INTERNAL — DRAFT, not published. Before publishing: set the effective date below, drop "— draft" from the title, delete this notice and the revision-history notice at the foot — and work through
privacy-policy/privacy-policy-open-items.md, which is blocking.Current draft status, 23 August 2026: the owner selected the outside-US account-disable rule, a United-States-only trial, and the telemetry lifecycle now described in sections 4.2, 5, 10, and 11. Do not publish until the remaining blocking implementation and verification items are closed.
Effective [publication date].
This policy covers the Sonik application for Windows, the website at soniksoft.com, and correspondence sent to Sonik while we run the product and business.
Privacy at a glance
- Transcription happens on your computer. Sonik does not upload recordings or transcript files as part of transcription. We can receive text you choose to put in feedback and previewed diagnostic material you choose to send; diagnostic scrubbing is best-effort.
- Recordings and transcripts are stored locally, under your control, and you can turn either off or delete everything at any time.
- In-app usage analytics and crash reports are off until you switch them on, and you see a crash report before it goes. Outside the EEA and UK, our website analytics are the other way round — on, with an opt-out (section 7).
- The trial needs no account. A few things can reach us before you ever have one: a check for a newer version, which the Microsoft Store build doesn't make and which you can turn off; analytics or crash reports if you switched those on; and feedback if you send us any. Once you have an account, Sonik also reaches us to sign you in and to check a licence.
- We use no third-party analytics or advertising trackers. Our website analytics run on our own server. Paddle's checkout script loads only when you start a purchase and may set its own cookies under Paddle's policy. No advertising networks, no data brokers, no sale of personal information.
- Our primary storage and service locations are in Europe.
- Payments are handled by Paddle. Your full card number and security code never reach us; card brand and last four digits may appear in Paddle's confirmation, and we discard them on receipt.
The rest of this document is the precise version.
1. Who we are
Sonik Software LLC
10/2 Levan Iosebidze Str.
3700 Rustavi, Georgia
Sonik Software LLC is registered in Georgia — the country in the Caucasus. Except for the independent controllers identified in section 8, we are the data controller for the personal data described here.
Where Sonik is available. The trial, accounts, licences, gift redemptions, and paid or zero-dollar upgrades are available only to people in the United States. Nobody under 18 may download or use Sonik. For the direct download and online acquisition requests, our server checks the request IP address against a locally hosted country database to determine whether the request comes from the United States; we keep no separate location profile from that check. The first-run trial condition remains local and sends no location merely to repeat the restriction. We ask which country you are in when you create an account, ask again before a gift redemption or zero-dollar upgrade, and check the country your payment details show for a base purchase or paid upgrade (sections 5 and 6). If an account holder ceases residing in the United States and notifies us, we disable the account and its authenticated backend services until they notify us that they reside in the United States again. Section 5 explains the data consequence.
Which law applies. We're a Georgian company, and we run and administer our systems from there, so the Law of Georgia on Personal Data Protection applies to our processing as our home law and the State Audit Office of Georgia is our supervisory authority. Other laws may also apply. Those laws bind us, not you.
The rights in section 11 are the ones Georgian law gives you, and we extend them to anyone who asks, wherever you live. Nothing in this policy takes away a right the law where you live gives you.
Privacy enquiries: privacy@soniksoft.com
General enquiries: contact@soniksoft.com
2. What stays on your computer
Sonik transcribes your speech locally. The speech recognition model runs on your own hardware, and your audio is processed in memory on your machine rather than uploaded anywhere for processing.
If you leave "save recordings to disk" switched on, that audio is also written to disk — on your computer, until it is deleted on the schedule in section 3. Saved or not, Sonik does not upload it for transcription.
This means:
- Sonik does not upload your voice recordings or transcript files as part of transcription.
- We cannot access, read, recover, or hand over the files stored locally on your computer.
- We can receive text you choose to put in a feedback message and previewed crash reports or diagnostic logs you choose to send. We scrub diagnostic material for dictated text before showing it to you, but that scrubbing is best-effort rather than a guarantee (sections 4.2 and 4.3).
3. What Sonik stores on your computer
Everything in the table below is stored locally on your device. Sonik does not upload a recording or transcript file from this table. A diagnostic log can leave only where you tick the box that attaches it to feedback, and a best-effort-scrubbed fragment can appear in a previewed crash report you choose to send (sections 4.2 and 4.3).
These are the current defaults. Where we change them in a future release, the release notes and our documentation will say so.
| What | Default | Your control |
|---|---|---|
| Transcripts — the text Sonik produces | Saved, and deleted after 7 days | Turn saving off, or set a longer or shorter retention period |
| Voice recordings — the audio itself | Saved, and deleted after 1 hour | Turn saving off, or set a longer or shorter retention period |
| Diagnostic logs | Not saved — logging is off | Turn logging on or off; while it is on, logs are kept until you delete them or the size cap removes the oldest entries |
Settings offer two delete actions at any time: Delete transcripts, recordings and logs, which clears everything in the table above; and Delete all local data, which additionally clears your settings, your sign-in, your device identifier and your analytics and crash-report choices, leaving Sonik as though it had never run on this machine.
If a trial telemetry identifier exists, Delete all local data first offers to use it to delete any telemetry from our server. The local deletion itself always works offline. If the server request fails or its result is uncertain, Sonik lets you retry, cancel, or continue with local deletion. If you continue without confirmed server deletion, Sonik warns that removing the identifier will make any submitted records impossible to locate through the app; they then expire under the six-month rule in section 10. A confirmed server deletion removes the telemetry payloads but leaves the minimal consent and withdrawal evidence for six months, as section 11 explains.
