Privacy
SONA Privacy Policy
Effective date: 15-06-2026
Last updated: 14-09-2026
SONA is a calm, private place to understand your tinnitus symptoms. Because this app handles information about your health, we take privacy seriously, and we’ve tried to write this policy the way we’d want one written for us: plainly, honestly, and without hiding the parts that matter.
This policy explains what we collect, why, who (if anyone) we share it with, how long we keep it, and the rights you have over your data under the EU General Data Protection Regulation (GDPR).
Who we are
SONA (“we”, “us”, “the app”) is provided by Rodrigo Felicio, operating as an individual sole trader, based in Madrid, Spain.
We are the data controller for the personal data described in this policy. That means we decide what data is collected and why, and we’re responsible for protecting it.
- Contact: hello@sona-care.com
- Data Protection Officer: We have not appointed a DPO. You can reach us about any privacy matter at hello@sona-care.com.
What data we collect
We only collect what the app actually needs to work. We don’t run advertising trackers or behavioural profiling SDKs. We do use one third-party crash-reporting service (Sentry — described below and in the sub-processors table) and we collect first-party usage data to understand how the app is performing.
Here’s everything, grouped by type.
Account data
- Email address and password. Your password is securely hashed (bcrypt) and managed entirely by our authentication provider (Supabase Auth). The app never sees, stores, or transmits your plaintext password or its hash.
- Username / display name.
- Google Sign-In (optional). If you choose to sign in with Google, Google provides us with your email address and basic profile information to create your account. We never receive your Google password.
- Apple Sign-In (optional). If you choose to sign in with Apple, Apple provides us with your email address and, the first time only, your name. We never receive your Apple password. If you use Apple’s “Hide My Email” option, the address we hold for you is a private Apple relay address rather than your real one, we never see your real address, and that relay address is what will appear in your data export.
- Waitlist (pre-launch only). If you joined a SONA waitlist before having an account, we may hold your email address, the sign-up source, and which device you said you use (iPhone or Android). This is not linked to any account and exists only to let us contact you about launch.
Health data (special category, see the section below)
This is the heart of what SONA does, and the most sensitive information we hold:
- Your THI (Tinnitus Handicap Inventory) score (0–100), grade, and your per-question answers, plus the history of every THI you’ve taken.
- Tinnitus details: side (left / right / both), start date, and duration.
- Somatic modulators: whether jaw, teeth, neck, or posture affect your tinnitus.
- Daily check-ins: tinnitus intensity (1–10), sleep hours and quality, stress, caffeine, alcohol, noise exposure, jaw tension, distraction, and mood.
- Free-text daily notes you choose to write.
- Self-reported tinnitus sound profile: frequency (Hz) per ear, relative loudness, dominant ear, and texture.
- Spike records. When you use the Spike Companion to ride out a sudden flare, we record that the spike happened, how intense it felt (1–10, optional), what you suspected triggered it, whether you completed the guided session, and, if you answer the follow-up the next day, how many days it took to settle. This is stored separately from your daily check-in, because a spike is a one-off event rather than a once-a-day rating.
- Relief sessions. Which relief tool you used (quick tricks, somatic exercises, guided mindfulness), which specific technique, how long you stayed, whether you finished, and, where the screen asks, whether it helped.
- AI-generated summaries: your weekly insight summaries and your specialist report summaries.
Health data from a smartwatch or phone (only if you turn it on)
If you connect a smartwatch or health device, SONA can read a small set of readings from Apple Health (iOS) or Health Connect (Android) so your check-ins fill themselves in and so we can spot patterns you’d never see by eye.
- What we read: total sleep and sleep stages (deep, REM, light), heart rate variability, resting heart rate, and ambient noise exposure. Ambient noise is iOS only, Android’s Health Connect doesn’t provide it to us, so on Android that value is always empty.
- We only ever read. We never write anything back into Apple Health or Health Connect, and we never ask for permission to.
