SonarSonar

Privacy Policy

Effective July 31, 2026 · Sonar by Distilled

What Sonar is

Sonar is a content platform for founders, operators and executives. It drafts, schedules, and measures LinkedIn and X content on your behalf, using information you provide and accounts you explicitly connect.

The Sonar for LinkedIn browser extension

The extension reads the analytics numbers already visible to you on your own LinkedIn analytics pages (post impressions, engagements, profile views, search appearances, followers, and audience demographics) while you browse them in your own logged-in session, and sends those numbers to your own Sonar workspace. It reads nothing else, visits nothing on your behalf, and performs no actions on your account.

  • Data collected: your own analytics numbers, and the pairing token you paste during setup.
  • Where it goes: only to the Sonar workspace the token belongs to. Never to anyone else.
  • Local storage: the pairing token and last-sync time, stored by your browser.
  • No sale, no third-party transfer, no advertising use, no credit or lending use.
  • Removal: uninstall the extension and, if you wish, regenerate the token in Sonar to revoke the old one.

What we collect

  • Account: your name and email, and how you signed in (email and password, or LinkedIn or X). Passwords are handled by our authentication provider and never stored by us in readable form.
  • What you create: the posts, drafts, notes, documents, recordings, and answers you enter, and the intelligence Sonar builds from them.
  • Connected accounts: when you explicitly connect LinkedIn, X, Google (Calendar and Meet), Slack, Microsoft 365 (Outlook and Teams), Zoom, Notion, Fireflies, Granola, or Wispr Flow, we store the access tokens needed to provide the feature you enabled, and the data you asked Sonar to read from them. Some sources also accept an API key you paste instead; either way the credential stays server-side, is used only to read your meeting content, and is deleted when you disconnect. Two of these have a boundary you choose at connect time: with Slack you pick up to five specific conversations and Sonar reads only those, including direct messages if you pick them; with Notion you pick the pages you grant, and Sonar sees nothing else in your workspace.
  • Public content: to build your competitive watchlist and weekly brief, Sonar reads publicly available posts and articles. It does not scrape private LinkedIn data or use your login to do so.
  • Payment: if you subscribe, our payment processor collects your card details directly. Sonar never sees or stores your full card number.
  • Usage: product analytics and, as described below, masked session replay.

How we use it

We use your information only to provide and improve Sonar: to learn your writing voice, draft and schedule content, surface what is happening in your niche, and measure how your content performs. We do not sell personal data, and we do not use it for advertising.

AI processing

Sonar generates content using a third-party AI provider (Anthropic's Claude). To draft in your voice, the relevant parts of your content and settings are sent to that provider to produce a response. Under our provider's API terms, your inputs and outputs are not used to train their models. Content is processed to serve your request, not to build a public model. Data received from Google Workspace APIs is never used, transferred, or sold to create, train, or improve any foundational or generalized AI or machine learning model, in line with the Limited Use requirements described under Google user data below.

Google user data

If you connect Google, Sonar requests only read-only access, and only to what the feature you switched on requires:

  • Google Calendar (calendar.events.readonly): Sonar reads the titles, times, and attendee names of your own calendar events from the last seven days, once a week, to suggest post-worthy moments from your real working week. This is the narrowest Calendar scope that permits reading events; Sonar does not request access to manage calendars or to list the calendars on your account.
  • Google Meet (meetings.space.readonly): if you separately switch on Meet transcripts, Sonar reads transcripts of your own recent Meet conferences for the same purpose, and to learn how you phrase things from sentences you yourself spoke.

We do not keep the raw content.Calendar text and meeting transcripts, from every connected source, are processed in memory to extract short, story-shaped summaries, and the raw text is discarded. What we store is those derived summaries, plus a short receipt of what was read: the titles of the meetings, notes, or pages processed in the last sync, so you can check our work. Nothing else from the source body is kept. You can see that receipt on each source's row in Settings under Connected sources, and delete the moments Sonar surfaces to you from the card itself on Home. Disconnecting a source deletes both its stored access token and its receipt, and deleting your account removes every stored moment along with the rest of your workspace, immediately.

