Privacy Policy
Last updated: September 7, 2026
Introduction
This Privacy Policy explains how Claim Copilot, Inc., doing business as Pinetree Research, collects, uses, discloses, and protects personal information in connection with Solari. In this policy, "Solari," "we," "us," and "our" refer to Claim Copilot, Inc.
This policy applies to getsolari.com, console.getsolari.com, docs.getsolari.com, our cloud browsers, virtual machines, sandboxes, APIs, SDKs, command-line tools, templates, snapshots, volumes, support, and any related product or service that links to this policy, collectively the "Platform."
This policy does not apply to websites, applications, APIs, model providers, or other third-party services that you or your agents access through the Platform. Their privacy practices are governed by their own policies.
The Short Version
We collect information needed to provide, secure, support, bill for, and improve the Platform. We do not sell personal information or share it for cross-context behavioral advertising. We do not use the contents of your browser, virtual machine, or sandbox sessions to train machine-learning models unless you explicitly consent.
Your agents may process information about other people through the Platform. For that information, you determine what is collected and why, and you are responsible for providing required notices, obtaining required permissions, and complying with applicable law.
Information You Provide
Account and contact information
When you create or manage an account, we may collect your name, email address, organization name, role, profile information, authentication information, and account preferences.
Billing and commercial information
When you purchase a plan or credits, our payment provider processes your payment details. We may receive limited billing information such as billing name and address, payment method type, the last four digits of a card, transaction identifiers, tax information, invoices, plan details, and purchase history. We do not intentionally store full payment-card numbers.
Communications
We collect information you include when you contact us, submit forms, request support, participate in research or feedback, attend an event, or otherwise communicate with us.
Content and configuration
We collect files, code, prompts, scripts, templates, snapshots, configurations, environment variables, support attachments, and other material you choose to submit to the Platform.
Session and Automation Data
When you or your agents use a browser session, virtual machine, sandbox, profile, API, or related feature, the Platform processes information needed to perform the requested task. We refer to this information as "Session Data."
Depending on your instructions and settings, Session Data may include URLs, page content, form inputs, cookies, local storage, credentials, files, commands, source code, console output, network activity, screenshots, recordings, desktop activity, logs, and outputs. Session Data may contain personal information about you, your users, or third parties.
We process Session Data to run your workloads, provide requested features, store and return results, preserve profiles or snapshots when requested, troubleshoot support issues, protect the Platform, investigate suspected abuse or security incidents, and comply with law.
Authorized personnel may access Session Data only when reasonably necessary for those purposes. We do not use Session Data to train machine-learning models unless you explicitly opt in.
Information Collected Automatically
Usage and device information
We may collect IP address, approximate location derived from IP address, browser type, operating system, device information, referring pages, pages viewed, features used, timestamps, and interactions with our sites and console.
API, SDK, and operational telemetry
We collect request metadata, API routes, response codes, error reports, latency, SDK and client versions, session identifiers, resource status, compute time, storage usage, concurrency, proxy usage, CAPTCHA usage, and similar operational and metering information.
Security information
We collect login events, authentication activity, credential-rotation events, network and device signals, abuse indicators, and other information used to detect fraud, attacks, unauthorized access, and violations of our Terms of Service.
Cookies and local storage
We use cookies, local storage, pixels, and similar technologies as described in the Cookies and Similar Technologies section below.
Information From Other Sources
Identity and authentication providers
If you use a third-party sign-in option, we receive information that provider makes available to us, such as your name, email address, profile image, provider identifier, and authentication confirmation.
Organizations, referrals, and partners
We may receive contact, account, role, or referral information from your organization, a person who invited you, an event organizer, a referral partner, or another business relationship.
Public and business sources
For business development, security, and account management, we may collect professional information from public websites, business directories, sanctions and restricted-party lists, and service providers that supply business contact or fraud-prevention information.
How We Use Personal Information
We use personal information to:
- Provide, operate, maintain, and improve the Platform and its features.
