Privacy Policy

Last updated: May 28, 2026

This Privacy Policy explains how Sonusly collects, uses, discloses, retains, and protects information when you use sonusly.com and related services. Sonusly is an independent music-industry discussion platform with public posts, replies, AI-assisted features, credits, tips, job posts, profile pages, saved posts, voting, flagging, and supported imports from shared links.

This Policy is part of our Terms of Service. If you do not agree with this Policy, do not use Sonusly.

Controller / operator: Sonusly is operated by Lorenzo Schiavone. Contact us at contact@sonusly.com.

1. summary

Sonusly is a public discussion platform. Public posts, public replies, public AI replies, usernames, karma, join dates, profile bios, saved public posts, job posts, source links, vote totals, timestamps, and other public activity may be visible to anyone and may be indexed, cached, copied, archived, or appear in search engines and AI search or chatbot tools.

We collect information needed to operate Sonusly, including account information, public content, private AI prompts, credits and payment metadata, technical logs, analytics, security signals, and support messages.

  • we do not sell personal information
  • we do not share personal information for cross-context behavioral advertising
  • we do not store payment card numbers on Sonusly servers
  • AI features are processed through Sonusly infrastructure, Vercel AI Gateway, and selected model providers

2. information we collect

account and authentication information

  • email address, user ID, username, password authentication state, OAuth identity data, and session information
  • join date, account settings, karma, credit balance, account status, and moderation status
  • LinkedIn identity information if you choose to sign in with or connect LinkedIn

profile and public activity

  • username, profile bio, join date, karma, and public profile details
  • public posts, public replies, public AI replies, public saved posts, source links, vote totals, comment counts, and ranking signals
  • job posts, company names, job locations, application links, and visible job metadata

content and activity you provide

  • post titles, post descriptions, comments, replies, edits, deletes, saves, votes, flags, and reports
  • job titles, company names, locations, job descriptions, skills, salary ranges, application links, edits, deletes, and flags
  • AI prompts, private AI follow-up prompts, selected post context, source URLs, generated AI output, and AI feature settings
  • ChatGPT shared links or other supported links you import, extracted conversation text, and transformed discussion content
  • credit actions, tips, balances, reservations, refunds, refund debt, and ledger entries
  • messages you send to us by email or support channels

payment and checkout information

Credit purchases are processed by third-party checkout providers such as Polar. We may receive payment-related metadata needed to grant, reconcile, refund, prevent fraud, and audit credits, such as checkout ID, order ID, customer ID, customer email, product ID, purchase amount, currency, refund amount, payment status, and metadata connecting the purchase to your Sonusly account.

Payment card details are handled by the payment provider and are not stored by Sonusly.

technical, analytics, and security information

  • IP address, approximate location derived from IP address, device type, browser, operating system, referrer, pages or URLs visited, timestamps, and request logs
  • Google Analytics page views and usage events
  • performance metrics, error logs, rate-limit data, abuse signals, security logs, and diagnostic traces
  • AI Gateway metadata such as model, provider routing, generation ID, token counts, latency, status, cost, and error information

AI usage information

  • prompts, private ask text, public post context, public replies, imported conversation content, source material, and role templates
  • model selection, provider routing information, token counts, request status, latency, generation IDs, cost telemetry, and error information

3. cookies and local storage

Sonusly uses cookies, local storage, and similar technologies for authentication, session continuity, preferences, security, checkout flows, analytics, performance measurement, and abuse prevention.

Where required, Sonusly will ask for consent before using non-essential analytics cookies or similar technologies. You can usually control cookies through your browser settings and, where available, through Sonusly's cookie or analytics controls. Disabling cookies may prevent account, checkout, AI, analytics preference, or security features from working correctly.

Sonusly does not currently respond to browser "do not track" signals. We will update this Policy if that changes.

4. public information

The following information is public by design when you use public features:

  • username, profile bio, join date, and karma
  • public posts, public replies, public AI replies, public source links, and public saved posts
  • public job posts and application links you submit
  • aggregate vote scores, comment counts, flag counts, and ranking signals where displayed

Public information may be viewed by users and non-users, indexed by search engines, crawled by third-party services, cached, archived, quoted, screenshotted, copied, or appear in AI-powered search and chatbot tools.

Do not publish secrets, credentials, private keys, private personal data, confidential business material, private contracts, unreleased material, or content you do not have permission to share publicly.

