Sonder (the "App") is developed and operated by an independent developer. We are the data controller for the information described here, and we are responsible for it under the laws that apply to us. You can reach us at support@sonder.app.
When you use camera translation, text translation, voice conversation, or the culture assistant, the App sends the following to our server: the photo you capture or select, the text you type, the audio you record, and the language you asked for. We call this Submitted Content.
We use Submitted Content for one purpose only: to produce the translation and explanation you asked for. Our server holds it in memory while the request is being processed and does not write it to persistent storage. Once the result has been returned, the copy on our server is discarded.
To operate the service, enforce the free usage limit, and protect against abuse, our server and our infrastructure provider record limited technical data with each request:
| What | Why | Retention |
|---|---|---|
| A random device identifier generated by the App | Counting how many free requests this device has made today; applying a cached result. | Rolling daily counters are deleted after 24 hours. The identifier itself stays on your device and is regenerated if you reinstall the App. |
| The IP address your request came from, and standard request metadata (time, endpoint, approximate region, error codes) | Delivering the response, rate limiting, diagnosing faults, and blocking abuse. | Up to 30 days as infrastructure log data, then deleted. |
| App and iOS version, device model, and interface language | Compatibility, crash diagnosis, and serving the correct interface language. | Up to 30 days. |
| A one-way hash of the submitted photo or text | Recognising a repeat request so we can return a cached result instead of calling the AI provider again — this is what makes repeat lookups instant. | Cached results are deleted after 24 hours. The hash cannot be reversed to reconstruct your photo or text. |
The device identifier is not an advertising identifier and is not used to build a profile of you. We do not collect your precise location, your contacts, your photo library beyond the specific image you choose, your health data, or your advertising identifier. We do not run third-party analytics or advertising SDKs.
Subscriptions and other in-app purchases are processed by Apple. We never see or store your payment card details. We receive only a confirmation that a purchase is active, tied to your Apple account, so the App can unlock the features you paid for. Apple's handling of that transaction is governed by Apple's Privacy Policy.
Translation history, saved phrases, settings, and your language preferences are stored locally on your device. They are not uploaded to us. Deleting the App removes them.
You can withdraw any of these permissions at any time in iOS Settings; the corresponding feature will simply stop working.
Where the GDPR applies, we rely on the following legal bases:
We work with a small number of third-party categories. For each of them, we require the recipient to provide the same or equal protection of your information as described in this policy, and to use it only to deliver the service you asked for:
| Recipient | What it receives | Purpose |
|---|---|---|
| Third-party AI model providers | Submitted Content — the photo, text, or transcribed speech, plus the target language. | Performing the actual translation and explanation. These providers act as our data processors and process this content outside your country. |
| Cloud infrastructure and hosting providers | IP address and standard request metadata; transient access to Submitted Content while a request is routed. | Hosting and operating the API that the App talks to. |
| Apple | Purchase records, and any content you send us by email or in a review. | Processing in-app purchases; distributing the App. |
We may also disclose information if we are legally required to do so, or where necessary to protect the rights, safety, or property of any person. If we are ever involved in a merger or acquisition, information may transfer as part of that transaction; we would tell you before your information became subject to a different privacy policy.
We do not sell your personal information, and we do not share it for cross-context behavioural advertising.
Traffic between the App and our server is encrypted with TLS. Access to our production systems is restricted to the developer, and API credentials are held as encrypted secrets rather than in the App binary where they would be extractable. Translation caches are keyed by a one-way hash rather than by your content. No system is perfectly secure, but we have deliberately kept the amount of data we hold small — the strongest protection available is not retaining what we do not need.
Depending on where you live, you may have the right to know what information we hold about you, to access it, to correct it, to delete it, to restrict or object to its processing, to receive it in a portable format, and to complain to your local supervisory authority. Under California law you also have the right to opt out of the sale or sharing of personal information — and, as stated above, we do not sell or share it in the first place.
The App is not directed to children and is not intended for use by anyone under 13 (or the minimum age of digital consent in your country, if higher). We do not knowingly collect personal information from children. If you believe a child has used the App in a way that provided us with personal information, contact us and we will delete it.
If we change how the App handles information, we will update this page and revise the date at the top. For a material change — for example, if we ever began storing Submitted Content — we would give clear notice inside the App before the change took effect, and where required we would ask for your consent first.
Questions, requests, or complaints about privacy: support@sonder.app.
