Effective 14 September 2026
Privacy Policy
Этот документ пока есть только на английском. Юридически действует английская версия.
This page lists what Sonatide stores about you, who can see it, and how to delete it. It covers the Sonatide apps (iOS, Android, macOS, Windows, Linux, web) and the website sonatide.app.
Who is responsible
Sonatide is operated by Artur Rafikov PR Novi Sad, a sole trader (preduzetnik) registered in Novi Sad, Serbia, publishing as BinaryCascade. Under the Serbian Law on Personal Data Protection (ZZPL) and, for people in the European Union, the GDPR, Artur Rafikov PR is the controller of your data.
Contact: hello@sonatide.app.
What we collect
When you sign in
- Your email address and, if your sign-in provider shares it, your name and profile photo. Sign-in runs through Firebase Authentication, a Google service. You can sign in with Google, with Apple, or with an email and password. We never see your password: Firebase stores it.
- A user identifier that Firebase assigns to your account.
Your profile
- Username, display name, an optional profile photo, and the music service you listen on. Profile photos are stored on our servers and can be read by anyone who has their address; they are shown to your correspondents and on your invite pages.
What you send and receive
- Letters: the track or album you share (a link plus the title, artist, artwork and duration we look up on music platforms), your note, the vibe you picked, and who you sent it to.
- Reactions and reply notes on letters you receive.
- Whether and when you listened to a letter, and whether you archived it. The sender of a letter can see whether you listened and how you reacted.
- Your address book: the people you exchange letters with, and the invite links you create, with their label, usage limit and use count.
- When you last opened each section of the app, so we can show what is new since your last visit.
Optional connections
- Last.fm: if you connect it, we store your Last.fm username and a session key, and retrieve your recently played tracks so you can choose music to send. Recent tracks may also be cached on your device. You can disconnect at any time in Profile, Last.fm, which deletes the session key from our service.
Notifications
- If you allow notifications, we store the push token Firebase Cloud Messaging issues for your device, together with its platform. It is removed when you sign out or turn notifications off.
Diagnostics
- Crash reports through Firebase Crashlytics: the stack trace, device model, operating system version, app version, and a Crashlytics installation identifier. Crash reports are linked to your account identifier so we can reproduce what happened to you. We use no analytics SDKs, no advertising SDKs, and no tracking across other apps or websites.
- Server logs: our servers record the IP address, the request path and the app version of each request, for security and debugging. Logs are kept for up to 30 days.
On your device
- Preferences (theme, language, layout density, your music service), cached app data such as received music and, if you connect Last.fm, recent listens, and unsent drafts. All of it is cleared when you sign out.
The website
- sonatide.app sets no cookies and runs no analytics. The web server keeps access logs (IP address, requested page, browser) for up to 30 days.
What we do not collect
We do not collect your location, device contacts, microphone recordings or health data. Choosing a music service does not give us access to your listening history. We look up the music you share; if you connect Last.fm, we also retrieve your recent listens as described above. We do not sell data and we show no ads.
Why we process it
- To provide the service you asked for: your account, letters, address book, and the notifications you enabled (performance of a contract; consent for notifications and Last.fm).
- To keep the service safe: handling reports, blocking, preventing abuse, fixing crashes (legitimate interests).
- To meet legal obligations, such as answering lawful requests.
Who can see your data
- Your correspondents see your name, username and photo, the letters you send them, your reactions and notes, and whether you listened to theirs.
- Anyone who opens an invite link you created sees your name and username.
- Processors working for us: Google (Firebase Authentication, Cloud Messaging and Crashlytics; United States), Apple (Sign in with Apple), and hosting providers in the European Union, where our servers, database and file storage live.
- Music platforms: to look up a track we send its link or identifier to the platform it came from and to the platforms we match against (Spotify, Apple Music, YouTube, Tidal, Yandex Music, Deezer, Last.fm, LRCLIB). We do not tell them who you are. When you open a track in your music service, that service learns what you opened, under its own privacy policy. Last.fm learns your identity only if you connect your Last.fm account.
- Nobody else, unless the law requires it or you ask us to.
If you report a letter or a person, we keep a snapshot of the reported content with the report, so we can act on it even after its author deletes it.
International transfers
Our servers are in the European Union. Google and Apple process data in the United States under their standard contractual clauses. Serbia recognises the European Union as providing adequate protection.
How long we keep it
- Account and content: as long as your account exists.
- Push tokens: until you sign out or disable notifications.
- Server and website logs: up to 30 days.
- Crash reports: 90 days.
- Reports you file, or that are filed about you: as long as needed to handle them and to prevent repeat abuse.
- Backups: copies of deleted data may persist in backups for up to 30 days.
Deleting your account
Open Profile and select your name to open Account, then choose Delete account. Your account is deleted immediately: your profile, received music, address book and your record of exchanged letters are removed, and your Firebase sign-in account is deleted. Letters you already sent stay with their recipients without your name or photo. Moderation records, crash reports and backups follow the retention periods above. Details and an email alternative: Delete your account.
Your rights
Under the ZZPL and, if you are in the EU, the GDPR, you can ask us to access, correct, export or delete your data, to restrict or object to processing, and to withdraw consent where processing rests on it. Write to hello@sonatide.app; we answer within 30 days, extendable where the law allows for complex requests. You can also complain to the Serbian Commissioner for Information of Public Importance and Personal Data Protection (poverenik.rs) or to your local supervisory authority in the EU.
If you live in California: we do not sell or share personal information as defined by the CCPA, and the rights above apply to you as well.
Children
Sonatide is not for children under 13. If your country sets a higher age for consenting to data processing (15 in Serbia, up to 16 in parts of the EU), you must be that age or have a parent’s permission. If we learn that we hold data of a child who does not meet these requirements, we delete it.
Security
Traffic is encrypted in transit. Access tokens live only in the app’s memory, never on disk. Only the operator has access to the servers. If we learn of a breach that affects you, we tell you.
Changes
We post changes here and update the date at the top. If a change materially reduces your rights, we tell you in the app or by email before it takes effect.