Privacy Policy
This Privacy Policy explains how SonIQ ("Company", "we", "us", or "our") collects, uses, shares, and protects your personal information when you use SonIQ, our agent-native project workspace and related services. We are committed to protecting your privacy and being transparent about our data practices.
1. Data We Collect
1.1 Account Data
When you create an account, we collect:
- Email address — used for account identification, authentication, and communication;
- Login / username — used for account identification;
- OAuth profile basics — if you sign in with GitHub or Google, we receive your email and basic profile information (name, avatar) from the provider;
- Authentication tokens — session tokens for keeping you logged in.
1.2 Service Data
When you use SonIQ, we store the following on our servers to provide the Service:
- Project files — the files of the projects you connect, sent by the soniq daemon so we can scan them and keep the documentation checked against the code. They are deleted with the project (soniq project delete) or with your account;
- Structural graph — the structural model extracted from those files: symbol names, types, file paths, endpoints, schemas, and their relationships;
- Knowledge entries — the documentation semantics your AI agents write, and their change history;
- Tasks, board content, and notes — work items you or your agents create;
- Usage logs — tool calls and scans with their timings, parameters and a shortened preview of each answer, which can include excerpts of your code; kept to operate and debug the Service.
1.3 Subscription Data
When you subscribe, the following data is managed by our payment processor, Paddle:
- Payment method details (credit card, PayPal, etc.);
- Billing address and tax information;
- Transaction history and invoices.
We do not directly store your payment method details. Paddle acts as the Merchant of Record and handles all payment data. We receive only your subscription status, plan type, and transaction identifiers from Paddle.
1.4 Data We Do NOT Collect
- AI inference data — your AI agents talk to their providers (such as Anthropic or OpenAI) directly from your own client, under your own subscription or API keys. These requests do not pass through our servers, and we never receive or store your AI provider keys.
- Payment details — handled entirely by Paddle; your card never touches SonIQ.
2. How We Use Your Data
We use the data we collect for the following purposes:
| Purpose | Data Used |
|---|---|
| Provide and operate the Service | Account data, project files, structural graph, knowledge entries, tasks and notes |
| Authenticate your identity | Email, login, session tokens |
| Process payments and manage subscriptions | Subscription data (via Paddle) |
| Send important service updates | Email address |
| Respond to support requests | Email address, account data |
| Improve the Service | Aggregated, anonymized usage patterns |
We do not sell your personal data. We do not use your data — including your structural graph and knowledge entries — to train AI models.
3. Third-Party Services
We use the following third-party services to operate SonIQ:
3.1 Paddle (Payment Processor)
Paddle (Paddle.com Market Limited) acts as our Merchant of Record for all subscription payments. When you subscribe, Paddle receives and processes your name, email address, payment information (credit card, PayPal, etc.), and billing address to handle payment processing, tax compliance, invoicing, and refunds. We do not directly store your payment method details. We receive only your subscription status, plan type, and transaction identifiers from Paddle. Paddle has its own privacy policy governing how they handle your payment data.
3.2 Resend (Transactional Email)
Resend is used to send transactional emails such as account verification, password resets, and important service notifications. We share only your email address with Resend for this purpose. Resend does not receive any other personal data.
3.3 Your AI Provider (via your own client)
When your AI agents work with SonIQ, inference requests are made by your own AI client (such as Claude Code, Cursor, or Windsurf) directly to its provider (such as Anthropic or OpenAI) using your own subscription or API keys. These requests are made from your machine and do not pass through our servers. Your interactions with these providers are governed by their respective privacy policies and terms of service.
3.4 Railway and Neon (Hosting and Database)
Our backend services are hosted on Railway and our database is hosted on Neon, cloud providers located in the United States. All account data, project files, the structural graph, knowledge entries, tasks, and notes are stored on this infrastructure. Railway and Neon act as data processors on our behalf.
4. Cookies and Local Storage
- Web application — uses an essential session cookie for authentication. We do not use tracking or advertising cookies.
- Command-line tool and daemon — store configuration locally on your machine (including the project marker and local settings).
- SonIQ API keys — are generated in the web application, displayed once, and stored on our servers only as one-way SHA-256 hashes; the secret itself is never stored or retrievable.
5. Data Retention
- Active accounts — your account data is retained for as long as your account remains active.
- After Pro cancellation — your account continues on the Free plan. Your data is retained — nothing is deleted on downgrade. Agent-written features pause; the structural documentation and task board keep working.
- After account deletion — when you request account deletion, all your personal data (account data, project files, structural graph, knowledge entries, tasks, notes) is deleted within 30 days. Some anonymized, aggregated data may be retained for analytical purposes.
- Billing records — transaction records, invoices, and billing history are retained for 7 years after the transaction date for tax compliance, legal obligations, and financial audit purposes, as required by applicable law.
- Backups — deleted data may persist in backups kept by our infrastructure providers until their retention windows expire.
6. Data Security
We implement appropriate technical and organizational measures to protect your data, including:
- Encrypted data transmission (HTTPS/TLS) for all communications between your machine and our servers;
- Encryption at rest of our database (knowledge entries, tasks, notes) is provided by our database provider (Neon); the copy of your repository is kept on our hosting provider's (Railway) storage. SonIQ does not add application-level encryption of its own;
- Passwords stored only as salted one-way hashes (scrypt; accounts from our earlier sign-in system use bcrypt);
- SonIQ API keys stored only as one-way SHA-256 hashes and displayed only once at creation;
- Token-based authentication with secure session management;
- Per-project access control: you can reach only the projects you own or are a member of.
While we take reasonable steps to protect your data, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security.
7. Legal Basis for Processing (GDPR)
If you are located in the European Economic Area (EEA), United Kingdom, or a jurisdiction where GDPR or similar data protection regulations apply, the legal basis for processing your personal data includes:
- Consent — you provide consent during account registration by agreeing to these terms and creating your account. You may withdraw your consent at any time by deleting your account.
- Contractual necessity — processing your account data, structural graph, and knowledge entries is necessary to provide you with the Service you have subscribed to.
- Legitimate interest — we have a legitimate interest in improving our services, ensuring security, and communicating with users about service updates and support. We balance these interests against your rights and do not use your data in ways you would not reasonably expect.
8. Your Rights (GDPR and Similar Regulations)
Regardless of where you are located, we provide the following rights to all users:
- Right to access — you can request a copy of all personal data we hold about you.
- Right to rectification — you can request that we correct any inaccurate data.
- Right to erasure — you can request that we delete all your personal data ("right to be forgotten").
- Right to data portability — you can request your data in a structured, machine-readable format.
- Right to restrict processing — you can request that we limit how we use your data.
- Right to object — you can object to our processing of your data for certain purposes.
- Right to withdraw consent — where processing is based on consent, you may withdraw it at any time.
To exercise any of these rights, please contact us at [email protected]. We will respond to your request within 30 days.
9. International Data Transfers
Our servers are located in the United States (hosted on Railway and Neon). If you are accessing the Service from outside the United States, your data will be transferred to and processed in the United States. We ensure appropriate safeguards are in place for such transfers in compliance with applicable data protection laws, including Standard Contractual Clauses where applicable.
10. Children's Privacy
SonIQ is not intended for use by children under the age of 16. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child under 16, we will take steps to delete that data promptly.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable laws. When we make material changes, we will notify you by email or through the Service at least 7 days before the changes take effect. The "Effective date" at the top of this page indicates when the policy was last updated.
12. Contact Us
If you have any questions about this Privacy Policy, your data, or wish to exercise your rights, please contact us:
- Email: [email protected]
- Website: soniqcloud.com