- This has its own separate consent. We ask for it on its own screen, apart from the consent for your tinnitus tracking, because reading your heart rate off your watch is a genuinely different thing from recording how loud your tinnitus felt today. Turning on watch sync without that consent is impossible: the app will not even ask your phone’s operating system for access until you have agreed.
- We deliberately did not carry anyone over. Everyone is asked fresh, including people who had already agreed to an earlier, broader consent screen. If you’d previously connected a watch, your sync is paused until you agree to the new, specific wording.
- Where it goes: into your own daily check-in record in our database, alongside a note of whether that day’s entry came from your watch, from you, or from both. It is never sent to any third party except as described in “AI processing” below.
- Turning the switch off pauses sync but keeps your consent, so you can switch it back on freely. To withdraw the consent itself, there’s a separate control in Connected devices, and withdrawing your general health-data consent switches watch sync off too, so data can’t keep arriving through the back door.
Messages between you and the founder
SONA has a small, deliberately narrow message channel so the founder can ask you a specific question about the app and hear back from you.
- Only the founder can start a conversation. You can reply to one, but you can’t open one, anything you want to raise unprompted goes through the normal feedback form instead.
- What we store: the text of each message in both directions (yours and ours), when each was sent, when each side last read the thread, and a short internal label describing what the thread is about (never shown to you).
- You can turn these off in your settings. That’s enforced in our database, not just in the app, so a bug can’t produce a message you asked not to receive. A conversation already open when you opt out stays readable rather than being cut off mid-sentence, but the app stops surfacing it and no new ones can be started.
- Your replies are yours. Neither you nor we can edit or delete the other side’s words once sent.
Behavioural data (how you use the app)
- Saved custom tones; sound-masking sessions; breathing sessions.
- Your Calm Space progress and any free-text reflections you write.
- News bookmarks and read state; clinical-trial matches and dismissals; community-interest signals.
- Your preferences and consent flags: research consent, health-data consent, smartwatch consent, trials opt-out, notification preferences, founder-message opt-out, your age confirmation, whether you’ve dismissed the one-time prompt to take the THI, and your chosen language (English or Spanish) for the app and for AI-written text.
- Any free-text feedback you send us.
Technical data
- A user UUID (a random internal ID that identifies your account in our database).
- Your authentication session token, stored encrypted on your device (iOS Keychain / Android Keystore via SecureStore).
- AI cost/usage telemetry (which AI feature ran, token counts, estimated cost), linked to your user ID so we can monitor and control costs. This is automatically de-identified (your ID is set to NULL) when you delete your account, see “Account deletion”.
- Crash and error reports (Sentry). If the app crashes or throws an unexpected error, a diagnostic report is sent to Sentry, Inc. (our crash-reporting sub-processor). Reports contain: the error message, a stack trace, device model, OS version, and app version. They do not contain your email, name, user ID, IP address, screen contents, or any health or symptom data — sensitive fields are stripped on-device before transmission, we never record your screen, and reports are only sent from released builds, never in development.
- App-open and feature-visit timestamps. Each time you open or foreground the app, and each time you navigate to a main screen (such as Home, Track, Sounds, News, or Community), we record a timestamp linked to your account. This data is stored in our own database (Supabase, EU), is never shared with third parties, and is used solely to understand how the app is being used so we can improve it.
- App update checks. When the app starts, it checks Expo’s update service for a newer version. Expo receives your device’s IP address and which version you’re running as part of that check. No account data and no health data is involved.
- Missing-translation reports. If a piece of Spanish text is missing and the app has to fall back to English, the app records the internal name of that missing label so we can fix it. This records only the label name and the language, never your account, never anything you’ve written or tracked. Because a missing translation can happen on the login screen before you’re signed in, this can be sent without an account attached.
Push notifications are local-only. SONA’s reminders are generated on your own device. We do not send a push token to any server, and no remote service tracks your notifications.
