Privacy Policy
Last updated: 22 July 2026
This is the privacy policy for Sonata (the “Service”). For questions about how your data is handled, contact privacy@sonatai.co.
What we collect
- Account data: email address, name, password (hashed, never stored in plaintext).
- Connected-account contents: when you connect Gmail, Google Calendar, or similar integrations, Sonata reads the contents of those accounts to generate your daily brief and answer your questions. For emails we store a short snippet, an AI-written one-sentence summary, and metadata (sender, subject, received-at) — never the full email body. For calendar events we keep the structured fields you’d expect (title, time, description, location, attendees) so we can reason about your day.
- Conversation history: messages you exchange with Sonata in the chat interface, plus the structured outputs Sonata produces (briefs, knowledge entries, draft emails).
- Usage telemetry: which screens you open, errors encountered, anonymous performance metrics. No tracking pixels, no third-party analytics SDKs at present.
What we do with it
- Generate your morning brief, surface meeting prep, draft replies, and answer your questions in chat.
- Send relevant subsets to AI providers— Anthropic (Claude), Perplexity (Sonar), and Voyage (embeddings). These providers process the data on Sonata’s behalf to produce the outputs you see. We do not train on your data, and we rely on each provider’s published terms prohibiting them from doing so. We are still completing our formal Data Processing Agreements with these providers and will say so here once they are in place.
- Store data on Neon (managed Postgres, hosted in AWS London, UK) and Vercel (application hosting, edge network). Sonata’s own database is in the UK; our AI providers process in the United States.
- Send other operational data to Resend (sending the emails you have asked for) and Upstash (queueing background jobs).
- Diagnose errors via Sentry (no email contents or message bodies sent to Sentry — error logs are scrubbed of user-identifiable content).
We do not sell your data, share it with advertisers, or use it to train any model. See the full list of every processor we use, and what each one does, on our subprocessors page.
How long we keep it
Account and conversation data are retained as long as your account is active. Research signals expire automatically after 14 days by default (configurable in Settings, 7–28 days). When you delete your account, we delete your data within 30 days. Deletion is irreversible after that window.
Beta-stage caveats
Sonata is in closed beta. While in beta, we may reset the beta database between iterations. If we do, we will give 24 hours’ notice via email. Production data (when you sign up post-launch) will not be subject to these resets and will be retained per the schedule above.
Your rights (UK GDPR)
- Access: ask us for a copy of your data via privacy@sonatai.co.
- Correction: ask us to fix anything inaccurate.
- Deletion: tap “Delete account” in Settings. This deletes every database row tied to your account, deletes any uploaded files (logo, contract documents), and revokes connected-provider access where the provider offers a revocation API (Google; Microsoft does not offer a per-app revoke endpoint, so also revoke Sonata’s access from your Microsoft account’s app-permissions page if you connected Outlook). All of this normally completes within minutes of the request, well inside the 30-day ceiling.
- Portability: tap “Export my data” in Settings for an instant, self-serve JSON download of your account, business, conversations, knowledge base, contacts/engagements, briefs, and connected-account metadata (not raw mailbox content, which lives at the source provider) — no email round-trip required.
- Complaint: if we’re not handling your data properly, you can complain to the UK ICO at ico.org.uk.
Cookies + tracking
The web app uses a session cookie set by Better Auth solely to keep you signed in. The mobile app uses platform-secure storage (Keychain on iOS) for the same purpose. We do not use third-party tracking cookies.
Changes
We’ll update this policy as the product changes. Material changes get an email; minor wording changes update the “Last updated” date above.
Contact
Privacy questions, deletion requests, or anything you’re not sure about: privacy@sonatai.co.