Privacy Policy
Our commitment to protecting your privacy.
Last updated: 19 April, 2026
Introduction
SonicBit ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our cloud storage service and website (collectively, the "Service").
As a global service with users from around the world, we strive to comply with data protection laws in multiple jurisdictions while providing a seamless experience regardless of where you access our Service from.
We value your trust and strive to be transparent about our data practices. Please read this policy carefully to understand how we handle your information and what rights you have regarding your data.
By accessing or using our Service, you consent to the data practices described in this Privacy Policy. If you do not agree with our policies and practices, please do not use our Service.
1. Information We Collect
1.1 Information You Provide to Us:
- Account Information: When you register for an account, we collect your email address, password, and payment information if you subscribe to a paid plan.
- Profile Information: You may choose to provide additional information such as your name, profile picture, and other personal details.
- Content: We store the files and data you upload to our Service.
- Communications: When you contact our support team or respond to surveys, we collect the information you provide in those communications.
- Authentication Information: If you sign up or log in using third-party services (like Google or Facebook), we receive certain information from those services as permitted by your privacy settings with them.
1.2 Information We Collect Automatically:
- Usage Data: We collect information about how you interact with our Service, including the features you use, the actions you take, and the time, frequency, and duration of your activities.
- Device Information: We collect information about your device, including IP address, browser type, operating system, and device identifiers.
- Cookies and Similar Technologies: We use cookies and similar tracking technologies to collect information about your browsing activities and to remember your preferences.
- Location Information: We may collect approximate location information based on your IP address.
2. How We Use Your Information
We use your information for various purposes, including:
- Providing the Service: To operate, maintain, and deliver the features and functionality of our Service.
- Authentication: To verify your identity and prevent fraud and unauthorized access.
- Personalization: To tailor your experience and provide content and features that match your profile and interests.
- Communication: To respond to your inquiries, provide customer support, and send administrative messages, updates, and security alerts.
- Improvement: To analyze usage patterns, diagnose technical problems, and enhance the functionality and user-friendliness of our Service.
- Marketing: With your consent, to send promotional communications about our products, services, and features.
- Legal Compliance: To comply with applicable laws, regulations, and legal processes.
We retain your information for as long as your account is active or as needed to provide you with the Service. We will retain and use your information as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements.
3. How We Share Your Information
We may share your information in the following circumstances:
- Service Providers: We may share your information with third-party vendors, consultants, and other service providers who perform services on our behalf, such as payment processing, data analysis, email delivery, hosting, and customer service.
- Business Transfers: If we are involved in a merger, acquisition, or sale of all or a portion of our assets, your information may be transferred as part of that transaction.
- Legal Requirements: We may disclose your information if required to do so by law or in response to valid requests by public authorities (e.g., a court or a government agency).
- Protection of Rights: We may disclose your information to protect the safety, rights, or property of SonicBit, our users, or others.
3.1 Subprocessors: The main third-party service providers we use are:
- Stripe, Inc. — payment processing. stripe.com/privacy
- Google LLC — OAuth sign-in and Analytics. policies.google.com/privacy
- Hetzner Online GmbH — EU-based data hosting. hetzner.com/legal/privacy-policy
- Cloudflare, Inc. — CDN, DDoS protection, and WAF. cloudflare.com/privacypolicy
- SMTP / transactional email provider — delivery of account, support, and billing emails.
3.2 What We Don't Share:
- We do not sell, rent, or trade your personal information to third parties for their marketing purposes.
- We do not share the content you store in SonicBit with third parties except as described in this Privacy Policy.
4. Payment Information
4.1 No Full Card Storage: We do not store your full credit card, debit card, or bank account numbers. All payment transactions are processed directly by Stripe, Inc., a PCI-DSS Level 1 certified payment processor.
4.2 What We Retain: For reference, reconciliation, and dispute resolution purposes, we retain:
- Your Stripe customer ID
- The last 4 digits of the payment card used
- The card brand (Visa, Mastercard, etc.)
- The billing country and postal code
- Transaction amounts, dates, and invoice history
4.3 Payment Processor Policy: Stripe's handling of your payment data is governed by its own privacy policy, available at https://stripe.com/privacy.
