SONDO Privacy Policy
Effective Date: June 25, 2026
Company: TUNESPHERE SG PTE. LTD.
Product: Sondo
1. Scope and Contact Information
This Privacy Policy explains how TUNESPHERE SG PTE. LTD. (“TUNESPHERE,” “we,” “us,” “our,” or the “Company”) collects, uses, stores, shares, protects, and deletes personal data when you download, register for, access, or use the Sondo mobile application, official website, web application, web console, website entry points, community integrations, AI music and video generation features, voice-cloning features, Sondo Chat, cookies, payment features, customer support, appeals, and other related services.
Unless otherwise stated, TUNESPHERE is the controller, business, or equivalent responsible entity for personal data processed in connection with the Service under applicable data protection laws.
Contact information:
- Company: TUNESPHERE SG PTE. LTD.
- Privacy contact: [email protected]
- User support: [email protected]
- Business inquiries: [email protected]
2. Information We Collect
2.1 Information You Provide
- Account information, such as your name or nickname, username, email address, phone number, profile picture, login credentials, language preference, country or region, account settings, and security-verification information.
- User Inputs, such as text prompts, descriptions, lyrics, project names, project metadata, uploaded images, photos, audio, voice samples, video clips, style parameters, remix settings, and other creative materials.
- Outputs and project records, such as generated audio, lyrics, videos, remixes, voice models, project history, saved items, downloads, public-posting status, and sharing links.
- Voice-cloning and biometric-related data. If you choose to use voice cloning, a personal voice model, or a similar feature, we may collect voice recordings you upload, acoustic features, voiceprint features, voice model configurations, verification records, and authorization information. Depending on where you live, this data may be considered sensitive personal data, biometric information, or a similar protected category.
- Parent or guardian verification data. If you are a minor or if guardian consent is required, we may collect a parent or guardian email address, phone number, consent record, verification status, and necessary guardianship information.
- Customer support, complaints, and legal communications, such as emails, complaints, refund requests, appeals, feedback, surveys, and related communication records.
- Web purchases and billing information. When you purchase a subscription, recharge credits, or buy other paid features through our website or web version, you may provide payment information to Stripe, PayPal, or another third-party payment processor. We may receive and store billing name, billing email address, billing country or region, order number, invoice information, subscription status, refund status, chargeback status, tax information, and transaction-risk status as needed to provide the Service. We do not receive or store complete card numbers, PayPal login credentials, or complete bank account information.
- Copyright complaint and DMCA notice information. If you submit a copyright complaint, DMCA notice, counter-notice, or other rights request, or if your content is the subject of such a complaint, we may collect your name, email address, phone number, rights documentation, electronic or physical signature, information identifying the disputed content, statements, authorization documents, and communications related to the request.
2.2 Information Collected Automatically
- Device and log information, such as IP information, device model, operating system, browser type, app version, mobile network, language settings, time zone, device identifiers, advertising identifiers, installation ID, crash logs, diagnostics, and access timestamps.
- Usage and interaction data, such as feature clicks, generation counts, parameter selections, time spent, saves, downloads, shares, subscription status, community interactions, Sondo Chat conversation records, and safety-review records.
- Anti-fraud and security data, such as device fingerprints, abnormal requests, login risk, payment risk, automation signals, proxy or VPN risk, repeated-account linkage signals, and content-safety review results.
- Web logs, such as pages visited, referring pages, click paths, browser events, session status, cookie-consent status, checkout events, subscription-management events, and web error diagnostics.
2.3 Cookies, SDKs, and Similar Technologies
When you visit the Sondo website, web application, or web console, we may use cookies, local storage, session storage, pixel tags, SDKs, device identifiers, and similar technologies to collect or store information. The main categories include:
- Necessary cookies, which support login sessions, authentication, account security, fraud prevention, checkout, subscription management, load balancing, cookie-preference records, and legal compliance. Without these technologies, the website or web version may not function properly.
- Functional and preference cookies, which remember language, region, interface settings, login status, creative preferences, and other personalization choices.
- Analytics and performance cookies, which help us measure traffic, page performance, error logs, feature usage, conversion paths, and product-improvement results. Where practicable, we use aggregated or de-identified analytics.
- Marketing and attribution cookies, which may be used, where permitted by law and subject to any required consent or choice mechanism, to measure advertising or promotional campaign performance, identify traffic sources, avoid duplicate impressions, and perform marketing attribution.
- Third-party cookies and payment-related technologies. Stripe, PayPal, anti-fraud providers, analytics providers, customer support providers, or cloud service providers may set or read cookies, SDKs, or similar technologies during checkout, security verification, risk control, payment confirmation, or technical-service delivery.
You can clear or block cookies through your browser settings and may manage non-essential cookies through any cookie preference tool we provide. Disabling necessary cookies or payment-related technologies may prevent login, checkout, subscription management, security verification, project saving, or other web features from working properly.