- Create and administer accounts, organizations, permissions, credentials, resources, and settings.
- Run browser sessions, virtual machines, sandboxes, profiles, snapshots, volumes, APIs, and requested workloads.
- Measure usage, apply plan limits, maintain credit balances, process payments, issue invoices, and prevent billing errors.
- Authenticate users and detect, investigate, prevent, and respond to fraud, abuse, security threats, prohibited activity, and technical failures.
- Respond to questions, provide support, debug issues, and communicate about accounts, billing, security, maintenance, and service changes.
- Analyze performance and product usage, develop features, and conduct research using aggregated or de-identified information where reasonably possible.
- Send product news, event invitations, surveys, and marketing where permitted by law and subject to your choices.
- Comply with legal obligations, respond to lawful requests, establish or defend legal claims, enforce agreements, and protect rights and safety.
- Carry out any other purpose disclosed when information is collected or to which you consent.
Legal Bases for Processing
Where the laws of the European Economic Area, United Kingdom, Switzerland, or another jurisdiction require a legal basis, we rely on one or more of the following:
- Performance of a contract, including providing the Platform, administering accounts, processing requested workloads, and billing.
- Our legitimate interests, including securing and improving the Platform, preventing abuse, supporting customers, communicating with business users, and operating our business, where those interests are not overridden by your rights.
- Consent, including for certain marketing, non-essential cookies, and any model-training use of Session Data.
- Compliance with legal obligations and protection of vital interests where applicable.
You may withdraw consent at any time. Withdrawal does not affect processing that occurred before withdrawal or processing based on another lawful basis.
Our Role and Your Role
We generally act as a controller or business for account, billing, website, security, support, and business-operations information that we determine how and why to process.
When we process Session Data or other personal information solely on your documented instructions to provide the Platform, we generally act as your processor or service provider. Legal roles depend on the facts and applicable law.
You are responsible for determining whether and how your agents may collect or use personal information, establishing a lawful basis, providing required notices, honoring applicable rights, and limiting your instructions to authorized purposes.
Contact us to request a data processing agreement. Protected health information may be processed only under an eligible Enterprise arrangement and a signed business associate agreement. Requests may be sent to hello@getsolari.com.
How We Disclose Information
Service providers and subprocessors
We disclose information to vendors that provide cloud hosting and compute, storage, payment processing, identity and authentication, email delivery, customer support, analytics, error monitoring, security, fraud prevention, communications, and professional services. They may use information only to provide services to us or as permitted by law and contract.
Your organization
Organization owners and administrators may access and manage account information, users, permissions, credentials, billing, usage, resources, and Session Data associated with their organization.
Services you direct us to use
When you connect an integration, direct an agent to visit a website, call an API, use a proxy, submit information, or otherwise interact with a third party, information is transmitted to that third party as necessary to carry out your instructions. The third party's terms and privacy policy apply to its processing.
Public or shared content
If you choose to publish or share content through the Platform, that content and associated account information may be visible to the people or public audience you select. Do not publish credentials, private information, or personal information you are not authorized to disclose.
Legal, safety, and security disclosures
We may disclose information when we reasonably believe disclosure is required by law or valid legal process, necessary to enforce agreements, or appropriate to detect or address fraud, abuse, security issues, threats, or harm to the rights, property, or safety of Solari, our users, third parties, or the public. Where legally permitted, we may notify the affected customer before disclosing Customer Data in response to legal process.
Business transactions
Information may be disclosed or transferred in connection with due diligence, financing, a merger, acquisition, reorganization, bankruptcy, sale of assets, or similar transaction. Any successor will be subject to this policy or provide notice of materially different practices.
With consent
We may disclose information for another purpose when you direct us to or give consent.
No Sale or Behavioral Advertising
We do not sell personal information for money. We do not share personal information for cross-context behavioral advertising, and we do not use Session Data to advertise to you or to the people whose information your agents process.
If our practices change, we will update this policy and provide any notices, consent mechanisms, opt-out links, and browser-signal controls required by law before beginning the new practice.
