
What we can and cannot promise
No single party ever holds the whole picture. The service that hears a voice sees no names. The service that reads text never hears a voice. The relays that carry notifications cannot open them. And your household exists, to every other household on SottoV, not at all.
Eight questions below, each answered in a line. Open one for the working. Everything here is either measured against the running service or read out of the source, and where a protection is a rule we keep rather than a wall we have built, it says which.
Can the people who work for me carry my household onward?They see only the work given to them, and they keep nothing when they go.
A member of your entourage sees the requests addressed to them and nothing else. That is a wall rather than a courtesy: every read is filtered by the person the request was given to, so there is no screen, no link and no scroll that reaches the rest of the house.
When somebody leaves, one action ends it. Every link they hold dies at once — not at the next password change, not when a session expires — and every device they bound to it goes with it. Compare that with a message thread, which they keep for as long as they keep the phone.
What no product can promise, and we will not: a person who has read something can repeat it. We limit what reaches them and we end it instantly. We do not claim to reach into anyone’s memory.
Is my voice recording kept?No. Not by us, not anywhere, not in any form.
A spoken note is held in your phone’s memory, sent once to be turned into text, and discarded. No table and no file store holds audio. There is no archive of your voice to be leaked, subpoenaed or sold.
The transcript is what survives, and it becomes the request. What travels with it, and to whom, is set out in full in the complete answer — including a list of names that goes with every recording, which is the part nobody thinks to ask about.
Can another household see mine?No — and we attack that boundary ourselves before a release.
Every read is scoped to the household it belongs to. That scoping is not merely tested: a script removes each boundary check in turn and requires the test suite to turn red for every one of them. Anything that survives is a test passing for the wrong reason.
It found two of those the first time it ran — one route where the request body failed validation before the boundary was ever consulted, and one whose condition appears three times in a file of which only two were exercised. It is run by hand before a release rather than on every build, and we would rather say so than imply an automation we have not built.
Where is my data kept?Frankfurt and the EU. Switzerland is about a week's work, on request.
The database is Postgres in Frankfurt; photographs sit in object storage under EU jurisdiction; the application runs in Frankfurt. All three suppliers are American companies, which is a separate question from where the disks are, and we state it because a supplier’s marketing page will not.
SottoV runs on standard Postgres, S3-compatible storage and a plain Node server, so Swiss hosting is a deployment exercise rather than a rewrite. What it does not move is the speech and language processing, or the notification relays, which belong to the phone’s maker.
Can the people who run SottoV read my words?Our tooling cannot. One exception exists, and it writes a line into your own log.
The operator console shows names, counts, states and timestamps — never the text of a request. The command line can create a household, suspend it, count rows and erase it, and has no path to a request, a message or a photograph.
The exception is the export that answers “give us everything you hold about us”. Somebody has to be able to read it in order to hand it to you. It costs a fresh passkey every time and writes a line into your household’s own security log, where your chief of staff reads it. We can look, and we cannot look without you being able to see that we did.
This is a rule we keep, not a wall we have built. See the next answer for what that distinction costs.
Is my household's content encrypted under its own key?Available on request. Off by default, and the reason is worth two sentences.
Encryption under your household’s own key — envelope AES-256-GCM, one key per household, every value bound to its own row so none can be lifted into another, and the key destroyed on erasure so that what is left in any copy is bytes nobody can open — is built and tested.
It is off by default, because losing that key means the content is gone finally: no restore, no support, no recovery. That is a category of accident this product does not otherwise have, and it is not one to hand a household without their asking. Until then what protects your words at rest is our suppliers’ disk encryption rather than a key of your own, and they sit readable in our database.
Founding households may switch it on from day one. Ask, and it costs nothing. We also review the default at ten households or in six months, whichever comes first.
How long is anything kept?Ninety days, a year, or indefinitely — your choice, dated in your own log.
