Sonary
Sonary Privacy Policy
Last updated: 7 July 2026
Application: Sonary — all-in-one AI audio toolkit (com.newagedevs.sonary), published by New Age Devs.
Privacy contact: imamagun94@gmail.com (placeholder — replace with a monitored support address before publishing)
The short version. Sonary is privacy-first. Your audio and video files are processed on your
device by default and never leave it for standard tools (extract, convert, trim, split, merge,
record) or for on-device AI. The only time an audio file leaves your device is when you
deliberately start a cloud AI job (for example, a highest-quality vocal separation or noise removal
that runs in the cloud). In that case the audio is sent over an encrypted connection, processed, and
deleted from the processing servers after the job. We do not require an account, we do not ask for
your name or email to use the app, and we never sell your data.
Contents
- Who we are
- What we collect and why
- Your audio & cloud AI processing
- What we do not collect
- Third-party processors & sub-processors
- How we protect your data
- Data retention
- Your rights & choices
- Device permissions we request
- Children’s privacy
- International data transfers
- Changes to this policy
- Contact us
1. Who we are
Sonary (“Sonary”, “we”, “us”) is a mobile audio toolkit that lets you extract audio from video, convert
between formats, trim, split, merge, record audio, and run AI features such as vocal/instrument
separation and background-noise removal. This policy explains what data the app handles, why, who
processes it on our behalf, and the choices you have.
This policy covers the Sonary mobile app. It does not cover third-party services you may open from the
app (for example, if you share an exported file to another app), which have their own policies.
2. What we collect and why
We collect the minimum needed to make the app work, keep it stable, process purchases, and (for the
free tier) show ads. Here is everything, grouped by purpose.
2.1 Audio, video & media you choose
- What: audio files, video files, and voice recordings that you select or record so the app can
process them. - Where it is processed: on your device for all standard tools (extract, convert, trim, split,
merge, recording playback) and for on-device AI. For these, your media never leaves your device.
On-device processing uses FFmpeg and an on-device AI runtime (ONNX Runtime). - Cloud exception: if you choose a cloud AI feature, the specific audio file for that job is
uploaded for processing (see Section 3). - Why: to perform the exact task you asked for.
2.2 Purchases & subscriptions
- What: your purchase and subscription status and history (which subscription or credit pack you
bought, whether a purchase is active, receipt/validation data). Payments are handled by Google Play
Billing — we never see or store your card number. - Processed by: RevenueCat (our purchase & entitlement manager) and Google Play Billing. RevenueCat
identifies your purchases with an anonymous, app-generated identifier, not your name or email. - Why: to sell and restore subscriptions and credit packs, unlock what you paid for, and prevent
purchase fraud. Balances and entitlements are verified on our server so they can’t be forged on the
device.
2.3 Advertising (free tier only)
- What: your device advertising ID (Google Advertising ID / Apple IDFA), ad interaction data
(impressions, clicks, rewarded-ad completions), and coarse/approximate location that ad partners may
derive from your IP address for ad delivery. - Processed by: AppLovin MAX (our ad mediation partner) and the ad networks it mediates.
- Why: to show ads that keep the free tier free, and to grant rewarded-ad credits you opt into.
Buying Pro removes all ads and this ad data collection.
2.4 Analytics, diagnostics & crash reports
- What: app-usage events (for example: a feature opened, a job started/completed, a paywall
viewed), a Firebase app-instance identifier and device/app identifiers, crash logs and stack traces,
and performance diagnostics. These payloads are scrubbed of personal data — they contain no file
contents and no raw file names or paths. - Processed by: Firebase (Google) — Analytics, Crashlytics, and Remote Config.
- Why: to understand which features are used, fix crashes and bugs, keep the app stable, and safely
roll out configuration changes.
2.5 Data stored only on your device
- What: your processing history, exported files, and app settings are stored locally on your
device. Short-lived authentication/entitlement tokens are stored in the platform’s encrypted secure
storage (Android Keystore / iOS Keychain viaflutter_secure_storage). Secure storage holds tokens
only — never your audio or media. - Why: so your history and exports are available offline, and so the app can prove to our server
what you’re entitled to without shipping any long-lived secret onto the device.
3. Your audio & cloud AI processing
This is the most privacy-sensitive part of the app, so we’re explicit about it.
Sonary’s stated privacy rule, quoted from our internal security policy, is: “User audio is the
user’s. Audio leaves the device only for an explicitly user-initiated cloud AI job, transmitted
over TLS, processed, and deleted server-side after processing (documented retention window). No
background uploads.”
- Only on your action. Audio is uploaded only when you choose a cloud AI feature and confirm it.
There are no background, automatic, or speculative uploads. - Where it goes. The file is sent over an encrypted (TLS/HTTPS) connection to our backend proxy,
which forwards it to our AI processing provider, Replicate, purely to run that one job. The AI
model runs, produces your output (for example, separated vocal and instrumental tracks), and the app
downloads the result. - Deletion after processing. Per the policy above, uploaded audio is deleted from the processing
servers after the job completes. The exact retention window is being finalized with our backend
team and will be stated here before or at launch. - On-device AI stays local. When an AI task runs on-device (for example, when you choose the
on-device “Lite” tier or you’re offline with a compatible model installed), your audio is not
uploaded at all.
4. What we do not collect
- We do not require an account. We do not ask for your name, email address, phone number, or
postal address to use the app. - We do not collect precise (GPS) location. The app requests no location permission.
- We do not access your audio, media, contacts, photos, or files except the specific items you pick
or record for a task. - We do not scan your library, upload media in the background, or read anything for advertising.
- We do not sell your personal data, and we do not share your audio with anyone except the AI
processing provider needed to run a cloud job you started.
5. Third-party processors & sub-processors
We use a small number of established providers to run parts of the service. Each processes data only
for the purpose listed and under its own privacy policy.
| Provider | Role in Sonary | Data it handles | Privacy policy |
|---|---|---|---|
| Google / Firebase | Analytics, crash reporting (Crashlytics), and Remote Config | App-instance & device identifiers, usage events, crash logs, diagnostics | firebase.google.com/support/privacy |
| Google Play | Processes in-app purchases and subscriptions (billing) | Purchase transactions (payment details handled by Google, not by Sonary) | policies.google.com/privacy |
| RevenueCat | Manages subscriptions, credit purchases, and entitlements | Purchase/subscription status & history tied to an anonymous app-generated ID | revenuecat.com/privacy |
| AppLovin MAX | Ad mediation for the free tier (removed by Pro) | Advertising ID, ad interaction data, IP-derived approximate location | applovin.com/privacy |
| Replicate | Runs cloud AI audio jobs you start (e.g. separation, noise removal) | The single audio file for that job, deleted after processing | replicate.com/privacy |
6. How we protect your data
- Encryption in transit. All network traffic — audio uploads, purchase checks, analytics, and
ads — uses encrypted TLS/HTTPS connections. - No secrets on the device. Provider tokens and signing keys live only on our server. The app
authenticates to our backend with short-lived, signed, replay-protected requests. - Server-authoritative. Credits, balances, and subscription entitlements are verified on our server
so they can’t be forged on the device. - PII-clean telemetry. Analytics and crash reports are stripped of personal data, file contents,
and raw file paths/names before they are sent. - Encrypted local secure storage. Tokens/entitlements are kept in the platform keystore/keychain,
not in plain app storage.
7. Data retention
- On-device data (history, exports, settings) stays on your device until you delete it in the app
or uninstall the app. - Cloud AI audio is deleted from the processing servers after the job completes (see
Section 3; exact window being finalized). - Purchase records are retained by RevenueCat and the app store for as long as needed to manage
your subscription, honor restores, and meet legal/accounting obligations. - Analytics, crash, and advertising data are retained by Firebase and AppLovin per their standard
retention policies.
8. Your rights & choices
- Access & deletion. You can request access to, or deletion of, data associated with you by
emailing imamagun94@gmail.com. Because we do not operate accounts, please send the request from the
device/context you used so we can locate the relevant identifiers (e.g. your anonymous purchase ID). - Delete on-device data yourself. Clearing history/exports in the app, or uninstalling Sonary,
removes locally stored data from your device. - Advertising choices. You can reset or limit your advertising ID in your device settings. On iOS,
the App Tracking Transparency prompt lets you decline tracking. In the EU, a consent prompt (CMP)
governs personalized ads. Upgrading to Pro removes ads entirely. - Analytics. Certain analytics event groups can be disabled remotely; you can also limit
ad/analytics identifiers via your device’s privacy settings.
9. Device permissions we request
| Permission | Why |
|---|---|
| Microphone (record audio) | Only to record audio when you use the voice recorder. |
| Photos / media & file access | Only to let you pick the video/audio files you want to process. Selection is user-initiated. |
| Internet | For cloud AI jobs, model downloads, purchases, and (free tier) ads. |
| Ignore battery optimizations (Android, optional) | Requested only when you run a long on-device AI job, so the system doesn’t kill it mid-process. You can decline. |
10. Children’s privacy
Sonary is a general-purpose audio productivity tool intended for a general audience. It is not
directed to children under 13 (or the equivalent minimum age in your region), and we do not knowingly
collect personal information from children. If you believe a child has provided us with personal
information, please contact us at imamagun94@gmail.com and we will delete it. This app is not enrolled
in Google Play’s Families program and is not designed for or marketed to children.
11. International data transfers
Our processors (including Google/Firebase, RevenueCat, AppLovin, and Replicate) may process data on
servers located in the United States and other countries. By using the app you understand that the
limited data described here may be processed in those countries under the safeguards those providers
maintain.
12. Changes to this policy
We may update this policy as the app evolves (for example, to state the finalized cloud-audio retention
window). We will change the “Last updated” date above and, for material changes, provide an in-app
notice where appropriate.
13. Contact us
For any privacy question or an access/deletion request, contact: imamagun94@gmail.com.
© New Age Devs. Sonary (com.newagedevs.sonary). Last updated 7 July 2026