Legal · Privacy
Privacy Policy
What we collect, where it lives, who touches it, and how to get it deleted — in plain language, because that is the whole point.
What Sonaloop is — and who is responsible
Sonaloop is a research operating system: a synthetic-research engine you can run locally inside your own AI agent (the open-core MCP server), plus a hosted cloud workspace at app.sonaloop.com, a persona catalog at data.sonaloop.com, and a portal for our research service. This policy covers this website (sonaloop.com) and those hosted services. The local open-core engine stores everything on your own machine — nothing reaches our servers unless you sign in to a hosted service.
Responsible for data processing (controller): Johannes Hötter. Contact: jt.hoetter@gmail.com — this personal address applies until a sonaloop.com address exists, and it is answered by the person who runs the service.
What we collect
Sign-in. You sign in with Google (OpenID Connect). We receive exactly three fields: your subject identifier (a stable account ID), your email address, and your name. We request the “openid email profile” scopes and nothing more — no contacts, no files, no calendar, and we never see your Google password.
Cookies — functional only. After sign-in we set one session cookie (sonaloop_session): an HMAC-SHA256-signed token, valid for 12 hours, scoped to Domain=.sonaloop.com so the sibling subdomains (app, data, research) recognize the same login. It is HttpOnly, Secure and SameSite=Lax. During the sign-in flow a short-lived (10-minute) state cookie protects against forged logins, and a small cookie remembers which workspace you last had open. There are no advertising or analytics cookies.
Workspace content. Everything you create in a cloud workspace — projects, personas, councils, syntheses, notes, uploads — is stored in that workspace’s own partition (its own database and file directory) on our server. Workspaces are isolated from each other: members of a workspace see that workspace’s data, nobody else does.
Catalog personas are fully synthetic. The personas in the catalog at data.sonaloop.com are authored characters with constructed biographies. They do not describe, sample or anonymize real persons, and they contain no real personal data.
Payments. Billing runs through Stripe once paid plans are live. When you upgrade, your payment details go directly to Stripe and never touch our servers. On our side we store only your subscription status and the Stripe customer/subscription reference IDs needed to map your payment to your workspace.
Server logs. Like practically every web service, our servers write technical access logs (IP address, requested URL, timestamp, status code) for operations, debugging and abuse protection. They are not used to profile you.
What we don’t do
No advertising. No tracking pixels. No analytics cookies. No fingerprinting. No selling or renting of data — there is nothing here to sell. This website serves static pages and sets no cookies at all; your light/dark theme preference is kept in your browser’s local storage and never transmitted.
One honest caveat: this website currently loads its fonts from Google Fonts, which means your browser requests font files from Google’s servers and thereby transmits your IP address to Google. That is the only third-party request the website makes.
Where your data lives
All hosted services run on a server operated by Hetzner Online GmbH in Nürnberg, Germany. Your data is processed and stored in the EU. Connections are TLS-encrypted in transit.
Backups are daily server snapshots; the seven most recent are retained and older ones roll off automatically. We do not currently claim encryption at rest for the underlying volumes — we would rather tell you that plainly than print a checkbox we can’t back.
Who else touches data
We share data with the infrastructure providers it takes to run the service — and with no one else:
- Hetzner Online GmbH (Nürnberg, Germany) — hosting and server snapshots.
- Google — sign-in provider (OpenID Connect); on this website additionally the delivery of fonts via Google Fonts.
- Stripe — payment processing, only once you upgrade to a paid plan.
- OpenAI — optional: only when a workspace uses the avatar-image or semantic-recall (embeddings) features does the server send the relevant persona text or image prompt to OpenAI’s API. If you don’t use these features, nothing is sent to OpenAI.
That is the complete list.
How long we keep it
- Workspace content — until you delete it, or until we close your account at your request. Deleted data also rolls out of the backups within seven days.
- Session cookie — expires after 12 hours.
- Your Google profile fields (ID, email, name) — for the life of your account.
