This policy explains how IA COMPA LLC handles information in the Sonedia app (iOS, iPadOS, watchOS). It applies to Sonedia specifically; our website has its own privacy policy.
What Sonedia handles
- Audio recordings, waveforms, edits, mixes, and export settings you create
- Transcripts, notes, tags, projects, albums, and other organization details you add
- Optional recording locations and the collaboration details needed for Shared Albums you choose to use
- For Pro AI features: pseudonymous app-attestation and subscription identifiers, quota usage, job metadata, and the selected audio submitted for analysis
Where your data lives
Recordings and metadata stay on your device unless you enable iCloud sync, place a recording in a Shared Album, or deliberately submit selected content to a Pro AI feature. Optional library sync uses your private iCloud account, and Pro Shared Albums use Apple CloudKit to share selected content with invited participants. A precise location attached to a shared recording can be visible to those participants. For AI processing, Sonedia's service stores pseudonymous entitlement, quota, and job records rather than a hosted recording library; temporary Gemini files are deleted after processing, with retry cleanup when deletion cannot finish immediately.
Data categories and purposes
Collection is feature-dependent. Sonedia uses the following categories only for app functionality, not for advertising or tracking. Shared content may be linked to a CloudKit participant; backend security, entitlement, and quota records use pseudonymous identifiers.
- Audio Data — Shared Album contributions and audio a subscriber explicitly submits for cloud AI processing.
- Other User Content — titles, notes, transcripts, shared metadata, AI text requests, comments, and moderation reasons.
- Name and User ID — Shared Album contributor display names and CloudKit participant identifiers.
- Precise and Coarse Location — recording coordinates in optional private sync, or the approximate area (about 500 meters) or precise location a creator explicitly shares with an album.
- Purchase History — StoreKit product and entitlement verification, represented in backend records by a keyed subscriber hash rather than a raw purchase identifier.
- Device ID — the App Attest app-instance key identifier used to authenticate the app and prevent replay.
- Product Interaction and Other Usage Data — AI allowance consumption, job state, rate limiting, provider-file cleanup, and moderation-workflow metadata.
Cloud AI consent and processing
Auto-Transcribe is enabled by default and can be turned off. Supported transcripts use Apple Speech Recognition and prefer on-device recognition when available; Apple may use its servers for some devices or languages. A paid subscription does not itself grant cloud-AI consent.
After an entitled subscriber explicitly chooses Allow AI Processing, Sonedia may prefer cloud AI while consent, network access, verified entitlement, and enough quota for the entire recording are available. The backend verifies those conditions before creating a restricted Gemini upload session. If they are not available or processing fails, Sonedia falls back to Apple Speech Recognition without a partial cloud upload.
The requested audio may be uploaded directly from the app to a restricted Gemini session created by Sonedia's Vercel API; text submitted for AI analysis and validated results pass through that API. Neon stores only limited pseudonymous job, model, language, recording-revision, consent-version, quota, entitlement, security, and deletion-reconciliation metadata. Sonedia does not use a cloud result to silently overwrite a user-entered title.
iCloud, sharing, and moderation
- Private iCloud sync is optional, off until enabled, and available on free and paid plans. Recording coordinates and place labels sync to your private CloudKit database only when you enable the relevant features.
- Shared Albums use CloudKit for invitations, participants, permissions, comments, shared recordings, titles, notes, and other shared metadata. Location remains off for each recording unless its creator selects Approximate or Precise sharing.
- A moderation report sends the selected reason and operational metadata only. It never attaches the reported audio automatically.
- Moderation metadata may include a pseudonymous reporter-instance hash, hashed shared-record identifiers, timestamps, and review status. Blocking, leaving an album, or invite revocation can affect future access, but copies another person exported outside Sonedia remain outside Sonedia's control.
Retention, deletion, and your controls
- Deleting a local recording moves it to Trash; it is permanently deleted after 30 days unless restored sooner. Content in your iCloud account remains there until you remove it through Sonedia or Apple's controls.
- Sonedia's backend does not log or store raw audio, transcripts, prompts, titles, filenames, model output, App Attest assertions, StoreKit payloads, or secrets.
- Operational logs are retained for up to 14 days; AI job metadata for up to 30 days; provider file identifiers and sanitized deletion-retry metadata until verified deletion or up to 48 hours; inactive App Attest instance metadata for up to 30 days; and entitlement/quota records through the billing period plus 35 days.
- You can turn off Auto-Transcribe, choose On-Device Only, withdraw AI consent, disable private sync, remove shared content you control, and use Sonedia's cloud-data deletion control. Withdrawing AI consent cancels cloud work and requests deletion on a best-effort basis; stale cloud completions are rejected and on-device fallback is used when Auto-Transcribe remains enabled.
- Content sent to Google Gemini remains subject to Google's data-handling and retention terms. Files exported or copied outside Sonedia are controlled by the destination you selected.
Service providers
- Apple iCloud and CloudKit — provide optional library sync and Shared Album collaboration through your Apple account (provider information).
- Apple WatchConnectivity — transfers a recording from your paired Apple Watch to your iPhone; if you enable iCloud library sync, iCloud can then carry it onward to your other Apple devices (provider information).
- Apple Speech Recognition — creates supported transcripts; Sonedia prefers on-device recognition when available, but Apple may use its servers and require a network connection for some devices or languages (provider information).
- Google Gemini — processes only the audio a Pro subscriber deliberately submits for AI analysis through Sonedia's production service (provider information).
- Vercel and Neon — host Sonedia's secured AI gateway and its pseudonymous subscription, quota, and job records; they do not provide a separate Sonedia recording library (provider information).
What we don’t do
- We don’t sell your personal information.
- We don’t use third-party advertising or tracking SDKs.
Your choices
You can remove data stored locally by deleting the app. If an app offers iCloud sync, you can also remove its synced data from your iCloud account. For any request or question, email sonedia@iacompa.com.
Children
Sonedia is intended for a general audience and isn’t directed to children under 13. We don’t knowingly collect personal information from children.
Changes to this policy
We may update this policy from time to time; we’ll change the “Last updated” date above when we do.
Contact
IA COMPA LLC — sonedia@iacompa.com.