5. how we use information

  • create and maintain accounts, sessions, profiles, and authentication
  • publish, rank, search, display, and moderate public posts, replies, jobs, profiles, and saved posts
  • provide AI-assisted features and process imported conversations
  • run supported web or search-assisted AI features
  • store source metadata and AI output where needed for the feature
  • process credit purchases, tips, refunds, reservations, balances, and refund debt
  • respond to support, privacy, security, billing, copyright, and legal requests
  • measure traffic, performance, reliability, conversion, and product usage
  • detect, prevent, and investigate spam, abuse, fraud, scraping, manipulation, security issues, and Terms violations
  • debug errors and improve reliability
  • comply with law, enforce agreements, and protect users, Sonusly, providers, and the public

We may use aggregated or de-identified information to understand trends, improve Sonusly, publish high-level product statistics, and debug reliability without identifying individual users.

6. AI processing

Sonusly uses Vercel AI SDK and Vercel AI Gateway to route AI requests to supported model providers. Depending on the feature, an AI request may include your prompt, post text, comments, selected role templates, source evidence, imported conversation content, private follow-up text, and system instructions.

Vercel AI Gateway may process provider routing, model usage, token counts, latency, spend, logs, and observability metrics. Selected AI model providers may process prompts and outputs to generate responses.

Provider retention, logging, abuse monitoring, and training behavior may vary by provider, model, route, account type, and configuration. Sonusly does not currently operate its own foundation model and does not use private AI prompts to train a Sonusly-owned model. You should still treat AI prompts and outputs as data processed by third parties.

Do not submit passwords, API keys, confidential information, unreleased music or business material, sensitive personal information, or anything you would not want processed by AI infrastructure. AI output may be inaccurate, incomplete, outdated, or unsuitable, and should not be relied on as professional advice.

7. how we disclose information

public disclosure

Public content is disclosed publicly by design. Other users, non-users, search engines, crawlers, archives, AI search tools, and external sites may access or store public content.

service providers

providerpurposeinformation processed
Supabasedatabase, authentication, row-level security, and server-side data operationsaccount data, auth records, public content, jobs, votes, flags, saved posts, and credit ledger data
Vercelhosting, serverless functions, deployment, logs, and AI Gatewaytechnical logs, page views, performance data, AI prompts, AI output, model usage, and request metadata
AI model providers via AI GatewayAI generation, provider routing, fallback, and structured outputprompts, post context, imported content, source evidence, and generated output
Polarcheckout, order processing, webhook delivery, refunds, and customer recordscustomer email, Sonusly user ID, checkout metadata, order IDs, product IDs, purchase amounts, and refund data
LinkedInoptional OAuth sign-in or profile trust signalidentity information LinkedIn provides after authorization
Google Analyticstraffic and product analyticspage views, device/browser data, referrer, approximate location, and usage events

legal, safety, and business reasons

We may disclose information when we believe it is reasonably necessary to:

  • comply with law, legal process, government requests, or provider requirements
  • enforce our Terms
  • investigate abuse, fraud, scraping, manipulation, or security incidents
  • protect the rights, property, safety, or integrity of Sonusly, users, providers, or the public
  • respond to claims that content violates rights
  • process a merger, financing, acquisition, reorganization, asset sale, or similar business transaction
  • act with your consent or at your direction

8. what we do not do

  • we do not sell personal information
  • we do not share personal information for cross-context behavioral advertising
  • we do not store payment card numbers on Sonusly servers
  • we do not intentionally collect personal information from people under 18
  • we do not use private AI prompts to train a Sonusly-owned foundation model

9. data retention

We keep information only as long as reasonably needed for the purposes described in this Policy, unless a longer period is required or permitted by law.

data typetypical retention
account and profile datawhile your account is active, then as needed for deletion, security, legal, and integrity purposes
public posts, replies, public AI replies, jobs, and saved-post recordswhile public or as long as needed to preserve discussion context, moderation integrity, legal records, and service integrity
private AI follow-upsas long as needed to provide the feature, show private post context, support users, debug issues, prevent abuse, and maintain auditability
imported conversation contentas long as the resulting public discussion remains available, or as needed for moderation, legal, or integrity reasons
credit ledger, purchases, refunds, and tipsas long as needed for billing, tax, accounting, fraud prevention, refund handling, and legal compliance
security logs, diagnostics, and rate-limit dataas long as needed for security, debugging, abuse prevention, and compliance
analytics datafor periods set by us and our analytics providers, generally only as long as useful for product analytics and reliability

When you request account deletion, we may delete or anonymize personal account information while retaining public content in anonymized form where needed to preserve discussion context, moderation records, safety, legal compliance, or service integrity.

We may retain records when needed for legal obligations, billing, accounting, security, fraud prevention, dispute resolution, provider compliance, or to enforce our Terms.