Special-category health data & your explicit consent
Most of what SONA stores is health data, which GDPR (Article 9) treats as a “special category” needing extra protection.
We process your health data on the basis of your explicit consent, which you give during setup before any health data is collected. Health-device data from a watch has its own separate explicit consent, asked on its own screen, because it’s a different purpose, see the smartwatch section above.
You are always free to withdraw either consent. Withdrawing is as easy as giving: there are controls for both in your settings. Withdrawing stops any further collection, pauses the features that depend on it, and leaves the data you already have in place until you choose to export or delete it (see “Account deletion & what persists”).
How we use your data, and our lawful basis
We use your data only for the purposes below. For each, we tell you the legal basis we rely on under GDPR.
| What we do | Why | Lawful basis |
|---|---|---|
| Create and run your account; let you log in | To provide the app you signed up for | Contract (Art. 6(1)(b)) |
| Store and display your tracking, profiles, sessions, spikes, relief sessions, bookmarks | Core app features | Contract (Art. 6(1)(b)); and explicit consent for the health-data parts (Art. 9(2)(a)) |
| Read sleep, heart-rate variability, resting heart rate and noise exposure from your watch | To fill in your check-ins automatically and find patterns you couldn’t see by hand | Separate explicit consent for health-device data (Art. 9(2)(a)) |
| Generate your weekly insight and specialist report summaries | To give you the personalised insights SONA exists for | Explicit consent for health data (Art. 9(2)(a)) |
| Match you to clinical trials and relevant news | To surface research that may matter to you | Contract / consent for the underlying health profile used |
| Send you a check-in message from the founder, and receive your reply | To hear directly from the people using SONA and improve it | Consent (Art. 6(1)(a)) — you can turn these off at any time |
| Show the app and write AI summaries in your chosen language | To give you SONA in English or Spanish as you prefer | Contract (Art. 6(1)(b)) |
| Keep the service secure; prevent abuse; monitor and control AI/infrastructure costs | To protect users and keep the app sustainable | Legitimate interests (Art. 6(1)(f)) |
| Measure how the app is used (app-open and feature-visit timestamps) | To understand engagement and improve the product | Legitimate interests (Art. 6(1)(f)) — first-party product analytics, not shared, not used for advertising |
| Email you before deleting a long-inactive account | To warn you so you can keep your account if you want it | Legal obligation (Art. 6(1)(c)) / legitimate interests (Art. 6(1)(f)) |
| Send you waitlist / launch emails (pre-launch) | To tell you when SONA is available | Consent (Art. 6(1)(a)) |
| Record your research-consent and other preference flags | To honour your choices | Consent (Art. 6(1)(a)) |
We do not use your data for advertising, profiling for ads, or automated decisions that produce legal or similarly significant effects about you.
AI processing, exactly what happens (and what never does)
SONA uses AI for two features: your weekly insight summary and your specialist report. We know AI and health data together make people nervous, so here is precisely how it works.
- The AI provider is Anthropic (the Claude API), a US company.
- Anthropic receives de-identified health metrics only, the numeric symptom data needed to write a summary.
- Anthropic never receives: your name, your email, your username, or your user UUID. No identifier of any kind is attached to the request, not in the text we send, and not in the technical details of the request either.
- Anthropic never receives any free text you write. Your daily notes, your reflections, your feedback, and your messages to the founder are never sent to any AI.
- All AI calls happen server-side, inside our secure backend functions. The app itself never talks to Anthropic and never holds an AI key.
- For news and clinical-trial features, the AI receives zero user data, only public article and trial text. That includes the Spanish versions of article and trial summaries, which are written once from the public text and shown to everyone, not generated per person.
- Your chosen language decides which language the summary is written in. Your language preference is not sent as data about you, it simply selects the instruction we give the AI.
