What we collect
Your account details (name, email, sign-in records), the records you create in your workspaces, your support requests, and your billing history. If you record your own customers in SONARA, their details are held on your behalf and belong to you.
Why we hold it
To run the service you signed up for: to sign you in, to show you your records, to take payment, and to answer your support requests. We do not sell it, and we do not use your records to advertise to you or anyone else.
Who else processes it
Four companies, because the service runs on them: Supabase stores the records, Vercel runs the server, Stripe takes the payments, and Resend delivers email. Each receives only what it needs to do that job. This is set out in more detail on the data processing page.
How long we keep it
For as long as your account is open. Deleting a record inside the product archives it rather than removing it, so it can be recovered if the deletion was a mistake -- an archived record is still stored. Billing records are kept after an account closes where tax rules require it.
Getting a copy
Your data page has an export that gives you your records as a file, immediately, with no request to make and nobody to ask. It names any record type it could not read rather than leaving it out silently.
Asking for erasure
The same page sends an erasure request. It is a request rather than a button because erasing an organisation's records cannot be undone, so a person confirms it is really you asking and then tells you what was removed and what had to be kept.
Cookies and tracking
Three cookies, all essential to signing you in, all first-party. No advertising or analytics cookie is set, and pages load no third-party font, script or tracker, so opening a page does not tell any outside company that you did.
Asking us about any of this
Send it through the contact route. If something here does not match what the product actually does, that is a defect and we want to hear about it.