Privacy Policy
Effective Date: September 16, 2026 ยท Version 2.0
This Privacy Policy describes how SoloOS collects, stores, processes, and protects your personal information and workspace financial records. SoloOS is designed from the ground up to provide independent professionals with an authoritative, private, and calm financial command center.
1. Overview & Nature of SoloOS
SoloOS is a software application and financial operating system for independent professionals, consultants, and solo business operators. SoloOS provides tools for cash tracking, invoicing, expense logging, client profitability analysis, debt and obligation tracking, tax-reserve planning, and financial decision support.
Important Distinctions Regarding SoloOS
- Not a Financial Institution: SoloOS is not a bank, credit union, depository institution, or money services business. SoloOS does not hold, custody, or transmit customer funds.
- Not a Certified Accounting or Tax Filing Service: SoloOS is not a certified public accounting firm or licensed tax preparer. Tax reserve percentages and Safe-to-Spend calculations are planning designations determined by user inputs and mathematical rules, not formal tax filings or legal compliance certifications.
- Software Ledger vs. Banking Settlement: The balances, accounts, and transactions tracked in SoloOS represent user-recorded ledger entries within your private workspace. They do not initiate automated bank transfers or touch clearing networks.
2. Information We Collect
We collect information you directly provide when using SoloOS:
- Account & Identity Information: Your email address, full name, optional profile avatar, and internal user identifier assigned during authentication.
- Workspace Configuration: Workspace name, optional logo image, business type, country, timezone, base ledger currency (such as MWK or USD), fiscal year start month, and tax reserve planning percentage.
- Customer Support Inquiries: Name, email address, subject line, message text, and diagnostic ticket identifiers submitted via our in-app support center or sent to hello@nuerexlabs.com.
3. How Financial Data Is Handled
When using SoloOS, you enter financial records required to operate your solo business. This information includes:
- Financial Accounts: Account names (e.g., "Bank Operating", "Airtel Money", "Cash Reserve"), account types, native currency codes, and opening balances.
- Transactions: Incomes, expenses, transfers, manual adjustments, transaction categories, descriptions, dates, and associated project or client linkages.
- Invoices: Client business names, client email addresses, billing addresses, line items, unit rates, tax designations, issued dates, due dates, and settlement records.
- Expenses & Deductibility: Vendor names, amounts, categories, tax deductibility flags, and notes.
- Obligations & Debts: Upcoming commitments, statutory or supplier liabilities, due dates, and repayment schedules.
- Tax Reserve Planning Data: User-set target tax rates and designated tax allocations.
- Clients & Projects: Client names, contact details, project budgets, hourly or fixed rates, and delivery milestones.
Your financial data belongs exclusively to you. SoloOS does not sell, rent, or monetize your financial records, transaction histories, or customer lists to advertisers or third-party data brokers.
4. Payment Processing & PayChangu
SoloOS paid subscriptions (Solo and Pro plans in MWK and USD) are processed through our authorized payment gateway partner, PayChangu.
Authoritative Payment Security Invariants
- Zero Card Storage: SoloOS servers never receive, store, or process raw credit card numbers, debit card numbers, CVVs, or mobile money PINs. Payment details are entered directly on PayChangu's secure checkout page.
- Server-Side Reconciliation: Before checkout, an authoritative pending transaction record is registered internally with the expected plan, expected currency, and expected amount. After payment, our backend verifies the transaction against PayChangu's verification API (verify-payment/{tx_ref}).
- Anti-Tampering Controls: A subscription is activated only if the transaction status is successful and the verified amount and currency match the expected plan price exactly. Tampered or mismatched requests are rejected.
5. Transactional Email & Resend
SoloOS uses Resend to deliver critical transactional emails. These include:
- Workspace invitations to team members
- Subscription activation and renewal receipts
- Support request submission confirmations
Only the recipient's email address and the specific message body are transmitted to Resend for message dispatch. SoloOS does not send unsolicited marketing emails, and we maintain an internal audit log of all email events for idempotency and delivery verification.