What survives an uninstall depends on where you got Sonik, and our documentation sets out each path. One difference is worth knowing here: a Microsoft Store uninstall clears the application's storage and everything Sonik kept in it. Our own installer leaves local content and preferences unless you ask it to delete them, but always clears stored sign-in credentials and telemetry choices. If trial telemetry was submitted, use Delete telemetry before uninstalling if you want the server copy deleted: uninstall can remove the random lookup identifier without contacting us, after which the submitted records cannot be located through the app and expire within six months.
Microphone and clipboard
Sonik needs your microphone to hear you. You can withdraw that permission at any time in Windows settings.
To insert text where you're typing, Sonik puts the transcribed text on your clipboard, replacing whatever was there. Just before it does, it reads your existing clipboard contents so that it can restore them immediately afterwards. Those contents are held in memory only; Sonik does not write them to disk, to a log, or to a crash report, and nothing about your clipboard is sent to us. Restoring is on by default, and you can turn it off in settings.
If a password manager marked something on your clipboard as sensitive — the marking that keeps it out of Windows clipboard history and cloud sync — Sonik is designed to preserve that marking when it restores.
4. What Sonik sends to us
This section sets out why Sonik contacts our servers. Section 4.5 covers what any request reveals simply by being a network request.
4.1 Signing in, and licence checks
Signing in is optional. You need no account to install Sonik or to run the trial; you will need one to buy a licence. Several things can reach us before you ever have an account: the update check in section 4.4, the analytics or crash reports in section 4.2 if you switched those on, and feedback you choose to send us (section 4.3). The telemetry identifiers are explained in section 4.2; the update check carries no account or device identifier. The Microsoft Store build doesn't make the update check at all.
Signing in or signing up is the first thing that reaches us carrying your account. It creates or opens that account, registers this installation as one of your devices, and, if the trial notice was shown earlier, uploads that notice's version and display time from this installation (section 5). The display record shows that the unilateral trial permission was communicated; it is not a record that you agreed to terms.
The trial timer reports nothing. Apart from any analytics or crash reports you switched on, the trial period ships with the application, counts down on your own computer, and ends by itself. We don't time it, extend it, or hear how it went. If you happen to be signed in while trialling, we know your account exists and which devices are registered to it — nothing about whether or how you are using the product.
After that, Sonik contacts our server when there is a licence to check: after you buy one, and whenever you press Check for licence in settings. That request sends:
- your account identifier
- a device identifier (see below)
- the application version, and your Windows major version rather than its full build number
The reply tells Sonik whether your licence is valid and whether you have a device slot free.
Before the first use under a licence, the account holder accepts the applicable Terms in Sonik. Sonik then sends the account identifier, the Terms version, and the acceptance time to record that contractual acceptance. It does not include a device identifier or usage data.
Unregistering this device. Sonik's settings offer an Unregister this device action. It deletes this installation's device record from your account on our servers. The request sends your account identifier and the device identifier.
Legal basis: before the account holds a licence, our legitimate interest in providing and securing the account and preparing the licence activity you request. After the licence contract begins, performance of that contract.
4.2 In-app usage analytics and crash reports — off unless you turn them on
This is separate from the website analytics in section 7, and controlled separately from it.
When you first run Sonik, we ask whether you're willing to send in-app usage analytics and crash reports. Both are off by default, and each has its own switch in Sonik's settings — you can send one without the other. You can change your mind at any time, and turning a switch off stops that collection immediately.
If you switch them on:
- Usage analytics record which features you use and how often, and how Sonik is configured — which settings you've changed from their defaults, and what you've set them to. Usage-analytics payloads contain only fixed choices, such as a retention period or a toggle state; they contain no free text, audio, or transcribed speech. Crash reports and diagnostic logs follow the separate rules below.
- Crash reports are prepared when Sonik fails, and contain the technical details of the failure, the application version, and your full Windows version including its build number. Sonik strips your Windows username and scrubs anything that could carry what you dictated. Scrubbing is best-effort rather than a guarantee, so Sonik shows you the report before it goes — you can read exactly what would be sent, and send it or discard it.
This data goes to our own server. No third-party analytics provider is involved.
Telemetry carries an identifier. If you first switch on trial analytics or crash reporting, Sonik creates a random telemetry identifier for that installation. It is not an account or registered-device identifier, and we never map its history to an account. It lets us relate accepted categories, withdrawal, analytics, and crash submissions from the same trial installation. If that installation becomes licensed, Sonik first offers to use the identifier to delete any trial telemetry, with the same retry, cancel, or continue choices and warning described for Delete all local data in section 3. Sonik then retires the trial identifier and asks you to make fresh analytics and crash-report choices. Future accepted submissions use your account identity, without carrying or linking the earlier trial history. Account-linked telemetry lets us honor account and deletion requests and reject submissions after the account is disabled. Neither identifier is used to collect a voice recording or transcript file; a previewed crash report can nevertheless carry a fragment that best-effort scrubbing missed. Section 4.5 covers what any request additionally reveals by being a request.
