SSSolomon
HomeThemesPricingDocsDownload
Download for Mac
§ legal

Privacy Policy

What Pantheon AI LLC, an Indiana limited liability company collects when you use Solomon, what it deliberately does not, who else touches it, and how to have it deleted.

Last updated: 11 September 2026Controller: Pantheon AI LLC, an Indiana limited liability companyApplies to: the Solomon apps, this site, and app.lomon.dev
contents
  1. The short version
  2. Who we are
  3. What we collect
  4. What we deliberately do not collect
  5. Why we process it, and on what basis
  6. How hosted content is protected, and the honest limit of it
  7. What you make visible to others
  8. Who else processes your data
  9. Cookies and local storage
  10. How long we keep things
  11. Your rights, and how to use them
  12. Children
  13. International transfers
  14. Security
  15. Changes to this policy
  16. Contact

The short version

Solomon is a notes application. The contents of your vault are the most private thing we could possibly touch, so the product is built to touch them as little as it can and to be specific about the times it must.

  • Your notes stay files on your disk. The application works signed out, offline, with no account.
  • We do not read your notes to run the business. Analytics, metering and billing never inspect note content. Usage is counted in bytes and calls, never in words.
  • We do not sell your data, we do not share it with advertisers, and we do not use it to train machine-learning models.
  • We can technically decrypt hosted content, because the sync service has to merge, index and serve it. We say so plainly rather than implying otherwise.
  • Product analytics are off by default outside the desktop app, and can be switched off inside it.

The rest of this page is the detail behind those five lines.

Who we are

Pantheon AI LLC, an Indiana limited liability company, is the controller of the personal data described here. You can reach us at support@lomon.dev. This policy covers the Solomon desktop and mobile applications, the Solomon command-line tools, this website, and the hosted service at app.lomon.dev.

What we collect

If you only download the app

Nothing reaches us but the download itself and, if you have not opted out, the content-free product analytics described below. The application checks for updates, which discloses your IP address and the version you are running to the update host, as any software update check does. Your vault is not uploaded and your search index is not uploaded.

If you create an account

  • Identity. Your email address, your name if you provide one, and the sign-in metadata our identity provider records (times, IP address, method).
  • Organisation and membership. Which vaults you own or belong to, and your role in each.
  • Devices and sessions. An identifier for each installed client, the client type (desktop, iPhone, command line, browser), and when a session attached and was last seen. This is what the connection list in your account is built from.

If you use hosted sync

  • Vault content. The documents you sync, their revision history, the files you attach, and the structure of the vault. This is stored so your devices and the people you invite can reach it.
  • Usage counters. Bytes stored, bytes written, number of synchronisation messages, hosted-agent calls, published-site requests, and a daily high-water mark of concurrent connections. These are integers per vault or per account and per day. They contain no note content, no titles and no paths.
  • Operational logs. Short-lived server logs, which may include IP addresses, request paths and error information, kept for diagnosis and abuse prevention.

If you pay us

Stripe collects and holds your payment details. We receive and store the identifiers and the transaction record — customer id, subscription id, plan, interval, status, period end, invoices, and the credit ledger. We never receive your full card number.

If you give us your email address on this website

We store your email address and nothing else. Your IP address is used momentarily to rate-limit the form and is not written to the record.

One form, two purposes, and we tell you which one you are using at the point you type it in. The waiting list is so that we can tell you when a seat on the hosted service opens. The announcements list is so that we can tell you when something we have said is coming — hosted agents, the iPhone app, Linux, Windows — has actually shipped. The second is marketing email, and we treat it as such: it is optional, you are asking us for it rather than us assuming, and you can have your address removed at any time by writing to support@lomon.dev. Both purposes are served from one stored address, so removing it removes you from both. We do not sell it, rent it, or hand it to anyone for their own marketing.

