SONDU LEGAL
Sondu Privacy Policy
Effective date: 12 September 2026 Last updated: 12 September 2026
This Privacy Policy explains how Sondu collects, uses, discloses, retains, and protects personal data when you use the Sondu website, mobile application, and related services. It also explains the choices and rights available to you.
In this Policy, “Sondu,” “we,” “us,” and “our” refer to Abenales Information Technology Services, located at Poblacion 2, Hindang, Leyte, Eastern Visayas 6523, Region VIII, Philippines. “Service” means the Sondu website, app, music generation features, accounts, subscriptions, credits, support channels, and related functionality.

What data we collect and share (summary)

To make our practices easy to understand, here is a summary of the main data categories we handle and with whom we share them:
•
Account data: email address, name, account identifier, authentication method, verification status.
Shared with: cloud hosting and security providers; authentication providers (e.g., Google Sign In).
•
Creative inputs and content: prompts, lyrics, titles, genres, moods, styles, instrumental preferences, generation settings; generated audio, artwork or thumbnails, track metadata, generation status; actions such as save, play, download, delete, or share.
Shared with: AI music provider (APIFrame AI) and the underlying model providers needed to generate music; hosting and storage providers.
•
Purchase and subscription data: product purchased, amount, currency, transaction identifier, purchase time, payment status, refund or dispute status, subscription status, and related account records.
Shared with: Google Play Billing, RevenueCat, PayMongo, and related billing and fraud prevention providers.
•
Usage and diagnostic data: device type, operating system, browser, app version, language, IP address, timestamps, session and feature activity, generation job events, error messages, application or server logs, performance data, and security events.
Shared with: hosting, security, and infrastructure providers.
•
Communications and waitlist data: email address, message, attachments, support history, and any information you choose to provide when you contact us or join a waitlist or product update list.
Shared with: email and customer support providers (e.g., Resend).
Sondu does not sell personal data.

1 Scope

This Policy applies when you visit the Sondu website, join a launch or product update list, create or use a Sondu account, generate or manage content, make a purchase, contact support, or otherwise interact with the Service. It does not govern third party websites, applications, payment pages, or services that have their own privacy notices.
The data practices described here align with Sondu’s Google Play Data safety form and Apple App Store privacy disclosures. If there is any inconsistency, the more protective practice applies until the materials are updated.

2 Personal data we collect

2.1 Account and identity data

When you register or sign in, we may collect your name, email address, account identifier, profile information, authentication method, verification status, and information needed to maintain and secure your account. Sondu supports email and password authentication, email verification using a one time password, and Google Sign In. If you use Google Sign In, we receive the account information Google makes available based on your settings and permissions.

2.2 Prompts and generated content

We collect the information you submit to create music, such as prompts, lyrics, titles, genres, moods, styles, instrumental preferences, generation settings, and other creative instructions. We also process generated audio, artwork or thumbnails, track metadata, generation status, and the actions you take to save, play, download, delete, or share content.

2.3 Purchase and subscription data

When you buy credits, top up an account, or start or manage a subscription, we may collect the product purchased, amount, currency, transaction identifier, purchase time, payment status, refund or dispute status, subscription status, and related account records. Android purchases and subscriptions are processed through Google Play Billing and managed through RevenueCat. Web payments are processed through PayMongo. These providers may collect payment card or billing information directly under their own privacy notices. Sondu receives transaction and entitlement information needed to apply credits, manage subscriptions, provide support, prevent fraud, and maintain required records. At this time, Sondu processes purchases and subscriptions only through Android and the Sondu website; Sondu does not currently offer or process purchases through Apple’s App Store. If purchases through iOS or the App Store become available, Sondu will update this Policy to describe Apple’s role as a payment processor before that option is offered.

2.4 Usage and diagnostic data

We may collect information about how the Service is used and performs, including device type, operating system, browser, app version, language, IP address, timestamps, session and feature activity, generation job events, error messages, application or server logs, performance data, and security events.

2.5 Communications and waitlist data

If you join a waitlist, request product updates, report a problem, or contact us, we may collect your email address, message, attachments, support history, and any information you choose to provide.

