← Back

Privacy Policy

Last updated: April 2026

1. What We Collect

We collect: your email address (for authentication), lesson progress and drill scores (to track your learning), and interval accuracy data (to personalise your practice). We do not collect payment information directly — this is handled by our payment processor.

2. How We Use Your Data

Your data is used to: authenticate your account, save your progress across devices, personalise drill difficulty based on your weak areas, and generate AI-powered exercises targeting your specific needs. We do not sell your data to third parties.

3. Data Storage

Your data is stored in Supabase (hosted on AWS). Lesson progress is also cached locally in your browser's localStorage for offline access. Audio files for lesson narration are pre-generated and served as static files — no personal data is sent to text-to-speech services.

4. Third-Party Services

We use: Supabase (authentication and database), OpenAI (AI-generated exercises — only your weak interval data is sent, never personal information), and Google OAuth (if you choose to sign in with Google). Each service has its own privacy policy.

5. Cookies & Local Storage

We use localStorage to cache your progress for fast loading and offline access. We use session cookies for authentication. We do not use tracking cookies or analytics cookies.

6. Microphone Access

If you enable "Play to answer" mode, we request microphone access for pitch detection. Audio is processed entirely in your browser — it is never recorded, stored, or sent to any server.

7. Your Rights

You can: view all your stored data through the Progress screen, delete your account and all associated data through the Account settings page, export your progress data by contacting us. We comply with GDPR and applicable data protection laws.

8. Data Deletion

When you delete your account, all your data (progress, drill history, lesson completions) is permanently removed from our servers within 30 days. Local browser data can be cleared through your browser settings.

9. Children

Sonata is suitable for all ages. We do not knowingly collect data from children under 13 without parental consent. If you believe a child has provided us data without consent, contact us to have it removed.

10. Contact

Privacy questions? Contact us at privacy@sonata.app.