Your weekly insight summary sends the last 7 days of check-ins, one line per day: the date, tinnitus intensity, sleep hours and quality, stress, caffeine, alcohol, noise exposure, and jaw tension. If you’ve connected a watch, it also sends four watch readings per day: your heart rate variability, your resting heart rate, your deep-sleep minutes, and your REM-sleep minutes. It does not send your total sleep time, your light-sleep minutes, or your noise-exposure reading. It also sends your THI score and grade, which side your tinnitus is on, and your somatic modulators.
Your specialist report is a bigger disclosure, and you should know that before you generate one. It sends 90 days of check-in data and every THI score you have ever recorded, with dates. It also sends your tested tinnitus frequency and loudness for each ear. Unlike the weekly summary, your day-by-day entries are averaged and counted before they leave our servers, the AI receives things like your average intensity, your worst and best days, and how many days were above a threshold, rather than each individual day. The specialist report sends no watch data at all.
In short: identifiable data about you never reaches Anthropic, and your private free-text writing is never sent to any AI.
Because Anthropic processes data in the United States, using these two summary features involves an international transfer of the de-identified metrics. See “International transfers”.
Who we share your data with
We do not sell your data, and we do not share it for advertising. We use a small number of carefully chosen service providers (“sub-processors”) who process data on our behalf, under contract.
| Sub-processor | What they do | What they receive | Where |
|---|---|---|---|
| Supabase | Hosts our database and authentication, stores all your data | All data described in this policy | EU (France) |
| Anthropic (Claude API) | Generates weekly + specialist summaries | De-identified health metrics only. Never name, email, username, UUID, or any free text | USA |
| Sign-in (only if you choose Google Sign-In) | Authentication identity (email + basic profile) | Per Google’s infrastructure | |
| Apple | Sign-in (only if you choose Apple Sign-In) | Authentication identity. If you use Hide My Email, we receive a relay address instead of your real one | Per Apple’s infrastructure |
| Resend | Sends the warning email before a long-inactive account is deleted | Your email address and the scheduled deletion date. No health data, no name | USA |
| Zoho Mail | Sends the founder an internal weekly report about missing Spanish translations | No user data at all, only the internal names of untranslated labels, sent to the founder’s own address | Per Zoho’s infrastructure |
| Expo / EAS | App build infrastructure and over-the-air app updates | No account or health data. On each app start, Expo’s update service receives your device’s IP address and app version. Push notifications are local-only, no push token is sent | Per Expo’s infrastructure |
| Sentry | Crash and error reporting | Error message, stack trace, device model, OS version, app version only. No email, name, user ID, IP address, health data, or screen contents | USA |
| ClinicalTrials.gov / PubMed / public research sources | Sources of public research content | No user data is sent, these are outbound fetches only | Public sources |
We may also disclose data if we’re legally required to (e.g. a valid court order), or to protect the rights and safety of our users.
Other tools we use that never touch your data
Some tools help us build SONA but never see anything about you. We list them here for transparency, not because they process your data, they don’t, which is exactly why they’re not in the table above.
- ElevenLabs (AI voice generation) is used to produce the calming spoken narration you hear in features like the Spike Companion. We write the scripts ourselves, generate the audio once on our own machine before the app is released, and ship the finished audio files inside the app. No user data, health data, or personal information is ever sent to ElevenLabs, only our own pre-written script text. Your voice is never recorded, and the app never contacts ElevenLabs while you’re using it.
Note on subscriptions: A subscription provider is not currently integrated. If and when paid subscriptions launch, this policy will be updated to describe that provider and the billing data involved.
International transfers
Your data is stored in the EU (France).
Three things leave the EU:
- The de-identified health metrics sent to Anthropic in the United States for your two summary features.
- Your email address, sent to Resend in the United States, only if we need to warn you that a long-inactive account is about to be deleted.
- Crash diagnostics sent to Sentry in the United States, technical information only, with your identity, IP address and health data stripped before it leaves your device.
