing for which we request consent. You may withdraw it as described in Sections 7 and 11.
  • Legal obligation: compliance with applicable tax, accounting, regulatory, and other legal duties.

Processing special-category information requires an additional applicable condition, such as explicit consent where appropriate. A user's acceptance of general Terms does not by itself provide every legal basis needed for information about other people. Third-party processing remains subject to the applicable arrangements and restrictions described in Section 3.4.

You may have rights of access, rectification, erasure, restriction, objection, portability, withdrawal of consent, and protections regarding certain solely automated decisions with legal or similarly significant effects. You may object to processing for direct marketing, including associated profiling. You may complain to the competent supervisory authority, including the UK Information Commissioner's Office where applicable. Contact details and request methods appear in Section 11, and transfer information in Section 10.

14. Children

The Services are intended only for people who are at least 18 years old. We do not knowingly permit minors to create Solid accounts. If you believe a minor has provided personal information through the Services, contact us at contact@solid.tech.

Projects may nevertheless encounter information about minors. Users are responsible for ensuring that they are authorized to provide and process that information and that the requested Project complies with applicable law.

15. Third-Party Services and User-Controlled Applications

Solid may interact with third-party websites, applications, accounts, platforms, and services. Those parties may collect information directly, receive information through Project activity, or independently determine how information is used. Their practices are governed by their own policies and arrangements, not this Privacy Policy.

Applications and services created or operated for a Solid customer may be controlled by that customer. Codapt is not responsible for the customer’s privacy practices. Individuals using a customer-controlled application should review that customer’s privacy notice and direct requests to the customer where appropriate.

16. Changes to This Privacy Policy

We may update this Policy and will identify the revised effective date. We provide additional notice or request consent where required. Provider or technology changes within disclosed practices do not necessarily require a new policy, but we update more specific notices and choices when required. Materially different uses of previously collected information remain subject to applicable notice, consent, and other legal requirements and prior commitments.

A separate written customer agreement may impose additional restrictions on provider use, retention, security, or other processing. To the extent of an express conflict, that agreement controls for the covered processing. It does not remove mandatory privacy protections.

17. Contact Us

Codapt Inc.
267 Eliot Street
Chestnut Hill, Massachusetts 02467
United States
Email: contact@solid.tech
Website: solid.tech