Privacy Policy

Effective date: September 2, 2026

Sontrove (“we”, “us”) provides tools for managing and listening to personal media across your devices. This policy explains what information we process, why we process it, and the choices available to you.

Information we process

  • Account information: email address, password hash, email-verification and password-reset records, account status, and subscription status.
  • Sign-in information: if you use Google, Facebook, or Apple sign-in, we receive the provider identifier and the basic profile information that the provider makes available, such as an email address when you grant that permission.
  • Service and device information: device identifiers, node and relay connection information, session tokens, security events, and diagnostic logs needed to authenticate devices, provide remote access, prevent abuse, and troubleshoot the service.
  • Library information: library indexes, playlists, playback queues, and related metadata needed for the features you use. Your media files live on your own device; we do not provide cloud storage for them. To deliver playback across networks, media data passes through our relay infrastructure in transit, and edge caches may hold it transiently. We do not claim that all media is invisible to our service; privacy-library features have their own documented limitations.
  • Payment information: subscription and transaction status from our payment provider. Payment-card details are handled by the payment provider and are not stored by Sontrove as card numbers.

How we use information

We use information to create and secure accounts, verify email addresses, authenticate devices, provide library and remote-access features, process subscriptions, send transactional messages, prevent abuse, comply with legal obligations, and improve reliability.

Service providers and sharing

We share information only as needed to operate the service or comply with law. Depending on the feature, providers may include our hosting and infrastructure providers, Paddle for payments, Resend for transactional email, and Google, Meta, or Apple when you choose their sign-in service. We do not sell personal information.

Retention and deletion

You can request deletion from the public web at Account after signing in. The deletion flow requires your current password and typing DELETE to confirm. It removes the account and control-plane data immediately; library data may be cleared by a background purge. The service may retain the minimum device revocation identifiers until associated certificates expire (up to 365 days), legally required transaction records held by the payment provider, and limited abuse-prevention records when required to enforce a repeat-infringer policy.

See Account and data deletion for the complete procedure and scope.

Your choices and rights

You may access or correct account information through the account interface, disconnect a social sign-in by stopping its use, and request deletion. You may also contact us about access, correction, or deletion requests.

Security

We use access controls, token revocation, password hashing, encrypted transport, and operational logging appropriate to the service. No internet service can guarantee absolute security.

Contact

For privacy questions or requests, email huangyingw@gmail.com. We may ask for information needed to verify that a request concerns your account.