If you visit this website

This site uses Vercel's aggregate web analytics: page views, referrer, country, device class. It sets no tracking cookie and no cross-site identifier, so there is no consent banner to click through. Requests are logged by the host in the ordinary way.

What we deliberately do not collect

These are properties of how the software is built, not aspirations, and each is worth stating because the obvious implementation would have done otherwise.

  • Product analytics carry no vault content — by construction. In the desktop application, automatic event capture, page-view capture, session recording and surveys are all disabled, so the analytics library never reads the interface. Every event is funnelled through one function that drops any property not on an explicit allowlist of identifiers, enumerations, booleans and bounded counts. A note title, a file path, a search query, a tag name, a folder name or a document body cannot travel on an event even if a developer puts one there by mistake.
  • Search stays on your machine. Search and its embeddings are computed on your own device; the index is not uploaded.
  • Metering does not read content. Usage is measured in bytes persisted, calls made and requests served. We make no attempt to determine what a document says, and we do not inspect content to decide whether a human or an agent wrote it.
  • No advertising, no data sale, no model training. We run no advertising network, embed no advertising pixel, sell no personal data, and do not use your content to train machine-learning models.
  • No analytics outside the desktop app. The analytics module no-ops unless it is running inside the desktop shell with a build-time key present and you have not opted out.

Why we process it, and on what basis

PurposeDataLegal basis (UK/EU)
Provide the hosted serviceIdentity, vault content, devices and sessionsPerformance of a contract
Bill you and meet tax obligationsBilling identifiers, transactions, usage countersContract; legal obligation
Enforce plan limits and prevent abuseUsage counters, session metadata, logsLegitimate interests
Improve the productContent-free desktop analytics eventsLegitimate interests; consent where required
Send service emailEmail addressContract; legitimate interests
Tell you when a seat opens, or when something has shippedEmail addressConsent — withdraw it by asking us to remove the address
Security and incident responseLogs, IP addressesLegitimate interests; legal obligation

Where consent is the basis, you can withdraw it at any time — for analytics, by switching it off in the application's settings — without affecting processing already carried out.

How hosted content is protected, and the honest limit of it

  • In transit. Everything between your devices and the service is encrypted with TLS.
  • At rest. Document state and stored files are encrypted before they are written to the database, under per-vault data keys that are themselves wrapped by a key held in the service environment and never stored in the database. Someone holding only a database dump, a backup or a leaked connection string sees ciphertext.
  • The limit. The running service holds those keys, because merging concurrent edits, indexing, publishing and hosted agents all require plaintext at the moment of use. So we are technically able to read hosted content, and we would have to if compelled by valid legal process. We do not describe this as end-to-end encrypted or zero-knowledge, because it is neither. In practice we do not read it: nothing in the ordinary operation of the service, the analytics, the metering or the billing looks at what a note says.
  • Sealed vaults. An opt-in mode in which the keys are held by your own devices is in limited release and is off on every vault by default.

What you make visible to others

Some disclosure is your decision, not ours, and it is worth being blunt about which:

  • A published site is public. It has a permanent, guessable address, serves the same content to everyone, and is available to search engines and archives. Anything you publish should be treated as permanently public, because we cannot recall what a third party has already fetched.
  • A share link grants access to whoever holds it, at the level you chose, until you revoke it or it expires.
  • Collaborators and agents see what you scope them to. A vault you share is visible to its members; an agent you authorise sees the folders you allow it.

Who else processes your data

We use the following service providers. They act on our instructions, are bound by contract, and each has its own privacy policy.

