Sonnet Live
Privacy
Policy
How Sonnet handles your data — from talent livestreams to daily moments to real-person verification.
— Document Details —
Effective DateJune 4, 2025
Version1.0
ScopeGlobal — 18+
LanguageEnglish (controlling)
Contactservice@sonnet.run
Welcome to Sonnet — a global stage where anyone can livestream their talent, share daily moments, or simply enjoy the show as a viewer. Because Sonnet broadcasts real people in real time, we require real-person verification — a liveness check confirming you're an actual human, without collecting any identity documents — before you can go live or post your own moments. Watching public streams doesn't require verification. This Privacy Policy ("Policy") describes how Sonnet ("we," "our," or "us") collects, uses, stores, shares, and protects your personal information when you use our mobile application and all related services (the "Service"). By using Sonnet, you agree to this Policy. If you do not agree, please discontinue use of the Service.
01
Information We Collect
1.1 — Account & Profile Information

When you create a Sonnet account, we collect the information you voluntarily provide: your display name, email address, date of birth (to verify you are 18 years of age or older), profile photo, country of residence, talent category or interests, and any personal bio you choose to write. If you register via Apple Sign-In or Google, we receive a limited profile dataset authorized by you and that provider.

1.2 — Real-Person Verification Data

To go live or post Moments, you must complete a liveness check confirming you are a real person. This involves a brief live camera capture (such as following on-screen prompts) processed to detect liveness. See Section 3 for full details.

1.3 — Livestream Data

When you broadcast, we collect livestream video and audio, stream titles and descriptions, thumbnail images, viewer counts, and chat/comment activity during your streams. See Section 4 for full details.

1.4 — Moments Data

When you post a Moment (a short update or clip sharing your day or talent), we collect the photo, video, or text content, captions, and any tags you add. See Section 5 for full details.

1.5 — Viewer Activity

Even without completing verification, viewers generate activity data: streams watched, comments posted, likes given, follows, and gifts sent, associated with a registered account. See Section 6 for details on viewer access.

1.6 — Device & Technical Information

We automatically collect device model, operating system version, unique device identifiers, IP address, mobile carrier, app version, crash logs, and performance diagnostics to maintain service quality, support live video delivery, and diagnose technical issues.

1.7 — Usage & Behavioral Data

We record how you use the Service: streams watched, categories browsed, search queries, and session frequency and duration. This data informs product improvements and optional personalization.

1.8 — Communications & Support Data

If you contact our support team, submit a report, or participate in surveys, we retain the content and metadata of those communications for resolution and service improvement purposes.

1.9 — Payment & Transaction Data

All payments are processed exclusively by Apple App Store or Google Play. We do not store your payment card details. We receive only anonymized transaction confirmation tokens and purchase entitlement data for virtual gifts and premium features.

02
How We Use Your Data
2.1 — Operating the Service

We use your information to authenticate your account, deliver livestreaming and Moments features, distribute live video to viewers, operate community features, enforce content policies, process purchases, and provide all core Service functions.

2.2 — Real-Person Verification

We use liveness check results to confirm that broadcasters and Moment-posters are real, unique humans before granting access to those features, and to detect fraudulent or automated (bot) accounts. See Section 3.

2.3 — Livestream Delivery

Your stream video and audio are processed and distributed in real time to viewers, recorded for optional replay if you enable that setting, and used to generate thumbnails and highlight clips where applicable.

2.4 — Community & Discovery

Your public streams and Moments populate community feeds and enable discovery by other users, including recommendation surfaces based on category and popularity.

2.5 — Personalization

Your viewing history, follows, and engagement signals are used to personalize which streams and Moments are recommended to you. See Section 9 for details.

2.6 — Safety & Platform Integrity

We process behavioral signals, verification status, and user reports to detect and prevent prohibited content, harassment, impersonation, and policy violations, including during live broadcasts.

2.7 — Product Improvement

Aggregated and de-identified usage data is analyzed to improve stream quality, recommendation accuracy, and overall platform performance.

2.8 — Marketing & Communications

With your consent where required by applicable law, we may send promotional communications about featured talent, new features, and platform offers. You may withdraw consent at any time via in-app settings or the unsubscribe link in any email.

2.9 — Legal Compliance

We process personal data as necessary to comply with applicable laws, respond to valid legal process, enforce our Terms of Service, and protect the safety of our users and the public.

03
Real-Person Verification
3.1 — Why Verification Is Required

Sonnet broadcasts real people to a real audience in real time. To protect the authenticity and safety of the community, you must complete a liveness check before you can go live or post Moments. Watching public streams as a viewer does not require verification.

