Skip to content
SonariTry it free
Sonari
Sonari for MacSonari RemoteGuidesSupportPrivacyTerms

Copyright © 2026 Shubhra Saha. All rights reserved.

Privacy Policy

Sonari collects nothing. What follows is the long version of that sentence.

Last updated: 28 August 2026

This policy explains what Sonari does with information, in plain language. It covers Sonari for Mac and Sonari Remote for iPhone, which are two halves of one instrument and are treated as one product throughout, and it covers this website.

Sonari is made by Shubhra Saha, an independent developer based in India. You can reach me at contact@playsonari.com.


The short answer

Sonari is a musical instrument, not a service. It has no account to create, no server to sign in to, and nothing it sends anywhere about you.

Read the two columns separately. The applications and the website are different things and they do not have the same answer on every line. There is exactly one line where they differ, it is marked, and it is explained in full further down.

Sonari for Mac and Sonari Remoteplaysonari.com
Personal information collectedNoneNone
Personal information shared or soldNone. Sonari has never sold data and never willNone
Accounts or sign-inNoneNone
CookiesNoneNone. There is no consent banner because there is nothing to consent to
Analytics or usage statisticsNone, of any kindA count of visits. No cookie, no identifier, nothing stored on or read from your device. This is the one line that differs. See This website below
Crash or diagnostic reportingNone. No reporting SDK is in either appNone
Advertising, tracking or profilingNone. Nothing is tracked across apps, sites or devicesNone
Third-party codeNone. Neither app has an external software dependencyNone. Everything the page loads is served from this domain
Where your music and settings liveOn your own devices, in files you can open, copy or deleteNot applicable
Payment detailsHandled entirely by Apple. Sonari never receives themNothing is sold here

Everything below is the detail behind that summary, written about what these two apps actually do. The website is a separate thing with a much shorter answer, and it is directly below.


This website

Nothing here applies to the applications. This section is about the pages you are reading in a browser. Both applications are covered by everything else in this policy, and neither of them counts anything.

The website counts how many times its pages are viewed, and that is the whole of it. Two small scripts do the counting. Both are served from this domain by the same host that serves the page itself, so no request leaves for anybody else's server and no third party is involved at any point.

Nothing is stored on your device and nothing is read from it. No cookie is set. Nothing is written to local storage and nothing is looked for there. That is not a claim made loosely: it is the reason this site has no consent banner, because in the United Kingdom and the European Union the rule that requires one turns on storing or reading something on your machine, and neither of these does either.

What the counting produces is a number: how many people looked at a page, which pages, roughly where in the world, and which kind of device and browser. There is no way to go from that back to a person, because nothing that identifies one is ever recorded. There is no visitor profile, no session replay, no heatmap, no funnel, and nothing that follows you from one visit to the next or from this site to any other.

The second script measures how quickly pages actually load for real visitors on real connections, rather than on a fast machine on a fast line. It exists so the site can be made faster for the people using it, and it records timings, not people.

And what every web server records anyway. This site is hosted by Vercel Inc. in the United States. Vercel's servers log the address your request came from, the page you asked for, the browser you asked with and the time you asked, as ordinary operational and security records, under Vercel's own privacy policy. An address of that kind can count as personal information in some countries, which is why it is written down here rather than left unsaid. The same is true of the sound pack catalogue, which the Mac application fetches from this same domain.

If any of this changes, whether a different tool, a different measurement or anything at all, this section changes in the same commit, and the date at the top of this page moves.


What "collect" means here

Sonari processes a great deal on your device. It reads the camera many times a second, it listens to the microphone when you ask it to, and it writes your recordings to your disk.

None of that is collection. Information is collected when it is sent to somebody, kept by them, or used for a purpose of theirs. Nothing in Sonari reaches me, and there is nowhere for it to go: there is no Sonari server, no database, and no account that could hold anything under your name.

Where this policy says nothing is collected, it means exactly that, and the sections below say what is processed instead, where it happens, and how long anything lasts.


