Privacy policy
Privacy is the product, not an afterthought. Here is exactly what sonex does and does not collect, in plain language.
Last updated August 20, 2026
The short version
sonex is built so there is very little to disclose. The tracker sets no cookies, never fingerprints a device, and collects no personal data about your visitors. We count visits, not people.
This policy covers two audiences: the visitors to sites that run sonex, and the account holders who sign in to the dashboard. Most of it is about how little we take.
Data from your visitors
When someone loads a page that runs the sonex tracker, we record an anonymous, aggregated view of the visit. There is no cookie, no local storage identifier, and no cross-site profile.
A visit may include:
- The page URL, referrer, and any UTM campaign tags on the link.
- Coarse location (country, region, city) derived on the fly from the IP address.
- Browser, operating system, device type, and screen size.
- Custom events and properties you choose to send with the tracker API.
The IP address is used only to derive coarse geography and to group requests from the same visit. It is never written to storage in a form tied to an individual, and it is discarded once the visit is resolved. No raw IP, no persistent visitor id, no personal data leaves that step.
Data from account holders
To use the dashboard you sign in with Google. From that we store your name, email address, and profile image so we can identify your account. We do not receive or store your Google password.
If you subscribe to a paid plan, billing is handled by our payments provider. We store your plan, subscription status, and monthly event usage. We never see or store full card numbers.
Cookies
The tracker uses no cookies at all, which is why sites running sonex need no consent banner for it.
The dashboard itself uses a single essential cookie to keep you signed in after you log in. It is strictly necessary for the app to function and is not used for tracking or advertising.
How the data is used
Visit data is used to produce the analytics you see in your dashboard: totals, trends, sources, pages, and reports. Account data is used to run your account, provide support, and bill paid plans.
We do not sell data, we do not build advertising profiles, and we do not share your analytics with third parties for their own purposes.
Who we share with
We use a small set of infrastructure providers to run the service. Each processes data only to deliver sonex to you:
- Google — sign-in with your Google account.
- Polar — subscriptions, checkout, invoices and usage billing, as Merchant of Record.
- Railway — application hosting, the PostgreSQL database, Redis, and encrypted database backups.
- Cloudflare — DNS, and hosting for the dashboard and this website.
- Sentry — error monitoring for the API and the dashboard, hosted in the EU. Cookies, headers, request bodies and query strings are excluded from every report.
Visitor analytics are not sent to any of them beyond the hosting and database providers that store them for us. Geographic lookup runs inside our own servers from a local database, so no visitor address is ever sent to a third party.
Retention
Analytics data is retained for the window that matches your plan, then purged automatically. Free plans keep six months of history and paid plans keep more. Account records are kept while your account is open.
Separately, we keep an append-only record of account activity — sign-ins, role changes, team invitations, subscription changes — for security and accounting. It is not covered by the analytics retention window, and when an account is erased those entries are pseudonymised rather than deleted, so the history stays intact without staying identifiable.
Your rights
sonex is designed to be GDPR, PECR, and CCPA-ready by default, largely because there is no personal visitor data to govern in the first place.
As an account holder you can:
- Delete a website and all of its analytics yourself, from that website's settings.
- Request a copy of your data, or deletion of your whole account and everything keyed to it, by emailing hello@trysonex.com.
- Ask us a question about any of the above.
Changes to this policy
If this policy changes in a way that matters, we will update the date at the top of the page and, for material changes, let account holders know.
This page explains how sonex works in plain language. It is written to be honest and useful, not to be legal advice. Questions? Reach us at hello@trysonex.com .