Data Retention
We retain personal information only for as long as reasonably necessary for the purposes described in this policy, including providing the Platform, honoring your settings and plan, maintaining security, resolving disputes, enforcing agreements, and meeting legal, tax, accounting, and compliance obligations.
- Account and organization information is generally retained while the account remains active and for a limited period afterward when needed for legitimate business or legal purposes.
- Session recordings, logs, screenshots, files, snapshots, profiles, and other Session Data are retained according to the applicable product, plan, configuration, console setting, documentation, or order form.
- Credentials and profiles are retained until you delete them, the applicable configuration or retention period expires, or the account is closed, subject to limited backup and security retention.
- Billing, transaction, tax, and accounting records are retained for the periods required by applicable law and our legitimate recordkeeping needs.
- Security, abuse-prevention, access, and support records are retained for as long as reasonably necessary to protect the Platform, investigate incidents, resolve issues, and establish or defend claims.
- Backups are deleted or overwritten through our normal backup lifecycle. Aggregated or de-identified information that cannot reasonably identify a person may be retained for longer periods.
The Platform is not your system of record. Export or independently back up information you need before its applicable retention period expires or before closing your account.
Security
We use administrative, technical, and organizational safeguards designed to protect personal information and the Platform. Safeguards may include access controls, authentication, encryption, monitoring, logging, network protections, secrets-management practices, and isolated execution technology appropriate to the relevant system and risk.
No system, network, storage method, or isolated environment is completely secure. You are responsible for safeguarding your credentials, applying least privilege, configuring retention and access appropriately, reviewing your agents' behavior, and maintaining independent backups.
If we discover a security incident involving personal information, we will investigate and provide notifications required by applicable law and any governing written agreement.
Report suspected vulnerabilities, compromised credentials, or security incidents to hello@getsolari.com.
International Data Transfers
We are based in the United States, and we and our service providers may process information in the United States and other countries. Those countries may have data-protection laws that differ from the laws where you live.
Where required, we use recognized legal mechanisms for cross-border transfers, such as adequacy decisions, data-protection agreements, and approved standard contractual clauses. Region selection for workloads or storage, where available, does not necessarily prevent all account, billing, support, security, or operational information from being processed in other locations.
You may request information about applicable transfer safeguards by contacting hello@getsolari.com.
Your Privacy Rights
Depending on where you live and subject to legal exceptions, you may have the right to:
- Request access to personal information and information about how it is collected, used, or disclosed.
- Request correction of inaccurate personal information.
- Request deletion of personal information.
- Request a portable copy of certain personal information.
- Object to or restrict certain processing.
- Withdraw consent where processing is based on consent.
- Opt out of marketing communications.
- Appeal a decision concerning a privacy request where applicable.
- Lodge a complaint with an applicable data-protection authority.
- Exercise privacy rights without unlawful discrimination or retaliation.
You may exercise available rights through your account settings or by emailing hello@getsolari.com.
We may request information reasonably necessary to verify your identity, authority, account, and jurisdiction. We will respond within the time required by applicable law. We may deny or limit a request where an exception applies and will explain the decision when required.
If your request concerns information processed by a Solari customer through its agents or workloads, that customer generally controls the information. We may direct you to the customer or assist the customer in responding, but we may be unable to identify the responsible customer from the information you provide.
Marketing choices
You may unsubscribe from marketing emails using the link in the message or by contacting us. You will continue to receive transactional, security, billing, and service communications that are necessary for your account or relationship with us.
California Privacy Notice
This section supplements the rest of this policy for California residents and describes categories of personal information we may have collected during the preceding 12 months. Whether a category is collected from a particular person depends on how that person interacts with the Platform.
Categories of personal information
- Identifiers, such as name, email address, IP address, account identifiers, device identifiers, and authentication identifiers.
- Customer-record and commercial information, such as organization, role, billing address, plan, purchases, credits, transaction history, and support history.
