Evidence & trust
Sol's privacy architecture is one of its stronger current signals. The August 15, 2026 privacy notice says projects, source code, worktrees, browser state, terminal sessions and chat history are stored locally by default and that the company does not routinely upload or maintain hosted copies merely because the browser is used.6 That is well aligned with a developer tool handling proprietary source code.
Local-first does not mean no data leaves the device. When a user invokes an AI agent, integration or cloud-backed feature, Sol may transmit the content needed for the request—including prompts, page context, file excerpts or tool results—to the selected provider or another service acting on Sol's behalf.6 The policy names providers that may include Anthropic, OpenAI and Cerebras, and says their own terms/privacy practices also govern processing.6
The current privacy notice also documents product telemetry and service providers including WorkOS, Stripe, Autumn, PostHog, Vercel, Sentry and Context Company.6 Session replay is not enabled by default and is described as something that may be activated specifically for troubleshooting/testing.6 This is materially more precise than vague “we respect privacy” language.
The main evidence gap is maturity rather than an identified security failure. Sol's present identity is new enough that most public third-party material still refers to Inspector. A current AISO Tools listing describes the present tab/worktree architecture but has no meaningful review population.5 The old Inspector Product Hunt launch had strong interest and detailed workflow discussion, but those reactions belong to a materially different surface.4 Current claims about Sol's stability, resource use, browser compatibility, extension behavior and multi-agent performance therefore remain lightly tested in public.