Privacy & terms

What we collect, and what isn't written yet.

A privacy policy needs a named data controller and terms need a named contracting party. Our US entity is being incorporated and isn't registered yet, so publishing either would mean naming a company that doesn't exist. Here is what's true in the meantime.

This website

  • We run no analytics. No page counts, no referrer logging, no third-party scripts of any kind. This site is static files; nothing about your visit reaches us.
  • One cookie, sondar-theme, storing whether you chose light or dark. It is a preference, not an identifier, and nothing reads it but your browser.
  • No advertising pixels, no tag manager, no session recording.
  • If we add analytics later it will be cookieless and it will be described here before it runs, not after.

The product

  • Sondar never receives your telemetry. It runs on your infrastructure and writes to your disks and your object storage.
  • Sondar never calls home. License keys verify offline against a public key in the binary. There is no activation server and no usage endpoint.
  • The consequence is that we cannot see your deployment at all, which is the point — and it is why we can't tell you how many Community installs exist.

Not yet published

The formal privacy policy, the terms of service, and the end-user license agreement are drafted and blocked on incorporation. When the entity registers, they go up at /privacy, /terms and in the docs, and this page is replaced. If you need to review any of them before signing something, ask and we'll send the drafts — hello@sondar.dev.