3.2 — What We Collect

The verification flow uses your device camera to capture a brief live sequence (for example, following on-screen prompts such as turning your head or blinking) solely to determine liveness — that a real, present human is completing the check. We do not collect a government ID, name-matching data, or any other identity document as part of this process.

3.3 — No Identity Matching
Sonnet's real-person verification is a liveness-only check. We do not compare your face against a photo ID, government database, or any external record, and we do not determine or store your legal identity through this process. It confirms only that a live human completed the check at that moment.
3.4 — Biometric Data Treatment

The liveness check involves processing of facial imagery, which may be treated as a special category of personal data under laws such as the EU/UK GDPR, or as "sensitive personal information" under laws such as the CCPA/CPRA. Where required, we obtain your explicit, opt-in consent before performing the check. You may decline verification; declining means you will not be able to go live or post Moments, but you may continue to use Sonnet as a viewer.

3.5 — Retention of Verification Data

Raw liveness-check video/images are processed transiently and deleted within 7 days of a successful check. We retain only the resulting verification status (verified/not verified) associated with your account thereafter, not the underlying footage.

3.6 — Re-Verification

We may require re-verification periodically or if we detect signals suggesting your account may be compromised, automated, or associated with suspicious activity.

3.7 — Consequences of Declining or Failing Verification

If you decline verification or do not pass it, you will not be able to broadcast or post Moments. Viewing public content and using core viewer features remain available regardless of verification status.

04
Livestreaming Data
4.1 — Live Broadcast Processing

When you go live, your video and audio are transmitted through our infrastructure to viewers in real time. Streams may be temporarily buffered or cached to support smooth playback and, where you opt in, recorded for replay.

4.2 — Optional Recording & Replay

You may choose whether your livestreams are saved as replays viewable after the broadcast ends. If you do not opt in, streams are not retained beyond the technical buffering necessary for live delivery and safety review.

4.3 — Live Moderation

Livestreams are subject to real-time and post-broadcast content moderation, including automated detection systems and human review, to enforce our Community Guidelines. See Section 8 for details.

4.4 — Chat & Viewer Interaction Data

Comments, reactions, and gifts sent during a livestream are associated with the sending account and visible to the broadcaster and other viewers of that stream, subject to your privacy settings.

05
Daily Moments
5.1 — What Moments Are

Moments are short photo, video, or text updates you share to give followers a glimpse of your day or talent journey between livestreams.

5.2 — Verification Required Before Posting

You must complete real-person verification (Section 3) before your account can publish Moments publicly. This helps ensure that content on Sonnet comes from real community members.

5.3 — Visibility & Expiry

Moments may be set to Public, Followers Only, or Private, and may be configured to automatically expire after a set period if that feature is enabled. You may delete a Moment manually at any time regardless of any expiry setting.

5.4 — Content Standards

Moments remain subject to our Community Guidelines and content moderation described in Section 8 of the Terms of Service.

06
Viewer Mode
6.1 — Watching Without Verification

You do not need to complete real-person verification to browse and watch public livestreams and Moments. Verification is required only to broadcast or post your own content.

6.2 — Account Required for Interaction

While watching does not require verification, a registered account is required to comment, like, follow, or send gifts. Standard account information described in Section 1.1 applies to registered viewer accounts.

6.3 — Viewer Data Use

Viewing history, engagement, and gifting activity are used to personalize your discovery feed and are not sold to third parties. See Section 9 for personalization details.

07
User-Generated Content
7.1 — Collection & Storage

Livestreams (where recorded), Moments, comments, and other content you publish publicly constitute User-Generated Content (UGC). UGC is stored on our secure cloud servers associated with your account.

7.2 — License Grant

By publishing UGC publicly on Sonnet, you grant us a non-exclusive, worldwide, royalty-free, sublicensable license to host, store, reproduce, display, and distribute your content within the Service and in connection with promoting Sonnet, subject to your visibility settings. You retain full ownership of your original content.

7.3 — Content Moderation

Community-shared UGC, including live broadcasts, is subject to automated screening and human review for compliance with our Community Guidelines. Content that violates our policies will be removed, and responsible accounts may face suspension or termination.

7.4 — Content Deletion

You may delete any published Moment, replay, or UGC at any time. Deleted content is removed from public view within 48 hours, from production servers within 30 days, and from backup archives within 90 days.

08
Community Features
8.1 — Discovery Feed

Public streams and Moments appear in Sonnet's discovery feed for other users to find. Public entries include your display name, profile photo, and the shared content.

