Privacy Policy
Last updated 1 August 2026
This explains what Sonorie collects, why, who else processes it, and how to get it back or deleted. It describes what the software actually does, not what a template says it might.
The short version
- No analytics, no advertising, no tracking cookies, no session replay. There is no third-party script in the browser at all — even the fonts are served from our own domain.
- We never sell or share your personal information, and we don’t train models on your content.
- Your prompts go to model providers so they can be answered. That is the main way your data leaves us — see who processes your data.
- We never see your card details. Stripe handles payments on its own pages.
Who we are
Sonorie is a service for building audio plugins by describing them. For data protection purposes we are the controller of the personal data described here.
Privacy questions and requests: [email protected].
What we collect
Account information
Your email address, an optional display name, and — if you sign up with a password — a bcrypt hash of it. We never store the password itself. If you sign in with Google we receive and store your Google account identifier, email address, whether Google has verified it, and your name; we do not receive your Google password and we ask for no other Google data. If you enable two-factor authentication we store the secret needed to verify your codes and hashes of your backup codes.
What you create
Your prompts and chat history, any images you attach, the plugins generated for you (DSP source, interface code, parameters), your project titles, and the version history of each project. If you publish to the marketplace, your listing text and the plugin snapshot behind it. If you write a review, its rating and text, shown publicly with your name.
Billing and usage
Your plan, subscription status, and the Stripe customer and subscription identifiers that link you to your payments. Purchases, top-ups and licences issued to you. Usage records for each generation: which route it took, whether it succeeded, how long it took, how many tokens it used and what it cost. Card numbers never reach us— payment details are entered on Stripe’s own pages.
Sign-in sessions
For each active session we store a hash of the session token, when it expires, and the browser user-agent string captured when you signed in. The last of those exists for one reason: so the security page can show you a recognisable list of your signed-in devices and you can end any you don’t recognise.
IP addresses
Your IP address is used transiently, in memory, to rate-limit sign-in and account actions so nobody can brute-force your account. We do not write IP addresses to our database. Cloudflare, which delivers and protects the site, necessarily sees the IP of every request as part of doing that, and processes it under its own terms.
What we do not collect
No advertising or analytics identifiers, no cross-site tracking, no behavioural profiling, no location beyond the coarse country your network implies, and no special-category data. We do not buy data about you from anyone.
Why we use it, and our legal basis
For anyone in the UK, EU or Switzerland, the GDPR requires us to name a lawful basis for each purpose:
| Purpose | Data | Legal basis |
|---|---|---|
| Running your account and generating plugins | Account details, prompts, projects, generated code | Performance of our contract with you |
| Taking payment, managing subscriptions and marketplace payouts | Billing identifiers, purchases, usage totals | Performance of a contract; legal obligation for tax records |
| Service emails — verification, password resets, receipts, security alerts | Email address, the relevant event | Performance of a contract; legitimate interest in account security |
| Keeping accounts secure and preventing abuse | IP address (transiently), user-agent, rate-limit counters | Legitimate interest in protecting users and the service |
| Improving reliability and cost of the pipeline | Aggregate timings, costs, pass rates | Legitimate interest in operating a working service |
| Meeting legal and accounting obligations | Invoices and transaction records | Legal obligation |
Where we rely on legitimate interests, we have considered your rights and use the least data that achieves the purpose — which is why, for example, rate limiting keeps IP addresses in memory instead of logging them.
Who processes your data
We use a small number of providers to run the service. Each acts on our instructions under a data-processing agreement, and each receives only what its job needs.
| Provider | What it does | What it receives |
|---|---|---|
| AI model providers | Turn your prompts into DSP code and interfaces | Your prompt text, attached images, conversation context, generated code |
| Stripe | Payments, subscriptions, marketplace payouts | Email, name, an internal user id, and your payment details, which you give directly to Stripe |
| Resend | Sends transactional email | Your email address and the content of that message |
| Sign in with Google — only if you use it | The sign-in exchange itself; Google returns your identifier, email and name | |
| Cloudflare | Delivers and protects the site; stores compiled build artifacts | Request metadata including your IP address; plugin binaries, which hold no personal data |
| Our database and server hosting | Stores everything described above | All account, project and billing data |
| Our compile and build workers | Compile generated C++ into a preview or a plugin binary | The generated source code only |
A word about prompts. The content you type is sent to third-party AI model providers so it can be answered, and they process it under their own terms and retention policies. Which providers we use changes as models improve; they are currently located in the United States and China. We don’t list them by name here because that list would be out of date within months, but it isn’t a secret — ask us and we will tell you which providers are handling your data. Please don’t put personal, confidential or client-sensitive information into a prompt. You don’t need to in order to describe a compressor, and it is the one part of this policy where your own habits matter more than our controls.
