Privacy Policy
Effective August 27, 2026
This is a draft template, not a substitute for review by a licensed attorney. It describes SonoArc's data handling as designed; update it whenever the list of third-party providers or data practices below actually changes, and have it reviewed before launch — data privacy law (GDPR, CCPA, and others) is jurisdiction-specific.
1. What We Collect
- Account information: email address and password (password is never stored in plain text).
- Content you create: lyrics, song/project metadata, and audio recordings you make in the Service.
- Microphone audio: processed locally in your browser for real-time analysis (chord/pitch detection); recordings you explicitly save are stored as described in Section 3.
- Payment information: handled entirely by Stripe — we receive confirmation of subscription status, never your full card number.
- Usage data: basic technical data (device/browser type, error logs) to keep the Service running and diagnose problems.
- Product analytics: which screens and features you use, and your plan tier, via PostHog — never the words, chords, or audio you create, which stay local as described in Section 3.
2. How We Use It
- To provide the Service you request — e.g., sending your message to our AI inference provider (Groq) to generate a Wizard reply, or a word to Datamuse to find rhymes.
- To process your subscription and maintain your entitlement to paid features.
- To store and let you retrieve your own projects, sessions, and recordings.
- To maintain security, prevent abuse, and diagnose technical issues.
- To understand which features are actually used, via product analytics, so we can prioritize what to build next.
We do not sell your personal information.
3. Where Your Data Lives
SonoArc is local-first for solo use: your account, projects, songs, lyrics, and recorded audio are stored only in your browser's local database on your own device, never on our servers. We have no copy of them and cannot access, recover, or transfer them on your behalf — if you clear your browser's site data or switch devices, that data does not follow you unless you export it yourself. The Wizard chat sends your message to Groq, our AI inference provider, to generate a reply (see Section 4); we do not separately store or log that conversation ourselves. Your subscription status and payment details are held by Stripe, not by us — see Section 4.
Band collaboration is the one exception. Because bandmates need to see each other's uploaded parts across their own separate devices, Band projects — the band's roster, its song/album projects, and any audio, images, video, or notes a member uploads to them — are stored in a real shared database (provided by Supabase) rather than only on one device. Access to a band's data is restricted to that band's verified members. This does not change how solo (non-Band) projects and recordings are stored, which remain local-only as described above.
4. Third Parties We Share Data With
We rely on the following service providers (“sub-processors”), each of which processes a limited slice of data necessary to perform its function:
- Datamuse — receives individual words (not full lyrics or audio) to return rhyme suggestions.
- Stripe — processes subscription payments and manages your billing status. We never see your full card number.
- Supabase — hosts the shared database and file storage for Band collaboration only (Section 3). Not involved in solo use.
- Groq — receives your Wizard chat messages (and any song context you've shared, like key/BPM/chords) to generate a reply. Groq does not receive your account, payment, or recorded-audio data.
- PostHog — receives product-analytics events (screens viewed, features used, plan tier) tied to a random local account id, never your email, lyrics, or audio.
We do not currently share your personal information with any other third party, and we do not share it with anyone for their own marketing purposes.
5. Data Retention
Because your account and content data live only in your browser's local database, you control retention directly: deleting a recording/project, deleting your account, or clearing your browser's site data for SonoArc removes it immediately and completely, on that device — we hold no copy to separately retain or purge. Stripe retains your subscription and payment records per its own policies and applicable legal requirements (e.g., tax law), independent of anything stored locally.
6. Children's Privacy
The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us personal information, contact us at cras.vruskin@gmail.com and we will delete it.
7. Your Rights
Depending on where you live, you may have rights to access, correct, export, or delete your personal data, and to object to certain processing (for example, under the GDPR if you are in the EU/UK, or the CCPA/CPRA if you are a California resident). You can exercise most of these rights directly in the app (account settings, project deletion) or by contacting cras.vruskin@gmail.com.
8. Security
Your password is never stored in plain text — it is salted and hashed with PBKDF2 before being saved to your device's local database. Connections between your browser and the Service are encrypted in transit. Because your content stays on your own device rather than a server we control, it isn't exposed by a breach of our infrastructure — but no method of transmission or storage is 100% secure, and we cannot guarantee absolute security, including of the device itself.
9. App Marketplace Distribution
If you obtain SonoArc through Apple’s App Store, Google Play, Microsoft Store, or another software marketplace, that marketplace operator separately collects and processes data under its own privacy policy (for example, purchase history, device identifiers, or install analytics it gathers itself) — that collection is governed by the marketplace’s own privacy policy, not this one, and is outside our control.
10. International Data Transfers
Because your content stays on your own device, the main cross-border transfer to consider is Stripe's processing of your payment/subscription data, which may occur outside your country of residence, including in the United States. Where required, we rely on the safeguards Stripe itself provides (such as standard contractual clauses) for that transfer.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be reflected by an updated effective date above.
12. Contact
Viginti Octo LLC — Attn: Legal & Compliance
3134 E McKellips Rd #73, Mesa, Arizona 85213
Questions about this Privacy Policy: cras.vruskin@gmail.com.