The camera

What it is for. Sonari watches your hands, and optionally your body and face, and turns movement into music. A reach becomes a note, a curve becomes a bend, a pause becomes a swell. Without the camera the instrument does not play.

Where it happens. Entirely on your Mac, using Apple's on-device Vision framework and Sonari's own code. Camera frames stay in memory for as long as it takes to measure them, which is a fraction of a second, and are then discarded.

What is kept. Nothing. No frame, no photograph, no video and no face or body measurement is written to disk, unless you deliberately record a session, in which case the video goes to a file of yours on your own disk and nowhere else.

What is never done. No face is identified, matched or recognised. Sonari measures where a hand or a face is, not whose it is, and it holds no template that could tell one person from another. Nothing derived from the camera is used to profile you, advertise to you, or train any model.

Turning it off. macOS controls this, not Sonari. System Settings, then Privacy and Security, then Camera. Sonari can still be played without it: Key Deck is played on the Mac's own keyboard, and Breath is played into a paired iPhone. A MIDI controller can be mapped to Sonari's controls, but it does not play the instrument.

TrueDepth API and Face Tracking Data

Sonari Remote for iOS includes an optional playing mode ("Face" way) that uses Apple's TrueDepth camera and ARKit face tracking APIs (ARFaceTrackingConfiguration) on compatible iPhone models.

  • Information Collected: When you choose the Face way, the app reads real-time facial expression blendshape coefficients (such as jaw opening, smiling, eyebrow movements, cheek puff, and deliberate eye blinks) and 3D head orientation angles (pitch, yaw, roll). This data consists solely of transient, normalized mathematical floating-point values (between 0.0 and 1.0) and rotation angles representing muscle and head motion. Sonari Remote does not collect, capture, or record facial photographs, video frames, depth map imagery, or biometric identity templates.
  • Purpose of Collection: Face tracking data is used solely and exclusively in real time to shape musical instrument parameters during a live performance (for example, mapping a smile to vibrato, eyebrow elevation to filter brightness, or head tilt to pitch bend). It has no other purpose.
  • Third-Party Sharing: Face tracking data is never shared with third parties. No face data, images, or expression values are ever transmitted to advertising networks, analytics platforms, data brokers, or external servers. The transient musical control values derived from your movements are transmitted only over your private, encrypted local Wi-Fi or peer-to-peer connection directly to your own paired Mac running Sonari to sound the instrument.
  • Storage and Retention: Face tracking data is strictly ephemeral. Blendshapes and orientation values are processed in volatile memory at 60 Hz on a per-frame basis and are immediately overwritten and discarded. Nothing is ever stored to disk, persistent storage, or the cloud. No face tracking information is retained once the frame has been processed or when the performance session ends.
  • Biometrics and Recognition: Sonari Remote does not perform facial recognition, user identification, user authentication, or person matching. Face data is never used to identify a person, track users across apps or services, or build advertising or behavioural profiles.

The microphone

On your Mac, Sonari uses the microphone for two things you start yourself:

  1. Recording a session's audio, when you press record.
  2. Sampling a sound you want to turn into an instrument.

On your iPhone there is a third use, and only while you have chosen the way of playing that needs it. Air plays breath and voice. The microphone is measured many times a second for how hard you are blowing and roughly what note you are humming, those two measurements become musical control values, and the sound itself is never written down and never leaves the phone.

Sampling on the iPhone is the one time audio is kept. A take of up to thirty seconds is saved on the iPhone and sent to the Mac you paired with, which turns it into an instrument. You start it, it goes nowhere else, and you can delete the take.

There is no background listening and no always-on capture: the microphone is live only while you are recording, sampling, or playing the Air way. No speech is recognised and nothing is transcribed, and nothing you play or say is matched against anything or sent anywhere. Audio you record on the Mac is written to a file on your Mac and is never uploaded.

Revoke it in System Settings, then Privacy and Security, then Microphone on the Mac, and in iOS Settings for Sonari Remote.


Screen recording

If you record a performance video, Sonari captures the performance window using Apple's screen recording API, and the result is a file on your disk.