2.4 Information from Third Parties
- Third-party login information. If you sign in with Apple, Google, Discord, or another third-party login provider, we may receive public profile information, account identifiers, verified email addresses, and related information according to your authorization and the provider’s permissions.
- Payment status. Apple, Google, Stripe, PayPal, or other payment processors may provide order numbers, subscription status, payment confirmations, refund status, chargeback status, billing email address, billing country or region, transaction tokens, customer or subscription identifiers, tax status, and anti-fraud status. We do not receive or store complete card numbers, PayPal login credentials, or complete bank account information.
- Legal, safety, and platform information. When handling unlawful content, fraud, security incidents, or legal requests, we may receive information from regulators, law enforcement, platform providers, or security service providers.
- Platform age signals (possible future integration). Where supported by the platform and where permitted or required by applicable law and user or guardian authorization, we may in the future use the Google Play Age Signals API (or successor or similar platform tools) and Apple’s Declared Age Range API or similar iOS/App Store age-assurance tools to receive age bands, age categories, guardian-approval status, applicable-region indicators, permission revocation status, significant-update acknowledgement status, or similar signals returned by Google, Apple, or the relevant app store or operating-system platform. We do not receive a full date of birth, original identity documents, full payment credentials, or complete identity-verification materials through these interfaces unless you separately provide them or the law otherwise requires.
2.5 Third-Party AI Service Providers
To support AI music-video generation, audio-to-video transformation, intelligent prompt processing, prompt optimization, and multimodal interactions, Sondo integrates with trusted third-party artificial intelligence services (“AI Providers”). When you use these features, relevant data may be securely transmitted to the applicable AI Provider for real-time or near-real-time processing.
AI Providers include:
- Wan AI (the Wan 2.5 video generation model), used for audio-to-video conversion and AI music video generation.
- Anthropic PBC, which provides Claude language model services for intelligent prompt processing, prompt optimization, instruction generation, or response generation.
- OpenAI, LLC, which provides ChatGPT multimodal model services for prompt generation, multimodal understanding, intelligent responses, or related creative assistance.
Data processed by AI Providers may include:
- Audio and image data. When you generate AI videos, visual content, or music videos, uploaded audio, images, video clips, or related materials may be processed by the Wan 2.5 video generation model to generate synchronized video outputs or visual content.
- Text and prompt data. Your prompts, keywords, lyrics, style selections, parameter selections, or creative instructions may be processed by Anthropic Claude or OpenAI ChatGPT to generate instructions, optimized prompts, content organization, or interactive responses used for AI generation.
AI Provider data retention. We require AI Providers to retain user data only for the shortest period necessary to complete the processing request and to delete it from temporary processing systems after the task is completed, unless limited retention is required for legal, regulatory, security, abuse-prevention, audit, or dispute-handling purposes. Unless you separately and expressly consent or applicable law permits otherwise, we do not authorize AI Providers to use your non-public User Inputs, private project files, original voice recordings, voiceprint features, personal voice models, or private Content from minor accounts to train their general foundation models.
3. How We Use Information and Our Legal Bases
We process personal data for the purposes below and, where required by applicable law, rely on the corresponding legal bases:
- Providing and performing the Service, including account creation, login verification, prompt and media processing, Output generation, project saving, downloads, device synchronization, subscription management, web checkout, Stripe and PayPal payment-status handling, refunds, invoices, and customer support. Legal bases may include performance of a contract, steps taken at your request before entering into a contract, and our legitimate interests.
- Operating AI generation and voice-cloning features, including processing your inputs, parameters, audio, video, and voice samples to complete generation, editing, remixing, or voice-cloning requests that you initiate. Where sensitive data or biometric data is involved, we rely on your explicit consent where required by applicable law.
- Safety, anti-fraud, and platform integrity, including detecting account farming, bots, payment fraud, chargeback risk, abnormal requests, policy-violating content, infringement risk, minor-safety risks, malicious code, and security attacks. Legal bases may include legitimate interests, contract performance, and legal obligations.
- Age-appropriate experiences and minor protection, including, after future integration of platform age signals, using age bands, age categories, and guardian-consent status returned by the Google Play Age Signals API, Apple’s Declared Age Range API, or similar platform tools to adjust age-appropriate content, public posting, social interactions, purchases, voice cloning, adult-content access, external sharing, and other higher-risk features. We will not use these platform age signals for cross-context behavioral advertising, unnecessary marketing, or profiling unrelated to age-appropriate experiences and compliance. Legal bases may include contract performance, legitimate interests, legal obligations, and consent where required by applicable law.
- Content review and compliance, including reviewing content that may violate these Terms, involve child-safety risks, non-consensual intimate content, infringement, fraud, hate, violence, unlawful conduct, or other high-risk activity. Legal bases may include legitimate interests, legal obligations, and protection of important public interests.
