Sonar
Signals
Get early access
SignalsWhat Sonar watches for
Get early access

Do Not Sell or Share My Personal Information

Nothing here to opt out of.

Sonar does not sell or share personal information, and never has. There is no buyer, no ad product, and no revenue line that would make building one worth it.

File the request anywayWhat we do hold

Where the money comes from.

Subscriptions, paid by the workspace whose data Sonar holds. That is the whole list.

Workspace subscriptions

All of it

Sale of personal information

$0

Advertising and ad targeting

$0

Data brokerage or enrichment

$0

Every company that touches it, and what it sees.

Service providers · barred from their own use

Anthropicus

Does

Claude is one of the two AI models that write your morning brief, summarise meetings and answer questions in Ask Sonar. We never send the contents of any message — only the structural facts (who, when, how often). Emails, phone numbers, and risky phrases are stripped before anything reaches the model. Anthropic's business terms say it does not train its models on data sent through its API by default.

Can see

  • Activity metadata: timestamps and event types — never message content
  • Signal summaries written in plain English (e.g. 'PR open 9 days, no review')
  • First names and job titles for personalization
  • Meeting transcripts — only when you explicitly invite the meeting bot to a call
OpenAIus

Does

An OpenAI model is the other AI model that writes your morning brief, summarises meetings and answers questions in Ask Sonar (Anthropic Claude is used as the backup). Same rules as above: never message content, and emails, phone numbers and risky phrases are stripped first. OpenAI's published API terms say data sent through the API is not used to train its models unless the customer opts in, and that it keeps API request logs for up to 30 days for abuse monitoring.

Can see

  • Activity metadata: timestamps and event types — never message content
  • Signal summaries written in plain English (e.g. 'PR open 9 days, no review')
  • First names and job titles for personalization
  • Meeting transcripts — only when you explicitly invite the meeting bot to a call
Resendus

Does

Transactional + opt-in email delivery for morning briefs, invitations, and export-ready notifications. Bounces + complaints feed our suppression list.

Can see

  • Recipient email address and first name
  • Email subject and body (the brief itself)
  • Delivery status — arrived, bounced, or marked spam
Stripeglobal

Does

Billing and subscription management. Your card number goes directly to Stripe — Sonar never sees it, stores it, or has access to it.

Can see

  • Your organization name and billing email
  • Subscription plan and seat count
  • Invoice amounts and payment status
PostHogus

Does

Product analytics — event names so we can see which features are used (e.g. "first brief sent", "integration connected"). Never message text. Browser-side capture (URL path, user agent, truncated IP) is gated on the cookie-consent banner.

Can see

  • Event names — what action was taken, not what was said (e.g. 'first brief sent')
  • Org ID and user ID — no email, no name
  • Structural properties — integration type, seat count
Vercelus

Does

Where the Sonar website and app actually run. Server logs are kept seven days and never contain message content.

Can see

  • Web request logs (page visited, response code, IP — never message content)
Deepgramus

Does

Speech-to-text for the meeting bot. Used only when an admin enables the meeting bot and a host invites it to a call. Audio is streamed to Deepgram, transcribed, and discarded after we receive the text.

Can see

  • Meeting audio (only when meeting bot is invited to a call)
  • Resulting transcript (returned to Sonar; not retained by Deepgram beyond their stated processing window)
Cloudflare R2global

Does

Object storage for short-lived encrypted meeting-bot audio blobs and customer data exports. Buckets are private; only Sonar can read them.

Can see

  • Encrypted audio blobs (deleted after transcription completes)
  • Customer data export bundles (auto-deleted after seven days)

Sonar also reads from the tools your workspace connects — Slack, GitHub, Google Calendar and any others you add. They are data sources, not service providers: Sonar reads from them and sends nothing back, so nothing about your team is disclosed to them.

Service-provider transfers are excluded from the CCPA definition of a sale: each one is contractually barred from using the data for its own purposes, including model training. The same list, with links to each company’s policy, is published at /privacy#subprocessors.

The statutory answer.

Cal. Civ. Code §§ 1798.120 · .121 · .130 · .140

Contents

  1. 01What a sale means
  2. 02What sharing means
  3. 03Service providers
  4. 04Your other rights
  5. 05Authorized agents
  6. 06How we answer
01

What a sale means

Disclosing personal information to a third party for money or other valuable consideration (§1798.140(ad)). No third party has ever paid us, in money or in kind, for anything about your team. Sonar does not sell or share personal information.

Never occurred

02

What sharing means

Disclosure for cross-context behavioural advertising (§1798.140(ah)). Sonar runs no ad business, buys no inventory, and embeds no ad trackers in the product or on this site. That is why there is no opt-out switch on this page: an opt-out would imply something is running that you could stop.

No ad business exists

03

Service providers

The companies above are service providers under §1798.140(ag). They handle the data only to perform the contracted service and are contractually prohibited from using it for their own purposes. Integrations you connect are data sources, not subprocessors: Sonar reads from them and sends nothing back.

8, all published

04

Your other rights

  • Know what we have collected about you in the last 12 months — the data export at /me.
  • Delete it — from /me. Thirty-day grace period, cancellable.
  • Correct it — your profile is editable; signal-level disputes go through /me/disputes.
  • Limit use of sensitive personal information — Sonar collects none as defined by §1798.140(ae): no government ID, no precise geolocation, no biometrics, no health data, no race, ethnicity or religion. There is nothing to limit.
  • Non-discrimination — we will never deny service, charge differently, or give you a worse product for using any of these rights.

Live in the product

05

Authorized agents

You may use an authorized agent to submit a request for you. We will ask the agent for written authorization signed by you, and may verify your identity directly. Email privacy@sonarwork.com to start.

Written authorization

06

How we answer

We acknowledge a request within 10 business days and substantively respond within 45 days, as §1798.130(a)(2) requires. For someone with an active Sonar account, signing in is enough to verify identity; without one, we may ask you to confirm an email address that matches data we hold.

45 days, in writing

Send one line. We answer in writing.

No portal, no form, no identity hoops. Your work email is enough to find the account.

privacy@sonarwork.com

Last updated 27 April 2026. The full privacy policy is at /privacy.

Sonar

The morning brief that tells you who on your team needs a conversation — before it’s too late.

Sonar

  • How it works
  • The 17 signals
  • Contact

Get the brief

Invite only right now. Free for up to 4 people, no card.

Get early access →

© 2026 Sonarwork, Inc.

PrivacyDo Not Sell