Sonize privacy@sonize.io

Privacy Policy

How Sonize handles account, music, event, device, billing, and support data.

· 2026-09-15.1

Authoritative version: English. Where a translation differs from the authoritative version, the authoritative version prevails.

Table of contents
  1. Controller and contact
  2. Personal data we process
  3. Purposes and legal bases
  4. Connected music accounts
  5. Recipients and processors
  6. International transfers
  7. Retention
  8. Your privacy rights
  9. Children
  10. Security, incidents, and automated processing

Controller and contact

The controller of the personal data described in this policy is SONIZE (Société par actions simplifiée (SAS)), 5 rue Jean-Marie David, 35740 Pacé, France, registered under SIREN 107390304, SIRET 10739030400015, RCS Rennes 107390304, RNE 107390304. Privacy questions, data-rights requests and complaints go to privacy@sonize.io, or through the privacy controls in account settings. Sonize has not designated a data protection officer; privacy@sonize.io reaches the people responsible for data protection and is monitored. The full registered identity of the publisher, including share capital and the publication director, is in the Legal Notice.

Personal data we process

Depending on the features used, we process account and profile data; authentication, passkey, session, device and security data; prompts, lyrics, uploaded or generated media and voice samples; event, guest questionnaire and collaboration data; comments, reactions, playlists and safety reports; purchase and billing identifiers; notification preferences and delivery data; support, copyright and privacy-rights submissions; and operational logs.

On web surfaces we also receive crash and error reports — the exception, the page it happened on, browser and device type, and the IP address the request came from — which are sent to our analytics processor so a broken page can be found and fixed, and which the Cookie Policy describes in full. If, and only if, you accept analytics cookies, we additionally receive product-usage events, click and scroll maps, and a session replay of your session: the layout of the page and where you clicked, with every piece of text and every form field masked and images and media excluded, as the Cookie Policy describes in full. If you refuse analytics cookies we still count the visit itself — which pages were viewed and how quickly they loaded — without any identifier from your device and without storing your IP address, which the Cookie Policy describes in full and which you may object to at privacy@sonize.io. Payment-card details are entered with the payment provider and are not stored by Sonize.

If an event organizer or guest names you as the person an event is about, we receive your name and the memories or questionnaire answers they supply about you from that person rather than from you. We use them to create the requested event song and protect the service, on the organizer's contract and our legitimate interests, and disclose them only to authorized event collaborators and the approved generation providers needed for that request. We delete that source material after 12 months and the resulting event song after 24 months unless a recipient keeps it or a legal hold applies. You may exercise the rights below at privacy@sonize.io.

Purposes and legal bases

We process data to create and administer accounts, deliver requested music and event features, provide support, and manage paid services where necessary to perform a contract. We process security, fraud, service-reliability, limited product measurement, and moderation data for legitimate interests after balancing those interests against user rights. We process accounting, consumer, copyright, regulatory, and lawful-request records to comply with legal obligations or establish, exercise, or defend legal claims. Optional analytics and marketing data are processed only on the consent or other lawful basis presented at collection, and consent can be withdrawn. Where you have opted in to announcements from us, we measure whether they worked: links in them pass through a redirect on our own domain so a click can be counted, and, only where we have enabled it, a single-pixel image records that the message was opened. Both are tied to that one send, neither is used to build a profile of you, and withdrawing marketing consent ends them along with the mail.

Some of this data you have to give us. An email address and either a password or a linked sign-in are required to enter into the contract: without them no account can be created. Billing and tax identifiers are required to perform a paid order and to issue the invoice accounting law obliges us to keep: without them a purchase cannot be completed. Everything else is optional — a display name, a profile picture, a voice sample, a questionnaire answer, analytics consent — and refusing it costs you nothing but the feature it powers.

Connected music accounts

Connecting a music account is optional. When you connect YouTube Music, Spotify or Apple Music, Sonize receives authorization tokens, the account or channel identity and display name available from that service, and the catalog information needed to match songs and save the playlists you request. We encrypt authorization tokens at rest; Sonize does not receive your music-service password. Your connection and save history are available only through your own Sonize login, not to other workspace members.

We use this information to maintain the connection, match tracks, show you the results for review, and create a playlist only after you confirm. We send the chosen service search terms and the playlist details needed for that operation. Sonize and its infrastructure providers process this information to deliver your requested connection and saves; the music service processes information under its own terms and privacy policy. Data obtained through connected music services is never used to train AI models.