- Stripe references and subscription status — for as long as your subscription exists, plus whatever accounting law requires of billing records.
Your rights
Under the GDPR you can ask for access, correction, deletion, export (data portability), restriction of processing, or object to it — one email is enough. On request we will export your workspace content in a portable format and delete your account. You can also lodge a complaint with your data-protection supervisory authority.
Contact for all of this: jt.hoetter@gmail.com.
Changes to this policy
When the service changes in a way that affects your data, this page changes with it and the effective date is updated. Effective June 12, 2026.
Deutsche Fassung
Datenschutzerklärung
Was wir erheben, wo es liegt, wer es berührt und wie Sie es löschen lassen — in klarer Sprache, denn genau darum geht es.
Stand: 12. Juni 2026
Was Sonaloop ist — und wer verantwortlich ist
Sonaloop ist ein Research-Betriebssystem: eine Engine für synthetische Forschung, die Sie lokal in Ihrem eigenen KI-Agenten betreiben können (der Open-Core-MCP-Server), dazu ein gehosteter Cloud-Workspace unter app.sonaloop.com, ein Persona-Katalog unter data.sonaloop.com und ein Portal für unseren Research-Service. Diese Erklärung gilt für diese Website (sonaloop.com) und die genannten gehosteten Dienste. Die lokale Open-Core-Engine speichert alles auf Ihrem eigenen Rechner — nichts erreicht unsere Server, solange Sie sich nicht bei einem gehosteten Dienst anmelden.
Verantwortlicher im Sinne der DSGVO: Johannes Hötter. Kontakt: jt.hoetter@gmail.com — diese persönliche Adresse gilt, bis eine sonaloop.com-Adresse existiert, und wird von der Person beantwortet, die den Dienst betreibt.
Welche Daten wir erheben
Anmeldung. Sie melden sich mit Google an (OpenID Connect). Wir erhalten genau drei Felder: Ihre Subject-Kennung (eine stabile Konto-ID), Ihre E-Mail-Adresse und Ihren Namen. Wir fordern die Scopes „openid email profile“ an und nicht mehr — keine Kontakte, keine Dateien, kein Kalender; Ihr Google-Passwort sehen wir nie.
Cookies — rein funktional. Nach der Anmeldung setzen wir ein Sitzungs-Cookie (sonaloop_session): ein HMAC-SHA256-signiertes Token, 12 Stunden gültig, mit Domain=.sonaloop.com, damit die Schwester-Subdomains (app, data, research) dieselbe Anmeldung erkennen. Es ist HttpOnly, Secure und SameSite=Lax. Während des Anmeldevorgangs schützt ein kurzlebiges State-Cookie (10 Minuten) vor gefälschten Logins, und ein kleines Cookie merkt sich, welcher Workspace zuletzt geöffnet war. Werbe- oder Analyse-Cookies gibt es nicht.
Workspace-Inhalte. Alles, was Sie in einem Cloud-Workspace erstellen — Projekte, Personas, Councils, Synthesen, Notizen, Uploads — liegt in der eigenen Partition dieses Workspace (eigene Datenbank, eigenes Dateiverzeichnis) auf unserem Server. Workspaces sind voneinander isoliert: Mitglieder eines Workspace sehen dessen Daten, sonst niemand.
Katalog-Personas sind vollständig synthetisch. Die Personas im Katalog unter data.sonaloop.com sind verfasste Figuren mit konstruierten Biografien. Sie beschreiben, sampeln oder anonymisieren keine realen Personen und enthalten keine echten personenbezogenen Daten.
Zahlungen. Die Abrechnung läuft über Stripe, sobald Bezahlpläne live sind. Beim Upgrade gehen Ihre Zahlungsdaten direkt an Stripe und berühren unsere Server nie. Bei uns liegen nur Ihr Abo-Status und die Stripe-Referenz-IDs (Kunde/Abonnement), die nötig sind, um Ihre Zahlung Ihrem Workspace zuzuordnen.
