Trust
What Sonar reads, what it keeps, and who sees it.
Sonar works from metadata: who did something, and when. It never keeps what anyone wrote. The lists below come from Sonar’s own code, and a test fails if the code starts keeping something this page does not mention.
None
Words of any message kept
90 days
Then activity records are deleted
30 days
The longest a deletion can wait
01
What Sonar reads
The timing of work, not the work itself. From each tool Sonar takes the events it needs: that a message was posted, that a pull request was reviewed, that a meeting took place.
- Slack: Timing and participants of messages.
- GitHub: Pull request, review and merge cadence.
- Google Calendar: Meeting times and lengths.
- Linear: Ticket movement and cycle time. Built, and switched on when you ask.
One source is enough to start, and this is not the whole list. More are built, and we turn them on for your workspace when you ask.
02
What it never reads
- The text of any message, in any tool
- Code, diffs and commit messages
- The words in pull requests, reviews, issues and comments
- Meeting titles, descriptions, locations and notes
- The text of documents, pages and tickets
- Direct messages in Slack, including group direct messages
How that holds. Slack and GitHub send each event with the words in it. The moment an event arrives, Sonar keeps only the fields listed in section 03 and drops the rest, before anything is saved. From a Slack message it keeps how long the text was and who it @-mentioned, then drops the text. Nothing later in Sonar can read words that were never saved.
The one exception. The meeting notetaker records and transcribes the meetings it joins. It is off unless your company turns it on, it is invited to each meeting separately, and anyone in the meeting can say no. The privacy policy has the details.
03
What it keeps, and for how long
Slack
Kept
- Who posted, replied or reacted, and when
- Which conversation it was in, as an id, never its name
- Whether that was a public or a private channel
- Whether a message started a thread or replied in one
- For a reply: who started the thread it is in, as an id
- How long a message was, in characters
- Who a message @-mentioned
- The kind of message, such as an edit, a join or a post by a bot
- For a reaction: which emoji, and whose message it was on
- The workspace, and Slack's ids for each message, so nothing is counted twice
Never kept
- The text of any message, reply or edit
- Files, images and link previews
- Channel names and topics
- Direct messages, including group direct messages. Sonar does not ask Slack for them.
GitHub
Kept
- Who opened, reviewed, merged or pushed, and when (their GitHub account)
- A pull request's number, state and size: lines added and removed, files changed
- Whether it is a draft, and who was asked to review it
- Review verdicts: approved, changes requested, or a comment
- Which repository, as an id, and whether it is private
- Branch names
- The folders a push touched, two levels deep (such as src/auth), and the names of files at the top of the repository
- How many commits a push held, and how many were merges
- That an issue or a comment was opened, by whom and when
- Whether a CI run passed or failed
Never kept
- Code, diffs and commit messages
- Titles and descriptions of pull requests and issues
- The words in reviews and comments
- Full file paths, and the names of files inside folders
Google Calendar
Kept
- When a meeting started and how long it ran
- How many people were invited
- Whether it repeats
- Whether each person from your company accepted, declined or did not answer
- Out-of-office blocks, so time off is not mistaken for someone going quiet
Never kept
- Meeting titles, descriptions and locations
- Attachments, notes and video links
- Anyone from outside your company
One Slack message, field by field
Kept
Dropped before saving
For how long
- Activity records, and the raw events they come from: 90 days, then deleted.
- Signals: 365 days for signals that were resolved or never shown. A signal that appeared in a manager’s brief is kept as the record of what Sonar told them, until the person’s data is deleted.
- Meeting transcripts, if the notetaker is on: 90 days.
If your company needs shorter windows, we can set them for your workspace.
04
Who can see what
- The person themselves. Every activity record Sonar holds about them, and the signals about them, on their own page. They can download all of it. The one thing they do not see is the leadership-only signals below.
- Their manager. The signals about the people who report directly to them, with the activity behind each one. Never the leadership-only signals.
- Leadership only. Manager health, Team retention risk, Stretch candidate, Onboarding drift and Team collaboration gap are for oversight above the manager. The person a signal is about never sees it, and their direct manager does not see it in their brief or team view.
- No one else. Sonar never sells your data. The companies that help run Sonar, and what each one does, are listed in the privacy policy.
05
How data is deleted
On a schedule. Activity records and the raw events behind them are deleted after 90 days, for everyone, without anyone asking.
When someone asks. A person asks from their own page. Their manager, or a workspace owner or admin, can approve it at once. Nobody can refuse it: if no one acts, it happens on its own after 30 days. The person can cancel until then.
What goes. Their activity records and the raw events behind them, every signal about them, the history Sonar used to learn their usual week, their time-off records, their 1:1 notes and their account. Sonar keeps a record that the deletion happened, not the data.
Pausing works the same way. The person asks, and collection about them stops once their manager or an owner or admin approves. They can resume whenever they like, without asking.
06
What Sonar asks permission for
Slack
A Slack app. It hears only the channels it has been added to.
- channels:read
- See the list of public channels in the workspace.
- channels:history
- Receive messages from public channels Sonar has been added to. Slack sends the text too; Sonar drops it before saving anything.
- groups:read
- See the private channels Sonar has been added to.
- groups:history
- Receive messages from private channels Sonar has been added to, with the text dropped the same way.
- users:read
- See people's names, to match Slack accounts to your team.
- users:read.email
- See people's email addresses, for the same matching.
- team:read
- See the workspace's name.
- reactions:read
- Hear which emoji people react with, and whose message it was on. Sonar keeps the emoji's name, not the message.
GitHub
A GitHub App, installed on the repositories you choose. Sonar never writes to a repository.
It receives events for pull requests, reviews, issues, comments, pushes and CI runs, and nothing else.
Google Calendar
Read-only access to calendars.
- openid
- Confirm which Google account is connecting.
- See that account's email address.
- profile
- See that account's name and picture.
- calendar.readonly
- Read calendars. Read-only: Sonar cannot create, change or delete anything.
- calendar.events.readonly
- Read the events on those calendars, also read-only.
07
The first two weeks
- Day 0. You connect your tools. Twenty minutes to set up.
- History. Google Calendar brings some with it: Sonar reads the last 60 days of meetings and the next 30. Slack and GitHub start from the moment you connect. Sonar does not go back through older messages or pull requests.
- Days 1 to 14. No brief yet. Sonar is learning what a normal week looks like for each person, before it compares anything to it.
- Day 15. The first brief arrives, and one arrives every weekday morning after that.
Some signals compare a person with their own usual pattern. Those need more history than two weeks, so some start later than the first brief.
A question this page does not answer?
Ask us directly. The legal version of all of this is the privacy policy.