🔊

Sonic Translation

Return to App
Legal Documentation

PRIVACY POLICY

Last Updated: July 21, 2026

Sonic Translation, LLC ("Company," "we," "us," or "our") respects your privacy and is committed to protecting the personal data we collect through our application and website (the "Application" or "Service").

This Privacy Policy explains how we collect, use, disclose, process, and safeguard your information when you visit our website, register an account, utilize our real-time audio translation services, or interact with our payment systems.

PLEASE READ THIS PRIVACY POLICY CAREFULLY. BY ACCESSING OR USING THE SERVICE, YOU ACKNOWLEDGE THAT YOU HAVE READ, UNDERSTOOD, AND AGREE TO BE BOUND BY ALL THE TERMS OF THIS PRIVACY POLICY. IF YOU DO NOT AGREE WITH THESE TERMS, PLEASE DISCONTINUE USE OF THE SERVICE IMMEDIATELY.

1. INFORMATION WE COLLECT

We collect information that identifies, relates to, describes, or could reasonably be linked, directly or indirectly, with a particular user or device ("Personal Data"). The types of data collected depend on your interactions with our Application:

A. Account & Identity Data

  • User Identifiers: Your email address (primary username) and account verification status.
  • Authentication Credentials: Encrypted, salted password hashes. Plaintext passwords are never stored.
  • Security & Session Tokens: Temporary 6-digit verification tokens, password recovery tokens, and expiration timestamps.

B. Financial & Payment Data

  • Vaulted Payment Tokens: Stripe Customer Identifiers and Stripe Payment Method Identifiers.
  • Transaction Metadata: Purchased credit hours, translation hours used, remaining balances, card brand, expiration date, card last 4 digits, and purchase receipts.
  • PCI-DSS Disclaimer: Full credit card numbers and CVVs are processed directly through Stripe Elements embedded secure iFrames and are never stored on our servers.

C. Live Audio Data (Input & Output)

  • Audio Input Streams: Real-time PCM raw audio captured via physical hardware microphone (getUserMedia) or browser/system window capture (getDisplayMedia).
  • Audio Output Streams: Real-time translated audio streams generated and played back through output devices.

D. Application Settings & Usage Metrics

  • UI & Configuration Preferences: Target languages, input routing modes, hardware IDs, speech voice modes, locked voices, and scheduled translation windows.
  • Accounting & Usage Metrics: Total translation hours purchased, total hours consumed, balance thresholds, and auto-replenishment settings.

E. Technical & Network Data

  • IP Addresses & Rate Limiting Logs: Transient metrics (e.g., Redis caches) for rate limiting, security, brute-force protection, and session verification.
  • WebSocket Metadata: Connection state, session identifiers, frame counters, and stream status headers.
Zero Persistence

2. HOW LIVE AUDIO DATA IS HANDLED (TRANSIENT PROCESSING)

Because our Service provides real-time audio translation, we hold ourselves to strict standards regarding audio data privacy:

Transient Streaming Only: When you initiate a live translation session, your browser streams PCM audio data over an encrypted WebSocket connection (wss://) directly to our server environment.

Immediate Third-Party Processing: Audio data received by our server is immediately routed in volatile memory (RAM) to third-party artificial intelligence engines (specifically, the Google Gemini API) to perform real-time speech recognition, translation, and synthesis.

NO PERMANENT AUDIO STORAGE: WE DO NOT RECORD, PERSIST, STORE, SAVE, OR ARCHIVE RAW AUDIO INPUTS OR TRANSLATED AUDIO OUTPUTS ON OUR SERVERS, DATABASES, OR DISK DRIVES. ONCE AN AUDIO FRAME HAS BEEN PROCESSED AND TRANSLATED, IT IS PERMANENTLY ERASED FROM ACTIVE VOLATILE MEMORY.

No AI Model Training by Company: We do not use your live audio streams to train, fine-tune, or improve our proprietary algorithms.

3. HOW WE USE YOUR INFORMATION

We use the collected information for the following specific operational purposes:

  • To Provide & Maintain the Service: Authenticating sessions, establishing WebSocket connections, executing live audio translations, and routing outputs.
  • Billing & Account Management: Tracking consumed translation hours, executing manual purchases, processing auto-replenishments via Stripe, and updating balance history.
  • Transactional Email Communications: Dispatching 6-digit verification codes, recovery tokens, purchase receipts, failed payment notices, and stream alerts.
  • Security & Fraud Prevention: Enforcing Redis-backed rate limiting, verifying JWT tokens, and maintaining CORS origin security.
  • Customer Support: Diagnosing connection issues or addressing billing inquiries.

4. THIRD-PARTY DATA SUB-PROCESSORS

To operate our Application, we share limited Personal Data with trusted third-party service providers ("Sub-processors"). These third parties are legally prohibited from using your data for any purpose other than providing services to us.