Sonari always says when this is happening. A red indicator appears, and a countdown runs before capture begins, so a recording cannot start without your knowing. macOS shows its own indicator in the menu bar as well.

Recordings are never transmitted. Revoke the permission in System Settings, then Privacy and Security, then Screen and System Audio Recording.


Your iPhone, and your local network

Sonari Remote turns an iPhone into a second controller: tilt, touch and motion become musical expression on the Mac.

The two devices talk to each other and to nothing else. They find each other with Bonjour on the network you are already on, you approve the pairing once with a six digit code, and after that they reconnect on their own. No part of that conversation leaves your network, and no relay, cloud or account is involved.

The connection is encrypted with Apple's CryptoKit: X25519 key agreement, Ed25519 signatures for the pairing, and an authenticated encryption channel for everything after. The keys are generated on your own devices and never leave them.

Sonari Remote stores its pairing with your Mac, your choice of playing surface, and any sample takes you have recorded and not yet deleted. That is all it stores.


What is stored on your devices

On your Mac, under ~/Library/Application Support/Sonari/:

  • Your presets, custom playing styles, custom scales and custom layouts
  • Your recordings, takes and loop sessions
  • Hand calibration measured for your reach
  • Any samples you imported or recorded
  • The performance journal, if you leave it on
  • The keys that identify your Mac to your own iPhone

A small number of preferences also live in the app's own settings file: your appearance and layout choices, the trial dates described under Buying Sonari, and which reminders you have already seen.

These are your files. You can open them in Finder, copy them to another Mac, put them in a backup, or delete them. Trust material is written with owner-only permissions. Nothing in either location is synced to me, backed up to me, or reachable by me, because there is no server and no account for it to reach.

The performance journal

The journal remembers the music you played so you can find a phrase again later. It is on by default, and Settings, then Recording, turns it off. Being exact about it matters:

  • It can hold only notes, expression values, sparse musical context and low-rate gesture anchors. It cannot hold pixels or audio. Those are not among the kinds of event it is able to store.
  • It is a file on your own disk, a few hundred kilobytes, that nothing uploads.
  • While it is on, Sonari says so. A clock symbol sits in the toolbar the whole time and a line appears in the Recordings bar. It never remembers without telling you.
  • Turning it off stops it and keeps what was already remembered. Purge deletes it, immediately.
  • Sonari can write you a page describing your own playing: the scales and keys you actually played in, where your hands sit, the grid your notes land on, the chord runs you come back to. It is worked out from this journal and nothing else, by arithmetic on your own Mac: no model is involved and nothing about you is sent anywhere. It is written only at the moment you ask for it, in Settings, then Recording, so if you never ask, it never exists. Nothing in Sonari reads it back. It changes no setting and makes no suggestion. It sits beside the journal, and Purge deletes it too.

Sonari remembers your music, never your image.


When Sonari uses the internet

Two things, both because you asked for them:

  1. The sound pack catalogue, so the Sounds page can show what is available, along with the cover pictures it lists.
  2. A sound pack you chose to install.

These are ordinary file downloads from a public host. No identifier is sent, and nothing about you is attached to the request. The host sees what any web server sees when a file is fetched, and there is nothing in the request that says which copy of Sonari asked or who is using it. No record of what you browsed or installed leaves your Mac, and no profile can be built from it, because nothing is collected to build one from.

Visuals are not downloaded at all. Every one of them ships inside the app.

Apart from these, and the connection to your own iPhone, neither app makes a network request. There is no phone-home at launch, no licence check, no update ping and no beacon.


Artificial intelligence

Sonari uses Apple's on-device foundation model for three kinds of convenience, and for nothing else:

  1. Searching in your own words. Typing "something like a harp for slow ambient sets" is turned into terms that already exist in what you have installed, and Sonari's own plain search does the finding and the ranking. Scales, rhythms, layouts, sounds, presets and the in-app help all go through the same seam.
  2. Naming and describing something you made. A preset, a recorded session or a visual gets a name and a line of its own instead of a timestamp.
  3. Putting a sentence to something Sonari already worked out. Why two controls are fighting over one movement, what a chord progression just did, or what a gesture you have not tried yet would do.

