Legal & privacy

Privacy Policy

How Sonixifi, a product of Sonixpace Teknoloji Anonim Şirketi, handles information used to provide and protect the service.

Last changed: July 20, 2026

Who we are and how to contact us

Sonixifi is provided by Sonixpace Teknoloji Anonim Şirketi, Üniversiteler Mah. İhsan Doğramacı Blv. No: 31 İç Kapı No: 20, Çankaya/Ankara, 06800, Türkiye. For privacy questions, data inquiries, or account-deletion support, email sonixifisupport@sonixpace.com. This address is active and regularly monitored.

People in Türkiye should also read the separate KVKK Clarification Notice, which identifies the processing purposes, legal bases, recipient groups, collection methods, transfers, and data-subject rights. The notice is information, not a request for consent. Accepting Terms does not constitute blanket consent to personal-data processing.

Data we process

Sonixifi processes data to provide app functionality, account management, subscriptions, safety, support, reliability, and legal compliance.

CategoryExamplesWhy it is used
Account and profileAuth0 subject, Sonixifi backend account identifier, email, account status, optional profile or display nameAuthentication, account display and management, deletion, support, and abuse prevention
Uploaded imagesImages you select or capture and submit for generationRequested image-to-audio processing, safety validation, and abuse prevention
Generated mediaAudio, stems, video, titles, metadata, previews, and processing artifactsGeneration, playback, saving, sharing, remixing, and support
Purchase and subscriptionGoogle Play product and purchase identifiers, entitlement state, and billing support referencesSubscription activation, entitlement, fraud prevention, support, and required records
Diagnostics and supportRequest identifiers, timestamps, error categories, request metadata, support messages, and deletion recordsReliability, troubleshooting, security, incident response, and support
Safety and moderationAI-content report reason or details, job or media reference, account reference, moderation, abuse-prevention, and security recordsContent safety, moderation, fraud and abuse prevention, legal compliance, and support escalation

Sonixifi does not intentionally collect location, contacts, microphone audio, SMS or call logs, health data, advertising ID, or an inventory of installed apps. Camera access is used only when you choose to capture an image for submission.

How we use data

  • Deliver the image-to-audio and video experience you request.
  • Authenticate users and manage accounts.
  • Verify Google Play subscriptions and entitlement.
  • Detect, review, and respond to prohibited content, fraud, abuse, and security incidents.
  • Provide support, investigate errors, and maintain reliability.
  • Meet legal, accounting, tax, dispute, and compliance obligations.

Service providers and sharing

Sonixifi uses Auth0 by Okta for authentication; Google Play and Google Payments for Android subscription billing; the Google Gemini API for AI-assisted scene analysis and processing; hosting, infrastructure, and private object-storage providers; and support, security, and abuse-prevention services. These providers receive data needed to perform services for Sonixifi, subject to their terms and the Gemini disclosure below. Data may also be disclosed when required for legal compliance, security, fraud prevention, or a corporate transaction with appropriate notice where required.

Sonixifi does not sell personal or sensitive user data.

Security

Sonixifi protects data in transit using HTTPS or equivalent modern cryptography. Accepted image uploads are held in private object storage for processing; raw image bytes are not stored as blobs in the API database. Production, support, log, and evidence access is restricted to authorized personnel and service providers. No system can guarantee absolute security.

Retention and deletion

Sonixifi retains data only as long as needed for app functionality, account management, support, abuse prevention, legal compliance, accounting and tax obligations, dispute resolution, backup recovery, and security. The owner approved the following ordinary schedule on July 19, 2026.

  • Account and profile: while the account is active; delete ordinary account-linked data after a verified deletion request within the documented 30-day completion target.
  • Uploaded images: delete from server storage after the generation job reaches a terminal outcome, subject to a protected moderation, abuse-evidence or legal-hold exception.
  • Generated media, previews and stems: delete from server storage immediately after authenticated device-delivery confirmation or, if delivery cannot be confirmed, no later than 24 hours after the fixed result deadline. On-device copies remain under the user’s control.
  • Purchase and entitlement records held by Sonixifi: while the subscription/account relationship is active, then delete or de-identify within 24 months after the later of subscription end or final billing/support resolution, unless a separately minimized record must be retained for an approved accounting, tax, fraud, chargeback or legal obligation.
  • Ordinary diagnostic and request logs: 90 days. General support and completed account-deletion records: 24 months after closure/completion.
  • Ordinary resolved AI-content reports and moderation records: 24 months after resolution. Confirmed or credibly suspected abuse/security evidence: up to 365 days with review before expiry. IP/device abuse signals: 12 months from the last relevant event.
  • Encrypted recovery backups: a rolling 30-day recovery window, after which copies are overwritten or destroyed. Restored data must have deletion tombstones replayed before normal service resumes.

You may request deletion in the app at Account > Delete account or through the external account-deletion resource. Verified deletion requests are targeted for completion within 30 days. The authenticated deletion flow deletes local backend account data and tracks Auth0 identity cleanup through the Auth0 Management API; temporary provider failures are retained for operator follow-up.

Deletion ordinarily covers the account/profile linkage, owned generation jobs, ordinary private input and result objects, usage records, and entitlement records held by Sonixifi. Limited records may be retained where required or permitted for security, fraud prevention, accounting, tax, legal compliance, chargebacks, disputes, abuse investigations, backup integrity, or legal holds. Where practical, retained audit or report references are de-identified.

Subscription reminder: deleting a Sonixifi account does not cancel a Google Play subscription. Manage subscriptions through Google Play subscriptions.

AI processing, model training, and product improvement

Sonixifi can send normalized uploaded image data and scene-analysis prompts to the Google Gemini API to support user-requested generation. Sonixifi also uses job metadata, moderation events, and AI-content reports for safety, abuse prevention, support, and reliability.

Production Sonixifi processing currently uses unpaid or free-tier Gemini API services. Under the applicable provider terms, submitted content and generated responses may be used by Google to provide, improve, and develop Google products, services, and machine-learning technologies, and human reviewers may process API input and output. Do not submit sensitive or confidential information.

Google Play Data Safety

Sonixifi’s Google Play Data Safety disclosures must remain consistent with this policy, the app’s final permissions and SDKs, Auth0, Google Play Billing, backend storage and deletion, support tooling, safety records, and service-provider processing.

Changes to this policy

We may update this policy when the app, backend behavior, providers, Data Safety answers, support tooling, model-processing use, retention practices, or legal requirements change. The visible “Last changed” date will change when a revision is published.