ProviderWhat it handlesLocation
RailwayHosting for the application and the sync service, and the PostgreSQL database that holds hosted vault state, accounts, and billing records.United States
VercelHosting for this marketing site, and privacy-friendly aggregate web analytics for it (no cookies, no cross-site identifier).United States
WorkOSAuthentication and identity: sign-in, sessions, and organisation membership. Holds your email address and sign-in metadata.United States
StripePayment processing, subscriptions, credit-pack purchases, invoices and tax calculation. Holds your billing details; we never receive your full card number.United States
PostHogProduct analytics for the desktop application only, restricted to the content-free events described below. Not used on this website or in the web app.United States
ResendTransactional email: invitations, usage warnings, and account notices.United States
Apple (APNs)Push notifications to the iPhone app. Not currently enabled; if it is turned on, a device token is stored so a notification can be routed to your device.United States

If you connect a third-party agent or model to your vault, that provider is not our sub-processor: you chose it, and its own terms and privacy policy govern what it does with what you give it.

We may also disclose data where we are legally required to, to establish or defend a legal claim, or to protect the rights and safety of our users. If we are ever acquired, data may transfer with the business, subject to this policy.

Cookies and local storage

  • This website sets no advertising or tracking cookies. Its analytics are cookieless and aggregate, which is why you are not being asked to dismiss a banner.
  • The web app sets cookies that are strictly necessary: your authenticated session, and a short-lived, path-scoped cookie when you open a share link so that the secret never has to stay in the URL.
  • The desktop and mobile applications store settings, your analytics opt-out and cached credentials locally on your device.

How long we keep things

WhatKept for
Hosted vault content and historyWhile your account holds it, plus a short recovery window after deletion
Connection and session metadataNo more than 30 days
Daily usage counters and rollupsUp to 24 months, so a year-over-year figure is possible
Operational logsShort-lived; retained by our hosting provider on its own rolling schedule
Billing and credit recordsAs long as tax and accounting law requires, typically seven years
Waiting-list and announcement-list email addressesUntil you ask us to remove it, or the list is retired
BackupsRolling; deleted content persists until the backup containing it rotates

Your rights, and how to use them

Depending on where you live you may have the right to access the personal data we hold about you, correct it, delete it, restrict or object to its processing, receive it in a portable form, and withdraw consent. Residents of California and other US states with comparable laws have equivalent rights, including the right not to be discriminated against for exercising them. We do not sell or share personal information as those terms are defined in California law.

Some of these you can exercise yourself and immediately: your notes are already portable — they are plain files on your disk — you can turn analytics off in settings, revoke a share link, and cancel a subscription from your account.

For the rest, including deletion of your account and the hosted copies of your vaults, write to support@lomon.dev. We will respond within 30 days. We may need to verify that the request comes from you, and we may have to keep records we are legally required to keep. Deleting the hosted copy never touches the files on your own devices.

If you are in the UK or the EEA and think we have got this wrong, you may complain to your local supervisory authority. We would rather you told us first.

Children

The Service is not directed to children. You must be at least 13 to use it, and at least 16 in the European Economic Area or the United Kingdom. We do not knowingly collect personal information from children below those ages; if you believe a child has given us personal information, write to support@lomon.dev and we will delete it.

International transfers

Pantheon AI LLCoperates in the United States, and the providers listed above process data there. If you use the Service from outside the United States, your data will be transferred to and processed in the United States, which may not offer the same level of data protection as your own country. Where a transfer from the UK or the EEA requires a safeguard, we rely on the European Commission's Standard Contractual Clauses and the UK Addendum, as incorporated in our agreements with those providers.

Security

We use TLS everywhere, encrypt hosted content at rest, scope access tokens narrowly, keep secrets out of the database, and design features so that the ordinary path does not require a human to look at your data. No system is perfectly secure. If a breach affecting your personal data occurs, we will notify you and the relevant regulators as the law requires.

Changes to this policy

We will update this page when our practices change, and the date at the top shows when it last happened. If a change is material — a new category of data, a new purpose, a new sub-processor handling your content — we will tell account holders by email or in the application before it takes effect.

Contact

Pantheon AI LLC, an Indiana limited liability company. For any privacy question or request, write to support@lomon.dev.

The Terms of Service govern your use of the Service, and this policy is part of them.

Solomon · 2026downloadthemespricingdocstermsprivacyclosed-source app · open vault