2.6 Cookies and similar technologies

The Sondu website may use cookies, local storage, or similar technologies for sign in, session management, security, preferences, and core functionality. The mobile app uses local storage, device identifiers, and push tokens for session management, security, and notifications. Sondu does not currently use Firebase Analytics or Google Analytics. If Sondu later introduces non essential analytics or advertising technologies, it will update this Policy and provide any notice or choice required by applicable law before those technologies are used.

2.7 Service infrastructure, storage, and analytics

Sondu operates its backend and database infrastructure through third party cloud hosting providers. Media uploaded directly to Sondu is stored on Sondu’s backend or server storage. Generated audio is hosted through external AI music provider URLs. Sondu’s internal analytics systems may receive the usage, device, generation job, error, performance, security, IP address, and timestamp information described in Section 2.4 when generated by the Service. Sondu uses this information to operate, secure, troubleshoot, and improve the Service.

2.8 SDKs and third‑party libraries

Sondu integrates third‑party software development kits (SDKs) and libraries to provide core functionality, security, and support. These SDKs may collect device identifiers, app version, operating system, IP address, and usage events as described in their own privacy notices. Current SDK categories include:
•
Authentication: Google Sign‑In SDK (OAuth). Purpose: sign‑in and account linking. Data shared: account identifiers and tokens made available by Google based on your permissions.
•
Payments and subscriptions: Google Play Billing SDK; RevenueCat SDK; PayMongo web checkout. Purpose: process purchases, manage entitlements, prevent fraud. Data shared: transaction identifiers, product IDs, purchase status, device and app version.
•
Communications and push notifications: Resend (email delivery and push notifications). Purpose: verification codes, password resets, service notices, and optional product updates; deliver service, security, and optional product notifications. Data shared: email address, message metadata, device tokens, app instance identifiers, limited device info.
•
AI music generation: APIFrame AI SDK/API client. Purpose: submit prompts and receive generated audio. Data shared: prompts, lyrics, preferences, generation settings, job status.
Sondu does not currently use analytics, crash reporting, or performance monitoring SDKs. If we add non‑essential analytics or advertising SDKs, we will update this Policy and provide any notice or choice required by law before activation. We maintain data processing agreements with processors where required and review SDK updates before release.

2.9 App permissions (Android/iOS)

Depending on your device and OS, Sondu may request the following permissions. You can change most permissions in your device settings; disabling some may limit features.
•
Microphone (RECORD_AUDIO): Used only when you explicitly start a voice input or voice‑based feature. Audio is processed on‑device or transmitted to our servers solely to fulfill that request. We do not continuously record in the background. Recordings are not retained beyond the session unless you choose to save generated content.
•
Storage / Photos and videos (READ/WRITE_EXTERNAL_STORAGE or media permissions): Used to save generated tracks to your device, load user‑selected audio for reference (if supported), and manage offline caches. Files you export are stored in your chosen location; app cache files are managed by the OS and may be cleared when you uninstall.
•
Notifications: Used to send service updates (e.g., generation complete), security alerts, and optional product announcements. You can opt out of promotional notifications at any time via device settings or in‑app controls. Push tokens are deleted when you revoke notification permission or delete your account.
We request permissions contextually where supported and explain the purpose before the OS prompt.

3 How we use personal data

We use personal data to:
•
Provide, operate, maintain, and improve the Service.
•
Create accounts, authenticate users, and keep sessions secure.
•
Validate prompts and requests, check available credits, submit generation jobs, return results, and save content to History.
•
Provide playback, download, deletion, and any user directed export or sharing tools available in the current version of the Service.
•
Process purchases, apply credits, manage subscriptions, handle refunds or disputes, and prevent duplicate or unauthorized transactions.
•
Monitor service reliability, investigate failed generations, restore or reconcile credits when appropriate, diagnose errors, and prevent abuse or fraud.
•
Respond to support requests and send service, security, transaction, and account notices.
•
Send product or launch updates when you request them, with a way to unsubscribe from promotional messages.
•
Comply with law, enforce applicable terms, protect users and the Service, and establish or defend legal claims.
•
Analyze aggregated or de identified information to understand performance and improve Sondu, where the information can no longer reasonably identify you.
Push notifications: With your consent (where required), Sondu sends push notifications for: (a) service messages (generation complete, security, transactional); and (b) optional product/launch updates. You may opt out of promotional notifications at any time in device settings or via in‑app controls. Push tokens and related identifiers are deleted when you revoke notification permission or delete your account.
Depending on where you live and which law applies, we may process personal data based on your consent, the performance of a contract with you, compliance with a legal obligation, or a legitimate interest that is not overridden by your rights.

