SotheSothe
ModelsRankingsPricingDocsSign Up

Privacy Policy

Last updated September 21, 2026 · Rothcroft LLC

This policy explains what sothe.net records about you, what it deliberately does not record, and who else is involved in running the service.

In short

  • We do not store your prompts or the models' replies. They pass through memory to serve the request and are gone.
  • We keep what billing needs: which model you called, how many tokens, what it cost, how long it took, and when.
  • Passwords and API keys are stored as one-way hashes; provider keys you bring are encrypted.
  • Card details go straight to Stripe. We never see them.
  • We run no advertising or third-party analytics cookies. The only cookie we set keeps you signed in.
  • You can delete your account yourself, and everything that identifies you goes with it.

This summary is for orientation only — the sections below are the agreement.

1. Scope

Rothcroft LLC, a limited liability company formed in New Mexico, United States is the controller of the personal data described here. This policy covers the Sothe website, dashboard and API. It does not cover the model providers' or our vendors' own handling of data where they act for themselves — see section 5.

2. What we collect

Account

Your email address, optionally a first and last name, a one-way hash of your password (scrypt — the password itself is never stored), and the preferences you set in the dashboard, such as your date format, notification choices and workspace budget.

Sessions

When you sign in we store a hash of your session token, its expiry and the browser's user-agent string, so you can see and end sessions. The token itself only exists in your cookie.

API keys

For each key: the name you gave it, a SHA-256 hash of the key, a masked prefix for display (sk-so-v1-797…29b), any limits or expiry, and when it was created and last used. The key itself is shown once at creation and never stored, which is why we cannot show it again or recover it for you.

Usage records

One row per API request: the model, the number of input, output and cached tokens, the price charged, our own cost, the latency, whether it succeeded, the key used, and the timestamp. These rows are what Activity, Logs, invoicing and the public rankings are built from.

Payments

Card data is collected and stored by Stripe, not by us. We keep your Stripe customer identifier and the ledger of credits added and spent. When the dashboard shows a saved card's brand and last four digits, it is reading them from Stripe at that moment.

Provider keys (BYOK)

If you connect your own AWS credentials, they are encrypted before storage (AES-256-GCM) with a key held in the server's environment, never in the database. We also keep a masked hint like AKIA…7Q2M · us-east-1 and when the key was last used. The plaintext is decrypted only in memory, only to send your request to AWS, and is never returned to your browser.

Technical data

Our servers and the CDN in front of them process IP addresses, timestamps and request metadata to route traffic, apply rate limits and investigate abuse. Application error logs may contain such details for a short time. We do not build profiles from them or sell them.

3. Prompts and completions

We do not log, store or train on the content of your requests. Messages, system prompts, tool definitions, images, audio and the model's replies exist in the server's memory for the length of the request and are not written to our database or to any file. That is why Logs can tell you a request cost $0.0021 and took 900 ms, but cannot show you what was in it — not even to us.

Two consequences worth knowing. First, we cannot reproduce a past request for you or debug its content after the fact. Second, your request is still sent to Amazon Bedrock in order to be answered; what happens there is covered by the Model Terms and by AWS's own terms.

Where a model supports prompt caching, a prefix of your request (the system prompt and tool list) may be held briefly in the provider's cache so repeated calls cost less. That cache belongs to the provider, is scoped to our account, and expires on its own.

4. How we use it

  • To run the service: authenticate you, route requests, and enforce the limits you set.
  • To bill accurately: reserve, charge and show what each request cost.
  • To keep the service safe: rate limiting, fraud and abuse investigation, and security incident response.
  • To support you: answering the emails you send us.
  • To publish aggregate statistics: the rankings sum token counts across every account and identify no one.
  • To meet legal and accounting obligations.

Where the GDPR applies, our legal bases are performance of a contract (running and billing the service), legitimate interests (security, abuse prevention, aggregate statistics) and legal obligation (accounting). We do not sell personal data and we do not use it for advertising.

