Do Not Sell or Share My Personal Information
Nothing here to opt out of.
Sonar does not sell or share personal information, and never has. There is no buyer, no ad product, and no revenue line that would make building one worth it.

Where the money comes from.
Subscriptions, paid by the workspace whose data Sonar holds. That is the whole list.
Workspace subscriptions
All of it
Sale of personal information
$0
Advertising and ad targeting
$0
Data brokerage or enrichment
$0
Every company that touches it, and what it sees.
Service providers · barred from their own use
Does
Claude is one of the two AI models that write your morning brief, summarise meetings and answer questions in Ask Sonar. We never send the contents of any message — only the structural facts (who, when, how often). Emails, phone numbers, and risky phrases are stripped before anything reaches the model. Anthropic's business terms say it does not train its models on data sent through its API by default.
Can see
- Activity metadata: timestamps and event types — never message content
- Signal summaries written in plain English (e.g. 'PR open 9 days, no review')
- First names and job titles for personalization
- Meeting transcripts — only when you explicitly invite the meeting bot to a call
Does
An OpenAI model is the other AI model that writes your morning brief, summarises meetings and answers questions in Ask Sonar (Anthropic Claude is used as the backup). Same rules as above: never message content, and emails, phone numbers and risky phrases are stripped first. OpenAI's published API terms say data sent through the API is not used to train its models unless the customer opts in, and that it keeps API request logs for up to 30 days for abuse monitoring.
Can see
- Activity metadata: timestamps and event types — never message content
- Signal summaries written in plain English (e.g. 'PR open 9 days, no review')
- First names and job titles for personalization
- Meeting transcripts — only when you explicitly invite the meeting bot to a call
Does
Transactional + opt-in email delivery for morning briefs, invitations, and export-ready notifications. Bounces + complaints feed our suppression list.
Can see
- Recipient email address and first name
- Email subject and body (the brief itself)
- Delivery status — arrived, bounced, or marked spam
Does
Billing and subscription management. Your card number goes directly to Stripe — Sonar never sees it, stores it, or has access to it.
Can see
- Your organization name and billing email
- Subscription plan and seat count
- Invoice amounts and payment status
Does
Product analytics — event names so we can see which features are used (e.g. "first brief sent", "integration connected"). Never message text. Browser-side capture (URL path, user agent, truncated IP) is gated on the cookie-consent banner.
Can see
- Event names — what action was taken, not what was said (e.g. 'first brief sent')
- Org ID and user ID — no email, no name
- Structural properties — integration type, seat count
Does
Where the Sonar website and app actually run. Server logs are kept seven days and never contain message content.
Can see
- Web request logs (page visited, response code, IP — never message content)
Does
Speech-to-text for the meeting bot. Used only when an admin enables the meeting bot and a host invites it to a call. Audio is streamed to Deepgram, transcribed, and discarded after we receive the text.
Can see
- Meeting audio (only when meeting bot is invited to a call)
- Resulting transcript (returned to Sonar; not retained by Deepgram beyond their stated processing window)
Does
Object storage for short-lived encrypted meeting-bot audio blobs and customer data exports. Buckets are private; only Sonar can read them.
Can see
- Encrypted audio blobs (deleted after transcription completes)
- Customer data export bundles (auto-deleted after seven days)
Sonar also reads from the tools your workspace connects — Slack, GitHub, Google Calendar and any others you add. They are data sources, not service providers: Sonar reads from them and sends nothing back, so nothing about your team is disclosed to them.
Service-provider transfers are excluded from the CCPA definition of a sale: each one is contractually barred from using the data for its own purposes, including model training. The same list, with links to each company’s policy, is published at /privacy#subprocessors.
The statutory answer.
Cal. Civ. Code §§ 1798.120 · .121 · .130 · .140
What a sale means
Disclosing personal information to a third party for money or other valuable consideration (§1798.140(ad)). No third party has ever paid us, in money or in kind, for anything about your team. Sonar does not sell or share personal information.
Never occurred
What sharing means
Disclosure for cross-context behavioural advertising (§1798.140(ah)). Sonar runs no ad business, buys no inventory, and embeds no ad trackers in the product or on this site. That is why there is no opt-out switch on this page: an opt-out would imply something is running that you could stop.
No ad business exists
Service providers
The companies above are service providers under §1798.140(ag). They handle the data only to perform the contracted service and are contractually prohibited from using it for their own purposes. Integrations you connect are data sources, not subprocessors: Sonar reads from them and sends nothing back.
8, all published
Your other rights
- Know what we have collected about you in the last 12 months — the data export at /me.
- Delete it — from /me. Thirty-day grace period, cancellable.
- Correct it — your profile is editable; signal-level disputes go through /me/disputes.
- Limit use of sensitive personal information — Sonar collects none as defined by §1798.140(ae): no government ID, no precise geolocation, no biometrics, no health data, no race, ethnicity or religion. There is nothing to limit.
- Non-discrimination — we will never deny service, charge differently, or give you a worse product for using any of these rights.
Live in the product
Authorized agents
You may use an authorized agent to submit a request for you. We will ask the agent for written authorization signed by you, and may verify your identity directly. Email privacy@sonarwork.com to start.
Written authorization
How we answer
We acknowledge a request within 10 business days and substantively respond within 45 days, as §1798.130(a)(2) requires. For someone with an active Sonar account, signing in is enough to verify identity; without one, we may ask you to confirm an email address that matches data we hold.
45 days, in writing
Send one line. We answer in writing.
No portal, no form, no identity hoops. Your work email is enough to find the account.
Last updated . The full privacy policy is at /privacy.