Skip to content

Privacy

Soma de-identifies supported sensitive information before it is stored in the database. Names, places, contact details, organization names, URLs, and monetary values are replaced with consistent placeholders.

You still see the original values in the app. Workspace privacy settings determine whether original values or their placeholders are used to generate a response from Soma.

When supported sensitive text is saved, Soma detects the value and replaces it with a placeholder. The same value maps consistently within a workspace, which preserves references across conversations without storing the original value directly in the text.

For example:

  • a person’s name becomes a person placeholder
  • an email address becomes an email placeholder
  • an organization name becomes an organization placeholder

The interface resolves placeholders for authorized users, so chats and pages remain readable.

De-identification applies to text surfaces such as chat messages, pages, narrative reports and protected profile fields. Data is also encrypted in transit and at rest.

Open Settings → Privacy to manage workspace-wide sharing controls.

The table groups controls into:

  • Organizations — organization names
  • People — full names and nicknames
  • Places — countries, cities, and addresses
  • Digital identifiers — email addresses, phone numbers, and URLs
  • Sensitive details — monetary values

Each row shows an example of what is used to generate responses with the current setting.

When Share is on, the original value can be used to generate a response. When it is off, the placeholder is used instead. Changing a switch does not change what is stored in the database; stored text remains de-identified.

These settings apply to the whole workspace and can be updated by admins. A change affects the next response for every member.

Review the settings against the kind of conversations your workspace expects to have. Sharing a name may make a response easier for Soma to follow; keeping it de-identified reduces how much identifying context is used.

What is stored, displayed, and used in responses

Section titled “What is stored, displayed, and used in responses”
  • In the database, protected text contains placeholders rather than the original values.
  • In the app, workspace members see the values they are authorized to view.
  • When generating a response, original values are used only for categories the workspace shares.

This distinction matters: a sharing switch controls what is used at response time. It is not an on/off switch for de-identification.

The Privacy page shows the workspace’s data region, such as the European Union or the United States.

The region is selected when the workspace is created and cannot currently be changed after creation.

  • Automated detection is not guaranteed to identify every sensitive value or phrasing.
  • Do not treat de-identification as a replacement for access control or careful handling of confidential information.
  • Turning a sharing setting off changes the context used for future responses. It does not need to rewrite stored text because that text is already de-identified.
  • Privacy settings are workspace-wide, not personal preferences.
  • Workspace settings contains the Privacy page.
  • Chat, Memory, and Pages use these controls when providing context for responses.
  • User settings contains profile fields covered by the People and Places categories.