SottoV

Questions and answers

Everything SottoV retains about your household — every request, every transcribed word, every photograph — is held in Switzerland by one Swiss company, under Swiss law, in a data centre in Rümlang. And no single party ever holds the whole picture: the service that hears a voice is given no structure, the service that reads text never hears a voice, the relays that carry notifications cannot open them, and the one channel that is not sealed — a text message — never names the request. Your household exists, to every other household on SottoV, not at all.

Eight questions below, each answered in a line. Open one for the working. Everything here is either measured against the running service or read out of the source, and where a protection is a rule we keep rather than a wall we have built, it says which.

Can the people who work for me carry my household onward?They see only the work given to them, and they keep nothing when they go.

A member of your entourage sees the requests addressed to them and nothing else. That is a wall rather than a courtesy: every read is filtered by the person the request was given to, so there is no screen, no link and no scroll that reaches the rest of the house.

When somebody leaves, one action ends it. Every link they hold dies at once — not at the next password change, not when a session expires — and every device they bound to it goes with it. Compare that with a message thread, which they keep for as long as they keep the phone.

What no product can promise, and we will not: a person who has read something can repeat it. We limit what reaches them and we end it instantly. We do not claim to reach into anyone’s memory.

Is my voice recording kept?No. Not by us, not anywhere, not in any form.

A spoken note is held in your phone’s memory, sent once to be turned into text, and discarded. No table and no file store holds audio. There is no archive of your voice to be leaked, subpoenaed or sold.

The transcript is what survives, and it becomes the request. What travels with it, and to whom, is set out in full in the complete answer — including a list of names that goes with every recording, which is the part nobody thinks to ask about.

Can another household see mine?No — and we attack that boundary ourselves before a release.

Every read is scoped to the household it belongs to. That scoping is not merely tested: a script removes each boundary check in turn and requires the test suite to turn red for every one of them. Anything that survives is a test passing for the wrong reason.

It found two of those the first time it ran — one route where the request body failed validation before the boundary was ever consulted, and one whose condition appears three times in a file of which only two were exercised. It is run by hand before a release rather than on every build, and we would rather say so than imply an automation we have not built.

Where is my data kept?Switzerland. One Swiss company, in a data centre in Rümlang.

The application, the database and every photograph run at Nine Internet Solutions AG in Zurich, in their data centre in Rümlang. One supplier, one contract, Swiss law and a Swiss forum — not a European region rented from an American company.

That distinction is the question behind the question, and a supplier’s marketing page will not draw it for you: storage in Europe is not a European supply chain. Where the disk stands and who can be compelled to reach it are two separate questions, and only the second one is answered by the name on the contract.

Which obliges us to give our own second answer. Nine’s list of the companies they rely on names one that reaches us: their own company in Canada, for emergency support and maintenance, covering all their products and so ours. The annex records Canada as the place of processing for that row; how far it reaches in practice is Nine’s to state rather than ours to guess, and we would rather write the narrower true thing than the wider comfortable one. Switzerland recognises Canadian law as adequate for commercial processing, so no further safeguard is required. We name it because a paragraph like the one above is only worth writing if it is turned on ourselves.

What no hosting decision reaches: speech and language processing, and the notification relays, which belong to the phone’s maker. Those are in the last answer, and in the complete answer.

Can the people who run SottoV read my words?Our tooling cannot. One exception exists, and it writes a line into your own log.

The operator console shows names, counts, states and timestamps — never the text of a request. The command line can create a household, suspend it, count rows and erase it, and has no path to a request, a message or a photograph.

The exception is the export that answers “give us everything you hold about us”. Somebody has to be able to read it in order to hand it to you. It costs a fresh passkey every time and writes a line into your household’s own security log, where your chief of staff reads it. We can look, and we cannot look without you being able to see that we did.

This is a rule we keep, not a wall we have built. See the next answer for what that distinction costs.

Is my household’s content encrypted under its own key?Not today. The key layer is written and tested; nothing is sealed with it yet, and the reason is worth two sentences.

Encryption under a key dedicated to your household — envelope AES-256-GCM, one key per household, every value bound to its own row so none can be lifted into another, and the key destroyed on erasure so that what is left in any copy is bytes nobody can open — is built and tested. To be exact about a phrase that is often stretched: the household’s key is wrapped under a master key held by us, so this is a key dedicated to your household rather than one you hold against us. Customer-held keys are a different thing and we do not claim them.