In every one of those the model rephrases facts Sonari already holds, or picks from a list that already exists. It never chooses a note, a scale, a chord or a sound, and when it returns nothing you get the plain wording instead.

It never uses a cloud model. Not a third-party provider, and not Apple's Private Cloud Compute, including while that is offered at no cost. Your prompts, presets, scales, recordings and music are never sent anywhere for processing, and nothing you make is ever used to train anything.

This is a permanent decision about what Sonari is, not a limitation waiting to be lifted.


Buying Sonari

Sonari is free to download, free to play for fourteen days, and then needs one purchase. There is no subscription, no account and no licence key.

Apple is the seller. The App Store takes the payment, holds your payment method, issues the receipt and handles refunds. Sonari has no payment form, no card field and no checkout of its own. The purchase happens in a sheet the operating system draws, above the app rather than inside it.

Sonari never receives your payment details. Not the card number, not the billing address, not your name, and not the email address on your Apple Account. None of it is passed to the app, so none of it can be stored, sent or lost.

What the app is told

Apple's StoreKit gives Sonari a short, cryptographically signed record for each purchase, held on your Mac by the operating system rather than by me:

Which productthe free trial, or the purchase
When it happenedthe date Apple signed
A transaction identifierApple's, and meaningless outside the App Store
Whether it was refundedso a refunded copy stops playing

Sonari reads that record to answer one question, which is whether this copy may play. It is never sent anywhere. There is no licence server and no receipt validation endpoint.

The two dates kept on your own disk

In Sonari's own settings, and nowhere else:

  1. The furthest date this Mac has seen, so the trial cannot be run twice by turning the clock back. It is one date, it only ever moves forward, and it can only ever end a trial sooner.
  2. Which of the two trial reminders have already been shown, so neither appears twice.

Neither identifies you, neither leaves the device, and deleting Sonari deletes both.

What Apple tells me

Apple gives every developer sales and payment reports: how many copies sold, in which countries and regions, and the money owed. They are counts, not customers. I am not told who bought Sonari, and there is no way for me to ask. Apple's own handling of your purchase is covered by Apple's privacy policy.

Refunds and Family Sharing

A refund is Apple's decision. Sonari can open the request for you, and learns the outcome only in the sense that a refunded purchase stops unlocking the app.

Sonari can be shared with your family group. Nothing about the other people in that group reaches Sonari: the app is told that this Mac may play, and not who is playing on it.


Children

Sonari is a musical instrument, suitable for any age, and is not directed at children. It collects nothing from anyone, and that includes children. It asks for no birthdate, no parental contact and no personal information of any kind, because it has no use for any.

If you are a parent and want the camera or microphone unavailable to Sonari, macOS Screen Time controls that at the system level, and Sonari has no way to override it.


Security

There is no database to breach and no account to compromise, which removes most of what a privacy policy usually has to promise about. What is left:

  • Your files stay yours. Sonari's data lives inside your user account, under macOS file protections, and trust material is written with owner-only permissions.
  • The link to your iPhone is encrypted end to end, with keys generated on your devices that never leave them.
  • Each app asks the system for four things, and nothing else. Sonari for Mac asks for the camera, the microphone, screen recording and your local network. Sonari Remote asks for the camera, the microphone, your local network, and motion, which is how tilting, turning and moving the iPhone becomes musical expression. Sonari Remote and the App Store build of Sonari also run inside Apple's sandbox; the directly downloaded Mac build runs under the hardened runtime instead, and asks for exactly the same four things as the App Store one.
  • Neither app loads code from the internet. What you installed is what runs.

No system is perfect, and I will not claim otherwise. What I can say is that the usual thing that goes wrong, a server holding many people's data, does not exist here.


How long anything is kept, and how to delete it

By me: nothing, for no time at all. I hold no copy of anything of yours, so there is no retention period to state and nothing for me to delete.

On your devices: your work stays until you delete it, because it is yours.

