The Ascension update is liveRead the post
Legal

Privacy policy

What Product 5 collects, who can see it, how long it is kept, and how to get it back or get rid of it.

Last updated August 25, 2026

Who we are

Product 5 is a customer relationship manager built by Solithix. This page says what happens to the information you and your team put into it. It is written to be read, not to be survived.

Product 5 is in early access. This policy will change as the product does, and the date at the top of this page is how you tell.

What we collect

Three kinds of information, and nothing else.

  • Your account. Your name, your email address, and your password — stored hashed, never as text anyone can read. If you sign in with Google or GitHub instead, we get your name and email from them and never see a password at all.
  • Your workspace. Whatever you put in it: contacts, companies, deals, tasks, notes, activities, custom fields, files you upload, forms you publish and the answers people send you. We do not decide what goes in here. You do.
  • How the product is used. An audit record of every change made in your workspace — who did what, to which record, and when. Your IP address is held in memory for a minute at a time to rate-limit sign-in attempts; it is not written to our database.

There are no advertising trackers or third-party analytics scripts on this site or in the product.

How we use it

To run the product for you: show you your data, let your team work on it together, send the email the product has to send — verifying an address, resetting a password, an invitation, a notification you asked for — and keep the whole thing secure and working.

That is the entire list. We do not sell your data. We do not rent it, share it for advertising, or train AI models on it.

Who can see it

Every row in Product 5 belongs to exactly one workspace, and which workspace you are in is worked out on the server from your session — never from anything your browser can change. One workspace cannot read another's data, and that is enforced by the database query itself, not by hiding a button.

Inside your workspace, what you can see and do depends on your role. Owners and admins can do more than members; deleting things and changing workspace settings are restricted on purpose.

A few outside services handle parts of the job — sending email, storing the files you upload, answering the assistant. They are listed, with what each one handles, on the sub-processors page. We will also hand over data if the law actually requires it.

How long we keep it

Nothing is kept forever. Every kind of data has a stated lifetime, and a sweep runs once a day at 04:00 UTC to enforce it.

DataKept forThen
Deleted contacts, companies, deals, tasks, activities and forms30 daysDeleted for good
Deleted workspaces30 daysErased, with everything in them
Expired sessions and sign-in tokensUntil they expireDeleted
Expired invitations30 daysDeleted
Notifications90 daysDeleted
Assistant conversations180 daysDeleted
Sent email content180 daysSubject and body blanked; the record that it was sent survives
Form submissions365 daysAnswers blanked; the record that it happened survives
Audit detail1 yearBlanked, so no names are left in it
Audit records7 yearsDeleted

An admin can see this same table in the product, with the date each one was last swept, under Settings → Data retention.

What you can do about it

  • Take it with you. Export your contacts, companies or deals to CSV from the product at any time. No request, no waiting.
  • Fix it. Every record in your workspace is editable by anyone on your team with permission to edit it.
  • Delete it. Delete a record and it disappears from the product straight away, then is erased permanently after 30 days.
  • Delete your account. Settings → Profile, confirmed by an emailed link. Work you created stays in the workspace attributed to a deleted user rather than vanishing from your colleagues' records.
  • Delete the workspace. An owner can delete a whole workspace. It is restorable for 30 days, and erased with everything in it after that.

How it is protected

  • Data travels over HTTPS, and the browser is told never to use anything else.
  • Every change is checked against your role on the server, in the same transaction that writes it.
  • Personal data is stripped out of our logs before they are written.
  • Any AI provider key your workspace saves is encrypted before it is stored.
  • Sign-in attempts are rate-limited, and the site runs under a strict content security policy.

No system is perfect, and we will not pretend otherwise. If you find a security problem in Product 5, tell us before you tell anyone else and we will fix it.

Changes to this policy

When we change this page we change the date at the top of it. If a change actually affects what happens to your data, we will email account owners rather than quietly editing the text.

Getting in touch

Questions about any of this, or about the data in your workspace, go to Solithix — the team that builds Product 5 — at solithix.com.