Sonder(以下称"本 App")由独立开发者开发和运营。就本政策所述的信息而言,我们是个人信息处理者, 并在适用法律范围内对其负责。联系方式:support@sonder.app。
当你使用拍照翻译、文本翻译、语音对话或文化助手时,本 App 会将以下内容发送至我们的服务器:你拍摄 或选取的照片、输入的文字、录制的音频,以及你选择的目标语言。以下统称「提交内容」。
我们处理提交内容只有一个目的:生成你所需要的译文和说明。服务器在处理请求期间在 内存中暂存该内容,不写入持久化存储;结果返回后,服务器上的副本即被丢弃。
为运行服务、执行免费额度限制并防范滥用,我们的服务器及基础设施提供方会随每次请求记录有限的技 术数据:
| 信息 | 用途 | 保存期限 |
|---|---|---|
| 本 App 生成的随机设备标识 | 统计该设备当日的免费请求次数;命中缓存结果。 | 每日计数在 24 小时后删除。该标识本身保存在你的设备上,重装 App 后会重新生成。 |
| 请求来源的 IP 地址及标准请求元数据(时间、接口、大致区域、错误码) | 返回响应、限流、故障排查、拦截滥用。 | 作为基础设施日志最多保留 30 天,之后删除。 |
| App 与 iOS 版本、设备型号、界面语言 | 兼容性处理、崩溃排查、以正确语言呈现界面。 | 最多 30 天。 |
| 提交照片或文本的单向哈希值 | 识别重复请求,从而直接返回缓存结果而不必再次调用 AI 服务商——这也是重复查询能做到秒开的原因。 | 缓存结果在 24 小时后删除。该哈希值无法反推出你的照片或文字。 |
设备标识不是广告标识,也不会被用于建立你的个人画像。我们不会收集你的精确位置、 通讯录、相册(仅限你主动选择的那一张图片)、健康数据或广告标识符。本 App 不接入第三方统计或广告 SDK。
订阅及其他 App 内购买由 Apple 处理。我们不会接触或存储你的支付卡信息,仅会收到"某笔购买当前有效" 的确认结果(与你的 Apple 账户关联),以便为你解锁已付费的功能。Apple 对该交易的处理适用 Apple 隐私政策。
翻译历史、收藏的常用语、设置项及语言偏好保存在你的设备本地,不会上传给我们。删除 App 即会同时 清除这些数据。
你可以随时在 iOS「设置」中撤回上述任一权限,对应功能将随之停止工作。
在 GDPR 适用的范围内,我们依据以下合法性基础处理信息:
我们与数量有限的几类第三方合作。对每一类接收方,我们都要求其提供与本政策所述同等或 等同的信息保护,并且仅将其用于交付你所请求的服务:
| 接收方 | 接收内容 | 用途 |
|---|---|---|
| 第三方 AI 模型服务商 | 提交内容——照片、文字或转写后的语音,以及目标语言。 | 实际执行翻译与解释。该等服务商作为我们的受托处理者,在你所在国家/地区之外处理这些内容。 |
| 云基础设施与托管服务商 | IP 地址与标准请求元数据;请求路由期间对提交内容的瞬时访问。 | 托管并运行本 App 所连接的接口服务。 |
| Apple | 购买记录,以及你通过邮件或评论主动发送给我们的内容。 | 处理 App 内购买;分发本 App。 |
如果法律要求,或为保护任何人的人身、权利或财产安全而有必要,我们也可能披露相关信息。若我们未来 涉及合并或收购,信息可能作为交易的一部分随之转移;在你的信息适用另一份隐私政策之前,我们会先行 告知你。
我们不出售你的个人信息,也不会将其用于跨场景行为广告。
App 与服务器之间的传输采用 TLS 加密。生产系统的访问权限仅限开发者本人,接口凭据以加密密钥形式 保管,而非置于可被提取的 App 二进制文件中。翻译缓存以单向哈希为键,而非以你的内容为键。没有任何 系统是绝对安全的,但我们有意将持有的数据量压到最低——最有力的保护,就是不保留我们并不需要的东西。
视你所在地区而定,你可能有权了解我们持有哪些关于你的信息、查阅、更正、删除这些信息,限制或反对 相关处理,以可携带格式获取这些信息,以及向当地监管机构投诉。依据加州法律,你还有权选择退出个人 信息的"出售"或"共享"——而如上所述,我们本就不存在出售或共享行为。
本 App 不面向儿童,也不适用于未满 13 周岁(或你所在地区规定的更高数字同意年龄)的用户。我们不会 在知情的情况下收集儿童的个人信息。如果你认为有儿童在使用本 App 的过程中向我们提供了个人信息,请 联系我们,我们会予以删除。
如果我们变更了本 App 处理信息的方式,我们会更新本页面并修订顶部日期。对于重大变更——例如我们开始 存储提交内容——我们会在变更生效前在本 App 内明确告知;在法律要求的情况下,我们会先征求你的同意。
有关隐私的问题、请求或投诉,请联系:support@sonder.app。