6. AI CFO & Language Model Processing
SoloOS includes an integrated AI CFO feature that provides strategic financial analysis and plain-English summaries of your business metrics.
How AI CFO Processing Operates
- Context Assembly: When you consult the AI CFO, a strictly bounded financial summary (current liquid cash, Safe-to-Spend runway, tax reserve estimates, active obligations, and monthly revenue totals) is transmitted to the configured AI model provider (such as Google Gemini via secure server functions) to formulate the response.
- Strictly Read-Only: The AI CFO operates with read-only permissions. The language model cannot execute financial transactions, modify account balances, generate invoices, or alter database records.
- Advisory Only: Output from the AI CFO is purely advisory and informational. It does not constitute formal legal, tax, accounting, or investment advice. Users remain solely responsible for all business and financial decisions.
- Untrusted Input Safeguards: User prompts and descriptions are treated as untrusted input with strict prompt boundaries to prevent prompt injection and data exfiltration.
7. Security, Row-Level Security (RLS) & Workspace Isolation
We protect your data using modern architectural safeguards without making unsupported compliance claims:
- PostgreSQL Row-Level Security (RLS): Every financial table (accounts, transactions, invoices, expenses, obligations, tax settings) is secured with database-level RLS policies. Database queries are restricted so that users can only view and modify records belonging to workspaces in which they are verified members.
- Role-Based Access Control (RBAC): Workspace permissions are enforced via roles (Owner, Admin, Finance, Manager, Viewer). Read-only members cannot execute modifications or access billing controls.
- Immutable Financial Audit Trails: Ledger adjustments, invoice status transitions, and subscription verification records maintain permanent audit timestamps and actor references.
- Encryption in Transit: All traffic between your browser and SoloOS is encrypted via standard TLS / HTTPS.
- Factual Compliance Notice: SoloOS does not claim SOC 2, ISO 27001, or PCI DSS certification for its application layer, nor do we use marketing phrases like "military-grade" or "bank-grade" security. We rely on the security engineering of our infrastructure providers (Supabase and Vercel) alongside our own verified database policies.
9. Data Retention & Deletion
Active Workspaces: Your records, invoices, transactions, and settings remain available for the lifetime of your workspace.
Plan Downgrades: If you cancel a paid Solo or Pro subscription, your paid features continue until the end of the current billing cycle. Your workspace then reverts to the Free plan. SoloOS never deletes your financial data upon plan cancellation or downgrade.
Account & Workspace Deletion: You may request complete permanent deletion of your account and associated workspaces at any time. Submit a request through our Support Center or email hello@nuerexlabs.com. Upon confirmed verification of ownership, your data will be purged within 30 days, except where retention is required by applicable statutory obligations.
10. User Rights & Privacy Requests
As a SoloOS user, you have the right to:
- Access and inspect all financial records and profile data entered.
- Update, edit, or correct transaction and profile information anytime.
- Export your data in standard formats (such as PDF invoices and financial reports).
- Request full deletion of your user account and workspaces.
To exercise any of these rights, contact us at hello@nuerexlabs.com with your registered account email.
11. International Data Processing
SoloOS is accessible globally and provides native multi-currency support (such as Malawi Kwacha and US Dollars). Data is hosted and processed on secure cloud infrastructure provided by Supabase (database hosting) and Vercel (application hosting). By using the service, you acknowledge that information may be transferred to and processed in data centers operated by these infrastructure providers.
12. Policy Updates & Contact Information
We may update this Privacy Policy to reflect improvements to SoloOS, regulatory developments, or changes to third-party integrations. Material updates will be reflected on this page with an updated effective date.
Direct Contact Channels
For privacy inquiries, data deletion requests, or trust questions:
- Email: hello@nuerexlabs.com
- In-App Support Desk: solo-finance-command.vercel.app/support