01
Who we are
Sonar (“Sonar”, “we”, “us”) operates the Sonar manager-intelligence platform that helps managers see where their teams need attention. The data controller for customer-workspace data is the customer organization that installed Sonar; Sonar acts as data processor on the customer’s behalf.
Contact for privacy questions: privacy@sonarwork.com
02
What we collect, and why
Sonar collects collaboration metadata from the integrations your workspace connects. The examples below cover the most common ones — new integrations follow the same rule: metadata in, message text never. Specifically:
- Slack (and similar messaging tools): message timestamps, channel ids (hashed), reaction events, message length and presence of thread/question marks. Never message text or attachments.
- Google Calendar (and similar calendar tools): meeting count, duration, attendee emails. Never event titles, descriptions, or attachments by default.
- GitHub (and similar code platforms): pull-request open / merge / review events, file-count + line-count totals, CI workflow status. Never diff contents, commit messages, or issue body.
- Meeting bot (opt-in only): when an admin enables it and a meeting host invites the Sonar bot, the audio is sent to Deepgram for transcription and the transcript + meeting title is sent to one of our AI providers (Anthropic or OpenAI, see the subprocessors below) for the meeting summary. Off by default; never silent.
We also collect account profile data (your name, email, role within the workspace, OAuth tokens for the connected services) and product analytics (page views, feature usage, click events) to improve the product.
The legal basis under GDPR is legitimate interest (helping managers run their teams effectively) for collaboration metadata, and consent for product analytics. You can withdraw consent for analytics at any time without affecting the core service.
03
How we use your data
- Generate signals + briefs: the metadata is transformed by signal evaluators (deterministic code) and an LLM (from Anthropic or OpenAI) into a brief that lands in the manager’s inbox each weekday morning (configurable per workspace).
- Our AI providers do not train on your data. Anthropic and OpenAI process a request only to return an answer. Their business terms say they do not train on data sent through their APIs unless a customer opts in. OpenAI keeps API request logs for up to 30 days for abuse monitoring.
- Detect bias: we monitor signal precision per cohort (role, tenure) to ensure no group is systematically mis-served.
- Improve the product: aggregate (non-identifying) metrics inform our roadmap.
We do not sell your data, do not use it for advertising, and do not share it with third parties beyond the subprocessors listed below.
04
Subprocessors (8)
These are every company Sonar sends your data to, what they do with it, and where they hold it.
Claude is one of the two AI models that write your morning brief, summarise meetings and answer questions in Ask Sonar. We never send the contents of any message — only the structural facts (who, when, how often). Emails, phone numbers, and risky phrases are stripped before anything reaches the model. Anthropic's business terms say it does not train its models on data sent through its API by default.
- OpenAI ↗us
An OpenAI model is the other AI model that writes your morning brief, summarises meetings and answers questions in Ask Sonar (Anthropic Claude is used as the backup). Same rules as above: never message content, and emails, phone numbers and risky phrases are stripped first. OpenAI's published API terms say data sent through the API is not used to train its models unless the customer opts in, and that it keeps API request logs for up to 30 days for abuse monitoring.
- Resend ↗us
Transactional + opt-in email delivery for morning briefs, invitations, and export-ready notifications. Bounces + complaints feed our suppression list.
- Stripe ↗global
Billing and subscription management. Your card number goes directly to Stripe — Sonar never sees it, stores it, or has access to it.
Product analytics — event names so we can see which features are used (e.g. "first brief sent", "integration connected"). Never message text. Browser-side capture (URL path, user agent, truncated IP) is gated on the cookie-consent banner.
- Vercel ↗us
Where the Sonar website and app actually run. Server logs are kept seven days and never contain message content.
Speech-to-text for the meeting bot. Used only when an admin enables the meeting bot and a host invites it to a call. Audio is streamed to Deepgram, transcribed, and discarded after we receive the text.
- Cloudflare R2 ↗global
Object storage for short-lived encrypted meeting-bot audio blobs and customer data exports. Buckets are private; only Sonar can read them.
We notify customers 30 days before any subprocessor is added or changed.
Data sources (3)
Sonar reads from the tools your workspace connects — Slack, GitHub, Google Calendar and any others you add. Nothing is sent back to them, and your company agreed terms with them directly, so they are data sources rather than subprocessors under GDPR Art. 28.
05
Data retention
Default retention windows (configurable per workspace):
- Activity events (raw metadata): 90 days
- Signal events: 365 days (cleared/dormant signals); surfaced + rated signals retained as audit trail
- Meeting transcripts (when meeting bot is enabled): 90 days
- Briefs: indefinite (the manager’s historical record)
On account deletion (see Section 7), we hard-delete all of your data within 30 days of the request, preceded by a 30-day grace period during which you can cancel.
06
International transfers
Sonar’s primary infrastructure is hosted in the United States. If you are accessing Sonar from the EEA or UK, your personal data will be transferred to the US under the EU-US Data Privacy Framework. All of our subprocessors (listed in Section 4) are either certified under the framework or rely on Standard Contractual Clauses. A Data Processing Agreement is available on request.
07
Your rights
Whether under GDPR, CCPA, or similar laws, you have the right to:
- Access the data we hold about you — at /me you can see everything in real time.
- Export your data in a portable JSON/CSV format — request from /me; delivered within 72 hours.
- Correct inaccurate data — your profile fields are editable; signal-level disputes go through /me/disputes.
- Delete your data — at /me you can ask for your data to be deleted. Your manager or a workspace admin can approve it straight away; if nobody does, it is deleted automatically after 30 days. You can cancel until then.
- Pause processing — ask to stop new data collection without deletion. It stops once your manager or a workspace admin approves.
- Object to processing — ask to switch off one tool without affecting the others, approved the same way.
- Lodge a complaint with your data protection authority — for EU residents, contact your country’s supervisory authority.
For California residents specifically: see our Do Not Sell or Share page. Sonar does not sell personal information.
08
Security
We encrypt data in transit (TLS 1.3) and at rest. Sensitive fields and OAuth tokens are sealed with AES-256-GCM at the application layer. Access is restricted to authenticated employees with role-based permissions; every admin action is logged in an append-only audit trail with chained hashes. An internal red-team operates today. An external penetration test and a SOC 2 Type I audit are both planned: we will name the auditor and the dates here once they are booked, and we will not claim either until it is finished.
09
Children's privacy
Sonar is a workplace tool intended for use by adults aged 18 and older. We do not knowingly collect data about anyone under 16. If we learn we have collected such data, we will delete it.
10
Changes to this policy
We will notify customers 30 days before any material change to this policy via email and an in-app banner. The date this version took effect is at the top of this page.
11
Contact
Privacy questions, data-subject requests, or complaints: privacy@sonarwork.com. For EU residents we will respond within 30 days as required by GDPR Art. 12(3).