8.2 — Comments & Gifts

Other users may comment on or send virtual gifts during your streams or on your Moments. This activity is associated with the sender's display name and is visible to relevant viewers. You may moderate and delete comments on your own content at any time.

8.3 — Following

You may follow other creators whose talent or content resonates with you. Follower relationships are visible in your profile activity unless you set your profile to private.

8.4 — Reporting & Blocking

You may report or block any user, stream, or content at any time. Reports are reviewed by our safety team, and your identity as the reporting user is kept confidential from the reported party.

09
Personalization Engine
9.1 — How It Works

Sonnet uses your viewing history, follows, gifting activity, and engagement signals to personalize which streams, creators, and Moments are surfaced in your discovery feed.

9.2 — No External Advertising Use

Your viewing and interaction data are not used to build an advertising profile or shared with third-party advertising networks for behavioral targeting without your explicit consent.

9.3 — Opting Out

You may disable personalized recommendations at any time in Settings > Privacy > Personalization. Sonnet will then present a non-personalized, editorially curated discovery feed.

10
Sharing & Disclosure
10.1 — Service Providers

We share personal information with trusted third-party service providers supporting our operations: cloud infrastructure and live-video delivery (CDN) providers, payment processors, analytics platforms, customer support tools, and content moderation systems. All providers are contractually bound to process your data only on our instructions and in compliance with applicable data protection law.

10.2 — No Sale of Personal Data

We do not sell your personal information, verification data, or viewing history to any third party, including advertisers or data brokers.

10.3 — Business Transfers

In the event of a merger, acquisition, or asset sale, your data may transfer to the acquiring entity. We will notify you in advance before your data becomes subject to a materially different privacy policy, giving you the opportunity to request account deletion.

10.4 — Legal Disclosure

We may disclose your information to law enforcement or government authorities when required by applicable law, valid legal process, or where necessary to protect the safety of any person. Where legally permitted, we will notify affected users prior to such disclosure.

10.5 — Publicly Visible Content

Your display name, profile photo, and public streams and Moments are visible to all Sonnet users. You may adjust visibility in account settings.

11
Third-Party Services & SDKs
11.1 — Live Video Infrastructure

We use third-party live-streaming and CDN infrastructure to transmit and distribute your broadcasts to viewers with low latency. These providers process video and audio data as technical intermediaries under data processing agreements.

11.2 — Analytics SDKs

Mobile analytics SDKs measure app performance and feature engagement, configured with privacy-preserving settings including anonymized event collection and suppression of advertising identifiers absent your consent.

11.3 — Cloud Storage & CDN

Moments, thumbnails, and optional stream replays are stored on cloud infrastructure and delivered via CDN providers, under data processing agreements.

11.4 — Authentication Providers

Apple Sign-In and Google authentication are governed by their own terms and privacy policies. Our use of data from these services is limited to account creation and basic profile population.

12
Data Retention
12.1 — Active Account Data

We retain your personal information for as long as your account is active. Accounts with no login activity for 24 consecutive months will receive a dormancy notice; following the notice period, inactive data may be anonymized or deleted.

12.2 — Verification Data

As described in Section 3.5, raw liveness-check footage is deleted within 7 days of a successful check. Only the resulting verification status is retained thereafter.

12.3 — Streams & Moments

Where you opt in to recording, stream replays and published Moments are retained for the life of your account or until you delete them. Non-recorded live streams are not retained beyond technical buffering.

12.4 — Transaction Records

Financial transaction records, including virtual gift purchases, are retained for a minimum of seven years to comply with applicable accounting, tax, and consumer protection obligations.

12.5 — Safety & Moderation Records

Records of content moderation actions, user reports, and enforcement decisions are retained for up to 36 months after account closure.

13
Data Security
13.1 — Technical Safeguards

We implement TLS 1.2+ encryption for all data in transit, AES-256 encryption for sensitive data at rest, strict role-based access controls, and automated anomaly detection.

13.2 — Organizational Safeguards

Data access is restricted on a need-to-know basis, requires multi-factor authentication, and is comprehensively audit-logged. Personnel with access to verification data receive specialized training and sign confidentiality agreements.

13.3 — Vulnerability Management

We conduct regular security assessments and third-party penetration testing. Report security vulnerabilities responsibly to service@sonnet.run.

13.4 — Breach Notification

In the event of a personal data breach posing risk to your rights and freedoms, we will notify relevant supervisory authorities within 72 hours where required by law and inform affected users without undue delay.

14
Tracking Technologies
14.1 — In-App Technologies

Sonnet uses session tokens, local storage, and analytics SDKs (not traditional browser cookies) to maintain your authenticated session, remember preferences, and support live streaming delivery.