Sub-Processor Purpose Data Shared
Google Gemini API Real-time AI Speech Recognition, Translation, and Audio Generation Transient Live PCM Audio Streams
Stripe, Inc. Payment Gateway, Card Vaulting, and Billing Execution Email, Payment Tokens, Purchase Amounts, Card Last 4
SMTP Email Provider Dispatching Transactional Emails & Verification OTPs Email Address, OTP Codes, Receipts
Cloud Infrastructure PostgreSQL (Data Persistence) & Redis (Volatile Caching/Rate Limiting) Profiles, Hashed Passwords, Balances, UI Settings

5. COOKIES, LOCAL STORAGE, AND TRACKING TECHNOLOGIES

We use essential technical cookies and browser local storage mechanisms strictly necessary for the application to function. We do not use third-party advertising, marketing, or tracking cookies.

A. HTTP-Only Authentication Cookie

Name: auth_token
Purpose: Stores an encrypted JSON Web Token (JWT) verifying your active login session.
Security Specifications: Configured with HttpOnly (inaccessible to JavaScript/XSS), SameSite=Strict (CSRF protection), and Secure (HTTPS).
Duration: Automatically expires after 24 hours (86,400 seconds).

B. HTML5 Local Storage

Stores non-sensitive UI settings locally in your browser, including selected languages, preferred voice models, hardware device IDs (lastInput, lastOutput), active username display properties, and fallback session tokens.

6. DATA RETENTION AND DELETION POLICIES

Account Information: We retain your email address, hashed password, payment history, and account settings for as long as your account remains active or as needed to provide access.

Audio Data: Audio data is retained for 0 seconds on our storage infrastructure. It exists transiently in system memory during live streaming and is purged immediately upon processing.

Account Erasure: You may request permanent account deletion by contacting support. Upon account deletion, your user record and payment history in our database will be permanently purged or anonymized, subject to statutory record-keeping requirements under applicable financial laws.

7. DATA SECURITY MEASURES

We implement robust administrative, technical, and physical security measures to shield your Personal Data:

  • Transport Encryption: Web traffic, WebSocket streams, and API requests are encrypted via TLS 1.2/1.3 (HTTPS/WSS).
  • Password Hashing: Passwords are hashed using bcrypt with cryptographic salts prior to storage in PostgreSQL.
  • Isolated Infrastructure: Caching and sliding-window rate limiters run in isolated Redis clusters to block brute-force attacks.
  • Database Security: Database connections utilize connection pooling with PgBouncer safeguards and parameterized SQL queries to prevent SQL injection vulnerabilities.

8. YOUR LEGAL RIGHTS (GDPR, CCPA/CPRA, & STATE PRIVACY LAWS)

Depending on your physical location, you may possess specific statutory rights regarding your Personal Data:

  • Right to Access / Know: Request copies of Personal Data held about you.
  • Right to Rectification: Request correction of inaccurate or incomplete information.
  • Right to Erasure: Request deletion of your Personal Data from active systems.
  • Right to Restrict or Object: Limit or object to how we process your records.
  • Right to Data Portability: Receive your data in a structured, standard, machine-readable format.
  • Non-Discrimination: We will not deny service or charge different rates for exercising your privacy rights.

9. THIRD-PARTY AI DISCLAIMER & LIMITATION OF PRIVACY LIABILITY

Third-Party AI Models: Real-time translation depends on third-party generative artificial intelligence sub-processors (Google Gemini API). While Google complies with enterprise data privacy standards, we are not responsible for software anomalies, unintended data disclosures, or privacy breaches occurring solely on third-party infrastructure.

User Wiretap & Eavesdropping Responsibility: You are solely responsible for ensuring that your capture of audio (including physical microphone inputs and captured browser/system sound) complies with all applicable national, state, and local privacy, wiretapping, and non-consensual recording laws. We disclaim all legal liability for unauthorized audio recording or privacy violations initiated by users of the Application.

10. CHILDREN'S PRIVACY (COPPA COMPLIANCE)

Our Service is intended strictly for individuals who are at least 18 years of age (or the legal age of majority in their jurisdiction). We do not knowingly solicit or collect Personal Data from children under the age of 13 (or under 16 in the European Union). If we become aware that a child has provided us with Personal Data without parental consent, we will immediately delete such information and terminate the associated account.

11. CHANGES TO THIS PRIVACY POLICY

We reserve the right to modify or update this Privacy Policy at any time to reflect changes in our operational procedures, legal obligations, or technical architecture. When changes are made, we will update the "Last Updated" date at the top of this document. Your continued use of the Application following the posting of an updated Privacy Policy constitutes your acceptance of the revised policy.

12. CONTACT INFORMATION

If you have questions, concerns, or legal requests regarding this Privacy Policy or our data handling practices, please contact us at:

Company Name: Sonic Translation, LLC

Mailing Address: 9481 Evergreen Pl, Davie, FL 33324, Sonic Translation, LLC

Support Email: [email protected]