Beyond these providers, we disclose personal data only where the law requires it, to establish or defend legal claims, or — with notice to you where we’re allowed to give it — if the business is ever transferred to another owner. We do not sell personal information and we do not share it for advertising.
International transfers
Our providers operate outside the UK, EEA and Switzerland, including in the United States and China. Where personal data is transferred out of those regions we rely on the European Commission’s Standard Contractual Clauses and the UK Addendum, together with the provider’s own safeguards. Not every destination has been found by the Commission to offer an equivalent level of protection — which is the practical reason for the caution about prompt content above.
How long we keep it
| Data | Kept for |
|---|---|
| Account details | While your account exists, then deleted on closure |
| Projects, chat history, generated code | Until you delete them, or until the account is closed |
| Sign-in sessions | 30 days, or until you sign out or revoke the device |
| Generation job records | 14 days, then swept automatically |
| Usage and cost records | Up to 24 months, for billing accuracy and capacity planning |
| Invoices, purchases and payouts | As long as tax and accounting law requires, typically 6–10 years |
| Marketplace licences | For the life of the licence, so buyers can re-activate a plugin they bought |
How we protect it
Passwords are hashed with bcrypt and never stored in the clear. Session tokens are stored only as hashes, so a copy of our database does not yield working sessions. Traffic is HTTPS-only with HSTS. Sign-in and account actions are rate-limited, and password checks take the same time whether or not the account exists, so they can’t be used to discover who has an account. Model-generated code is compiled in an isolated, hardened service and runs in the browser inside a sandboxed frame that cannot reach the network. Two-factor authentication is available and we recommend it.
No system is perfectly secure. If we ever suffer a breach affecting your personal data, we will notify you and the relevant regulator as the law requires.
Your rights
Depending on where you live you may have the right to access your data, correct it, delete it, receive a portable copy, restrict or object to certain processing, and withdraw consent where we relied on it. If you are in California or a similar US state, you have the right to know, delete and correct, and the right to opt out of sale or sharing — which we can satisfy immediately, because we do neither. We will not discriminate against you for exercising any of these rights.
Some of it you can do yourself, right now:
- Change your name, email or password on the account page.
- Review and revoke signed-in devices on the security page.
- Delete individual projects from the studio.
- Manage or cancel your subscription through the billing portal.
For account deletion or a copy of your data, email [email protected] from your account address and we will action it within 30 days. Deleting your account removes your projects, chat history, generated code, sessions and usage records; we keep billing records where tax law requires it, and marketplace purchase and licence records so that people who bought from you keep working plugins.
If you think we have handled your data badly, please tell us first — but you also have the right to complain to your data protection authority. In the EU that is the supervisory authority where you live or work; in the UK, the Information Commissioner’s Office; in Switzerland, the Federal Data Protection and Information Commissioner.
Cookies and local storage
Sonorie sets three cookies, all of them strictly necessary to sign you in and keep the sign-in flow safe. There are no analytics, advertising or tracking cookies, so there is nothing here to opt out of — and blocking these would simply stop you being able to sign in.
| Cookie | Purpose | Expires |
|---|---|---|
sonore_session | Keeps you signed in. Holds a random token; the server stores only its hash. | 30 days |
sonore_2fa | Bridges the gap between your password and your two-factor code. | 10 minutes |
sonore_oauth | Protects the Google sign-in exchange against forgery and interception. | 10 minutes |
All three are HttpOnly, restricted to our own site with SameSite=Lax, and sent only over HTTPS in production. That means no script — ours or anyone else’s — can read them.
We also keep a few preferences in your browser’s local storage. These never leave your device and are not sent to us:
| Key | What it remembers |
|---|---|
sonorie-theme | Light or dark, if you chose one explicitly |
sonore-store | Studio preferences such as output level |
sonore-cart | What’s in your marketplace cart |
sonore-pending-prompt | A prompt you typed before signing up, so it survives the redirect. Expires after 24 hours. |
sonorie-cookie-notice | That you dismissed the cookie notice, so we don’t show it again |
You can clear all of it at any time through your browser’s settings. Clearing it signs you out and resets your preferences; nothing else is lost.
Children
Sonorie is not for people under 18. We don’t knowingly collect their personal data, and if we learn we have, we delete it. If you believe a child has given us information, please email [email protected].
Changes to this policy
If we change what we collect or who processes it, we will update this page and change the date at the top. For material changes we will tell you by email or in the app before they take effect. If we ever add a service that is not strictly necessary — analytics, for example — we will ask for your consent first rather than assume it.
Contact
[email protected] for anything in this policy, or [email protected] for everything else.
See also our Terms of Service.