If you accept analytics or crash reporting, Sonik keeps the choice on your device and sends us the category, acceptance time, and notice version so that we can show when and on what notice you agreed. If you decline before anything has been sent, that choice remains on your device and we receive no decline record. Turning off a previously accepted category stops future submissions immediately. When the server is reachable, it also updates the corresponding server-side record with the withdrawal time. While offline, Sonik keeps only a separate encrypted withdrawal instruction—not telemetry content—and retries it until the server acknowledges it or you destroy the applicable local identifier. The dedicated trial-telemetry deletion control uses the same separate channel and preserves the identifier until the deletion is acknowledged. If a withdrawal instruction cannot be delivered before identifier destruction through another action, the server record expires within six months of the last submission. Licensing, account disablement, account deletion, and use of the trial-telemetry deletion control end the affected current choices; licensed use and later account re-enablement require fresh choices. A server record also expires after six months without a submission; if the unchanged local choice later sends again, its payload recreates the record with the original acceptance evidence. Analytics and crash reporting remain separate choices.
If the server is temporarily unavailable, accepted analytics or a crash report you chose to send may wait encrypted in Sonik's local queue for up to 7 days. Sonik deletes an item after that deadline instead of sending it late. Turning the applicable category off, licensing the installation, receiving an account-disablement or deletion event, deleting telemetry, deleting all local data, or uninstalling clears the affected payload queue immediately. The separate minimal withdrawal or deletion instruction described above is not a telemetry payload.
Legal basis: your consent.
4.3 Feedback you send us
If you use the feedback form inside Sonik, we receive your message, the application version, and your full Windows version. If you're signed in, we can see which account it came from. If you are not already covered by the Terms of Service feedback clause, the separate Feedback Submission Terms apply and the form requires an email address so we can send the durable contract confirmation. You can instead contact us by ordinary email without using that separate form contract.
Diagnostic logs are attached only if you tick the box to include them. They go through the same scrubbing as a crash report, and Sonik shows you what would be attached before it goes, so you can read it first. Logging is off by default (section 3): with it off there is no log to attach, and the box isn't offered.
You can also simply email us instead.
The feedback form is available only to people aged 18 or older who have legal capacity for the applicable submission agreement. It does not infer permission to use feedback merely from submission. If the submitter is a contracting party covered by the Terms of Service feedback clause, that clause applies. Otherwise, contractual permission to use the feedback depends on acceptance of the separate Feedback Submission Terms. We keep their version and time with the message and send the supplied address a durable confirmation identifying that version. A licensed account holder is already covered and is not asked to form a duplicate feedback contract. Email sent outside the form does not use the separate short terms.
Legal basis: performance of the applicable Terms of Service or Feedback Submission Terms for a covered form submission, and our legitimate interest in supporting and improving the product for support and other correspondence.
4.4 Updates
If you installed Sonik from the Microsoft Store, Windows handles updates and the application performs no check of its own.
Otherwise, Sonik may contact our server to check for a newer version and to download it. This happens whether or not you have an account or are signed in. The check carries no licence, no account identifier and no device identifier; like any request, it shows your IP address (section 4.5). You can turn automatic updating and the check itself off in settings.
Legal basis: our legitimate interest in keeping installed software current and secure.
4.5 What every request reveals
Any request to any server discloses the address it came from.
So: whenever Sonik does reach us — signing in, recording the first-licensed-use acceptance, a licence check, unregistering a device, telemetry you switched on, feedback you sent, an update check or the update itself — our server sees your IP address and the time, and records them in its access log along with the request. The same happens when you visit our website. On the direct-download and online acquisition routes described in section 1, we also check the request IP address transiently against our locally hosted country database to determine whether the request comes from the United States. We retain no separate IP-derived country or location profile.
Those logs are deleted after 30 days. We keep them to operate the service and to investigate abuse. Outside an abuse investigation, we don't join them to your account, to your telemetry, or to anything else.
Legal basis: our legitimate interest in operating and securing the service.
5. Your account
An account exists to hold your licence, along with the handful of things listed below that go with it. You don't need one to transcribe during the trial, and it holds nothing about what you transcribe.
What we store:
- your email address — with Apple this may be a private relay address that forwards to yours, rather than the address itself
- your name, if you choose to give one
- your sign-in method — a password, a magic link, or a linked account with one of the providers listed in section 8
- the country you told us you were in when you created the account and each fresh country declaration made for a later gift redemption or zero-dollar upgrade
- which licences you hold
- your registered devices
- the version and time of contractual acceptances made through the account
- the version and time showing that the account-creation notice and, if applicable, the earlier Trial Permission Notice were displayed
- any server-side record of your acceptance or later withdrawal of in-app analytics or crash reporting that is associated with the account
- whether you asked to receive product emails
- whether you separately agreed to measurement of opens and link clicks in those product emails
- whether your account is disabled because you told us that you ceased residing in the United States, when it was disabled, and when it was re-enabled
Your email address and the United States country declaration are required to create an account. Your name is optional. If you do not provide both required items, we cannot create the account.
Country and a move outside the United States. We ask which country you are in when you create an account because accounts and new acquisitions are offered only in the United States. Gift redemption and a zero-dollar upgrade are acquisition events, so we ask again immediately before each one rather than treating an old sign-up answer as current. We keep each answer with the event so that we can show we applied the restriction. A paid base purchase or upgrade instead uses the country in Paddle's payment details, described in section 6. The request-country check in sections 1 and 4.5 helps apply the acquisition boundary; we do not use it to infer that an existing account holder has moved, and temporary travel does not trigger disablement. If you tell us that you have ceased residing in the United States, we record the account-disable status and its time, disable authenticated backend account and licence services, reject future account-linked telemetry, and stop optional product marketing. The public identifier-free update endpoint and feedback you voluntarily submit remain available. We keep the account and licence data because the worldwide licence continues offline and the same account can be re-enabled if you later tell us that you reside in the United States again. We record the re-enablement time; we do not need your exact foreign address or country for this purpose. Re-enablement does not restart telemetry: Sonik asks for fresh analytics and crash-report choices.