5. Who else touches it

We share only what each of these needs to do its job:

WhoWhat forWhat they receive
Amazon Web ServicesRunning the models (Bedrock, US regions)The content of your request, at the moment it is answered
StripeCard payments and receiptsYour card details, email and payment amounts
CloudflareDNS, TLS and protection in front of the siteConnection metadata such as IP address
Our hosting providerRunning the application and its databaseWhatever is stored, at rest on their infrastructure

We may also disclose data where the law requires it, to enforce our Terms of Service, or as part of a merger or sale of the business — in which case this policy continues to apply until you are told otherwise.

6. Cookies and local storage

  • sothe_session — the only cookie we set. It holds a random session token, is HttpOnly, SameSite=Lax and sent over HTTPS only. It is strictly necessary: without it you cannot stay signed in.
  • sothe-theme in your browser's local storage remembers light or dark mode. It never reaches our servers.
  • We run no advertising cookies and no third-party analytics. The “analytics cookies” switch in Preferences is there for if we ever add optional analytics; today nothing depends on it.

7. How long we keep it

  • Account data — until you delete your account.
  • Sessions and balance reservations — until they expire; a background job deletes expired rows.
  • API keys — until you delete them.
  • Usage records — kept indefinitely for accounting and statistics. When you delete your account, these rows are detached from you: the account and key identifiers are set to null, leaving a model, token counts, a price and a timestamp that identify no one.
  • Payment records — Stripe keeps them under its own retention and legal obligations; our own ledger entries stay with the account.

8. How we protect it

Traffic is served over HTTPS end to end. Passwords are hashed with scrypt, session tokens and API keys are stored only as SHA-256 hashes, and BYOK credentials are encrypted with AES-256-GCM bound to the row that owns them. Database errors are logged without their query parameters, so identifiers do not leak into logs. The single most effective measure is structural: we do not keep the thing most worth stealing, because prompts and completions are never written down.

No system is perfectly secure. If we discover a breach affecting your personal data we will notify you and any regulator as required by law. If you find a vulnerability, please write to [email protected] before disclosing it publicly.

9. Your choices

  • See and correct your account details under Profile, and your usage under Activity and Logs.
  • Change your password, which signs every other session out.
  • Delete your account under Preferences. It is immediate and cannot be undone.
  • Choose what we email you under Notifications.

Depending on where you live — for example under the GDPR in the EEA and UK, or the CCPA in California — you may also have rights to access, correct, delete, restrict or port your data, to object to processing, and not to be discriminated against for exercising them. Write to [email protected] and we will respond within the time the law allows. You may also complain to your local data protection authority.

10. Children

Sothe is not for anyone under 18 and we do not knowingly collect their data. If you believe a child has created an account, tell us and we will delete it.

11. Where data is processed

Rothcroft LLC is based in the United States and the service is operated and hosted there, as are the models — every request runs in a US AWS region. If you use Sothe from outside the United States, you are sending your data to the United States, where data protection law differs from your own.

12. Changes

We will update this policy as the service changes. The date at the top always reflects the current version, and we will tell you in the dashboard or by email before a material change takes effect.

13. Contact

Privacy questions and requests: [email protected] (Rothcroft LLC, a limited liability company formed in New Mexico, United States).

Terms of ServiceModel Terms[email protected]
On this page
ScopeWhat we collectPrompts and completionsHow we use itWho else touches itCookies and local storageHow long we keep itHow we protect itYour choicesChildrenWhere data is processedChangesContact
SotheSothe

Access hundreds of AI models through a single API. Better prices, better uptime.

Product

ModelsRankingsPricing

Developers

DocsQuickstartAPI ReferenceErrors

Company

AboutBlogCareersContact

Legal

PrivacyTerms of ServiceModel TermsCookies
© 2026 Sothe, a Rothcroft LLC company.All systems operational