Cookie Policy
How Sonize uses necessary, analytics, and marketing storage on web surfaces.
· 2026-09-15.1
Authoritative version: English. Where a translation differs from the authoritative version, the authoritative version prevails.
Table of contents
Necessary storage
Necessary cookies and local storage keep authentication, CSRF protection, language, consent choices, checkout continuation, media preferences, and requested app drafts working. The consent choice is stored under sonize.cookieConsent.v2 for up to 180 days. Necessary storage is used under the service contract or legitimate security interest and cannot be disabled through the preference panel.
Crash reporting before any choice
One script loads on every web page view before you make a cookie choice: PostHog, running in a crash-only state. In that state it writes nothing to your device — no cookie, no local-storage entry, no identifier that outlives the page — and it captures nothing you do. It sends only unhandled errors and rejected promises: the exception, the page it happened on, browser and device type, and the IP address your request came from. That is how a page that breaks for you gets found and fixed, and it is the only reason the script is there before consent. Because it stores nothing on your device it needs no consent under the ePrivacy rules; the data itself is processed on our legitimate interest in keeping the service working, and you can object at privacy@sonize.io. If your browser sends Do Not Track, this reporting is switched off entirely. In the mobile and TV apps, error reporting is off unless you accept analytics and diagnostics in the privacy settings.
Analytics and marketing
If you accept analytics, PostHog is upgraded out of the crash-only state described above: it then writes a cookie and a local-storage entry to recognise your browser and records page views, feature use, web-vitals timings, and consent-gated client diagnostics. PostHog is the only client analytics processor.
Accepting analytics also records where on a page people click and how far they scroll, and flags clicks that did nothing — a button that looks interactive but is not. These capture the position of the click and the shape of the page, never the text of what you clicked.
Accepting analytics also switches session replay on. Sessions are reconstructed from the structure of the page so that a fault can be seen as it happened. Every piece of text and every form field is masked in your browser before anything is sent, and images, video, canvas, embedded frames and other media are not captured at all: a replay shows the layout of the page and where you clicked, never what you wrote, read or listened to. Request and response bodies, request headers and console output are never recorded. Recordings are kept for 30 days and then deleted. The mobile and TV apps do the same once you enable analytics and diagnostics in the app privacy settings, with every text field and every image masked. Withdrawing consent stops recording immediately.
No advertising or retargeting tag is currently loaded. Apart from the crash-only reporting above, no optional tag is loaded and no optional cookie or device-storage entry is written before the corresponding choice. Withdrawing consent stops analytics capture, stops session replay, resets the analytics identity, expires the known optional cookies, and leaves only the storage-free measurement described in the next section.
If you refuse analytics
Refusing analytics switches off everything in the section above: no analytics cookie, no local-storage entry, no session replay, no click or scroll map, no record of which features you used, and no profile of you. What continues is a count of the visit itself — which pages were viewed and how quickly they loaded — and the crash reporting described earlier.
That count carries no identifier taken from your device. PostHog derives a value on its own servers from your IP address, your browser's user-agent string and a secret that changes every day, and that value is what distinguishes one visit from another. It is one-way, it is specific to Sonize, and because the secret rotates daily it cannot link today's visit to tomorrow's or to any account. Your IP address is discarded at collection and is not stored.
Because nothing is written to or read from your device, the ePrivacy consent rule that governs cookies and similar storage does not apply. The measurement is strictly limited to producing anonymous statistics about our own service. It is never used for advertising, never combined with any other site's data, never sold or shared, and never used to single you out. The data itself is processed on our legitimate interest in understanding whether the service works and which pages people reach; you may object at privacy@sonize.io, and if your browser sends Do Not Track it is switched off without you having to ask. In the mobile and TV apps there is no equivalent measurement: refusing analytics and diagnostics there leaves the apps entirely silent.
Your choices
Necessary storage is always on for security and core service delivery. Analytics and marketing storage are optional, disabled by default until consent where required, and can be accepted, rejected, or changed through cookie preferences. Refusing optional storage must be as easy as accepting it.
Browser and mobile choices
Use Manage preferences in the site footer to change a browser choice. Authenticated choices are also recorded in the consent history. Browser settings can delete storage independently. When a browser sends Global Privacy Control, Sonize keeps marketing, targeted-advertising, sale, and sharing signals denied even if an older browser choice allowed marketing. Mobile analytics is disabled unless enabled in the app privacy settings; mobile permission and store disclosures must match the released native build.