When a window passes, the words are overwritten rather than the rows deleted: that a request existed, at that hour, and was settled survives — a record about nobody. Titles, details, the conversation, the private note for the staff and every name attached to any of them go. The proof photograph is deleted outright.
“Kept indefinitely” is an answer somebody gave and not the absence of one: it carries the date it was chosen and a line in your own log. That distinction matters on the day anybody asks whether you knew.
The honest limit: overwriting reaches the live database and not last night’s snapshot, which rolls past on its own thirty-day clock. No command can reach into a backup.
How would somebody get in?There is no password to steal — none exists in the database.
Sign-in is by passkey: a private key that never leaves the owner’s device. A second factor is mandatory for the desk. Your staff have no account, no password and no e-mail address to phish — they hold a signed link bound to the browser that answered a one-time code.
A passkey held in an Apple or Google account exists on every device signed into it, so a device your household has never seen is held until a second channel answers, and the permission then lives as a row we can withdraw rather than a cookie we hope expires.
One deliberate trade, named rather than left to be found: a recovery path by e-mail exists, so control of a principal’s mailbox is a route in. It is what stands between a locked-out principal at midnight and losing their household altogether.
What have you not solved yet?Six things, named — and the list is kept current on purpose.
Content is not sealed under your household’s own key unless you ask. Executed countersigned copies of every supplier agreement do not all exist, though each binds by incorporation. Two AI accounts are still being moved onto the company’s name. There is no formal Art. 30 record of processing activities yet. We have never rehearsed a restore, and a backup nobody has restored is a hope rather than a backup. And we have not measured what Apple and Google do with dictation audio from their own recognisers — we describe their documented behaviour and will not claim we watched it.
The complete answer carries each of these at length, along with a defect in our own speech handling that we found while writing that page and named before we had finished fixing it.
What is already true
A list of unsolved things deserves a list of the same precision beside it, or the balance it presents is false.
- No password exists anywhere in the database. Passkeys only.
- No recording of any voice is stored, in any form, anywhere.
- A photograph taken in SottoV’s own camera is drawn onto a canvas, so EXIF and GPS never exist rather than being stripped afterwards.
- Household isolation is attacked before a release, not merely tested.
- Every outstanding link a person holds dies in one action, on every device, at once.
- No analytics, no tracking pixels, no advertising identifiers, no error-reporting service. The content security policy forbids the pages from loading anything at all from another company.
- Everything stored sits inside the European Union.
The alternatives, honestly
Most households run on some mixture of these four. The first row goes against us and stays in — a table you cannot check is worth nothing, and the row where we lose is the one that proves the rest.
| Text message | SottoV | |||
|---|---|---|---|---|
| Can the carrier read what you wrote? | Yes — your provider and theirs | Yes — both networks, and it is stored unencrypted | No — sealed end to end | Yes — it sits readable in our database, and we say so |
| Who learns who is talking to whom? | Your provider and theirs, in full | Both carriers, plus anyone with a warrant | Meta — the words are sealed, the pattern is not | Us, and nobody else |
| When somebody leaves your household, what do they keep? | Every message you ever sent them | Every message, on their own phone | Every message, and the group with it | Nothing — access ends in one action, on every device, at once |
| Where does it live afterwards? | Their mailbox, indefinitely | Their phone, indefinitely | Their phone and their cloud backup, indefinitely | Our servers. Nothing is left behind on their phone |
| Can you take it back? | No | No | Within about two days — unless it was read, copied or screenshotted | The request can be withdrawn and its words overwritten |
| Does it expire on its own? | No | No | Only where disappearing messages are switched on for that chat | Ninety days, a year, or never — the household decides |
| What does your staff have to sign up for? | An address | A number | An account with Meta, tied to their private number | Nothing — no account, no download, no password |
The line that matters for a household is the third: what somebody keeps after they stop working for you. That is the question behind most of the others, and it is the one a message thread answers worst.
Everything above, at the depth an adviser needs — every hop, every supplier, every agreement, and what each one receives — is published in full. Questions, including the awkward ones: contact@sottov.com