Transfers of personal data outside the EU/EEA require appropriate safeguards under GDPR (Chapter V), such as the European Commission’s Standard Contractual Clauses (SCCs) together with a transfer risk assessment.
Data retention
We keep your personal data for as long as your account is active, so the app can show you your history and trends.
If your account is inactive for 24 consecutive months, we will delete it and its associated data. We will email you a warning before this happens, so you have the chance to keep your account active.
Waitlist emails are kept for up to 6 months from when you join the waitlist, or until you ask us to remove your email, whichever comes first.
When you delete your account, your data is removed as described in “Account deletion & what persists” below. Residual copies may persist in our provider’s encrypted backups for a limited period before they are cycled out, in line with our hosting provider’s backup practices.
Security
We protect your data with measures including:
- Encryption at rest and encryption in transit (TLS) for all data on our backend.
- Row Level Security in the database, so each user can only ever access their own data.
- Authentication via bcrypt-hashed passwords, Google OAuth, or Apple Sign-In, with short-lived signed (JWT) sessions.
- Your session token stored encrypted on your device (iOS Keychain / Android Keystore).
- Backend secrets and AI keys held server-side only, never shipped inside the app.
- Consent rules enforced in the database itself, not only in the app, so a bug in the interface cannot cause data to be collected or a message to be sent against your wishes.
No system is ever perfectly secure, but we work to protect your data and to keep improving these measures.
Your rights
Under GDPR, you have the right to:
- Access the personal data we hold about you.
- Rectify data that is wrong or incomplete.
- Erase your data (“right to be forgotten”).
- Restrict how we process your data.
- Port your data, receive it in a portable format.
- Object to processing based on legitimate interests.
- Withdraw consent at any time (this won’t affect processing that already happened before you withdrew).
- Lodge a complaint with a data protection supervisory authority. Rodrigo, the person who runs SONA, is based in Spain, so the AEPD (aepd.es) is our lead authority, that applies to every SONA user, wherever you live. You’re also always free to complain to the data protection authority in your own EU country instead, if you’d rather.
How to exercise your rights: You can access and delete most of your data directly in the app (Profile settings), including a one-tap export of your data as a file. For anything else, email us at hello@sona-care.com and we’ll respond within the timeframe GDPR requires (normally within one month).
A note on the export. When you export your data, the app saves it to a file and hands it to your phone’s normal share menu. From that moment, where it goes is entirely your choice, your email, a cloud drive, a messaging app. Once you pick a destination, that file is outside SONA’s control, so treat it as carefully as you would any other health record.
Account deletion & what persists
You can delete your account at any time from within the app. This triggers a secure server-side process that deletes your authentication account and cascade-deletes all of your data across every table in our database, including your spike records, your relief sessions, your watch readings, and your founder-message conversations.
For full honesty, here’s what remains after deletion, and why:
- AI usage-cost records are kept, but your user ID on them is set to NULL, they are no longer linked to you and become anonymous cost data.
- Aggregate, non-personal cost snapshots (totals that don’t identify anyone) are kept.
- A record that a deletion happened, kept for our own audit trail. It stores only the domain of the email address (the part after the @), never the address itself.
- Waitlist email: If you joined the SONA waitlist, deleting your account also deletes a matching waitlist entry automatically. If you joined the waitlist but never created an account and you want that email removed, email us at hello@sona-care.com and we will delete it.
Children
SONA is intended for adults and is not directed to children. You must confirm you are at least 18 years old to create an account, and we record that confirmation.
Changes to this policy
We may update this policy as SONA evolves. When we make a material change, we’ll update the “Last updated” date above and, where appropriate, let you know in the app. Significant changes affecting how we use your health data will be brought to your attention so you can review them.
Contact
Questions, requests, or concerns about your privacy?
Rodrigo Felicio
Email: hello@sona-care.com
Because Rodrigo is based in Spain, you also always have the right to contact the AEPD (aepd.es), Spain’s data protection authority, at any time, no matter where you live.