Devices. When you sign in, the application generates a random identifier for that installation and registers it. Alongside it we store the name you give the device and your Windows major version. The identifier is a random value with no meaning outside your account. You can view and remove devices at any time on your account page, or unregister the one you're on from Sonik's settings. Either action deletes that device's record from your account.
Product emails. If you opt in at sign-up, we may use your name and email address to tell you about Sonik products and offers. This is off unless you choose it, and you can turn it off at any time from your account page or from the unsubscribe link in any such email. We don't pass your address to anyone else for their marketing. We stop optional product marketing when an account is disabled because its holder ceased residing in the United States. We may still send the administrative, privacy, security, legal, complaint, and other notices needed to administer the disabled account or required by law or the Terms.
Email measurement is a second, separate choice. You may receive product emails without agreeing to tracking. If you separately switch measurement on, we may record whether you opened one of these emails and whether you clicked a link in it, so that we can tell what is worth sending. To measure that, AhaSend may process the IP address and browser or mail-reader information attached to the open or click request. These engagement records follow the 12-month period in section 10. You can turn measurement off independently at any time; later product emails then contain no tracking. This applies only to product emails. Account emails — sign-in links, password resets, account notices — are never tracked this way.
Legal basis for product emails and, separately, their measurement: your consent. We keep and apply the account-disable status to stop optional marketing when the account is outside the market we service.
A report that a licensed user has died. Because the licence ends rather than transferring, support asks only for the least intrusive reliable evidence needed to prevent somebody maliciously ending another person’s licence. Unrelated fields may be redacted. We ask about the reporter only where needed to authenticate the report or resolve a dispute, and we do not ask for beneficiary or probate evidence as a condition. We do not disclose account information to the reporter. Material supplied only to verify the death is deleted when the decision is complete, unless it is needed for a related unresolved dispute. We retain a minimal decision record—the licence/account reference, effective end date, decision time, broad evidence-source type, and reviewer—for six years after the licence ends.
Contract-confirmation evidence. When a purchased licence begins, a paid or zero-dollar upgrade takes effect, or a gift is redeemed, we send the contracting person a confirmation with a dated PDF. A paid upgrade that has payment confirmation but is not yet safely associated receives a recovery notice, not its contract confirmation; the confirmation is sent when the upgrade takes effect. Separately from ordinary email logs, we keep the recipient address, send time, delivery or final-failure result, and the PDF version and hash for the life of that licence and six years after its final end. If the same licence is restored, its life continues and the earlier end does not start the six-year period. We archive each dated PDF version once for as long as a retained record identifies it. We do not keep a separate copy of the email or PDF for every recipient, and our email provider’s content storage remains off.
Deleting, disabling, or permanently closing your account. There's a delete button on your account page. If sign-in is disabled because you ceased United States residence, you can instead request deletion at privacy@soniksoft.com. After you delete the account, we keep its data for 30 days, purely so we can restore it if you change your mind, and then delete it permanently. An account disabled after its holder reports ceasing United States residence is different: it continues to exist and is retained while its worldwide licence continues, because already-activated offline use remains available and the same account may later be re-enabled. If we permanently close an account under the Terms of Service and that closure stands after the applicable contest process, its data enters the same 30-day deletion process. A verified death decision also starts that process for the deceased account holder, without the ordinary change-of-mind cancellation; support halts or corrects it if reliable evidence shows the determination was wrong. Records of paid transactions are kept for six years after the end of the accounting year the transaction falls in, as Georgian accounting law requires—so up to seven years from the transaction itself. Contract-confirmation evidence follows the separate licence-life-plus-six-years period above. In-app analytics and crash-report consent/end evidence remains for six months after account deletion. The separate product-email and measurement consent/withdrawal records, and the account-disable suppression record, are kept while relevant to the applicable activity and for one year after that activity stops.
Legal basis: before a licence is obtained, our legitimate interest in providing the account you requested, preparing a purchase or gift redemption, and securing the service, balanced by the account’s limited data and your control over deletion. While a licence contract is active, performance of that contract. During the 30-day process after deletion, a permanent closure that stands, or a verified account-holder death, our legitimate interest in completing deletion safely and consistently and preserving the limited evidence needed for restoration, a contest, correction of an erroneous death determination, or a claim. For contract-confirmation evidence, compliance with our legal confirmation and burden-of-proof duties and, after the licence ends, our legitimate interest in retaining limited evidence for compliance and legal claims.
6. Purchases and paid upgrades
Base purchases and paid upgrades are handled by Paddle, which acts as merchant of record — legally, Paddle is the seller and is responsible for the payment. When you open checkout, Paddle's script loads directly in your browser and receives the browser and network information needed for that interaction under Paddle's own policy. Your full card number and security code go directly to Paddle and never reach our servers.
From Paddle we receive what it takes to give you your licence or paid upgrade and to keep a lawful accounting record: your email address, your country, an order identifier, which product and tier you bought or upgraded to, the amount and currency, any tax charged, and the date. Paddle's confirmation may also carry your name, billing address, card brand, and last four digits. We discard those fields on receipt and do not store them; we never receive the full card number or security code.
The country here is the one your payment details place you in, and it is what determines the tax you are charged. It sits in the paid-transaction accounting record rather than in your account, and it is not the same thing as an eligibility country declaration under section 5.
