sonarsense.io
Sonar Assistant Privacy Policy
Appendix No. 1 to the Privacy Policy · Effective date: May 25, 2026

1. General Provisions

This Sonar Assistant Privacy Policy is an appendix to General Privacy Policy SonarSense services and is used in conjunction with it. In case of discrepancies in the functionality of the Sonar Assistant, this addendum takes precedence.

2. What data do we receive from you

  • 2.1. Microphone audio stream— voice of the User and potentially other participants in the conversation within microphone range. Contains personal data. Voice data is considered biometric if used for identification (Art. 11 of Federal Law 152-FZ).
  • 2.2. System audio stream (loopback) when the function is enabled — the voices of interlocutors transmitted through any telephony or video conferencing software on the User's device. The service does not use voice to identify participants.
  • 2.3. Screenshots of the primary monitorwhen the "Screenshots" option is enabled. May contain images of third parties (Art. 152.1 of the Civil Code of the Russian Federation).
  • 2.4. Meeting metadata: ID, start and end time, duration, title, description (set by User).
  • 2.5. Client technical data: application version, operating system, session ID.
  • 2.6. Account credentialsvia Keycloak authentication system: email address, name (if available), user ID.

3. What is processed locally on your device (not transferred to the Operator)

  • App Settings (stealth.json, quick_settings.json) — catalog%LOCALAPPDATA%\SonarAssistant\on Windows
  • Voice activity recognition modelsilero_vad.onnx— pre-trained, contains no personal data
  • Authorization token in the system credential store (Windows Credential Manager)
  • Local application logs (in debug mode) are not sent to the Operator's servers

4. Where we transfer data and for what purposes

RecipientJurisdictionWhat we transferGoalRecipient's expiration date
Soniox, Inc.USA (HQ), Frankfurt (DE) serversPCM 16 kHz audio streamReal-time speech recognitionNot saving
Hetzner Online GmbHGermanyEncrypted Network TrafficNetwork egress proxyTransit only
OpenRouter, Inc.USATranscript + screenshot (base64)AI hint generationUp to 30 days
Google LLC (Gemini)USATranscript + screenshotFallback LLMUnder the Google policy
DeepSeek AIPRCTranscriptFallback LLM (no vision)Under the DeepSeek policy
SONAR LLC (Keycloak, auth.sonarsense.io)RFEmail, Full Name, OAuth claimsAuthenticationAccount + 30 days
SONAR LLC (backend Timeweb)RF (Moscow)Transcript, metadata, hintsStorage and display in the personal accountAccount + 30 days
SONAR LLC (updater)RFClient version, OSChecking for updatesNot saving

5. Voice data

  • Voice data may be considered biometric if used to establish a person's identity (Art. 11, 152-FZ).
  • Processing only for the purpose of implementing the Service function (real-time STT and AI-prompt generation)
  • The service does not use voice for personal identification
  • Not hosted in the Unified Biometric System (UBS)
  • Not used to train the Operator's or its contractors' models
  • If voice is used for identity verification in a specific scenario, such processing requires the Data Subject’s legally mandated consent (Consent to processing of biometric personal data)

6. Screen captures and third parties

When the "Screenshots" option is enabled, the application captures a single image of the main monitor. If the screenshot contains images of third parties, the User must obtain their consent in accordance with Art. 152.1 of the Civil Code of the Russian Federation.

Screenshots are not stored on the Operator’s servers or used to train models. They are transferred once to the selected LLM provider to generate a single AI hint.

7. Application deletion and local data

When the application is uninstalled normally (Control Panel → Programs and Features on Windows), the following is automatically removed: the directory %LOCALAPPDATA%\SonarAssistant\with all settings and temporary files, application registry keys.

Not deleted automatically:authorization token in the Windows Credential Manager. To delete it: Control Panel → Windows Credentials → Web Credentials → find entry sonar-assistant→ Delete.

8. Sonar Assistant data retention periods

  • Audio stream (microphone, system sound) —not saved
  • Screenshots —are not saved on the server, transferred to LLM once
  • Meeting transcripts, AI suggestions, and metadata—for as long as the account is active; deleted within 30 days after the account is deleted
  • Credentials—for as long as the account is active; deleted within 30 days after the account is deleted
  • Update check logs are not saved (no user identifier)

9. Application auto-updates

Update check endpoint: assistant.sonarsense.io/updates/latest.json.

Shared: current application version, operating system. Not transmitted: device ID, user ID, information about installed programs. Updates are digitally signed and verified before installation.

© 2026 sonarsense.io