Legal

Privacy Policy

Last updated: April 20, 2026

Overview

Sonata ("Sonata", "we", "us") turns publicly available song links into playable piano sheets. This policy explains what information we collect when you use the service, how we use it, and the choices you have.

We designed Sonata so you can try the full flow without creating an account. When you don’t sign in, we don’t save your transcriptions or link them to an identity.

Information we collect

When you use Sonata without signing in

  • The song URL you submit, while we process it. We fetch the audio on our servers, transcribe it, and return the result.
  • Standard server logs (IP address, user agent, timestamps) kept briefly for security, abuse prevention, and debugging.

We do not retain the source audio, the resulting MIDI, or any generated files after your session ends unless you sign in.

When you sign in

  • Your email address and basic profile information from your sign-in provider (for example, name and avatar from Google).
  • The song links you submit and the MIDI / sheet files Sonata generates for you, so you can access them later.
  • Metadata about your sheets (title, arrangement mode, created date, etc.).

When you pay for a plan

  • A Stripe customer ID and subscription metadata so we can grant access to paid features.
  • We do not receive or store your full payment card details. Payment information is collected and stored directly by Stripe under Stripe’s privacy policy.

Third-party services we rely on

Sonata uses a small set of third-party services. Each receives only the data it needs to do its job.

  • Google — identity when you sign in with Google. Google receives your basic profile information as part of the sign-in flow.
  • Stripe — payment processing. Stripe handles card and billing data and sends us limited subscription metadata.
  • Hosting and infrastructure providers — run our servers, store our database, and route email.
  • Source sites (YouTube, TikTok, etc.) — when you submit a link, our server fetches the public audio from that site. Your interaction with those sites is governed by their own terms and policies, not ours.

Cookies and similar technologies

We use a small number of cookies, and only for essential functionality:

  • A session cookie to keep you signed in.
  • Short-lived cookies from Stripe during checkout.

We do not use advertising cookies or third-party tracking pixels. If that changes, we’ll update this policy and surface a cookie notice on first visit.

How we use your data

  • Run the transcription service you requested.
  • Keep a history of your sheets so you can reopen them (signed-in users only).
  • Authenticate you, process payments, and manage your plan.
  • Operate, debug, and improve the service — for example, diagnosing why a particular link failed to transcribe.
  • Detect and prevent abuse, fraud, and copyright-violating use.
  • Comply with legal obligations and valid legal requests.

We do not sell your data, and we do not use your transcriptions to train machine-learning models.

Data retention

  • Guest transcriptions: audio and generated files are deleted at the end of the session (typically within minutes).
  • Signed-in transcriptions: kept for as long as your account is active or until you delete them.
  • Account data: kept for the life of your account. We delete it within 30 days of account deletion, except where we’re legally required to keep it longer (for example, billing records).
  • Server logs: rotated and deleted within 30 days unless retained for a specific security or legal reason.

Your rights

Depending on where you live, you may have the right to access, correct, export, or delete the personal information we hold about you, and to object to or restrict certain processing. To exercise any of these rights, email us at chibernard321@gmail.com from the address associated with your account.

You can also delete your sheets individually from the Sheets page, and delete your account and all associated data by emailing us.

Children

Sonata is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe we have collected information from a child, please contact us and we will delete it.

International transfers

Sonata is operated from, and our servers may be located in, regions outside your own. When you use the service, your information may be processed in those regions. We rely on standard safeguards (such as our service providers’ contractual protections) to keep your data secure in transit and at rest.

Security

We use reasonable technical and organizational measures to protect your data, including encryption in transit (HTTPS), access controls on our systems, and vetted third-party providers. No system is perfectly secure; we’ll notify affected users promptly if a breach occurs that meaningfully affects their data.

Changes to this policy

When we make material changes to this policy, we’ll update the “Last updated” date above and, for significant changes, notify signed-in users by email or in-app notice at least 14 days before the changes take effect.

Contact us

Questions, requests, or concerns about privacy? Email chibernard321@gmail.com.

See also our Terms of Use.