Sonize privacy@sonize.io

Subprocessors

The approved categories of third parties used to operate Sonize.

· 2026-09-15.1

Authoritative version: English. Where a translation differs from the authoritative version, the authoritative version prevails.

Table of contents
  1. How this register works
  2. Core infrastructure and delivery
  3. Payments, identity, and app stores
  4. Product analytics and error reporting
  5. AI, transcription, and music rendering
  6. Changes and objections

How this register works

Only providers approved for the current production legal release may receive personal data. Activation requires a recorded purpose, data categories, processing locations, retention instructions, contract, security review, and international-transfer assessment where required. Configured but inactive integrations are not subprocessors until they receive production personal data.

Core infrastructure and delivery

Microsoft Azure provides application compute, PostgreSQL database, container registry, key management, and observability object storage. Cloudflare provides DNS, edge security/CDN, and R2 media storage. Resend delivers email and processes bounce or complaint events. Expo provides push delivery when notifications are enabled. These providers receive service, network, recipient, device-token, media, or operational data only as needed for those functions.

Payments, identity, and app stores

Stripe processes checkout, subscriptions, invoices, refunds, tax and connected-account workflows; payment-card data is collected by Stripe. Google processes Google sign-in when chosen. Apple and Google process native app distribution and in-app purchase verification under their respective platform roles.

Product analytics and error reporting

PostHog processes product analytics and error reporting for Sonize on its European Union host, eu.i.posthog.com, under a data processing agreement; the EU Standard Contractual Clauses cover the support access its United States staff may have to that host. It receives a pseudonymous user identifier, the account identifier, product events such as page and screen views, feature use and web-vitals timings, device and session metadata, unhandled web errors including the IP address the request came from, and — only where you have accepted analytics and diagnostics — mobile and TV error reports. Where you have accepted analytics, PostHog also receives a session replay for a sampled share of sessions, masked as the Cookie Policy describes, and keeps it for 30 days.

Sonize also sends PostHog purchase and render events from its own servers, on receipt of a Stripe webhook or a verified App Store or Google Play receipt. No browser can observe those events, so that capture is not consent-gated: it runs on the legitimate interest in product and revenue measurement declared in the Privacy Policy, and carries identifiers and amounts, not payment details.

PostHog is the sole measurement processor used by Sonize. No advertising or retargeting tag is currently loaded. Write to privacy@sonize.io for the measurement controls applicable to the release you are using.

AI, transcription, and music rendering

The active, approved AI registry may route prompts, questionnaire-derived lyrics, requested transcription audio, cover-art instructions, embeddings, and output metadata to Google Gemini or OpenAI for the selected workload. When active for a request, Google Cloud Lyria receives the title, lyrics, style instructions, generation settings, and required media to render one song. No provider in the live routing chain uses your prompts, lyrics, or rendered songs to train its own models: the paid Google Gemini and OpenAI API terms exclude API content from model training. Approved music providers may be used only when listed in the production routing configuration. Inactive fallback integrations do not receive production personal data. Contact privacy@sonize.io for the legal entity, location, and transfer mechanism recorded for the provider used for a specific request.

Changes and objections

Material processor changes are published before activation when feasible and contractually required notices are sent to affected business customers. Questions or objections can be sent to privacy@sonize.io. If an objection cannot be resolved, available remedies may include disabling the affected optional feature or closing the account without loss of statutory rights.