Sonary
Sonary Privacy Policy
Last updated: 15 September 2026
Application: Sonary — all-in-one AI audio toolkit (com.newagedevs.sonary), published by New Age Devs.
Privacy contact: imamagun94@gmail.com
The short version. Sonary is privacy-first. Your audio and video files are processed on your device by default and never leave it for standard tools (extract, convert, trim, split, merge, record) or for on-device AI. The only time an audio file leaves your device is when you deliberately start a cloud AI job (for example, a highest-quality vocal separation or noise removal that runs in the cloud). In that case the audio is sent over an encrypted connection, processed, and deleted from the processing servers after the job. We do not require an account, we do not ask for your name or email to use the app, and we never sell your data.
1. Who we are
Sonary (“Sonary”, “we”, “us”) is a mobile audio toolkit that lets you extract audio from video, convert between formats, trim, split, merge, record audio, and run AI features such as vocal/instrument separation and background-noise removal. This policy explains what data the app handles, why, who processes it on our behalf, and the choices you have.
This policy covers the Sonary mobile app. It does not cover third-party services you may open from the app (for example, if you share an exported file to another app), which have their own policies.
2. What we collect and why
We collect the minimum needed to make the app work, keep it stable, process purchases, and (for the free tier) show ads. Here is everything, grouped by purpose.
2.1 Audio, video & media you choose
- What: audio files, video files, and voice recordings that you select or record so the app can process them.
- Where it is processed: on your device for all standard tools (extract, convert, trim, split, merge, recording playback) and for on-device AI. For these, your media never leaves your device. On-device processing uses FFmpeg and an on-device AI runtime (ONNX Runtime).
- Cloud exception: if you choose a cloud AI feature, the specific audio file for that job is uploaded for processing (see Section 3).
- Why: to perform the exact task you asked for.
2.2 Purchases & subscriptions
- What: your purchase and subscription status and history (which subscription or credit pack you bought, whether a purchase is active, receipt/validation data). Payments are handled by Google Play Billing — we never see or store your card number.
- Processed by: RevenueCat (our purchase & entitlement manager) and Google Play Billing. RevenueCat identifies your purchases with an anonymous, app-generated identifier, not your name or email.
- Why: to sell and restore subscriptions and credit packs, unlock what you paid for, and prevent purchase fraud. Balances and entitlements are verified on our server so they can’t be forged on the device.
2.3 Advertising (free tier only)
- What: your device advertising ID (Google Advertising ID / Apple IDFA), ad interaction data (impressions, clicks, rewarded-ad completions), and coarse/approximate location that ad partners may derive from your IP address for ad delivery.
- Processed by: AppLovin MAX (our ad mediation partner) and the ad networks it mediates.
- Why: to show ads that keep the free tier free, and to grant rewarded-ad credits you opt into. Buying Pro removes all ads and this ad data collection.
2.4 Analytics, diagnostics & crash reports
- What: app-usage events (for example: a feature opened, a job started/completed, a paywall viewed), a Firebase app-instance identifier and device/app identifiers, crash logs and stack traces, and performance diagnostics. These payloads are scrubbed of personal data — they contain no file contents and no raw file names or paths.
- Processed by: Firebase (Google) — Analytics, Crashlytics, and Remote Config.
- Why: to understand which features are used, fix crashes and bugs, keep the app stable, and safely roll out configuration changes.
2.5 Data stored only on your device
- What: your processing history, exported files, and app settings are stored locally on your device. Short-lived authentication/entitlement tokens are stored in the platform’s encrypted secure storage (Android Keystore / iOS Keychain). Secure storage holds tokens only — never your audio or media.
- Why: so your history and exports are available offline, and so the app can prove to our server what you’re entitled to without shipping any long-lived secret onto the device.
3. Your audio & cloud AI processing
This is the most privacy-sensitive part of the app, so we’re explicit about it.
Our rule: “User audio is the user’s. Audio leaves the device only for an explicitly user-initiated cloud AI job, transmitted over TLS, processed, and deleted server-side after processing. No background uploads.”
- Only on your action. Audio is uploaded only when you choose a cloud AI feature and confirm it. There are no background, automatic, or speculative uploads.
- Where it goes. The file is sent over an encrypted (TLS/HTTPS) connection to our backend, which forwards it to our AI processing provider, Replicate, purely to run that one job. The AI model runs, produces your output (for example, separated vocal and instrumental tracks), and the app downloads the result.
- No identifying information is sent. Replicate receives only the audio bytes for that one job — no name, email, account, Apple ID, device identifier, advertising ID, or purchase data. It cannot link the file to you.
- Deletion after processing. Our backend deletes the uploaded file from Replicate through its API as soon as the job finishes — on success, failure, or cancellation. Result files are delivered to your device over short-lived links; we keep no copy of your audio on our own servers.