If your payment details put you in a country where Sonik isn't sold, we do not issue the base licence or apply the paid upgrade, and we place the payment in our manual refund queue. For an ineligible paid upgrade, the existing tier and support deadline remain unchanged. We also recheck the purchaser and account information available to us when signed payment confirmation arrives. If those records show that another licence became active while a base-purchase checkout was open, we create no second entitlement, notify the payer, and place that payment in the same manual queue for refund through the original route.
How your purchase or paid upgrade reaches your account. We send Paddle no Sonik account identifier, user identifier, device identifier, correlation token, prefilled email address, or other Sonik-side reference. Information travels from Paddle to us instead. Normally, your signed-in browser return associates Paddle’s transaction with your account; after Paddle confirms payment, we send the base-licence or effective-upgrade record and contract confirmation to that account’s verified email. If the return is missed, the payment email may select an account only where that verified-email account has exactly one compatible pending pre-checkout record for the product, tier, and purchase window; the signed-in account holder confirms that they personally completed the transaction before attachment. If there is no unique compatible record or confirmation, we send the base-licence record and confirmation, or a pending-upgrade recovery notice, with a one-time recovery link to the Paddle email. The link is only for the same purchaser. A base licence may be attached only to an eligible United States account. If the purchaser ceases United States residence first, the licence and its minimal recovery record remain, but the claim must wait until the purchaser again resides in the United States. A paid upgrade remains pending until Paddle has confirmed payment and it is safely associated with that purchaser's identified eligible existing chain; only then do we send its contract confirmation to the account's verified email. We permit only one pending upgrade for a chain and use the price and retained-credit calculation recorded when checkout began. Before day 90, we send at least one reminder or replacement-link notice to the Paddle email and keep its delivery or final-failure result. If our failure prevented delivery of both a reminder and a working replacement link, we issue a working replacement and extend that pending state to day 120; otherwise day 90 is terminal. A cancellation is confirmed through an authenticated account tied to the chain or a one-time confirmation link sent only to the Paddle email, with same-purchaser confirmation. Fixed rules flag a valid cancellation, an upgrade still unassociated at its applicable day-90/day-120 deadline, or an earlier condition in which the effective chain ends, becomes ineligible, reaches the same or a higher tier, shrinks, or loses a payment included in the frozen credit. A person reviews the flagged record, applies the required entitlement outcome, and manually initiates any refund. A later base-purchase claim revealing another active same-product licence follows the same review and manual-refund process.
Refund instructions are the one outbound Paddle data flow. After a person reviews a refund case, they manually send Paddle its own order identifier and an instruction to refund through the original payment route. We send no Sonik account, user, licence, or device identifier with that instruction.
Automated flags and human decisions. The country, duplicate-licence, pending-upgrade, and deadline rules above can automatically flag a case, but a person reviews the case before the adverse entitlement result is treated as final and before any refund instruction is sent. The rules do not profile you or predict personal characteristics. If you think the result is wrong, email privacy@soniksoft.com. You can explain your position and contest it; another human review remains available where correction is still possible.
Paddle handles your payment data under its own privacy policy, at paddle.com.
Legal basis: performance of our contract with you for an eligible base purchase, recovery of its existing licence, or an associated eligible paid upgrade; our legitimate interest in safely associating transactions, applying the published country, existing-chain, and one-active-licence restrictions, notifying the payer, and returning an ineligible or orphaned payment; and compliance with our legal obligations for tax and accounting records.
7. The website
Analytics. We are trying to understand whether our pages explain the product well. We measure the event date, which pages people visit, an event's order within the visit, allow-listed buttons or links they click, a coarse time-on-page range, how they arrived, the path they take through the site, and whether a page version leads to a download or other conversion. We do not collect query strings, page titles, free-text form contents, user-agent strings, or browser, operating-system or device details in analytics. A referrer is reduced to its domain or a broad source category.
To connect events during one visit, we use a random session identifier that expires after 30 minutes of inactivity. To estimate unique browsers and recognize a returning browser within a short period, we use a separate random browser identifier. No later than 30 days after it was created, we delete its linked raw events and replace it without keeping an old-to-new mapping. These identifiers are not connected to an account, device registration, email address, access-log row, fingerprint, or information from another site. A person using several browsers or clearing site data may be counted more than once, so “unique visitors” is an estimate rather than a count of people. A/B page variants and conversions are connected to these identifiers for the same limited analytics purposes.
We do not run website analytics for visitors whose IP address places them in the European Economic Area or United Kingdom. Before analytics starts, our server checks the request against a locally held country lookup. We do not store the country result or IP address in analytics. The request may still appear in the separate 30-day security access logs described below.
If analytics applies to your visit, we tell you when you first arrive, in a small notice at the foot of the page, and you can switch analytics off from there. The same control stays available afterwards from our website footer and from this policy as it appears on our site. Visitors suppressed by the EEA/UK check are told briefly that analytics are off. Switch analytics off and we collect nothing beyond the server logs described below.
Your opt-out is stored in your browser. Turning analytics off deletes the analytics identifiers from that browser and the linked raw events on our server, and stops future collection. Earlier contributions to aggregate counts cannot be separated from everyone else's and expire on the schedule in section 10. Clearing your site data removes the opt-out, so analytics can turn back on if you are outside the EEA and UK.
We do not use Google Analytics, advertising pixels, or any third-party tracking service. Your analytics data stays on our own infrastructure.
Legal basis: our legitimate interest in understanding how our website is used, weighed against the short identifier and event periods, the absence of IP addresses and direct identifiers from analytics storage, our geographic suppression, and the opt-out.