10. your choices and rights

  • update your username and profile bio
  • delete or edit certain content where the product allows it
  • request access to your personal information
  • request correction of inaccurate information
  • request export of your information
  • request deletion of your account or certain information
  • request restriction or objection to certain processing
  • disconnect supported OAuth identities where available
  • control cookies through your browser or available cookie controls
  • opt out of non-essential emails

Send privacy requests to contact@sonusly.com with the subject "privacy request". We may need to verify your email or account before acting on a request.

Some requests may be limited by law, security, billing records, fraud-prevention needs, moderation integrity, public discussion integrity, or the rights of others. For example, when deleting an account, we may anonymize public content rather than remove entire discussion histories.

11. EEA, UK, and Swiss users

If you are in the EEA, UK, or Switzerland, you may have additional rights under applicable data protection laws, including rights to access, correct, delete, restrict, object, port data, withdraw consent where processing is based on consent, and complain to a supervisory authority.

purposelegal basis
providing accounts, authentication, posting, replies, profiles, saved posts, jobs, credits, tips, and AI featurescontract
security, abuse prevention, spam prevention, moderation, ranking integrity, debugging, service reliability, and service improvementlegitimate interests
non-essential cookies or analytics where consent is requiredconsent
basic privacy-conscious analytics where consent is not requiredlegitimate interests
billing, tax, accounting, legal requests, consumer rights, copyright claims, regulatory compliancelegal obligation
public display of content you intentionally publishcontract and/or legitimate interests

Sonusly and its providers may process information in the European Union, the United States, and other countries. Those countries may have data protection laws different from where you live. Where required, we rely on appropriate transfer mechanisms, provider commitments, contractual protections, or other lawful safeguards.

To exercise GDPR-related rights, email contact@sonusly.com with the subject "GDPR request". You may also complain to your local supervisory authority. If you are in Italy, you may contact the Garante per la protezione dei dati personali.

12. U.S. privacy rights

Where applicable, California residents and residents of other U.S. states may have rights to know, access, correct, delete, receive information about certain disclosures, opt out of certain uses, and not be discriminated against for exercising privacy rights. This section applies only to the extent those laws apply to Sonusly.

Sonusly does not sell personal information and does not share personal information for cross-context behavioral advertising.

Categories of personal information we may collect include:

  • identifiers such as email address, username, user ID, customer ID, IP address, and linked identity data
  • internet or network activity such as pages viewed, browser/device data, logs, and interactions
  • commercial information such as credit purchases, refunds, products, checkout metadata, and tips
  • approximate geolocation derived from IP address
  • user-generated content, job posts, support messages, imported content, and AI prompts
  • inferences such as karma, ranking signals, moderation signals, abuse signals, and product usage patterns

To exercise privacy rights, email contact@sonusly.com with the subject "privacy request".

13. minors

Sonusly is not directed to people under 18, and we do not knowingly collect personal information from people under 18. If you believe someone under 18 provided personal information to Sonusly, contact us at contact@sonusly.com with the subject "underage privacy", and we will take appropriate steps.

14. security

We use technical and organizational measures designed to protect information, including HTTPS/TLS, authentication controls, database access controls, row-level security, server-side operations for sensitive writes, webhook signature verification, restricted environment variables, rate limits, and security logging.

No online service can guarantee perfect security. You are responsible for keeping your account credentials safe and for avoiding the submission of sensitive information to public posts or AI features.

If you believe your account or Sonusly data is at risk, email contact@sonusly.com with the subject "security issue".

15. third-party links and policies

Sonusly may link to third-party websites, public source pages, job application pages, music platforms, payment pages, OAuth providers, and AI-generated sources. We do not control those third parties. Review their terms and privacy policies before sharing information with them.

  • Supabase privacy policy
  • Vercel privacy policy
  • Polar privacy policy
  • LinkedIn privacy policy
  • Google privacy policy
  • Vercel AI Gateway documentation

16. changes to this policy

We may update this Privacy Policy as Sonusly, providers, laws, or data practices change. We will update the "last updated" date when we post changes. Material changes may be communicated by email, in-product notice, or another reasonable method before or when they take effect, where required.

17. contact

Email: contact@sonusly.com

  • subject: privacy request - access, export, deletion, correction, restriction, or objection requests
  • subject: GDPR request - EEA, UK, or Swiss privacy rights
  • subject: underage privacy - reports about personal information from people under 18
  • subject: security issue - vulnerabilities or account security concerns
  • subject: billing - credit purchase or checkout questions
  • subject: copyright notice - copyright matters
  • subject: legal - legal inquiries
  • subject: account deletion - account deletion requests

Sonusly is an independent platform created for music-industry discussion. Sonusly is not affiliated with, endorsed by, or connected to any record label, music publisher, artist, employer, AI provider, payment provider, or music platform unless expressly stated.