- Internet or electronic-network activity, such as website activity, API requests, SDK telemetry, browser and device data, logs, session activity, and interactions with the Platform.
- Professional or employment-related information, such as company, title, team, business contact details, and organizational relationships.
- Audio, electronic, visual, or similar information, such as screenshots, browser recordings, desktop recordings, support-call information, and content you submit.
- Approximate geolocation derived from IP address and region or proxy selections you make.
- Sensitive personal information, such as account credentials, the contents of communications or sessions, precise location, financial information, health information, or other sensitive data only when you or your organization submit it or direct the Platform to process it.
- Inferences derived from account, usage, device, or security information to detect fraud, abuse, compromise, or product needs.
- Other personal information included in Session Data or content that you, your organization, users, or agents choose to process.
Sources and purposes
We collect these categories from you, your organization and users, your devices and use of the Platform, identity and payment providers, service providers, referrals and partners, public sources, and third-party services you connect. We use and disclose them for the business and commercial purposes described in How We Use Personal Information and How We Disclose Information.
Sale, sharing, and sensitive personal information
We do not sell personal information and do not share it for cross-context behavioral advertising. We do not use or disclose sensitive personal information for purposes that require a right to limit under California law, except to the extent your organization directs us to process Session Data for its own purposes.
California rights
Subject to applicable exceptions, California residents may request to know, access, correct, or delete personal information; request information about categories, sources, purposes, and disclosures; opt out of sale or sharing; limit certain uses of sensitive personal information; and receive equal service and pricing when exercising their rights.
You may use an authorized agent to submit a request. We may require proof of authorization and may ask you to verify your identity directly. Because we do not sell or share personal information for behavioral advertising, an opt-out preference signal such as Global Privacy Control does not change our current practices. If those practices change, we will honor legally required signals.
California privacy requests may be submitted through available account tools or by contacting hello@getsolari.com.
EEA, United Kingdom, and Switzerland
Individuals in the European Economic Area, United Kingdom, and Switzerland may have the rights described above, including rights of access, correction, erasure, restriction, objection, portability, and withdrawal of consent. You may also lodge a complaint with the data-protection authority where you live, work, or believe a violation occurred.
We do not use personal information we control to make decisions based solely on automated processing that produce legal or similarly significant effects. Customer agents and workloads may perform automated processing under the customer's control, and requests concerning that processing should generally be directed to the customer.
Questions about legal bases, transfers, or applicable representatives may be sent to hello@getsolari.com.
Cookies and Similar Technologies
We use cookies, local storage, pixels, and similar technologies on our sites and console. The technologies used may include:
- Strictly necessary technologies used to authenticate users, maintain sessions, secure the Platform, prevent fraud, route traffic, and remember core preferences.
- Functional technologies used to remember optional settings and improve features.
- Analytics and performance technologies used to understand use, diagnose errors, measure performance, and improve the Platform.
- Marketing technologies, if used, that measure campaigns or communications. Where required, these are used only after consent.
You can control cookies through your browser and, where available, our consent controls. Blocking strictly necessary technologies may prevent the Platform from functioning. We do not currently respond to Do Not Track signals because there is no uniform standard. We process legally recognized opt-out preference signals as required by applicable law.
Children
The Platform is intended for adults and is not directed to anyone under 18. We do not knowingly collect personal information from children. If you believe a child has provided personal information to us, contact us so we can investigate and take appropriate action.
Third-Party Sites and Services
Our sites may link to third-party services, and your agents may interact with websites, applications, APIs, proxy networks, identity providers, and other services we do not control. This policy does not govern their practices. Review their privacy policies before providing information or directing agents to use them.
Changes to This Policy
We may update this policy as our products, practices, and legal obligations change. If a change is material, we will provide notice by email, through the Platform, or by another reasonable method before it takes effect when required by law. The Last Updated date identifies the current version.
Contact Us
Privacy questions, rights requests, security reports, and other inquiries may be sent to hello@getsolari.com.
Claim Copilot, Inc., doing business as Pinetree Research, operator of Solari.