Do Not Track. Some browsers can send a "Do Not Track" signal. If your browser sends it, we don't record your visit in analytics at all.
Other parties. No third party tracks what you do on this site, or follows you across other sites over time.
Checkout. Paddle's checkout script loads when you buy something and may set its own cookies, under Paddle's own privacy policy.
Download counts. We count how many times the application is downloaded. The tally records the date, the version and which link it came from.
Server logs. Separately from analytics, our web server records requests — including full IP addresses — as a normal part of running and securing the site, and to produce the download count above. They're the same logs described in section 4.5, kept for as long as section 10 says.
Legal basis: our legitimate interest in operating and securing the service.
8. Who else handles your data
Some of these companies process your data on our behalf. The others are independent controllers, and we have marked them because it changes who is answerable to you:
| Provider | What they handle | Primary storage/service location | Acting as |
|---|---|---|---|
| Hetzner | Our servers — the account database, sign-in, licence checks, telemetry, feedback, website, update file, privacy/compliance records, deletion-protection journal, and encrypted backups | Germany | Our processor |
| AhaSend | Our email — address confirmation, password resets, sign-in links, contract and account notices, and product emails if you opted in | Netherlands | Our processor |
| Infomaniak | Our own mailboxes, including support and privacy correspondence | Switzerland | Our processor |
| Paddle | Payments and billing | United Kingdom / United States | Independent controller |
| Microsoft | Distribution and updates, if you installed Sonik from the Microsoft Store | Varies | Independent controller |
| The sign-in provider you choose, if you use one | Proving you are you, at sign-up and sign-in — see below | Varies | Independent controller |
Our processors act on our instructions and under written data-protection terms for the services within those agreements' scope. Their legal entities and contact addresses are: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany; AhaSend B.V., Willem Fenengastraat 16, 1096 BN Amsterdam, Netherlands; and Infomaniak Network SA, Rue Eugène-Marziano 25, 1227 Acacias, Geneva, Switzerland.
The three independent controllers are different, and worth understanding. Paddle is the legal seller for the purchase, while Sonik grants the licence under the separate Terms of Service. Paddle therefore collects your payment details from you directly, decides for itself how to handle them, and answers to you under its own privacy policy. Microsoft, for Store installations, likewise collects its own data under its own privacy statement. A sign-in provider does the same for the sign-in itself.
Signing in with an existing account. Rather than make you invent another password, we let you sign in through providers you may already use — currently Apple, Google, GitHub, Microsoft, Discord, Facebook, Twitch, GitLab, Bitbucket, LinkedIn, Slack, Notion, Figma, Spotify, Twitter/X, Zoom, and Kakao. The list follows what our sign-in software supports and may gain or lose entries over time; the ones actually offered are the ones shown on the sign-in screen.
We use each sign-in integration for one purpose only: proving you are you, at sign-up and sign-in. Choosing one tells that provider you have signed in to Sonik, and returns to us the email address and name it holds for you. The provider may process that interaction for its own security, compliance, and other purposes as an independent controller under its privacy policy. You can sign in with an email address and password, or a magic link, instead.
We do not sell personal information, and we do not share it with advertisers or data brokers.
Business correspondence. If you write to us as a contact at a provider, counterparty, or public body, we keep your name, business email address, role or title, message content, and any relevant account, client, or registration number. We use that information to manage the relationship, handle invoices, and keep the evidence behind our legal and compliance work. Infomaniak holds the mailbox and Hetzner holds anything filed on our own systems, in the locations shown above. Our legal basis is our legitimate interest in running the company and preserving proportionate compliance evidence; where the correspondence forms part of an accounting record, we also process it to comply with Georgian accounting law. Section 10 gives the retention periods.
9. Where your data is stored
Our company is in Georgia — the country — and our primary storage and service locations are in Europe. Your account and licence records live on our own servers in Germany; the emails that confirm your address or reset your password are sent from the Netherlands; our encrypted backups are held in Germany; and our own mailboxes are in Switzerland. For practically all our customers, that means your data is stored outside your home country.
The processors in section 8 are bound by written data-protection terms for the services within those agreements' scope.
Georgian law requires a permitted safeguard before we transfer personal data abroad. For our current processor locations, we rely on the official list of countries recognised as offering adequate protection. Germany, the Netherlands and Switzerland are all on that list.
We don't store your data on systems in Georgia. What connects it to Georgia is us: we run the company from there, and we administer those servers from there.
For data protected by the EU or UK GDPR, that administration can involve our European processors making personal data available to us in Georgia. We have accepted that transfer risk without putting a separate processor-to-controller SCC or UK transfer safeguard in place.
Three independent-controller interactions sit outside that European picture. We send no Sonik account or device data for checkout, sign-in, or Store distribution. The provider still receives the request and browser or network information needed for the interaction you initiate. A refund is the separate exception described in section 6: we send Paddle its own order identifier and the refund instruction.
Paddle, which is the seller for your purchase, uses its US company for buyers in the United States. Sonik grants the licence under the separate Terms of Service. You give Paddle your payment details directly in its own checkout window. We receive the fields listed in section 6. We return only Paddle's order identifier and an instruction when a refund is required; we send no Sonik account or device identifier.
The United States is not on Georgia's adequacy list, and we do not hold a Georgian Article 37(3) transfer permit for that manual refund instruction.
The sign-in provider you choose, if you use one, is the same shape. You authenticate with Apple, Google or whoever it is, on their systems; they tell us your email address and name. Many are US companies. We send no Sonik account or device data; the provider receives the sign-in request and ordinary browser/network information.