- Product improvement and AI training, within the boundaries in Section 4, including using public Content, aggregated or anonymized data, feedback, and authorized data to improve model quality, recommendations, safety, and user experience. Legal bases may include legitimate interests, consent, or other applicable legal bases.
- Marketing, notices, and web analytics, including sending service notices, subscription reminders, security alerts, feature updates, policy-change notices, promotional communications, or user surveys, and using cookies or similar technologies for web analytics, conversion analysis, and marketing attribution where permitted by law. You may unsubscribe or manage non-essential marketing and analytics through email tools, in-app settings, or cookie preferences.
- Legal requests and rights protection, including handling appeals, law-enforcement requests, regulatory communications, disputes, claims, audits, compliance records, and legal defenses. Legal bases may include legal obligations and legitimate interests.
- Copyright complaints and rights protection, including receiving, verifying, and processing copyright complaints, DMCA notices, counter-notices, infringement disputes, repeat-infringer determinations, notice forwarding, record retention, and related legal defenses. Legal bases may include legal obligations, legitimate interests, and, where applicable, processing necessary to protect rights holders and the platform.
4. AI Training and Data Protection Boundaries
We may use public Outputs, public remixes, public work parameters, general prompts, feedback, aggregated data, anonymized data, and data you otherwise authorize to improve, test, evaluate, fine-tune, or train our models, content-safety systems, and product features.
Unless you provide separate express consent, or unless otherwise permitted by law, we will not use the following data to train, fine-tune, or develop foundation models made available to the public or to third parties:
- Private project files, uploaded materials, prompts, audio, video, or images that you set as private;
- Original voice recordings, voiceprint features, personal voice models, or other biometric data used for voice cloning;
- Materials that clearly contain identity documents, financial accounts, health information, children’s information, intimate scenes, precise identity information, or other sensitive personal information;
- Private Content from minor accounts; or
- Data that law prohibits us from using, or data for which you have effectively objected to processing, withdrawn consent, or requested deletion.
We use access controls, data classification, review rules, permission separation, logging, de-identification, aggregation, anonymization, and retention controls to reduce the risk of data being used beyond the permitted scope.
5. Voice Cloning and Biometric Data
If you choose to use voice cloning, a personal voice model, or a similar feature, we may extract acoustic features, voiceprint features, or create a voice model associated with your account from the recordings you upload. In some jurisdictions, this data may be treated as sensitive personal data or biometric information.
We process this data only after you actively enable the relevant feature, complete the required authorization, and agree to the applicable processing notice. The purposes are limited to:
- Creating, operating, maintaining, and improving the personal voice model in your account;
- Verifying sample quality, authorization status, and impersonation risk;
- Detecting unauthorized voice cloning, impersonation, infringement, or unlawful content; and
- Complying with legal obligations, handling complaints, and protecting users and platform safety.
Unless you separately and expressly agree, we will not sell, rent, trade, or otherwise separately profit from your voiceprint or biometric data, and we will not use your original voice recordings or personal voiceprint features to train public foundation models. We will delete or anonymize the relevant data after account closure, deletion of the voice model, withdrawal of consent, or expiration of the legally required retention period, as described in Section 8, unless limited retention is necessary for legal, dispute, safety, audit, or rights-protection purposes.
7. International Transfers
TUNESPHERE is based in Singapore, and the Service may use cloud services, technology vendors, and operations teams located in different countries or regions. If you use the Service from outside Singapore, your personal data may be transferred to, stored in, or processed in countries or regions outside where you live.
We take reasonable steps required by applicable data protection laws to protect personal data in cross-border transfers, including entering into appropriate data processing agreements, using standard contractual clauses where applicable, conducting transfer risk assessments where required, limiting access permissions, and applying technical security measures.
8. Data Retention and Deletion
We keep personal data only for as long as needed for the purposes described in this Privacy Policy, unless a longer retention period is required for legal, regulatory, dispute, security, anti-fraud, accounting, audit, minor-protection, or rights-protection purposes. General retention rules include:
- Account information is retained while your account is active and is typically deleted or anonymized from active systems within 30 business days after account closure, unless limited retention is needed for legal or safety reasons.
- User Inputs and Outputs are retained while your account is active or while you keep the relevant project. After you delete specific Content or close your account, the data is typically deleted or anonymized from active systems within 30 business days. Public posts, sharing links, remixes, collaborations, community interactions, or Content already saved by others may not be fully retractable.
- Voice-cloning data and personal voice models are retained while the feature is enabled and your account is active. After you delete the voice model, withdraw consent, or close your account, the data is typically deleted or anonymized from active systems within 30 business days, unless limited retention is needed for legal, complaint, dispute, safety, or audit purposes.