14.2 — Advertising Identifiers

On iOS, we request ATT consent before accessing your IDFA. On Android, we respect your opt-out via device advertising settings. Advertising identifiers are used only to measure our own user acquisition campaigns.

14.3 — Web Properties

Our website may use standard browser cookies for session management and analytics, manageable via your browser settings.

15
Cross-Border Transfers
15.1 — Global Infrastructure

Sonnet serves a global community and operates cloud and live-video infrastructure across multiple regions to minimize streaming latency. Your personal data may be transferred to and processed in countries other than your country of residence.

15.2 — Transfer Safeguards

For transfers from the EEA, UK, or Switzerland to countries lacking an adequacy decision, we rely on EU Standard Contractual Clauses (SCCs) and, where applicable, the UK International Data Transfer Addendum (IDTA). Equivalent safeguards apply to other cross-border transfers.

15.3 — Data Localization

Where applicable national laws impose mandatory data localization requirements, we take reasonable steps to store and process the required data categories within the mandated territory.

16
Your Privacy Rights
16.1 — Access

Request a copy of personal data we hold, including your verification status and content history, via in-app settings or by emailing service@sonnet.run with subject "Data Access Request."

16.2 — Rectification

Correct inaccurate personal information directly in account settings. For data that cannot be self-corrected, contact us and we will action the correction within 30 days.

16.3 — Erasure

Request deletion via Settings > Account > Delete Account or by emailing us. See Section 22 for full account deletion details.

16.4 — Portability

Request your content and personal data in a structured, machine-readable format suitable for personal archiving or transfer to another platform.

16.5 — Objection & Restriction

Object to or request restriction of processing in certain circumstances, including processing related to verification. We pause relevant processing while assessing your objection.

16.6 — Consent Withdrawal

Withdraw consent for real-person verification, marketing, or personalization at any time via in-app settings or by contacting us. Withdrawing verification consent will disable broadcasting and Moments posting going forward.

16.7 — How to Submit

Email service@sonnet.run with "Privacy Rights Request" in the subject, your registered email, and a description of your request. We verify your identity and respond within applicable legal timeframes.

17
GDPR — EEA & UK Users
17.1 — Data Controller

For EEA and UK users, Sonnet acts as the data controller of your personal information under the GDPR and UK GDPR respectively.

17.2 — Legal Bases

We process your data under: (a) contractual necessity (to provide the Service); (b) legal obligation (regulatory compliance); (c) legitimate interests (safety, service improvement, fraud prevention), where not overridden by your rights; and (d) consent (for marketing, optional personalization, and real-person verification, which involves special category biometric-adjacent data under Article 9 and requires your explicit consent).

17.3 — Supervisory Authority

You may lodge a complaint with your national data protection supervisory authority if you believe your data has not been handled lawfully. We encourage you to contact us first to attempt direct resolution.

18
CCPA / CPRA — California
18.1 — California Rights

California residents have rights under the CCPA as amended by the CPRA, including the right to know, delete, correct, and opt out of the sale or sharing of personal information, and additional rights regarding sensitive personal information (which may include your liveness-check data). Sonnet does not sell personal information and does not share it for cross-context behavioral advertising.

18.2 — Non-Discrimination

Exercising your California privacy rights will not result in denial of services, different pricing, or reduced quality of experience.

18.3 — Authorized Agents

California residents may designate an authorized agent by providing written proof of authorization. We verify both agent and resident identity before processing any request.

19
Brazil — LGPD
19.1 — Rights Under LGPD

Brazilian users have rights under the Lei Geral de Proteção de Dados (LGPD) including confirmation, access, correction, anonymization, deletion, portability, and withdrawal of consent — including consent for the processing of sensitive personal data under Article 11, such as liveness-check data.

19.2 — Legal Bases

We process Brazilian users' data based on contract performance, legal obligation, and consent where applicable, including explicit consent for real-person verification.

19.3 — ANPD Complaints

Brazilian users may lodge complaints with the Autoridade Nacional de Proteção de Dados (ANPD) where they believe data processing violates the LGPD.

20
Children's Privacy & CSAE Policy
20.1 — Age Restriction

Sonnet is designed for users who are 18 years of age or older. We implement date-of-birth verification at registration, and our real-person liveness check provides an additional safeguard for broadcasting and Moments. Confirmed underage accounts are immediately and permanently terminated with all associated data deleted.

20.2 — Parental Notification

If you are a parent or guardian and believe a minor has created a Sonnet account, contact us immediately at service@sonnet.run. We will investigate and, where confirmed, permanently delete the account and all associated data without delay.