Microsoft, if you installed from the Store, likewise collects its own data directly from you. We send it nothing.
10. How long we keep things
| What | How long |
|---|---|
| Account and licence data | While your account exists, including while disabled after a move outside the United States; then 30 days after deletion or permanent closure |
| Paid-transaction accounting records | 6 years after the end of the accounting year — up to 7 years in practice |
| Minimal paid-transaction recovery records | For an unattached base licence, until attachment or valid end; for a pending paid upgrade, until safe association or a human-reviewed cancellation/end and manually initiated refund, with review flagged at day 90 or, if our notice-delivery failure triggers the fixed cure, day 120 |
| Contract-confirmation delivery evidence | Life of the purchased, gifted, or upgraded licence chain, then 6 years after its final end; restoration cancels an earlier end-based deletion date; each identified PDF version is archived for at least as long |
| Server access logs, including IP addresses — website and app alike | 30 days |
| Usage analytics and crash reports | 6 months, if you opted in |
| Accepted telemetry waiting in the encrypted local payload queue | Up to 7 days; cleared earlier on withdrawal, licensing, account disablement or deletion, telemetry deletion, deletion of all local data, or uninstall |
| In-app analytics and crash-report consent and end evidence | While accepted submissions continue; after they end, 6 months from the applicable end event: withdrawal, trial-telemetry deletion, trial-identifier retirement, account disablement or deletion, or—if none is received—the last submission |
| Linked website analytics events and identifiers | 30 days |
| Aggregate website analytics | 6 months |
| Download counts | Kept indefinitely — they are totals, with nothing in them to expire |
| Support and feedback conversations, attached diagnostic logs, and Feedback Submission Terms acceptance/confirmation evidence | 24 months after the conversation ends — longer where a dispute or complaint is unresolved |
| Records of privacy requests | Until the later of 24 months after receipt and the end of the active request or related correspondence; verification-only material is deleted when it is no longer needed |
| Business correspondence | Until the later of 24 months after receipt and the end of the active correspondence; accounting documents follow their separate statutory period |
| Ordinary AhaSend delivery logs and metadata | 30 days — the separately listed confirmation and recovery evidence follows its own period |
| Per-recipient message content stored by AhaSend | Not retained after delivery or final failure — support correspondence and canonical legal-document versions follow their separate periods |
| Evidence supplied only to verify a licensed user’s death | Until the verification decision is complete; longer only while a related dispute is unresolved |
| Minimal licensed-user-death decision record | 6 years after the licence ends |
| Product-email engagement records, including opens, clicks, and associated request IP/browser or mail-reader information, if you separately opted in to measurement | 12 months |
| Records of product-email and measurement consent/withdrawal, and account-disable suppression | While relevant to the applicable sending or measurement activity, then 1 year after that activity stops |
| Paid-transaction claim links | Up to 30 days, and never beyond a pending upgrade's applicable day-90/day-120 deadline — we send at least one reminder or replacement-link notice before day 90; support may reissue only to the same Paddle email while the applicable recovery record remains |
| Pending-upgrade cancellation-confirmation links | Until first use, 30 days after issue, or the pending upgrade ends—whichever happens first; never beyond its applicable day-90/day-120 deadline |
| Our register of personal data incidents (section 13) | 24 months |
| Backups | Up to 30 days |
| Pseudonymous deletion-protection record — keyed hash of the account identifier and deletion timestamp | 12 months after final account deletion |
| Transcripts, recordings, local logs | Yours to set — 7 days, 1 hour and off by default (section 3); Sonik does not upload recording or transcript files, but a diagnostic log you attach or a previewed crash report you send can contain a best-effort-scrubbed fragment |
We don't track opens or clicks in account emails. Product emails are measured only if you separately opted in to measurement — see section 5.
The archived confirmation PDFs are legal-document versions kept once, not retained copies of each email or attachment sent to each person.
Data you've asked us to delete may still exist in a backup until that backup expires. Because account deletion has a 30-day grace period and backups can last another 30 days, a deleted account can remain in a backup for up to about 60 days from your request. We don't use backups to bring deleted data back; reapplying deletions is part of any restore.
After final account deletion, the pseudonymous deletion-protection record lets us reapply that deletion if we restore an older backup. It uses a keyed hash whose key is held separately, and contains no readable account identifier or other account data. We keep it on our legitimate interest in making deletion reliable, and use it for no other purpose.
11. Your rights
You can ask us to:
- confirm whether we process personal data about you and explain that processing
- give you a copy of the personal data we hold about you
- correct anything that's wrong
- delete your data
- block our use of it
- send your data to another provider in a portable format, where that is technically feasible
- withdraw consent you previously gave — for in-app analytics, crash reports, product emails, or measurement of product-email opens and clicks — which stops that use from then on
- obtain human review of, express your view about, and contest a decision based solely on automated processing that has a legal or similarly significant effect on you
Disabling an account or stopping backend services does not limit any privacy right that applicable law gives you. You may continue to make a privacy request by email while the account is disabled.
For trial telemetry, Sonik's privacy settings show the random telemetry identifier and provide export and deletion controls while that identifier remains on the installation. We use possession of that unguessable identifier to locate the trial telemetry without learning or creating an account identity. The deletion control turns analytics and crash reporting off, deletes queued and submitted telemetry, and leaves only the consent and withdrawal evidence for six months. An account request cannot locate earlier trial telemetry because we deliberately never create that mapping.