4 How AI music generation works

Sondu processes your prompts, lyrics, preferences, and related generation information to create requested output. Sondu currently routes music generation through APIFrame AI. Generation may occur asynchronously, so job status and related data may remain associated with your account while a request is processed, retried, completed, or investigated after a failure. To fulfill generation requests, Sondu transmits the prompts, lyrics, preferences, and other information necessary to APIFrame AI and the underlying AI model providers it uses.
APIFrame states that it may temporarily process submitted inputs and does not retain generated content beyond what is necessary to complete a request unless optional storage features are enabled. APIFrame retains API request logs for 90 days. Data processed by underlying AI model providers may be subject to their separate storage, retention, and deletion practices.
Do not submit personal data, confidential information, or content you do not have the right to use unless it is necessary and you are authorized to provide it. Before using prompts or generated content for model training or product improvement beyond providing the Service, Sondu will provide any notice or choice required by applicable law.
Ownership and license: You retain ownership of your original inputs (prompts, lyrics) to the extent you hold rights. Sondu requires a limited, non‑exclusive license to host, reproduce, and display your generated tracks and thumbnails solely to provide the Service (e.g., playback, download, sharing you initiate). Before using prompts or generated content to train models or improve Sondu beyond providing the Service, we will provide any notice or choice required by applicable law.

5 How we disclose personal data

We may disclose personal data only as reasonably necessary to the following recipients:
•
Cloud hosting, database, storage, content delivery, and security providers.
•
APIFrame AI, and, when configured, related audio processing and moderation providers used to fulfill your request.
•
Google and other authentication or identity providers when you choose their sign in method.
•
Google Play Billing, RevenueCat, PayMongo, and related billing providers used for purchases, subscriptions, refunds, entitlements, and fraud prevention.
•
Resend and other communications or customer support providers used to deliver verification, password reset, service, and support messages (including push notifications).
•
Professional advisers, auditors, insurers, regulators, courts, law enforcement bodies, or other parties when disclosure is required or permitted by law.
•
A buyer, investor, successor, or other relevant party in connection with a proposed or completed financing, merger, acquisition, reorganization, or transfer of assets, subject to appropriate safeguards.
•
Other people or services when you direct us to share content or expressly consent to the disclosure.
Sondu does not disclose personal data to third parties for their independent purposes unless this is explained at collection, authorized by you, or otherwise permitted by law. Sondu does not sell personal data.

6 Public and user directed sharing

Generated tracks and account History are private by default. Sondu does not currently provide public publishing as a released feature, although users may download or export content and share it outside Sondu. If Sondu introduces public profiles, public tracks, share links, or other community features, information you choose to publish may be visible to others and may be copied or reshared outside Sondu. Review the audience and content before publishing or sharing. Deleting the original item may not remove copies previously saved or shared by other people.

7 Data retention

Account and content data are retained while your account is active. After you request deletion, the account and associated Sondu stored content remain during a 72 hour recovery period and are then scheduled for permanent deletion. When that recovery period expires, Sondu deletes the user account, generated track records, associated History, unused credits, and media uploaded to storage controlled by Sondu.
Operational logs, diagnostics, security events, and identifiable analytics are retained only while needed to operate, troubleshoot, and protect the Service. The retention period depends on the nature of the event, whether an investigation remains active, security or fraud prevention needs, and whether the information can be aggregated or de identified. Support communications are retained until the request is resolved and as needed to document the response. Transaction records are retained for the periods required for accounting, tax, refunds, disputes, fraud prevention, and legal compliance. Backup copies are protected from ordinary use and removed or overwritten according to the applicable backup cycle. APIFrame retains API request logs for 90 days. Generated content and data processed by underlying AI model providers are subject to the practices described in Sections 4 and 9.

8 Account and data deletion

You may request deletion through the in app account settings or through the Sondu account deletion page at https://www.sondu.ai/delete-account. Sondu may take reasonable steps to verify your identity and prevent unauthorized deletion.

