Privacy
Last updated 23 August 2026
Sondo is operated by Mahdi Farra. This page says what Sondo stores, why, and who else touches it. It is written to be read, not to be survived. Anything unclear, or any request about your data, goes to [email protected].
Two different people show up in this page, and it matters which one you are:
- Customers are the people who sign up for Sondo and put the widget on their own website.
- Visitors are the people who then chat with that widget. Sondo stores their conversations on the customer’s behalf, and the customer decides what happens to them.
What Sondo stores about customers
- Account details: your email address, your name if you give one, and records of your sign-ins, so we can keep you signed in and tell your account apart from everyone else’s.
- Workspace settings: the widget’s appearance, its persona, the sites it is allowed to load on, and the rest of your configuration.
- Knowledge Base content: the text you paste, upload, or point us at, plus the numeric representations of it that make search work.
- Your OpenRouter API key: stored so Sondo can send your visitors’ questions to the model you chose. It is kept server-side, is never sent to a browser, and is never shown back to you in full.
- Cost telemetry: for each answer, which model produced it and what it cost, so your usage page can show you real numbers.
- Billing state: your plan, your subscription status, and renewal dates. Payments go through Stripe, and Sondo never sees or stores your card number.
What Sondo stores about visitors
Sondo stores the conversations your widget has. That is not a side effect, it is a feature: reading them in your inbox is one of the reasons to use Sondo at all. Concretely, for each conversation we store:
- the visitor’s messages and the assistant’s replies, with timestamps;
- an email address, only if the visitor chooses to give one, so you can reply to them;
- a random identifier stored in the visitor’s browser, so a returning visitor continues the same conversation instead of starting over;
- a salted, one-way hash of the visitor’s IP address. Sondo does not store the address itself. The hash exists so an abusive visitor can be blocked and so rate limits work;
- a short AI-written summary and title of the conversation, generated so the inbox is readable at a glance.
Sondo does not build advertising profiles, does not sell any of this, and does not use one customer’s content to answer another customer’s visitors.
Where the AI part happens
When a visitor asks a question, the relevant parts of the customer’s Knowledge Base and the conversation so far are sent to an AI model through OpenRouter, using the customer’s own OpenRouter key and the model the customer chose. That request is governed by the customer’s agreement with OpenRouter and by the policies of whoever runs the chosen model. Customers who care about how a particular model provider handles data should choose their model with that in mind, which is one of the reasons the key and the model choice are the customer’s and not ours.
Who else processes this data
These are the services Sondo relies on to run. Each one sees only what its job needs:
- OpenRouter routes each chat message to the AI model the workspace owner chose, on the owner's own OpenRouter account.
- Stripe takes subscription payments and stores the billing details.
- Resend delivers sign-in links and account emails.
- Hetzner hosts the servers and the database, in Falkenstein, Germany.
- Cloudflare serves the site at the network edge and filters abusive traffic.
Analytics on our own website
On usesondo.com, including this page, we count visits with Peeko. Peeko is our own analytics tool, built by us and running on our own infrastructure, so those page views go to nobody else: it is not a third party and it is not in the list above. We use it on our marketing pages only, never inside the widget and never on a customer’s site.
Cookies
The dashboard sets a cookie to keep you signed in and one to remember which workspace you are looking at. Stripe sets its own cookies during checkout. The widget itself sets no cookies on your visitors. It keeps two things in the browser’s local storage: the random identifier described above, and enough about the current conversation to pick it back up if the visitor returns.
How long it is kept
Customer and workspace data is kept for as long as the account exists. If a subscription lapses or is cancelled, the widget stops answering but nothing is deleted: the workspace, the Knowledge Base and the conversation history are all still there if you come back. Data is deleted when you ask for it to be deleted.
Deleting your data
Email [email protected] and say what you want removed: a single conversation, a workspace, or the whole account. There is no self-serve delete button yet, which is exactly why there is a real address here instead. The same address handles requests to see a copy of your data or to correct it, and it also handles requests from a visitor who chatted with a customer’s widget, though in that case we will normally pass the request to the customer, whose data it is.
Changes
When this page changes, the date at the top changes with it. If a change materially affects customers, we will email them rather than quietly editing the page.
Contact
Mahdi Farra, by email at [email protected]. The Terms of Service cover the rest of the agreement.