Privacy Policy

Effective Date: June 23, 2026 · Last Updated: July 14, 2026

1. Introduction

Somodus ("we," "us," or "our") is an AI-powered platform that enables users to create, configure, and deploy AI agents, operated by Iridium Studio, Inc. (the "Operator"). This Privacy Policy explains how we collect, use, and protect your personal data when you use our service at somodus.com (the "Service"). "Personal data" means any information relating to an identified or identifiable individual.

By using the Service, you agree to the collection and use of information as described in this policy.

2. Information We Collect

Google OAuth data — We collect the following information through Google OAuth authentication:

  • Name — Your display name from your Google account
  • Email address — Your primary Google email address
  • Profile picture — Your Google profile photo URL
  • Google account identifier — A unique identifier for your Google account
  • Email verification status — Whether your Google email is verified

Usage data — In addition to Google OAuth data, we also collect:

  • Service usage data — Actions you take within the Service (agent configurations, deployment settings)
  • Technical data — IP address, browser type, and device information collected automatically through server logs
  • API credentials — Third-party API keys you provide for your Generated Agents (stored encrypted)
  • Connected service data — When you enable Google Workspace or other third-party integrations, your Generated Agents access and process content from those services (such as emails, calendar events, files, or documents) on your behalf and according to your configuration. The OAuth tokens that authorize this access are stored encrypted

3. Legal Basis for Processing

We process your personal data on the following legal bases under GDPR Article 6:

  • Contract performance — Processing necessary to provide the Service you have requested (account creation, agent deployment, subscription management)
  • Legitimate interests — Processing necessary for our legitimate interests, such as improving the Service, ensuring security, and preventing fraud, where these interests are not overridden by your rights
  • Legal obligation — Processing necessary to comply with legal requirements (tax records, regulatory compliance)
  • Consent — Where required by law, we obtain your explicit consent for specific processing activities. You may withdraw consent at any time by contacting us

4. How We Use Your Information

We use the information we collect solely for the following purposes:

  • Authentication — To verify your identity and provide secure access to the Service
  • Account management — To create and maintain your user account
  • Service delivery — To provide the AI agent creation and deployment functionality
  • Subscription management — To manage your subscription status and billing through Polar

5. Google User Data Disclosure

Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically:

  • For sign-in, Somodus's own OAuth client requests only the openid, email, and profile scopes
  • If you enable Google Workspace integrations (Gmail, Calendar, Drive, Sheets, Docs, or Photos), the additional scopes those features require are requested and authorized through your own Google Cloud OAuth application that you register and control. Your Generated Agents access this data only on your behalf and according to your configuration
  • We do not share Google user data with third parties for advertising purposes
  • We do not sell Google user data to any third party
  • We do not use Google user data for purposes unrelated to the Service
  • We do not allow humans to read your Google user data unless required for security purposes, legal compliance, or with your explicit consent

6. Data Storage and Security

Your data is stored and protected as follows:

  • Database — User account data is stored in MongoDB with access controls
  • Authentication tokens — JWT tokens are stored in httpOnly cookies to prevent XSS attacks
  • Billing data — Payment information is processed and stored by Polar and Stripe; we do not store your credit card details
  • Transport security — All data is transmitted over HTTPS

While we implement reasonable security measures, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security of your data.

International data transfers — Your personal data may be transferred to and processed in countries outside your country of residence, including the United States, where our hosting providers (Render, Cloudflare) and third-party service providers operate. Where such transfers occur, we rely on standard contractual clauses or other lawful transfer mechanisms to ensure your data is protected in accordance with applicable data protection laws.

7. Third-Party Services

The Service integrates with the following third-party services:

  • Google — OAuth authentication (name, email, profile picture)
  • Polar (polar.sh) — Subscription management and billing as Merchant of Record
  • Stripe — Payment processing (through Polar)
  • Cloudflare — CDN, DNS, and edge computing services
  • Render — Application hosting
  • AI model providers (Anthropic, OpenAI) — To provide AI agent creation and deployment functionality (your code queries are processed but not used for model training by these providers under our API agreements)

Any data collected, processed, or stored by AI agents you create through the Service ("Generated Agents") is determined solely by your configuration. We are not responsible for any data handling practices of your Generated Agents, and you are solely responsible for ensuring your Generated Agents comply with applicable data protection laws and regulations. When your Generated Agents transmit data to third-party APIs using your API keys, we are not responsible for how those third-party providers process, store, or use that data.

Each third-party service has its own privacy policy governing the use of your data.

8. Data Retention and Deletion

We retain your personal data for as long as your account is active or as needed to provide the Service. Server logs and technical data are retained only for as long as necessary for security, diagnostics, and abuse prevention.

You may request deletion of your account and associated data at any time by contacting us at support@somodus.com. Upon receiving a deletion request, we will delete your data within 30 days, except where retention is required by law.

9. Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will:

  • Notify the relevant supervisory authority within 72 hours of becoming aware of the breach, where required by applicable law
  • Notify affected users without undue delay when the breach is likely to result in a high risk to their rights and freedoms
  • Document the breach, its effects, and the remedial actions taken

Notifications will be sent to the email address associated with your account.

10. Your Rights

You have the following rights regarding your personal data:

  • Access — Request a copy of the personal data we hold about you
  • Deletion — Request deletion of your personal data
  • Revoke access — Revoke our access to your Google data at any time through your Google Account permissions
  • GDPR rights — If you are in the EEA, you have rights under GDPR including data portability, the right to rectification, the right to restrict processing, and the right to object to processing
  • CCPA rights — If you are a California resident, you have rights under the CCPA including the right to know and the right to opt-out of sale of personal data (we do not sell personal data)

To exercise any of these rights, contact us at support@somodus.com.

11. Cookies

We use only essential cookies required for authentication. Specifically, we use httpOnly session cookies to maintain your login state. We do not use advertising cookies, tracking cookies, or any third-party analytics cookies.

12. Children's Privacy

The Service is not intended for use by children under the age of 13, or the minimum age required in your country to consent to use online services. We do not knowingly collect personal data from children under these age thresholds. If we become aware that we have collected data from a child below the applicable age, we will take steps to delete that information promptly.

13. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you via email at least 30 days before the changes take effect and update the "Effective Date" at the top of this page. For material changes to how we process your personal data, we may require your explicit consent before the changes apply. Your continued use of the Service after the 30-day notice period constitutes your acceptance of non-privacy-related changes.

14. Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us at: support@somodus.com

Iridium Studio, Inc., 2810 N Church St STE 89969, Wilmington, DE 19802, United States