5. Fraud Prevention & Account Monitoring
To protect our business, our legitimate users, and the wider payment ecosystem from fraud, chargeback abuse, and account compromise, we perform the following monitoring:
- Login and payment logs: We log IP addresses, device and browser fingerprints, and timestamps for every account signup, login, and payment attempt.
- Concurrent session detection: We monitor for simultaneous sessions originating from geographically distant or mismatched locations, which may indicate credential sharing, account resale, or compromise.
- Payment pattern monitoring: We flag rapid card changes, multiple failed payment attempts, unusual plan-change velocity, and other signals associated with fraud or chargeback abuse.
- Stripe Radar: We integrate Stripe Radar and custom rules for real-time fraud scoring on payment transactions, including velocity checks and geo-card mismatches.
- Support correlation: We cross-reference support tickets, disputes, and reported security incidents against the above telemetry to identify abusive patterns.
5.1 Consequences of Violations: Violations of our Terms of Service — including account sharing, use of stolen or unauthorized payment methods, refund abuse, or fraudulent chargebacks — may result in immediate account suspension, termination without refund, and blacklisting of associated IP addresses, devices, email addresses, and payment instruments.
5.2 Retention of Fraud-Related Data: Records related to fraud investigation, disputes, and security incidents may be retained beyond the normal retention periods described in Section 7 for as long as necessary to investigate, defend against, or resolve the underlying issue.
6. Data Security
We implement appropriate technical and organizational measures to protect the security of your personal information. However, please be aware that no method of transmission over the Internet or method of electronic storage is 100% secure.
Our security measures include:
- Encryption of data in transit and at rest
- Regular security assessments and audits
- Access controls and authentication procedures
- Monitoring for suspicious activities
- Employee training on data security and privacy practices
While we strive to use commercially acceptable means to protect your information, we cannot guarantee its absolute security. You are responsible for maintaining the secrecy of your unique password and account information.
6.1 Breach Notification: In the event of a personal data breach likely to result in risk to your rights, we will notify affected users and the relevant supervisory authorities without undue delay, and where feasible within 72 hours of becoming aware of the breach, in accordance with applicable laws including the GDPR.
7. Data Retention
We retain personal information only for as long as needed to provide the Service, comply with legal obligations, resolve disputes, and enforce our agreements. Typical retention periods are:
- Active account data: for the lifetime of your active account, and up to 30 days after account deletion (to recover from accidental deletions).
- Payment and transaction records: up to 7 years, as required by accounting and tax regulations.
- Access and security logs (IP, device, login events): up to 12 months.
- Support tickets and correspondence: up to 3 years after last activity.
- Backup snapshots: up to 90 days.
- Fraud and dispute records: retained for as long as reasonably necessary to investigate, defend against, or resolve the matter.
After these periods, data is either permanently deleted or irreversibly anonymized.
8. Your Rights and Choices
Depending on your location, you may have certain rights regarding your personal information:
- Access: You can request access to the personal information we hold about you.
- Correction: You can request correction of inaccurate or incomplete personal information.
- Deletion: You can request deletion of your personal information (subject to certain exceptions).
- Data Portability: You can request a copy of your personal information in a structured, machine-readable format.
- Objection: You can object to our processing of your personal information in certain circumstances.
- Withdrawal of Consent: You can withdraw your consent at any time if we rely on consent to process your personal information.
To exercise these rights, please contact us at support@sonicbit.net with the subject line "Privacy Rights Request." We will respond to your request within 30 days or as required by applicable law.
Account Deletion: You can delete your account at any time by visiting your account settings or by contacting us. Upon deletion, we will remove your personal information from our active systems, though some information may remain in our backup systems for a limited time.
9. Children's Privacy
Our Service is not directed to children under the age of 13 (or 16 in the European Union). We do not knowingly collect personal information from children.
If you are a parent or guardian and believe that your child has provided us with personal information without your consent, please contact us at support@sonicbit.net with the subject line "Children's Privacy." If we discover that a child has provided us with personal information, we will promptly delete such information from our servers.