To deleteDo this
One recording, style or scaleDelete it inside Sonari
The performance journalSettings, then Recording, then Purge
Everything Sonari has storedDelete ~/Library/Application Support/Sonari/
The app and all of its settingsDrag Sonari to the Trash, then delete the folder above
The pairing with your iPhoneUnpair in Settings, or delete Sonari Remote

Deleting the app does not cancel anything, because there is nothing running to cancel. Your purchase stays with your Apple Account, so installing Sonari again later does not mean buying it again.


Consent, and taking it back

Sonari for Mac asks for the camera, the microphone, screen recording and your local network. Sonari Remote asks for the camera, the microphone, your local network and motion. Every one of them is asked for through the operating system, one at a time, at the moment it is first needed, and each with a sentence saying what it is for.

You can withdraw any of them at any time in System Settings, then Privacy and Security. Sonari does not treat that as a fault: it keeps working with whatever is left, tells you plainly what has stopped, and offers a way back if you change your mind. Refusing everything still leaves a usable instrument driven by MIDI or by your iPhone.

There is no separate consent for data processing, because there is no data processing to consent to.


Your rights

Data protection law gives you rights over personal information an organisation holds about you. This includes the GDPR in the European Economic Area, the UK GDPR, the CCPA and CPRA in California, and the Digital Personal Data Protection Act, 2023 in India.

Those rights are the rights to know, to access, to correct, to export, to delete, to restrict processing, to object, and not to be discriminated against for exercising any of them.

I hold none of your personal information, so:

  • There is nothing to disclose, because nothing has been collected.
  • There is nothing to correct, export or delete on my side.
  • Nothing has been sold or shared, so there is nothing to opt out of.
  • No automated decision is made about you, and no profiling is performed.
  • Everything Sonari knows about you is a file on your own device, which you can read, copy, move or delete yourself at any moment, without asking me.

If you want this confirmed in writing for a compliance process, a data subject access request, or your own records, write to contact@playsonari.com and you will get a written answer. You do not need to prove anything or create anything to ask.

If you believe your rights have not been respected, you can complain to your data protection authority: your national authority in the EEA, the Information Commissioner's Office in the UK, or the Data Protection Board of India.


Sharing, and third parties

The applications share nothing, with anyone, for any purpose. Neither app contains third-party code, so there is no embedded SDK collecting anything on somebody else's behalf, and there is nothing collected for one to collect.

Two companies are involved in Sonari at all, and here is the whole list.

Apple distributes both applications and takes payment for them. That relationship is between you and Apple and is governed by Apple's own privacy policy. I receive no personal information from it: not your name, not your address, not your card.

Vercel Inc. hosts this website. Their servers answer every request for a page, and they also do the visit counting described under This website above. That makes them a processor for the website and only for the website: they see nothing from either application except the ordinary file requests the Mac makes for the sound pack catalogue, which carry nothing about you.

There is no advertising partner and no data broker, for either the applications or the website, and there never will be.


International transfers

From the applications, none occur. Information that never leaves your device cannot cross a border, and nothing you play, record or sample ever leaves it.

The sound pack downloads described above are ordinary file requests to a public host and carry nothing personal, so there is no personal data in transit to transfer.

From the website, yes, and it is worth being plain about. This site is hosted in the United States by Vercel Inc., so a request from anywhere else in the world reaches a server there, and the address it came from is recorded in that server's ordinary logs. If you are reading this in the United Kingdom or the European Union, that is a transfer, and it is unavoidable for a site hosted where this one is. Nothing about it identifies you by name, because nothing that would is ever asked for.


Changes to this policy

If this policy changes, the date at the top changes with it, and the updated text appears inside both apps in the next release as well as on the web.

A change that made Sonari collect something would be a change to the product, not only to this page. It would be described here in the same plain terms as everything else, and it would ask for your agreement first rather than announce itself afterwards.


Contact

Questions about this policy, about anything in it, or a request you would like in writing:

contact@playsonari.com


Apple, Mac, macOS, iPhone and Neural Engine are trademarks of Apple Inc., registered in the U.S. and other countries and regions.