- On-device AI stays local. When an AI task runs on-device (for example, when you choose the on-device “Lite” tier or you’re offline with a compatible model installed), your audio is not uploaded at all.
- Asked before it happens. The app itself — not just this policy — names Replicate and states what is sent before the first cloud upload, and asks you to allow it.
4. What we do not collect
- We do not require an account. We do not ask for your name, email address, phone number, or postal address to use the app.
- We do not collect precise (GPS) location. The app requests no location permission.
- We do not access your audio, media, contacts, photos, or files except the specific items you pick or record for a task.
- We do not scan your library, upload media in the background, or read anything for advertising.
- We do not sell your personal data, and we do not share your audio with anyone except the AI processing provider needed to run a cloud job you started.
5. Third-party processors & sub-processors
We use a small number of established providers to run parts of the service. Each processes data only for the purpose listed and under its own privacy policy.
| Provider | Role in Sonary | Data it handles | Privacy policy |
|---|---|---|---|
| Google / Firebase | Analytics, crash reporting (Crashlytics), and Remote Config | App-instance & device identifiers, usage events, crash logs, diagnostics | firebase.google.com/support/privacy |
| Google Play | Processes in-app purchases and subscriptions (billing) | Purchase transactions (payment details handled by Google, not by Sonary) | policies.google.com/privacy |
| RevenueCat | Manages subscriptions, credit purchases, and entitlements | Purchase/subscription status & history tied to an anonymous app-generated ID | revenuecat.com/privacy |
| AppLovin MAX | Ad mediation for the free tier (removed by Pro) | Advertising ID, ad interaction data, IP-derived approximate location | applovin.com/privacy |
| Replicate | Runs cloud AI audio jobs you start (e.g. separation, noise removal) | The single audio file for that job, deleted after processing | replicate.com/privacy |
6. How we protect your data
- Encryption in transit. All network traffic — audio uploads, purchase checks, analytics, and ads — uses encrypted TLS/HTTPS connections.
- No secrets on the device. Provider tokens and signing keys live only on our server.
- Server-authoritative. Credits, balances, and subscription entitlements are verified on our server so they can’t be forged on the device.
- PII-clean telemetry. Analytics and crash reports are stripped of personal data, file contents, and raw file paths/names before they are sent.
- Encrypted local secure storage. Tokens/entitlements are kept in the platform keystore/keychain, not in plain app storage.
7. Data retention
- On-device data (history, exports, settings) stays on your device until you delete it in the app or uninstall the app.
- Cloud AI audio is deleted from the processing servers after the job completes (see Section 3).
- Purchase records are retained by RevenueCat and the app store for as long as needed to manage your subscription, honor restores, and meet legal/accounting obligations.
- Analytics, crash, and advertising data are retained by Firebase and AppLovin per their standard retention policies.
8. Your rights & choices
- Access & deletion. You can request access to, or deletion of, data associated with you by emailing imamagun94@gmail.com. Because we do not operate accounts, please send the request from the device/context you used so we can locate the relevant identifiers (e.g. your anonymous purchase ID).
- Delete on-device data yourself. Clearing history/exports in the app, or uninstalling Sonary, removes locally stored data from your device.
- Advertising choices. You can reset or limit your advertising ID in your device settings. On iOS, the App Tracking Transparency prompt lets you decline tracking. In the EU, a consent prompt governs personalized ads. Upgrading to Pro removes ads entirely.
- Analytics. You can limit ad/analytics identifiers via your device’s privacy settings.
9. Device permissions we request
| Permission | Why |
|---|---|
| Microphone (record audio) | Only to record audio when you use the voice recorder. |
| Photos / media & file access | Only to let you pick the video/audio files you want to process. Selection is user-initiated. |
| Internet | For cloud AI jobs, model downloads, purchases, and (free tier) ads. |
| Ignore battery optimizations (Android, optional) | Requested only when you run a long on-device AI job, so the system doesn’t kill it mid-process. You can decline. |
10. Children’s privacy
Sonary is a general-purpose audio productivity tool intended for a general audience. It is not directed to children under 13 (or the equivalent minimum age in your region), and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us at imamagun94@gmail.com and we will delete it. This app is not enrolled in Google Play’s Families program and is not designed for or marketed to children.
11. International data transfers
Our processors (including Google/Firebase, RevenueCat, AppLovin, and Replicate) may process data on servers located in the United States and other countries. By using the app you understand that the limited data described here may be processed in those countries under the safeguards those providers maintain.
12. Changes to this policy
We may update this policy as the app evolves. We will change the “Last updated” date above and, for material changes, provide an in-app notice where appropriate.
13. Contact us
For any privacy question or an access/deletion request, contact: imamagun94@gmail.com.
© New Age Devs. Sonary (com.newagedevs.sonary). Last updated 15 September 2026.