10. Cookies and Tracking Technologies
10.1 Cookies: Cookies are small data files stored on your device. We use cookies to:
- Remember your preferences and settings
- Understand how you interact with our Service
- Enable certain features and functionality
- Analyze usage patterns to improve our Service
- Provide security and prevent fraud
10.2 Types of Cookies We Use:
- Essential Cookies: Necessary for the operation of our Service. These cannot be disabled.
- Functional Cookies: Enable personalized features and remember your preferences.
- Analytics Cookies: Help us understand how users interact with our Service and improve performance.
- Marketing Cookies: Used to deliver relevant advertisements and track campaign performance.
10.3 Cookie Management: Most web browsers allow you to control cookies through their settings. You can usually find these settings in the "Options" or "Preferences" menu of your browser. You can also set your browser to notify you when you receive a cookie, giving you the chance to decide whether to accept it.
10.4 Do Not Track: Some browsers include the ability to transmit "Do Not Track" signals. We do our best to honor such signals.
11. International Data Transfers and Global Operations
SonicBit operates globally, with users from around the world. Our servers and operations are located in multiple jurisdictions, with our primary data centers in France and additional infrastructure in other countries to ensure reliable service delivery worldwide.
11.1 Cross-Border Data Transfers: Your information may be transferred to, stored, and processed in countries other than the one in which you reside. Data protection laws in these countries may differ from those in your location.
11.2 Legal Safeguards: When transferring data from the European Economic Area (EEA), United Kingdom, Switzerland, or other jurisdictions with data protection laws, we implement appropriate safeguards including:
- Standard Contractual Clauses approved by the European Commission
- Data Processing Agreements with our service providers
- Compliance with local data protection requirements
- Implementation of technical and organizational security measures
11.3 Regional Compliance: We strive to comply with applicable data protection laws in the regions where we operate, including:
- European Union: General Data Protection Regulation (GDPR)
- United States: California Consumer Privacy Act (CCPA) and other state laws
- Canada: Personal Information Protection and Electronic Documents Act (PIPEDA)
- Brazil: General Data Protection Law (LGPD)
- Australia: Privacy Act 1988
- Other applicable national and local privacy laws
11.4 Consent to Transfer: By using our Service, you acknowledge and consent to the transfer of your information to countries outside your country of residence. If you are located in a region with restrictions on data transfers, please do not use our Service if you do not want your information transferred to or processed in other countries.
If you have questions about our international data practices or specific regional requirements, please contact us at support@sonicbit.net with the subject line "International Data Privacy."
12. Changes to This Privacy Policy
We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date at the top of this Privacy Policy.
For material changes to this Privacy Policy, we will make reasonable efforts to provide notice before the changes take effect, such as through a prominent notice on our website or by sending you an email notification.
We encourage you to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.
13. Legal Basis for Processing (EU Users)
If you are located in the European Union, we collect and process your personal information on the following legal bases:
- Contractual Necessity: To provide the Service you have requested, including processing your registration, managing your account, and responding to your inquiries.
- Legitimate Interests: To operate and improve our Service, protect the security of our systems and users, and prevent fraud. We balance our legitimate interests against your privacy rights.
- Consent: For specific activities such as marketing communications or certain types of cookies. You can withdraw your consent at any time.
- Legal Obligation: To comply with applicable laws and regulations.
14. California Privacy Rights
If you are a California resident, you have specific rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA):
- Right to know what personal information we collect, use, disclose, and sell
- Right to delete certain personal information
- Right to correct inaccurate personal information
- Right to opt-out of the sale or sharing of personal information
- Right to limit the use and disclosure of sensitive personal information
- Right to non-discrimination for exercising your rights
To exercise these rights, please contact us at support@sonicbit.net with the subject line "California Privacy Rights."
15. Data Protection Officer
If you have questions or concerns about our Privacy Policy or data processing practices, you can contact our Data Protection Officer at:
Email: support@sonicbit.net (Subject: Data Protection Officer)
16. Contact Us
If you have any questions, concerns, or feedback about this Privacy Policy or our privacy practices, please contact us at:
Email: support@sonicbit.net (Subject: Privacy Policy Inquiry)
We will respond to your inquiry within 14 business days.