Nothing is sealed with it today. It is attached to no column, so what protects your words at rest is Nine’s disk encryption — our supplier, not this product — and they sit readable in our database. Two reasons, and the first is the uncomfortable one: as long as our master key lives in the hosting account, sealing the database would not keep the words from the company that holds it. The second is that losing that key means the content is gone finally — no restore, no support, no recovery — which is a category of accident this product does not otherwise have.

So there is no switch to throw, and we would rather write that than take an order we cannot fill. We review the decision at ten households or in six months, whichever comes first, and immediately if you ask.

How long is anything kept?Ninety days, a year, or indefinitely — your choice, dated in your own log.

When a window passes, the words are overwritten rather than the rows deleted: that a request existed, at that hour, and was settled survives — a record about nobody. Titles, details, the conversation, the private note for the staff and every name attached to any of them go. The proof photograph is deleted outright.

“Kept indefinitely” is an answer somebody gave and not the absence of one: it carries the date it was chosen and a line in your own log. That distinction matters on the day anybody asks whether you knew.

The honest limit: overwriting reaches the live database and not last night’s snapshot, which rolls past on its own thirty-day clock. No command can reach into a backup.

How would somebody get in?There is no password to steal — none exists in the database.

Sign-in is by passkey: a private key that never leaves the owner’s device. A second factor is mandatory for the desk. Your staff have no account, no password and no e-mail address to phish — they hold a signed link bound to the browser that answered a one-time code.

A passkey held in an Apple or Google account exists on every device signed into it, so a device your household has never seen is held until a second channel answers, and the permission then lives as a row we can withdraw rather than a cookie we hope expires.

One deliberate trade, named rather than left to be found: a recovery path by e-mail exists, so control of a principal’s mailbox is a route in. It is what stands between a locked-out principal at midnight and losing their household altogether.

What is true today

Each of these is either measured against the running service or read out of the source, and each is checkable by somebody who asks.

  • No password exists anywhere in the database. Passkeys only.
  • No recording of any voice is stored, in any form, anywhere.
  • A photograph taken in SottoV’s own camera is drawn onto a canvas, so EXIF and GPS never exist rather than being stripped afterwards.
  • Household isolation is attacked before a release, not merely tested.
  • Every outstanding link a person holds dies in one action, on every device, at once.
  • No analytics, no tracking pixels, no advertising identifiers, no error-reporting service. The content security policy forbids the pages from loading anything at all from another company.
  • Everything stored sits in Switzerland, with a Swiss company, under Swiss law.

The alternatives, honestly

Most households run on some mixture of these four. The first row goes against us and stays in — a table you cannot check is worth nothing, and the row where we lose is the one that proves the rest.

E-mailText messageWhatsAppSottoV
Can it be read on the way?Yes — your provider and theirsYes — both networks see it in the clearNo — sealed end to endNo — sealed in transit; the one unsealed channel, a text message, never names the request
Who learns who is talking to whom?Your provider and theirs, in fullBoth carriers, plus anyone with a warrantMeta — the words are sealed, the pattern is notUs, and nobody else
When somebody leaves your household, what do they keep?Every message you ever sent themEvery message, on their own phoneEvery message, and the group with itNothing — access ends in one action, on every device, at once
Where does it live afterwards?Their mailbox, indefinitelyTheir phone, and the carrier’s own recordsTheir phone and their cloud backup, indefinitelyOur servers, where it sits readable — and we say so. Nothing is left behind on their phone
Can you take it back?NoNoWithin about two days — unless it was read, copied or screenshottedThe request can be withdrawn and its words overwritten
Does it expire on its own?NoNoOnly where disappearing messages are switched on for that chatNinety days, a year, or never — the household decides
What does your staff have to sign up for?An addressA numberAn account with Meta, tied to their private numberNothing — no account, no download, no password

The line that matters for a household is the third: what somebody keeps after they stop working for you. That is the question behind most of the others, and it is the one a message thread answers worst.

Everything above, at the depth an adviser needs — every hop, every supplier, every agreement, and what each one receives — is published in full. Questions, including the awkward ones: contact@sottov.com

PrivacyTermsImprintBack