Answers

Will my colleagues' names end up in my posts?

No. Private people who appear in your meetings, messages and documents never reach a draft: a colleague, a client or a candidate is written as a role, such as "our recruiter" or "a client's COO". The rule is applied twice, once when a moment is extracted from your week and again when a post is written from it, and you approve every post before it goes anywhere.

The rule, in the words the model is given

Every draft Sonar writes is produced under a standing instruction called PEOPLE. It says that private individuals are never named in anything publishable: posts, X siblings, captions, scripts read to camera, comments, carousels. A colleague, a client, a candidate, a meeting participant, a member of a Slack channel or direct message, anyone in your documents: all private, however their name reached the model.

That last clause matters, because names arrive from many directions. The instruction lists them: a moment mined from your week, a provenance label, a meeting or channel name, an attached file, a recalled earlier conversation, and your own grounding lines. Knowing what happened is never permission to publish who was there. The model is told to write the role or the relationship instead, and to keep the story while dropping the name.

Three groups stay named: public figures, the employers and clients your own credibility block cites, and anyone you name yourself in a request. When in doubt, the role.

Why it is applied twice

A moment is the seed of a public post, and every drafting surface reads a moment's title, angle and detail straight into a prompt. So the first place a name can be kept out is the moment itself. The miner that reads your transcripts, calendar and messages carries its own copy of the rule: everyone in the material except you is a private individual, and the title, the angle and the detail never carry a personal name. Its worked example is literal: "our recruiter's hiring debrief showed where the funnel actually leaks" is good; the same sentence with the recruiter's first name is bad.

The miner goes further where someone else's private life is concerned. When the material touches another person's health or a family member's, a bereavement, personal leave, their pay, a performance review or a departure in progress, it retells nothing. It extracts your own lesson, written so the person cannot be identified, with no name, role, team, figure or reason, and where even that would identify them it drops the moment. Pay is called out by name in the instruction, because in a small team a number identifies a person.

The one place a real name survives, and who sees it

Each moment keeps a pointer to the meeting or document it came from, so you can check the work: "Meet: pricing review", "Slack: #leadership". That pointer is for your eyes. On Home, in the Moments desk and on a sync receipt you see the specific label; every prompt that lists moments to the model sees only the generic source, "Meet" or "Slack", through one function that renders it. The weekly deck's brief for a moment card ends with the same instruction: the people in it are private, and they are written as roles.

Names also ride into a read and leave with it. Google Calendar attendees enter the week's text so a one-to-one can be told from a team review; Zoom and Meet speaker labels enter so the model can follow a conversation. The text is discarded after the mining pass, and only the moment is stored.

The honest limits

The rule is an instruction the model follows, backed by a structure that keeps specific names away from the drafting prompts. It holds in practice. An instruction to a language model is still an instruction, which is why the last gate is you. A draft waits on your board until you move it; only a post you scheduled or pressed Post on ever publishes. You read every post before it goes out, and if a role reads too thinly for the story, you change it. When Sonar gets this wrong, we treat it as a bug: the people rule was tightened in August 2026 and again in September after a draft named a colleague from a Meet moment, and both fixes were structural.

What to do next

Read the rule at work in your own week.

Connect one source and open the Moments desk in Settings: every moment shows its role-written title beside the provenance only you see. The full account of what Sonar reads and keeps from each source is on Security.

Start free

The longer answer.

The full account is Security, which covers what Sonar reads and keeps from every source. Also asked: Does Sonar read my whole calendar? and What happens to my transcript?