Sonomir

Last updated

How your files are handled

Bank statements, invoices and recordings are private. This page follows a file from the moment you pick it to the moment it is gone, and names every service that touches it on the way. The legal version is the privacy policy; this is the practical one.

The short version

  • Your file goes from your browser into private storage, is read by the one service that does the reading, and is deleted from storage when the job ends, whether it worked or not.
  • The result stays for 24 hours, or 30 days if you choose, and you can delete it sooner with one button.
  • Passwords for locked PDFs never leave your device.
  • The services that read files do not train their models on them: Google's terms rule it out, and every Deepgram request opts out of its training programme.
  • Nothing is published, sold or shown to anyone else. Results open only in the browser that made them, or under the email that owns them.

1. Uploading

When you choose a file, your browser asks Sonomir for a one-time upload link and sends the file straight to private storage at Supabase, over an encrypted connection. The file's storage path is tied to your browser session, so a path copied into another browser is refused before anything reads it. Storage is never public: there is no link anyone could guess or share.

The page counts pages or minutes in your browser before anything is uploaded, so the price is known first. A file the free allowance covers then starts straight away; one that needs credits waits for you.

2. Password-protected PDFs

Many banks lock statement PDFs with a password. Sonomir unlocks them in your browser: the password and the locked file are handled by a small program that runs on your own device, and only the unlocked copy is uploaded. The password is never sent to Sonomir or to anyone else, and it is cleared from the page once the file opens.

3. Reading the file

Each tool sends the file, or the page being read, to one service and gets the result back:

  • Bank statements, invoices, images and scans: Google's Gemini models on Vertex AI, Google Cloud's paid business service. Google's terms for it say customer data is not used to train or fine-tune its models without the customer's permission.
  • Audio and video: Deepgram, which is given a private link to the recording that expires after an hour. Deepgram enrols audio in its Model Improvement Program unless a request opts out, so every Sonomir request sends its opt-out.
  • YouTube links: the transcript is read from YouTube's own captions for the video you paste.
  • Citations: the details of the source are looked up from Crossref, Open Library, YouTube or the web page you link.

Summaries and chapters are written by the same Gemini models from the text already extracted.

4. Deleting the upload

When the job finishes, the uploaded file is deleted from storage. That happens whether the job worked or failed. If a deletion is ever missed, deleting or expiring the result removes the upload again.

5. Keeping the result

The result (the rows of a statement, a transcript, a table) is kept with the job so the page and your downloads still work if you come back. Before you start a job you choose how long: 24 hours by default, or 30 days.

  • Delete it sooner: every result has a "Delete this result" button. It removes the result and the job's input straight away. Your credit balance is not affected.
  • When the time is up: a scheduled cleanup runs every day and removes expired results, and opening an expired result removes it on the spot.
  • Who can open it: only the browser that made it, or, after you sign in, your email address. Sharing a network or an IP address grants nothing.

For bank statements, only the last four digits of an account number are kept in the result. The database's own backups follow Supabase's retention rules, so deletion from a backup is not instant.

6. Paying and email

Checkout is run by Dodo Payments, the merchant of record. Your card details go to Dodo directly and never reach Sonomir; Sonomir receives your email address, the pack bought and a payment reference. Sign-in links and receipts are sent through Resend. There are no passwords to leak: signing in is a one-time link.

7. Hosting and analytics

The site runs on Vercel, and the database and file storage are at Supabase. When product analytics are switched on, PostHog counts page views and button presses through Sonomir's own address; it never receives file contents, and screen recording is off.

Questions, or something looks wrong

Email hello@sonomir.com. To have everything about you deleted (jobs, results, your email and your balance), say so in the email; it is done within 30 days, usually much sooner. If you find a security problem, please write before publishing it, and include the steps to reproduce it.

The full legal text is in the privacy policy and the terms.