Deleting all local data is different from using that dedicated telemetry control. Sonik offers server deletion whenever a trial identifier exists, but local deletion remains available offline. If the server request fails or its result is uncertain, you can retry, cancel, or continue. If you proceed without confirmed server deletion, the removed random identifier cannot later be used to locate submitted trial telemetry; those records expire within six months. After confirmed server deletion, the payloads are gone but the minimal consent and withdrawal evidence remains for six months. The same offer and warning appear before licensing retires a trial identifier.
For website analytics, the website privacy control similarly uses possession of the current random browser identifier. It lets you export or delete the linked raw events, or block future analytics. Identifier replacement deletes the outgoing identifier's linked events before the old identifier is removed, so no inaccessible earlier generation remains on the server. Aggregate counts cannot be separated by visitor and expire after six months.
Email privacy@soniksoft.com. We'll answer within 10 working days, the limit Georgian law sets for us, and a decision on a request to block processing reaches you within 3 working days. On a request to see or copy your data, the law lets us take a further 10 working days where the request is genuinely complicated; we'll tell you if we need them. Before we hand over or delete personal data we need to be reasonably sure the request comes from the person it concerns, so we may ask you to confirm who you are.
We keep the request, the address it came from, the related correspondence, and what we did so that we can administer the request and show that we met our legal duties. Our legal basis is compliance with those duties. Section 10 gives the retention rule and the shorter rule for verification-only material.
Cost. We don't charge for reasonable requests. Georgian law allows us to decline where someone makes an unreasonable number of requests; for repeated access or copy requests, it also allows a reasonable fee in the circumstances it specifies. If we refuse a request, we explain the reason and how to appeal.
Complaints. You can complain about us to our supervisory authority, the State Audit Office of Georgia, or to a court. If your own country has a privacy regulator you can complain to it instead, or as well. You don't have to come to us first, though we'd appreciate the chance to put things right.
12. Age
Sonik is available only to adults aged 18 or older, including the free trial, accounts, licences, gift redemption, and feedback. We do not routinely ask for or store age or date of birth. If you believe somebody under 18 has given us personal data, write to privacy@soniksoft.com and we will investigate and delete it where appropriate.
13. Security
Traffic between Sonik, our website and our servers is encrypted. Passwords are stored so that we cannot read them. Our backups are encrypted.
If something goes wrong. We keep a record of incidents affecting personal data because Georgian law requires us to document them.
Telling the regulators. Where an incident puts personal data at risk we notify the State Audit Office of Georgia within 72 hours of identifying it, as Georgian law requires — that one happens wherever you live, because it is our own supervisory authority.
Beyond that, we notify any other regulator the law requires us to notify, on its timetable and to its threshold. Which regulators those are depends on who was affected and where they live.
Telling you. We notify affected people whenever applicable law requires it or a breach is likely to put them at real risk. We contact you directly where we hold contact details and use a legally permitted public or substitute notice where we do not, without undue delay and with the information the applicable law requires.
14. When your data might go somewhere you didn't choose
Two situations worth naming.
If we're legally compelled. We're a Georgian company and we have to comply with valid orders from Georgian courts and authorities, and from others where they have jurisdiction over us or over one of the providers in section 8. If we receive one, we will:
- check that it is valid and genuinely binds us, and push back where we believe it doesn't
- disclose only what the order specifically demands
- tell you it happened, unless we're legally barred from doing so — and then tell you as soon as that bar lifts
An order can reach the data we actually hold, described in sections 4 to 10. Depending on its scope, that could include account, licence and purchase records; messages you sent us; telemetry you enabled; server and website records; and our privacy and compliance records. It does not include the local recording or transcript files described in sections 2 and 3: we hold no copy of those files, so an order to produce them from our systems would find nothing to produce.
If the business changes hands. If Sonik Software LLC is sold, merged, or reorganised, the data described in this policy that is needed to continue or transfer the product and business may pass to the successor. Our legal basis is our legitimate interest in completing that change while preserving the service, records, and rights attached to it, subject to applicable law. We would email account holders before the transfer took effect.
15. Changes to this policy
We keep a dated revision history at the foot of this page, and the effective date at the top always reflects the current version.
If we make a change that materially affects how we handle your data, we'll email account holders before it takes effect. If it changes in-app analytics or crash reporting, Sonik shows the new notice and asks for fresh choices before further collection. If it changes website analytics, the website shows the revised notice before further analytics collection. Minor clarifications and corrections get a new date and a revision entry, without an email.
16. Contact
Questions, requests, or complaints about privacy:
Privacy Officer: Hans Peter Buhr, Director
Sonik Software LLC
10/2 Levan Iosebidze Str.
3700 Rustavi, Georgia
He is the person accountable for how Sonik handles personal data, and the person who answers the address above. “Privacy Officer” is our voluntary internal accountability role. It is not a personal data protection officer appointment under the Law of Georgia on Personal Data Protection, and we have not made one.
Revision history
INTERNAL — not for publication. This document has never been published, so there is no public history yet. On the day it goes live, delete this notice and start the table beneath it with a single "First version" row carrying the publication date. Section 15's promise of a dated revision history applies from that point forward. Delete the draft notice at the top of the document at the same time, and drop "— draft" from the title.
Moved out on 17 August 2026, so that neither can be published from here by accident: the pre-publication drafting log, now a compressed dated summary at the foot of
privacy-policy/privacy-policy-rationale.md; and the unresolved claims this text makes, nowprivacy-policy/privacy-policy-open-items.md.privacy-policy/privacy-policy-open-items.mdis blocking — read it before publishing, not after.
| Date | Change |
|---|