SSonder

Privacy Policy

Effective date: September 10, 2026 · Last updated: September 10, 2026

Sonder is a travel translation app: point your camera at a menu, sign, or medicine box and get a translation and a short explanation. This policy explains what information the app handles, why, where it goes, and what you can do about it.

1. The short version

2. Who we are

Sonder (the "App") is developed and operated by an independent developer. We are the data controller for the information described here, and we are responsible for it under the laws that apply to us. You can reach us at support@sonder.app.

3. What we handle, and why

3.1 Content you actively submit

When you use camera translation, text translation, voice conversation, or the culture assistant, the App sends the following to our server: the photo you capture or select, the text you type, the audio you record, and the language you asked for. We call this Submitted Content.

We use Submitted Content for one purpose only: to produce the translation and explanation you asked for. Our server holds it in memory while the request is being processed and does not write it to persistent storage. Once the result has been returned, the copy on our server is discarded.

The important part: to produce a translation, Submitted Content is transmitted to a third-party AI provider (see Section 5). We do not store it, but that provider receives and processes it under its own terms. If you do not want a photo, recording, or block of text to reach a third party, please do not submit it.

3.2 Information collected automatically

To operate the service, enforce the free usage limit, and protect against abuse, our server and our infrastructure provider record limited technical data with each request:

WhatWhyRetention
A random device identifier generated by the App Counting how many free requests this device has made today; applying a cached result. Rolling daily counters are deleted after 24 hours. The identifier itself stays on your device and is regenerated if you reinstall the App.
The IP address your request came from, and standard request metadata (time, endpoint, approximate region, error codes) Delivering the response, rate limiting, diagnosing faults, and blocking abuse. Up to 30 days as infrastructure log data, then deleted.
App and iOS version, device model, and interface language Compatibility, crash diagnosis, and serving the correct interface language. Up to 30 days.
A one-way hash of the submitted photo or text Recognising a repeat request so we can return a cached result instead of calling the AI provider again — this is what makes repeat lookups instant. Cached results are deleted after 24 hours. The hash cannot be reversed to reconstruct your photo or text.

The device identifier is not an advertising identifier and is not used to build a profile of you. We do not collect your precise location, your contacts, your photo library beyond the specific image you choose, your health data, or your advertising identifier. We do not run third-party analytics or advertising SDKs.

3.3 Purchases

Subscriptions and other in-app purchases are processed by Apple. We never see or store your payment card details. We receive only a confirmation that a purchase is active, tied to your Apple account, so the App can unlock the features you paid for. Apple's handling of that transaction is governed by Apple's Privacy Policy.

3.4 Data stored on your device

Translation history, saved phrases, settings, and your language preferences are stored locally on your device. They are not uploaded to us. Deleting the App removes them.

3.5 Device permissions

You can withdraw any of these permissions at any time in iOS Settings; the corresponding feature will simply stop working.

4. Legal bases (EEA, UK and Switzerland)

Where the GDPR applies, we rely on the following legal bases:

5. Who else is involved

We work with a small number of third-party categories. For each of them, we require the recipient to provide the same or equal protection of your information as described in this policy, and to use it only to deliver the service you asked for:

RecipientWhat it receivesPurpose
Third-party AI model providers Submitted Content — the photo, text, or transcribed speech, plus the target language. Performing the actual translation and explanation. These providers act as our data processors and process this content outside your country.
Cloud infrastructure and hosting providers IP address and standard request metadata; transient access to Submitted Content while a request is routed. Hosting and operating the API that the App talks to.
Apple Purchase records, and any content you send us by email or in a review. Processing in-app purchases; distributing the App.
International transfers. Our servers and all of the providers listed above are located outside your country — predominantly in the United States and the European Union. That means your Submitted Content may be transferred to, stored in, and processed in a jurisdiction whose data protection laws differ from your own. Where required, transfers rely on standard contractual clauses or an equivalent safeguard put in place by the relevant provider.

We may also disclose information if we are legally required to do so, or where necessary to protect the rights, safety, or property of any person. If we are ever involved in a merger or acquisition, information may transfer as part of that transaction; we would tell you before your information became subject to a different privacy policy.

We do not sell your personal information, and we do not share it for cross-context behavioural advertising.

6. How long we keep things

7. How we protect it

Traffic between the App and our server is encrypted with TLS. Access to our production systems is restricted to the developer, and API credentials are held as encrypted secrets rather than in the App binary where they would be extractable. Translation caches are keyed by a one-way hash rather than by your content. No system is perfectly secure, but we have deliberately kept the amount of data we hold small — the strongest protection available is not retaining what we do not need.

8. Your rights

Depending on where you live, you may have the right to know what information we hold about you, to access it, to correct it, to delete it, to restrict or object to its processing, to receive it in a portable format, and to complain to your local supervisory authority. Under California law you also have the right to opt out of the sale or sharing of personal information — and, as stated above, we do not sell or share it in the first place.

An honest note about exercising these rights. Because the App has no account, we cannot identify you from your name or email. What we hold is a random device identifier and short-lived technical logs. We will help you as far as we reasonably can — for example we can delete cached entries or trace a specific request if you can give us the approximate time and describe the content. To make a request, write to support@sonder.app. You also do not need us for most of it: clearing the App's data or deleting the App removes all on-device history immediately.

9. Children

The App is not directed to children and is not intended for use by anyone under 13 (or the minimum age of digital consent in your country, if higher). We do not knowingly collect personal information from children. If you believe a child has used the App in a way that provided us with personal information, contact us and we will delete it.

10. Changes to this policy

If we change how the App handles information, we will update this page and revise the date at the top. For a material change — for example, if we ever began storing Submitted Content — we would give clear notice inside the App before the change took effect, and where required we would ask for your consent first.

11. Contact

Questions, requests, or complaints about privacy: support@sonder.app.