Server-Logs. Wie praktisch jeder Webdienst schreiben unsere Server technische Zugriffsprotokolle (IP-Adresse, aufgerufene URL, Zeitstempel, Statuscode) für Betrieb, Fehlersuche und Missbrauchsschutz. Sie werden nicht zur Profilbildung verwendet.
Was wir nicht tun
Keine Werbung. Keine Tracking-Pixel. Keine Analyse-Cookies. Kein Fingerprinting. Kein Verkauf oder Vermieten von Daten — es gibt hier nichts zu verkaufen. Diese Website liefert statische Seiten aus und setzt selbst keinerlei Cookies; Ihre Hell-/Dunkel-Einstellung liegt im Local Storage Ihres Browsers und wird nie übertragen.
Eine ehrliche Einschränkung: Diese Website lädt ihre Schriften derzeit von Google Fonts. Ihr Browser ruft die Schriftdateien also von Google-Servern ab und übermittelt dabei Ihre IP-Adresse an Google. Das ist die einzige Drittanbieter-Anfrage, die die Website stellt.
Wo Ihre Daten liegen
Alle gehosteten Dienste laufen auf einem Server der Hetzner Online GmbH in Nürnberg. Ihre Daten werden in der EU verarbeitet und gespeichert. Verbindungen sind während der Übertragung TLS-verschlüsselt.
Backups sind tägliche Server-Snapshots; die sieben jüngsten werden vorgehalten, ältere laufen automatisch aus. Eine Verschlüsselung der zugrunde liegenden Volumes im Ruhezustand (encryption at rest) behaupten wir derzeit nicht — wir sagen Ihnen das lieber offen, als ein Häkchen zu drucken, das wir nicht belegen können.
Wer sonst Daten berührt
Wir geben Daten an die Infrastruktur-Dienstleister weiter, ohne die der Dienst nicht läuft — und an niemanden sonst:
- Hetzner Online GmbH (Nürnberg) — Hosting und Server-Snapshots.
- Google — Anmeldedienst (OpenID Connect); auf dieser Website zusätzlich die Auslieferung der Schriften über Google Fonts.
- Stripe — Zahlungsabwicklung, erst wenn Sie auf einen Bezahlplan wechseln.
- OpenAI — optional: Nur wenn ein Workspace die Funktionen Avatar-Bilder oder semantische Erinnerung (Embeddings) nutzt, sendet der Server den betreffenden Persona-Text bzw. Bild-Prompt an die OpenAI-API. Nutzen Sie diese Funktionen nicht, wird nichts an OpenAI gesendet.
Das ist die vollständige Liste.
Wie lange wir Daten aufbewahren
- Workspace-Inhalte — bis Sie sie löschen oder wir Ihr Konto auf Ihren Wunsch schließen. Gelöschte Daten laufen innerhalb von sieben Tagen auch aus den Backups aus.
- Sitzungs-Cookie — läuft nach 12 Stunden ab.
- Ihre Google-Profilfelder (ID, E-Mail, Name) — für die Dauer Ihres Kontos.
- Stripe-Referenzen und Abo-Status — solange Ihr Abonnement besteht, zuzüglich der handelsrechtlichen Aufbewahrungsfristen für Abrechnungsunterlagen.
Ihre Rechte
Nach der DSGVO können Sie jederzeit Auskunft, Berichtigung, Löschung, Export (Datenübertragbarkeit), Einschränkung der Verarbeitung oder Widerspruch verlangen — eine E-Mail genügt. Auf Wunsch exportieren wir Ihre Workspace-Inhalte in einem portablen Format und löschen Ihr Konto. Sie können sich außerdem bei Ihrer Datenschutz-Aufsichtsbehörde beschweren.
Kontakt für all das: jt.hoetter@gmail.com.
Änderungen dieser Erklärung
Ändert sich der Dienst auf eine Weise, die Ihre Daten betrifft, ändert sich diese Seite mit — und das Datum wird aktualisiert. Stand: 12. Juni 2026.