Privacy Policy
Last updated: August 12, 2026
This Privacy Policy describes how Solstice Health, Inc. ("Solstice," "we," "us," or "our") collects, uses, stores, and shares personal information in connection with the Solstice platform, websites, and related services (collectively, the "Services"). By using the Services, you agree to the practices described in this Policy.
1. Scope
This Policy applies to personal information processed through our public sites (including www.solsticehealth.co and www.info.solsticehealth.co), our customer-facing application, and related support channels. It does not replace customer agreements that govern Customer Content processed on behalf of enterprise customers.
2. Information We Collect
Depending on how you interact with us, we may collect:
- Account information: name, work email, job title, organization, and authentication identifiers (including SSO attributes when your organization enables SSO).
- Customer Content: documents, brand materials, claims, annotations, and other materials you or your organization upload or create in the Platform.
- Usage and device data: IP address, browser type, device identifiers, pages viewed, timestamps, and diagnostic logs needed to operate and secure the Services.
- Support communications: messages you send to privacy, security, or support contacts, including data deletion requests.
3. How We Use Information
We use personal information to:
- Provide, maintain, and improve the Services
- Authenticate users and enforce role-based access controls
- Respond to support, privacy, and security inquiries
- Monitor availability, performance, and security events
- Meet legal, regulatory, and contractual obligations
- Communicate product updates and service notices to account administrators
Solstice does not use Customer Content to train, fine-tune, or improve our AI models or third-party models. Customer Content is processed to fulfill your requests and provide the Services.
4. Legal Bases
Where applicable law requires a legal basis, we process personal information to perform a contract with you or your organization, to comply with legal obligations, based on legitimate interests (such as securing and improving the Services), and where required, based on consent.
5. Sharing and Subprocessors
We do not sell personal information. We share information with trusted subprocessors that help us operate the Services, subject to contractual data-protection obligations. Categories include cloud infrastructure, authentication, AI inference hosting, search/vector storage, and observability. Current examples include AWS, Auth0 (Okta), Azure OpenAI Service, Pinecone, and Datadog. A complete list is available on request, and customers are notified of material subprocessor changes at least 30 days in advance.
We may also disclose information if required by law, to protect the rights and safety of Solstice or others, or in connection with a merger, acquisition, or sale of assets.
6. Data Retention
We retain personal information for as long as needed to provide the Services and meet legal and contractual requirements. When a verified customer data deletion request is completed, Customer Content and associated account data are permanently deleted from production systems within 30 days, with residual backup copies purged within 90 days, as described on our Data Deletion Request page. Aggregated, anonymized metrics that cannot identify your organization may be retained for service improvement.
7. Security
We maintain administrative, technical, and physical safeguards designed to protect personal information, including encryption in transit (TLS 1.2+) and at rest (AES-256-GCM), tenant isolation, access controls, audit logging, and continuous monitoring. Solstice maintains SOC 2 Type II compliance. Additional detail is available on our Data & Security page.
8. International Transfers and Residency
Customer data is stored and processed in secure AWS regions within the United States unless otherwise agreed. Where personal information is transferred across borders, we use appropriate safeguards consistent with applicable law.
9. Your Rights
Depending on your location and relationship with Solstice, you may have rights to access, correct, delete, or export personal information, or to object to or restrict certain processing. For organization-owned Customer Content, please contact your organization administrator first. Individuals may also contact us at the email below. Enterprise customers can submit deletion requests via our Data Deletion Request form.
We will not discriminate against you for exercising privacy rights available under applicable law.
10. Children
The Services are intended for business use by authorized adults and are not directed to children under 16. We do not knowingly collect personal information from children.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be posted on this page with an updated "Last updated" date. Where required, we will provide additional notice to account administrators. Continued use of the Services after the effective date constitutes acceptance of the updated Policy.
12. Contact
For privacy questions or requests, contact: