Privacy policy

Your recordings, your data.

Sonarnote is built around the idea that interview audio is sensitive by default. This is what we collect, how we use it, and the controls you have.

Last updated · July 9, 2026

Overview

Sonarnote records locally on your device, then uploads each recording to our service automatically when it ends so it can be transcribed and synced to your workspace. This page describes what we collect, how we use it, and the choices you have.

Who we are

SIA Sonarnote (registration number 40203712513, registered in the Commercial Register of the Republic of Latvia) operates Sonarnote and is the data controller for the account, billing, and usage data described in this policy.

For the recordings and transcripts you create, you act as the controller and Sonarnote acts as your processor, handling that content only to provide the service to you. You are responsible for the lawful basis to record participants and for informing them that the conversation is recorded and transcribed.

Registered address: Taisnā iela 5, Riga, LV-1063, Latvia. For any privacy question or request, contact us at [email protected].

Information we collect

Account data: your name, email, and authentication credentials when you sign up or sign in with email and password, Google, or LinkedIn. Signing in with a social provider may also share your profile photo.

Recording data: audio files and generated transcripts. When a recording ends, it is uploaded to our service for transcription, storage, and sharing across your workspace. Recordings may contain the voices and personal data of other participants. You are responsible for ensuring you have the right to record and process their data.

Calendar data: if you connect your calendar, we sync upcoming events, such as titles, times, meeting links, and attendee names and email addresses, to show your meetings in the dashboard. We use this data only to provide calendar features, and you can disconnect your calendar at any time.

Usage data: basic telemetry such as feature interactions and error reports, used to keep the product reliable.

Billing data: handled by our payment processor. We do not store full payment card details on our servers.

How we use your data

To provide the service: transcribing recordings, syncing your workspace across devices, and powering search and AI highlights.

To communicate with you: account notifications, security alerts, and product updates you have opted into.

To improve the product: aggregated, de-identified analytics. We rely on third-party providers to transcribe and process your content. They handle it under their own data terms and may use it in accordance with those terms, which may include improving or training their models.

Legal bases for processing

If you are in the European Economic Area or the United Kingdom, we process your personal data on the following legal bases: to perform our contract with you (providing the recorder, transcription, and workspace), to pursue our legitimate interests (keeping the service secure and reliable), to comply with legal obligations, and on the basis of your consent where required, which you can withdraw at any time.

Candidate sourcing

Some plans include a candidate sourcing feature. When you record a hiring brief and ask us to find candidates, we use third-party data providers to search public web sources and return a short list of matching professional profiles. These may include a person's name, role, work history, and location, and, only when you explicitly request it for a specific candidate, professional contact details such as an email address or phone number.

These candidates are not Sonarnote users. We process their professional data to provide the sourcing feature to you, relying on the legitimate interests of you and of Sonarnote in professional recruitment. The data originates from third parties and public web sources and may be incomplete, out of date, or inaccurate; a search or a contact lookup may return no results.

We retain sourced candidate data only as long as needed for your recruitment workflow. A candidate, or you on their behalf, can ask us to remove their data at any time by contacting [email protected], and we will delete it. When you contact or evaluate candidates surfaced by this feature, you act as the controller for that activity and are responsible for complying with applicable laws.

Data sharing

We share data only with subprocessors required to run the service, such as our cloud storage, transcription, candidate data, analytics, and email providers, and with internal tools we use to operate the business, such as for support and operational notifications.

We do not sell your data, and we do not share it for advertising.

Cookies and tracking

We use strictly necessary cookies to keep you signed in and to operate the service. We also use privacy-friendly, self-hosted analytics to understand aggregate usage; it does not build advertising profiles or track you across other sites.

You can block cookies in your browser settings, though some parts of the service may not work without the necessary ones.

Social logins

You can sign in with Google or LinkedIn. When you do, the provider shares basic profile information with us, such as your name, email address, and profile photo, which we use to create and secure your account. We do not receive your social account password.

Google API Services Limited Use

Sonarnote's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

We only use Google user data to provide and improve features you have requested, we do not transfer it except as necessary to provide or improve those features or as required by law, and we do not use it for advertising or to train generalized AI or machine learning models. Humans do not read your Google user data unless we have your consent for a specific purpose, it is necessary for security or to comply with the law, or the data is aggregated and de-identified.

International data transfers

We are based in Latvia and our service is operated within the European Union. Some subprocessors may process data outside the EEA. Where that happens, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.

Children

Sonarnote is intended for business use by adults. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us data, contact us and we will delete it.

Retention and deletion

Recordings and transcripts persist according to your plan's history window. You can delete any recording from the dashboard at any time, and deletion is permanent within thirty days.

If you close your account, we delete or anonymize your personal data within sixty days, except where law requires us to retain records.

Your rights

You can access and delete your data from the workspace settings. Data export is available on request by emailing [email protected]. For requests covered by GDPR, CCPA, or other privacy laws, write to the same address and we will respond within thirty days.

Security

Data in transit is encrypted with TLS. Data at rest in our cloud storage is encrypted with industry-standard ciphers. Access to production systems is restricted and audited.

Changes to this policy

We will post material changes to this page and notify active users by email. Continued use of Sonarnote after a change means you accept the updated policy.

Contact

Questions about privacy or data handling go to [email protected].