How to request account deletion

You can delete your account at any time from the in app account settings or by visiting https://www.sondu.ai/delete-account. After you submit a deletion request, your account enters a 72 hour recovery period. If you do not recover the account during that period, permanent deletion begins when the recovery period ends.
Permanent account deletion removes the user account, generated tracks, associated History, uploaded media stored by Sondu, and unused credits. Unused credits are forfeited and cannot be restored after permanent deletion. Essential transaction records may be retained where required for accounting, fraud prevention, refunds, dispute resolution, or legal compliance, with personal information removed or anonymized where reasonably possible. Sondu removes the account’s references to externally hosted generated audio. APIFrame states that it does not retain generated content beyond what is necessary to complete a request unless optional storage features are enabled, but it retains API request logs for 90 days. Data transmitted to underlying AI model providers may follow their separate retention and deletion practices. Transaction records, backups, provider records, and other records that Sondu is permitted or required to retain may therefore follow separate retention periods.

9 Your privacy rights and choices

Subject to applicable law and any lawful exceptions, you may have the right to be informed about processing; access personal data; object to certain processing; correct inaccurate or incomplete data; request erasure or blocking; withdraw consent; receive certain data in a portable format; and seek compensation or file a complaint.
You may also:
•
Update available profile information through your account settings.
•
Unsubscribe from marketing or launch emails using the link in the message or the stated contact channel.
•
Manage available website permissions or non essential cookie choices through your browser or consent controls.
•
Request access, correction, deletion, or other privacy assistance through Sondu’s published privacy contact channel.
Depending on where you live, you may have rights to access, correct, delete, or export your personal data, and to object to or restrict certain processing. You can exercise these rights by contacting us at [email protected] or [email protected].
We may ask for information necessary to verify your identity and understand your request. We will respond within the period required by applicable law (typically within 30 days, extendable as permitted by law). If you are in the Philippines, you may also contact or submit a complaint to the National Privacy Commission.

10 Security

Sondu applies reasonable organizational, physical, and technical safeguards selected according to the nature of the personal data, the risks of the processing, and the production systems in use. These safeguards include access restrictions, secure transmission where supported, system monitoring, backup controls, incident handling procedures, and limits on staff and provider access. Sondu reviews these safeguards as the Service changes.
We use TLS/HTTPS encryption for data transmitted between your device and Sondu’s servers and between Sondu and our service providers. We also apply access controls, monitoring, and backup protections to help protect personal data. No service can guarantee absolute security. You are responsible for protecting your credentials and should notify Sondu promptly if you suspect unauthorized account activity.

11 International data transfers

Sondu is based in the Philippines, but providers supporting hosting, authentication, payments, communications, and AI music generation may process or store personal data in other countries or regions described in their privacy notices. Where required, Sondu uses appropriate contractual, organizational, and technical safeguards and remains accountable for personal data under its control.
Our service providers may process or store data in countries including the Philippines, the United States, and other regions where they operate.

12 Children

Sondu is intended for users aged 13 and older (or the higher minimum age in your jurisdiction). Children under 13 must not create or use a Sondu account or submit personal data through the Service. If Sondu learns that it collected personal data from a child under 13, it will take appropriate steps to delete or restrict that data. A parent or legal guardian may contact Sondu to request access to, correction of, or deletion of a child’s personal data. Users who are old enough to use Sondu but have not reached the age of legal majority where they live should review the Service with a parent or legal guardian and obtain any authorization required by applicable law.

13 Third party services and links

The Service may link to or integrate with third party services. Their handling of personal data is governed by their own terms and privacy notices. Review those notices before providing information or authorizing a connection.

14 Changes to this Policy

Sondu may update this Policy to reflect changes in the Service, technology, providers, law, or business practices. The updated version will show a new effective or last updated date. If a change materially affects your rights or how personal data is used, Sondu will provide additional notice or obtain consent where required.

15 Contact Sondu

For privacy questions, requests, or complaints, contact our Privacy Officer at [email protected] or [email protected]. Our business address is Poblacion 2, Hindang, Leyte, Eastern Visayas 6523, Region VIII, Philippines.
For account deletion, use the in app deletion option or visit https://www.sondu.ai/delete-account.
Want to delete your account?
Read the deletion steps, recovery period, and what data is removed.
Deletion guide
© 2026 Sondu AI
Policy
Delete account
RESTORING SONDU