Match reviews are valid for 24 hours. Provider match metadata and saved-playlist identifiers and links expire 30 days after the save request and are removed by scheduled cleanup. Cleanup can be delayed during an outage. Your connection identity is periodically refreshed while the connection remains valid. Disconnect in the playlist’s “Save to your music service” section to stop future access and immediately remove Sonize’s stored authorization tokens, connected identity, provider match metadata and saved-playlist links. The original Sonize playlist and a record of the expired save may remain under the general account retention rules. Playlists already created in the music service remain there; manage or delete them in that service.

The YouTube Music connection uses YouTube API Services. Google’s Privacy Policy applies to Google’s processing: https://policies.google.com/privacy. You can also revoke Sonize’s access in Google’s permissions settings: https://security.google.com/settings/security/permissions. For questions or deletion requests, contact privacy@sonize.io.

Spotify is a beneficiary of this Privacy Policy as described in our Terms of Service.

Recipients and processors

Authorized Sonize personnel and account collaborators receive only the data needed for their role. Infrastructure, storage, email, push, payment, app-store, analytics, authentication, AI, transcription, and music-generation providers receive the minimum data required for the requested function. The current approved register, purposes, data categories, and processing locations are published in Subprocessors.

International transfers

When personal data is transferred outside its originating country, Sonize uses the transfer mechanism recorded for that recipient in the approved processor register, such as an adequacy decision or Standard Contractual Clauses with supplementary measures where required. A provider is not activated for production until its contractual and transfer review has been approved.

Retention

Your account and profile data, your song library, the prompts and lyrics behind it, the media you uploaded or generated, your playlists, comments and social connections are kept for as long as your account exists, and are deleted or anonymized when it is closed. A confirmed deletion runs 72 hours after you confirm it, and Sonize completes the erasure and chases each processor holding a copy to a 30-day deadline. The Account Deletion document lists what survives and why.

Everything else has its own clock. Expired one-time authentication state is deleted promptly and revoked-session metadata after 30 days. Guest contact data is scrubbed 90 days after the event; questionnaire and event-wall data after 12 months; event songs and play-event analytics after 24 months; expired gift recipient data after 90 days; processed delivery work after 14 days and local development email files after 7 days; support and contact submissions after 3 years; copyright notices 6 years from receipt. Spoken-brief audio is held only in memory while it is transcribed, then discarded; Sonize creates no reusable voice profile. A transcript persists only when you submit it as a song input.

Records the law obliges us to keep outlive the account: invoices and accounting records for the statutory period of the seller's country — 10 years in France under art. L123-22 of the Code de commerce — and fraud, safety, moderation, copyright, and security evidence for the applicable limitation period. Access to them is restricted to the people who need it, and any deletion suspended by a legal hold is recorded with a case reference, a scope, and a review date.

Product-analytics events are a case where we do not control the clock, so here it is stated plainly. They sit with PostHog for as long as the retention entitlement attached to our organisation's plan allows — currently 84 months. PostHog confirmed on 9 September 2026 that this value is derived from the plan and cannot be set by us, that no self-serve plan carries a shorter window, and that the enforcement flag it exposes stops old events being returned by queries without deleting them. We keep the exposure small instead of the period: those events carry a pseudonymous identifier and technical metadata, never your lyrics, prompts, uploaded media or payment details. Withdrawing analytics consent stops the collection, and an erasure request reaches PostHog like every other processor. Session replay is governed separately and is deleted after 30 days.

Your privacy rights

Depending on your location and the processing involved, you may have rights to know or access data, correct it, delete it, restrict or object to processing, receive portable data, withdraw consent, opt out of covered sale, sharing, targeted advertising, or profiling, use an authorized agent, and appeal a refusal. Sonize does not sell personal data. Use the privacy controls or open a rights request; identity will be verified and requests are tracked to the applicable deadline, which is one month from receipt under Article 12(3) GDPR, extendable by two further months for a complex request if we tell you inside the first month. Sonize's lead supervisory authority is the Commission nationale de l'informatique et des libertés (CNIL), 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France, www.cnil.fr, to which you may lodge a complaint; you may also complain to the authority of the country where you live or where the alleged breach happened, and going to a regulator does not stop you going to court.

Children

Sonize account registration is restricted to people aged 18 or older. There is currently no child-account or parental-consent registration path. If we learn that an ineligible child created an account, contact privacy@sonize.io so the data can be reviewed and deleted.

Security, incidents, and automated processing

Sonize uses encryption in transit and at rest, least-privilege access, forced tenant row-level security, credential hashing, rate limits, audit records, and monitored backups. Security incidents are assessed and notified to regulators and affected people when applicable law requires it. Automated systems may assist content safety and fraud detection, but account sanctions and privacy-rights refusals are not made solely by automation without an available human review path.