20.3 — Child Sexual Abuse and Exploitation (CSAE)
Zero tolerance — absolute and without exception. Sonnet enforces an unconditional zero-tolerance policy toward any content, conduct, or activity that constitutes, facilitates, promotes, or glorifies Child Sexual Abuse and Exploitation (CSAE) in any form. Prohibited conduct includes without limitation: child sexual abuse material (CSAM); grooming, solicitation, or exploitation of individuals under 18; and any content depicting, targeting, or endangering persons under 18 — including during live broadcasts.

We deploy automated CSAM hash-matching on uploaded and recorded media, AI-assisted content analysis (including real-time signals during livestreams) and dedicated human safety reviewers. Upon confirmed detection or credible report: all associated content is immediately and permanently removed, live broadcasts are terminated instantly; the responsible account is permanently terminated and all associated identifiers are blocked; a mandatory report is filed with the NCMEC CyberTipline or the legally required equivalent national authority; and we cooperate fully with all resulting law enforcement investigations. CSAE-related terminations carry no right of appeal.

To report: use the in-app Report function on any content, stream, or user profile, or email service@sonnet.run immediately with subject "CSAE Report."
21
In-App Purchases & Gifts
21.1 — Payment Processing

All in-app purchases, including virtual currency used for gifts, are processed exclusively through Apple App Store or Google Play. Sonnet does not store your payment card details. We receive only anonymized transaction confirmation tokens and entitlement data.

21.2 — Virtual Gifts

Virtual gifts sent to broadcasters during livestreams are recorded as part of your activity data and the recipient's earnings data, where applicable. Gift-sending activity may be visible to the broadcaster and other viewers of the relevant stream.

21.3 — Transaction Records

Transaction records are retained for a minimum of seven years to satisfy applicable accounting, tax, and consumer protection requirements.

22
Account Deletion & Data Erasure
22.1 — How to Delete

Delete your account at any time via Settings > Account > Delete Account, or by emailing service@sonnet.run with subject "Account Deletion Request."

22.2 — What Is Deleted

Your profile, Moments, stream replays, community posts, and all associated data are removed from public view within 48 hours and from production servers within 30 days. Backup archives are purged within 90 days of the next scheduled rotation. Any residual verification footage (already subject to the 7-day deletion in Section 3.5) is confirmed deleted if not already removed.

22.3 — Export Before Deletion
We encourage you to export your Moments and content before deleting your account, as deletion is permanent. You can export your data from Settings > Data > Export.
22.4 — Retained Data

Certain data is retained where required by law: transaction records (up to 7 years); safety and moderation records (up to 3 years); data subject to a legal hold. All retained data is isolated and processed only for the specific legal purpose requiring its retention.

23
Face Data Collection, Use, and Protection
23.1 — Purpose and Method of Collection

To ensure user safety and authentic identity verification, our app provides a real-person verification feature. For this purpose, the app accesses two temporary facial images: one photo uploaded by the user and one live selfie captured via the camera. These two images are compared strictly to confirm that the account owner is a real person.

23.2 — Storage and Non-Retention

We do not store any face data, facial recognition templates, or biometric features on our remote servers or on the user's local device. Facial images are processed temporarily in volatile memory solely for the instantaneous 1:1 comparison.

23.3 — Immediate Deletion

Immediately upon completion of the comparison process (whether verification succeeds or fails), all facial data and temporary memory caches are permanently destroyed and erased. No historical face data is retained.

23.4 — Third-Party Sharing and Disclosure

We do not sell, share, transfer, or disclose any face data to third parties, advertising networks, analytics providers, or external partners under any circumstances.

24
Policy Updates
24.1 — Notification

Material changes are communicated at least 14 days before taking effect via in-app notice, push notification, and/or email to your registered address. Non-material corrections may be made without advance notice.

24.2 — Continued Use

Continued use of Sonnet after any revised Policy's effective date constitutes acceptance. If you do not agree, delete your account before the changes take effect.

24.3 — Version Archive

Prior versions are available upon request at service@sonnet.run.

25
Contact Us
25.1 — Privacy Inquiries

For questions, data rights requests, or privacy concerns:

We acknowledge inquiries within 5 business days and respond within 30 days.

25.2 — CSAE & Child Safety Reports

Use the in-app Report function on any content, stream, or user profile, or email service@sonnet.run immediately with subject "CSAE Report." These are our highest-priority safety matter, actioned without delay.

© 2026 Sonnet. All rights reserved. Privacy Policy · Version 1.0 · August 3, 2026