Privacy Policy
Last updated: August 11, 2026
1. What we collect
We collect the email you sign up with, the projects, files, database rows, and environment variables you create, and metadata about API calls you make (timestamps, endpoints, response codes). If you pay for Builder, our payment processor (Stripe) collects billing details directly — we only ever see the last four digits of your card.
2. How we use it
To run the platform: storing your code and data, routing traffic to your apps, billing you accurately, and helping you when something goes wrong. We also use aggregated, non-identifying usage patterns to improve the product. We do not sell your data.
3. Content end users send to your apps
When an end user of one of your apps submits data (form posts, uploads, auth sign-ups), we process that content on your behalf so your app can store or display it. You are the controller of that data; we are the processor.
4. Signing in to an app with Google
somewhere.tech provides sign-in for applications built and hosted on the platform. When an end user signs in to one of those applications using their Google Account, Google returns that user’s email address, basic profile information (their name), and a Google account identifier. We store that information against the application the user signed in to, and we provide it to the operator of that application so the application can recognise and serve that user. We do not sell it, use it for advertising, or share it with any other application. The operator of the application the user signed in to is the controller of that data; we are the processor. Google user data is used only to provide sign-in and is retained and deleted on the same terms as other end-user data described below.
5. AI requests
When you call /v1/ai/*, your prompt and response are forwarded to the underlying model provider (Anthropic, OpenAI) subject to their terms. We retain minimal logs (token counts, latency, error codes) for billing and reliability. We do not train models on your prompts.
6. Sharing, transfer, and disclosure
We share data in exactly two ways. First, with the infrastructure sub-processors that make the platform run: our hosting provider, our database provider, our payments processor, and our email sender. Each is contractually bound to handle your data only for the services they provide to us. Second, where an end user signs in to an application built on somewhere.tech, we provide that user’s sign-in details — including the email address, name, and account identifier returned by Google where Google sign-in is used — to the operator of the application that user signed in to, as described in section 4. We do not sell personal data, we do not use it for advertising or profiling, and we do not disclose it to anyone else except where required by law.
7. Retention
Project data, files, and database rows persist until you delete them or close your account. Request logs are kept for 30 days. After account closure we keep minimal records required by law (invoices, fraud prevention) and delete the rest within 90 days.
8. Your rights
You can export your projects, database rows, and files at any time via the API. You can delete them the same way. To close your account or request deletion of everything we hold on you, email support@somewhere.tech.
9. Cookies
We set a session cookie so the dashboard remembers you're signed in. We do not use third-party advertising or tracking cookies.
10. Security
Keys, passwords, and tokens are stored hashed or encrypted at rest. The developer key starting withsmt_ grants full access to your account — keep it server-side only, and rotate it immediately if you suspect it leaked.
11. Contact
Questions: support@somewhere.tech.