Privacy Policy
Last updated June 26, 2026
This policy explains what information SonoTale collects, how we use it, which parties we share it with, how that sharing happens, and the security measures we take to protect it. SonoTale turns the manuscripts you own into AI-produced audiobooks; protecting your work and your data is core to that.
1. Who we are
SonoTale (“SonoTale”, “we”, “us”) operates the SonoTale website and audiobook-production service at sonotale.com. We are the data controller for the personal data described here, and our service is subject to the EU General Data Protection Regulation (GDPR).
Our registered details:
SonoTale
Nachtegaalstraat 31
6165 BH Geleen, The Netherlands
Chamber of Commerce (KvK): 84956526
You can reach us about privacy at support@sonotale.com.
2. Information we collect
- Account data: your email address and the authentication identifiers used to sign you in.
- Content you provide: the manuscripts and text you upload, book and chapter titles, voice/cast and pronunciation settings, and the audio we generate from your content on your instruction.
- Payment data: when you buy credits, payment is processed by Stripe. We receive a customer reference and transaction metadata (e.g. amount, status, last four digits) — we do not store full card numbers.
- Usage & technical data: render history and credit usage, plus log and diagnostic data such as IP address, device/browser information, and timestamps, used to operate and secure the service.
- Team data: if you invite collaborators to a workspace, the email address and role of each member you add.
- Cookies: a small number of essential, preference, and security cookies (see “Cookies” below).
3. How we use your information
- To provide and operate the service — turning your manuscript into a produced audiobook, storing your projects, and delivering your files.
- To process payments, manage your credit balance, and prevent billing errors.
- To provide customer support and send you transactional messages (e.g. “your chapter is ready”, account and billing notices).
- To keep the service secure — authentication, abuse and fraud prevention, rate limiting, and bot protection.
- To maintain, debug, and improve the service.
- To comply with our legal obligations.
Our legal bases under the GDPR are: performance of our contract with you (providing the service and billing), our legitimate interests (securing and improving the service), your consent where we ask for it, and compliance with legal obligations. We do not use your manuscripts to train general-purpose AI models, and we do not sell your personal data.
4. Which parties we share it with, and how
We share information only with service providers (processors) who help us run SonoTale, each acting on our instructions under a data-processing agreement and receiving only the data needed for their function. We share data with these categories of providers:
- Payment processing — Stripe: to take payment and manage your credit purchases securely.
- Cloud hosting, database & storage: to host the website and store your account, projects, and generated audio.
- AI voice synthesis & audio rendering: to synthesize the voices and produce the final mixed audio from your script.
- AI text processing: to analyze your manuscript so it can be cast and produced (e.g. detecting who is speaking).
- AI image generation: to create optional cover artwork when you request it.
- Transactional email: to deliver account, billing, and “render ready” notifications.
- Security & bot-protection: to protect sign-in and forms against automated abuse.
Sharing happens over encrypted (HTTPS/TLS) API connections, transferring only the specific data each provider needs. We may also disclose information where required by law, to enforce our terms, or to protect the rights and safety of our users and the service. A current list of our specific sub-processors is available on request at support@sonotale.com.
5. International transfers
Some of our providers may process data outside the European Economic Area. Where that happens, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses (or an equivalent adequacy mechanism) to protect your data.
6. Security measures
We take the following measures to protect your information:
- Encryption in transit — all traffic to and from the service uses HTTPS/TLS.
- Strict per-account isolation — database row-level security and owner-scoped storage so one account cannot read another account’s data.
- Access controls and least-privilege — secrets are stored securely and access to systems is limited to what is necessary.
- Authentication safeguards, rate limiting, and bot protection on sign-in and sensitive endpoints.
- Regular dependency and security review of the codebase.
No method of transmission or storage is completely secure, but we work to protect your data using industry-standard practices.
7. Data retention
We keep your account and content for as long as your account is active. You can permanently delete individual books from your library at any time, and you can ask us to delete your account and associated personal data by emailing support@sonotale.com. We may retain limited records (such as invoices) for as long as required to meet legal and tax obligations.
8. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you, and request a copy;
- have inaccurate data corrected;
- have your data erased;
- restrict or object to certain processing;
- data portability;
- withdraw consent at any time, where processing is based on consent.
To exercise any of these rights, email support@sonotale.com. You also have the right to lodge a complaint with your local supervisory authority — in the Netherlands, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl).
9. Cookies
We use a small number of cookies: essential cookies that keep you signed in, preference cookies that remember settings such as your theme, and security cookies used by our bot-protection. We do not use advertising or cross-site tracking cookies.
10. Children
SonoTale is not directed to children under 16, and we do not knowingly collect personal data from them.
11. Changes to this policy
We may update this policy from time to time. When we make material changes we will update the “Last updated” date above and, where appropriate, notify you. Continued use of the service after an update means you accept the revised policy.
12. Contact us
Questions about this policy or your data? Email support@sonotale.com.