- Payment and accounting records are retained for the period required by tax, accounting, anti-fraud, app store, Stripe, PayPal, and other payment-processor rules.
- Cookies and web logs are retained for the period needed for login, security, checkout, or preference records. Retention periods for non-essential cookies are described in the cookie preference tool, browser settings, or the relevant third-party notices.
- Security logs and anti-fraud records are retained for the period needed to maintain platform security, investigate anomalies, and prevent abuse.
- Customer support, complaint, and legal records are retained for the period needed to handle requests, disputes, defenses, and legal obligations.
- Backup data is deleted, overwritten, or anonymized during the normal backup rotation cycle.
- Temporary data processed by third-party AI Providers is retained by those providers only for the shortest period necessary to complete the processing request and is deleted from temporary processing systems after the task is completed, unless limited retention is required for legal, regulatory, security, abuse-prevention, audit, or dispute-handling purposes.
You may delete certain Content in the application or contact [email protected] to request account closure, deletion of personal data, or withdrawal of consent. After verifying your identity, we will process your request according to applicable law.
- Copyright complaints, DMCA notices, counter-notices, rights disputes, repeat-infringer reviews, and related communications are retained for as long as needed to process complaints, disputes, appeals, audits, legal compliance, or rights protection.
9. Your Privacy Rights
Depending on where you live, you may have one or more of the following rights:
- Access personal data we hold about you;
- Correct inaccurate or incomplete personal data;
- Delete personal data;
- Restrict or object to specific processing activities;
- Receive a copy of your data in a structured, commonly used, machine-readable format;
- Withdraw consent;
- Opt out of sale, sharing, targeted advertising, profiling, or non-essential cookies where applicable law provides such rights;
- Appeal automated-decision or privacy-request decisions; and
- Complain to a data protection regulator.
You may submit requests to [email protected]. To protect account security, we may require identity verification. If you authorize another person to submit a request for you, we may require proof of authorization.
9.1 Users in the European Economic Area, the United Kingdom, and Switzerland
If you are located in the European Economic Area, the United Kingdom, or Switzerland, you may exercise rights of access, rectification, erasure, restriction, data portability, objection, withdrawal of consent, and complaint to a supervisory authority under applicable data protection laws. Our legal bases for processing personal data include contract performance, your consent, legitimate interests, legal obligations, and, in limited cases, protection of vital interests or public interests.
9.2 U.S. State Privacy Rights
If you are located in California, Texas, or another U.S. state with an applicable privacy law, you may have rights to know, access, correct, delete, receive data portability, opt out of sale or sharing, opt out of targeted advertising, limit use of sensitive personal information, appeal, and be free from unlawful discrimination for exercising privacy rights. We will not treat you in an unlawfully discriminatory manner because you exercise your privacy rights.
10. Children’s Privacy
The Service is not directed to children under 13 or to children below the higher minimum age required by local law. We do not knowingly collect personal data from such children. If we learn or receive reliable notice that a child below the applicable minimum age created an account or submitted personal data without appropriate consent, we will take reasonable steps to delete the data and close the account.
If you are a parent or legal guardian and believe your child used the Service without authorization or uploaded a face photo, voice recording, contact information, school information, identity document, or other personal data, contact us at [email protected].
For minor accounts, we may restrict public posting, external direct messaging, social interactions, purchases, voice cloning, adult content, external sharing, and other higher-risk features, and we may require guardian consent or other reasonable verification.
After future integration of platform age signals, we may use age bands, age categories, guardian consent, approval revocation, or significant-update acknowledgement signals provided by Google, Apple, or other platforms to trigger age-appropriate feature restrictions, guardian-consent flows, or minor-protection measures. If you or your guardian does not agree to provide platform age signals, or if such platform signals are unavailable, we may restrict certain features or request other reasonable verification.
11. Security Measures
We use reasonable technical and organizational measures to protect personal data, including access controls, transmission protection, storage protection, permission separation, log auditing, vulnerability remediation, anti-fraud detection, content-safety review, and vendor management. However, no internet service, cloud service, or electronic storage method can be guaranteed to be completely secure. Please protect your account credentials and contact us promptly if you notice abnormal activity.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If a change materially affects data categories, processing purposes, cookie use, third-party payment processing, third-party AI service providers, AI training boundaries, voice cloning, biometric data, minor protection, platform age signals, international transfers, or your rights, we will notify you through an in-app pop-up, notice, email, app store update note, or another legally permitted and reasonable method.
13. Contact Us
If you have questions about this Privacy Policy, data processing, cookies, third-party payments, voice cloning, biometric data, minor protection, AI training, or account deletion, contact us at:
- Privacy and compliance: [email protected]
- User support: [email protected]
- Business inquiries: [email protected]
© 2026 TUNESPHERE SG PTE. LTD. All rights reserved.