Who we share it with. We do not sell Google user data, and we do not transfer it to advertisers, data brokers, or any third party for their own purposes. It is disclosed only to the infrastructure providers that operate Sonar on our instructions: Supabase (database and storage, where derived summaries are held), Vercel (application hosting), and Anthropic (AI processing, where relevant text is sent transiently to generate your drafts and is not retained for model training under their API terms). We may also disclose data if legally required, or to you.

Limited Use. Sonar's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular, we do not use, transfer, or sell Google user data, whether raw, aggregated, or derived, to create, train, or improve any foundational or generalized artificial intelligence or machine learning model. Google user data is used only to provide the features you switched on inside Sonar.

Revoking access. You can disconnect Google at any time in Settings under Connected sources. Disconnecting revokes our access token with Google immediately, and you can also remove access from your Google account permissions page.

How we protect your data

Sensitive data, including anything read from a connected account, is protected by these measures:

  • Encrypted in transit and at rest: all traffic runs over HTTPS/TLS, and our database and file storage are encrypted at rest by our infrastructure provider.
  • Isolated per workspace: every table enforces database-level row security, so data is readable only by members of the workspace that owns it. This is enforced by the database itself, not only by application code.
  • Connection tokens are server-only: the tokens for connected accounts are stored in a table that browser-side credentials are explicitly denied access to, and are never sent to the browser. Disconnecting always deletes our copy, and for the providers that offer a revocation endpoint (Google, Slack, Zoom, X, Notion, Granola, Fireflies) we also revoke the grant at the provider. Microsoft, LinkedIn, Fathom and Wispr Flow offer no such endpoint on the tiers we use, so for those you can additionally remove Sonar from your own account settings at the provider.
  • Minimised by design: every source we read is granted read-only access, and we request the narrowest scope that runs the feature you switched on. The one exception is publishing: if you connect LinkedIn or X to let Sonar post for you, that connection carries permission to publish as you, and only that. Raw calendar and transcript content is processed transiently, and only the short derived summaries the product needs are stored.
  • Restricted access: administrative access to production systems is limited to the people who operate Sonar, protected by two-factor authentication, and used only to run and support the service.

Service providers

We rely on a small set of vetted providers to run Sonar, each handling only what their function requires: database and authentication, hosting, AI generation, payment processing, product analytics, and public-content research. They act on our instructions and are not permitted to use your data for their own purposes.

Product analytics and session replay

To understand how Sonar is used and to improve it, we use privacy-first product analytics, including session replay. Replays are recorded with all text and form inputs masked, so we can see how the interface is navigated but never the content you write, draft, or connect. We do not sell this data or use it for advertising, and analytics can be limited through your browser's standard controls.

Cookies

We use only the cookies needed to keep you signed in and to remember preferences such as your theme. We do not use advertising or cross-site tracking cookies.

Retention and deletion

We keep your data for as long as your workspace is active. You can disconnect any connected account in Settings at any time, which deletes its stored tokens. You may request deletion of your workspace and its data at any time; on a verified request we remove it, except where we are required to retain limited records (for example, for tax or fraud-prevention purposes).

Your choices

You can access, correct, export, or delete your workspace data, and disconnect any integration, from within Sonar or by contacting us. Depending on where you live, you may have additional rights over your personal data; we honor those rights for verified requests.

Children

Sonar is a professional tool intended for adults and is not directed to anyone under 18. We do not knowingly collect data from children.

Changes to this policy

We may update this policy as Sonar evolves. When we make a material change, we will update the effective date above and, where appropriate, notify you in the product.

Contact

Questions or deletion requests: hello@meetdistilled.com. We respond within a reasonable period and honor verified deletion requests for your workspace data.