Privacy policy
What Product 5 collects, who can see it, how long it is kept, and how to get it back or get rid of it.
Last updated August 25, 2026
Contents
Who we are
Product 5 is a customer relationship manager built by Solithix. This page says what happens to the information you and your team put into it. It is written to be read, not to be survived.
Product 5 is in early access. This policy will change as the product does, and the date at the top of this page is how you tell.
What we collect
Three kinds of information, and nothing else.
- Your account. Your name, your email address, and your password — stored hashed, never as text anyone can read. If you sign in with Google or GitHub instead, we get your name and email from them and never see a password at all.
- Your workspace. Whatever you put in it: contacts, companies, deals, tasks, notes, activities, custom fields, files you upload, forms you publish and the answers people send you. We do not decide what goes in here. You do.
- How the product is used. An audit record of every change made in your workspace — who did what, to which record, and when. Your IP address is held in memory for a minute at a time to rate-limit sign-in attempts; it is not written to our database.
There are no advertising trackers or third-party analytics scripts on this site or in the product.
How we use it
To run the product for you: show you your data, let your team work on it together, send the email the product has to send — verifying an address, resetting a password, an invitation, a notification you asked for — and keep the whole thing secure and working.
That is the entire list. We do not sell your data. We do not rent it, share it for advertising, or train AI models on it.
Who can see it
Every row in Product 5 belongs to exactly one workspace, and which workspace you are in is worked out on the server from your session — never from anything your browser can change. One workspace cannot read another's data, and that is enforced by the database query itself, not by hiding a button.
Inside your workspace, what you can see and do depends on your role. Owners and admins can do more than members; deleting things and changing workspace settings are restricted on purpose.
A few outside services handle parts of the job — sending email, storing the files you upload, answering the assistant. They are listed, with what each one handles, on the sub-processors page. We will also hand over data if the law actually requires it.
How long we keep it
Nothing is kept forever. Every kind of data has a stated lifetime, and a sweep runs once a day at 04:00 UTC to enforce it.
| Data | Kept for | Then |
|---|---|---|
| Deleted contacts, companies, deals, tasks, activities and forms | 30 days | Deleted for good |
| Deleted workspaces | 30 days | Erased, with everything in them |
| Expired sessions and sign-in tokens | Until they expire | Deleted |
| Expired invitations | 30 days | Deleted |
| Notifications | 90 days | Deleted |
| Assistant conversations | 180 days | Deleted |
| Sent email content | 180 days | Subject and body blanked; the record that it was sent survives |
| Form submissions | 365 days | Answers blanked; the record that it happened survives |
| Audit detail | 1 year | Blanked, so no names are left in it |
| Audit records | 7 years | Deleted |
An admin can see this same table in the product, with the date each one was last swept, under Settings → Data retention.
What you can do about it
- Take it with you. Export your contacts, companies or deals to CSV from the product at any time. No request, no waiting.
- Fix it. Every record in your workspace is editable by anyone on your team with permission to edit it.
- Delete it. Delete a record and it disappears from the product straight away, then is erased permanently after 30 days.
- Delete your account. Settings → Profile, confirmed by an emailed link. Work you created stays in the workspace attributed to a deleted user rather than vanishing from your colleagues' records.
- Delete the workspace. An owner can delete a whole workspace. It is restorable for 30 days, and erased with everything in it after that.
How it is protected
- Data travels over HTTPS, and the browser is told never to use anything else.
- Every change is checked against your role on the server, in the same transaction that writes it.
- Personal data is stripped out of our logs before they are written.
- Any AI provider key your workspace saves is encrypted before it is stored.
- Sign-in attempts are rate-limited, and the site runs under a strict content security policy.
No system is perfect, and we will not pretend otherwise. If you find a security problem in Product 5, tell us before you tell anyone else and we will fix it.
Changes to this policy
When we change this page we change the date at the top of it. If a change actually affects what happens to your data, we will email account owners rather than quietly editing the text.
Getting in touch
Questions about any of this, or about the data in your workspace, go to Solithix — the team that builds Product 5 — at solithix.com.