Skip to content

Privacy policy

Last updated:

In short: you do not have to tell us anything to read the site. We set no cookies for visitors, run no ads, count page views without cookies or personal data, and sell no data. Below is everything we do store, and for how long.

Site visitors

The site has no accounts. We set no cookies for visitors and write nothing to your browser's storage. The pages carry no pixels, ads or Google Analytics. We count page views with Umami, which we host ourselves: it sets no cookies, does not store IP addresses and keeps only aggregate numbers — which pages were opened, from which country and referring site, on which kind of device.

Pages are built on our server. When that server fetches data for a page from our own API, your IP address is not passed along. Fonts are served from our server, not from Google Fonts.

The site's web server keeps no log of your requests.

What your browser loads from other sites

Story images are loaded by your browser straight from the sites of the publishers that published them. Those servers see your IP address and browser details in these requests, as with any image download; what they do with them is governed by their own policies.

Links to articles take you to the publishers' sites, where their rules apply.

The API key request form

You can ask for a key on the Pricing page. We store what you enter: your email, your name (optional), the plan you chose and your description of what you are building, plus the time of the request. We may add our own working note to it and mark it as answered.

We use this only to reply to you and issue a key. We do not add you to mailing lists and do not pass it to anyone. It is kept until you ask us to delete it.

API keys

We do not store the key itself: the database holds only its hash (SHA-256) and its first few characters, so a key can be recognised in a list. If you lose a key we cannot recover it, only issue a new one.

With a key we record a label, an owner (as we entered it when issuing the key — a name, a company or an email), the plan, the issue date, the expiry date and when it was last used (to within a few minutes). A revoked key stays in the database together with its usage history. These records are kept until you ask us to delete them.

Requests to the API

For each key we count requests per day to each API endpoint. Requests without a key go into one shared count per endpoint, with no addresses and no breakdown by who made them. These counters are kept without a time limit: they show us the load and how much of a plan is used.

To enforce limits on requests without a key, we count calls from one address in the current minute and the current day. We do not store the IP address itself: a record holds only a hash of it made with a secret key, from which the address cannot be recovered, plus the start of the minute or day and the number of requests. Records older than two days are deleted every hour. Requests with a key are counted per key, not per address.

The API server keeps no log of individual requests with IP addresses. Only errors go into its technical log, which is capped in size, so old entries are pushed out by new ones.

Who we share data with

Nobody buys it and nobody gets it for advertising. Your data sits in a database on a server we run ourselves.

The service does call outside services, but it does not send them your data. News texts (the headline, the feed summary and the article text from the publisher's site) are sent to OpenAI to determine tone (positive, neutral, negative) and topic. Feeds and articles are downloaded from publishers' sites. None of these requests contains visitor data, emails from the form or your keys.

Admin console

The only cookie in Sonar is the session for the console the team uses to run the service. It is set only for someone who signs in to the console with the password; site visitors never get it. It is signed, not readable by page scripts, and lasts 12 hours.

Your rights

You can ask us to show what we store about your email or your key, to correct it, or to delete it. Deleting a key means it stops working. We reply within 30 days.

Changes

If the service starts collecting anything new — card payments or accounts, for example — we will update this page before it goes live and change the date at the top.

Who we are and how to reach us

Sonar is operated by the team that builds it.

Send questions, data deletion requests and publisher notices through the API key request form on the Pricing page — describe what you need in the “What are you building” field and leave an email we can reply to.