Legal

Privacy Policy

Last updated: 19 May 2025

The short version: We collect only what's necessary to run the service. We don't sell your data. Audio streamed through Sono passes directly between your devices peer-to-peer — it never touches our servers.

Contents
  1. Who we are
  2. What data we collect
  3. How we use your data
  4. Audio data
  5. Third-party services
  6. Cookies and storage
  7. Data retention
  8. Your rights (UK GDPR)
  9. Security
  10. Contact us

1. Who we are

Sono is operated as a personal project based in the United Kingdom. For any privacy-related questions, you can contact us at support.sonno@gmail.com.

When we say "Sono", "we", "us" or "our", we mean the operator of this service. When we say "you" or "your", we mean the person using our website or service.

2. What data we collect

We collect the minimum data needed to operate the service:

We do not collect: audio content, names, phone numbers, location data, or any tracking data beyond standard server logs.

3. How we use your data

We use the data we collect exclusively to:

We will never sell your data, share it with advertisers, or use it for any purpose not listed above.

4. Audio data

Sono streams audio directly between your laptop and your phone using WebRTC peer-to-peer technology. Audio content is never routed through, stored on, or processed by our servers.

Our signalling server only facilitates the initial connection handshake (exchanging connection metadata). Once the connection is established, all audio flows directly between your devices.

When a TURN relay server is used (for connections across different networks), audio packets may pass through the relay server momentarily, but they are not logged, recorded, or inspectable in transit.

5. Third-party services

We use the following third-party services:

We do not use analytics platforms, advertising networks, or any tracking services.

6. Cookies and browser storage

We use a single httpOnly session cookie called sono_token to keep you logged in. This cookie:

We also use localStorage to store the cooldown timestamp for free sessions. This data lives only in your browser and is automatically cleared when the cooldown expires.

We do not use any third-party cookies or tracking cookies.

7. Data retention

To request deletion of your account and all associated data, email us at support.sonno@gmail.com with the subject "Data deletion request".

8. Your rights (UK GDPR)

As a UK resident, you have the following rights under UK GDPR:

To exercise any of these rights, email support.sonno@gmail.com. We will respond within 30 days.

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) if you believe we have not handled your data correctly.

9. Security

We take reasonable steps to protect your data:

No system is perfectly secure. If you discover a security vulnerability, please disclose it responsibly by emailing support.sonno@gmail.com.

10. Contact us

For any privacy questions, data requests, or concerns:

We will respond to all privacy-related enquiries within 30 days.

We may update this policy from time to time. Material changes will be communicated via email if you have an account with us. The "Last updated" date at the top of this page will always reflect the most recent revision.