Privacy Policy
Last updated: 8 October 2026
This explains what Souna collects when you use Souna, and what it does not.
The short version: nothing you make is published, sold or used to train AI. The details
are worth stating precisely rather than broadly.
What you make and upload in the app (images, video, music, exports, your uploaded files, your
projects and your chat history) is kept in your account on our servers until you delete it, so you
can open it from any device (section 1). Your prompts and your chat messages are also kept on our
servers so that we can investigate abuse, enforce our Terms, and answer a lawful demand. Earlier
versions of this policy said we kept nothing, then that results stayed in your browser with a
7-day copy on our side; since 8 October 2026 neither describes the app. If these details matter to
you, read sections 1 and 2 before you use the Service.
1. What we collect
You give us
- Account. Your email address and a hashed password. Optionally a display name, a phone
number and an avatar if you add them.
- Payment. Records of purchases: an order reference, the amount, the status and the
time. Card details are handled by the payment provider and never reach our servers.
- Correspondence. Anything you write to support.
We collect automatically
- Metering. One row per generation, recording which action you ran, which model, how
many credits it cost, what it cost us, and when. This row exists to bill you correctly and to
catch abuse. It contains no prompt and no result.
- Job state. For video and music, which are asynchronous, we hold a queue reference,
the model, the credits reserved and the status, so the result can be returned to you and
refunded if it fails. These records include the full prompt and are kept like prompts
(section 5). The output itself is handled as described under "Your generated media" below.
- Prompts and chat messages. The text you send to a model and the text it sends back,
with the model used, the time, and your IP address. We keep this to investigate abuse reports,
to enforce our Terms, and to be able to respond to a lawful demand. It is not sold, and it is
not used to train models. Only administrators can read it, and every single access is written
to an internal audit record.
- Technical. Your IP address and browser user-agent, used for rate limiting, fraud
prevention, security, and to choose a starting language. Free-tier quotas are counted per
account and per IP.
- Session. A login cookie, and a cookie recording your language choice.
Your library: what you make and upload
- Results. Every image, video, music track, voiceover and export you make is stored in
your Library, in storage we control, until you delete it there or delete your account.
- Uploads. Files you upload (product photos, videos, audio) are stored in your Library
the same way, so you can reuse them in projects.
- Projects and drafts. Your timelines, scripts and storyboards are stored in your account.
- Chat history. Your conversations are stored in your account so they open on any
device. You can delete each one; the copy kept for safety (above) is handled separately.
None of it is published, sold or used to train anything. Administrators can open stored files,
and every such access is written to an internal audit record. Your Library has a storage quota;
we tell you before it is full and never delete your files to make room.
Exports are rendered on our own servers. For captions, the audio of the file you choose is sent
to a speech-to-text provider. Screenshots or files you attach to a support request are kept for
90 days.
About the provider that renders your media: we ask them to delete their copy on a schedule
rather than instantly, so that a failed download can still be recovered. We cannot independently
verify when they actually remove it, and we will not claim otherwise.
2. What your browser keeps
Only small interface settings, such as the theme and whether the guided tours have played, are
kept in your browser. Your work is not: it lives in your account (section 1), so clearing your
browser or changing device loses nothing.
3. Why we use it
- To run your account and let you sign in.
- To meter credits, take payment and issue receipts.
- To enforce free-tier limits and detect abuse, fraud and automated signups.
- To send transactional email: verification, password reset, receipts, and low-balance or
product notices you can opt out of.
- To keep the Service secure and available.
Where the law requires a legal basis, ours is performance of our contract with you (running
the account, billing), our legitimate interests (security, abuse prevention, service
improvement), your consent (optional email), and legal obligation (tax and accounting records).
4. Who we share it with
- Model providers. Your prompt, the earlier messages of a chat, any file you attach and,
for captions, the audio you choose are sent to the third-party provider that runs the model you chose, so it can be executed. They
handle it under their own terms. We do not send them your identity. Models marked
Anonymized in the model picker are run by a provider that passes the request on to
another vendor; that provider does not guarantee the same privacy as models marked
Private.
- Payment provider. Handles your card details directly and returns us a status.
- Email provider. Delivers transactional email; receives your address and the message.
- Infrastructure. Our hosting provider, which operates the servers the Service runs on.
- Country lookup. We ask a geolocation provider which country your IP address is in,
to choose a starting language and the currency we show. The provider receives your IP address
and nothing else, and the answer is cached for 24 hours. The lookup is skipped when our CDN
reports the country itself.
- Analytics and advertising. When enabled, we use Google Tag Manager, Microsoft Clarity
and Meta (the Meta Pixel and the Meta Conversions API). Clarity records how pages are used,
which can include what is shown on the screen. Meta receives page and purchase events, your IP
address, browser details, and a hashed email address and account ID, which we use to measure
and run our advertising.
- Fonts. Pages load fonts from Google Fonts, which receives your IP address.
- Legal. Where we are legally required, or where it is necessary to protect someone
from serious harm. We hold the text of your prompts and chat messages and the files in your
Library, so a lawful demand can reach them.
- A successor in a merger or sale of the business, under the same commitments.
We do not sell your personal data, and we do not use your content to train models.
5. Retention
- Account data: while your account exists.
- Metering rows: retained for billing, tax and abuse-prevention purposes.
- Payment records: kept as long as accounting and tax law requires.
- Video and music job records, including the prompt: retained like prompts.
- Prompts and chat messages: retained indefinitely. We do not delete them on a schedule. You
can ask us to erase yours at any time (see section 6).
- Your Library (results, uploads, exports), projects, drafts and chat history: until you delete
them, or your account.
- Support attachments: 90 days.
- Encrypted backups of our database: replaced within 14 days.
6. Your rights
You can access, correct, export or delete your personal data, object to processing, and
withdraw consent for optional email at any time. Most of it you can do yourself from your
profile; for the rest, write to
privacy@souna.si.
You can delete your account yourself from your profile. The account is locked immediately and
permanently deleted after seven days; until then you can cancel from the email we send you.
Deletion removes your sign-in details, your prompts and chat messages, your Library, projects and
drafts, and your support conversations, and remaining credits are forfeited. We keep payment
records for as long as accounting and tax law requires, usage metering rows for billing, and any
prompt that was blocked as illegal content.
You can also ask us to erase the prompts and chat messages we hold about you without closing
your account. Write to the address above and we will carry it out. We may retain a narrow
portion where the law obliges us to, for example material that is the subject of an active legal
claim or an ongoing abuse investigation; if that applies, we will tell you.
7. Security
Passwords are hashed, traffic is served over HTTPS, and access to production systems is
restricted. Stored prompts and chat messages can be read only by administrators, and every read
is recorded. Backups are encrypted before they leave the server.
An earlier version of this policy said that a breach of our servers could not expose a single
prompt, because none were kept. Now that we keep prompts and your Library, that is no longer
true, and we would rather say so plainly than leave the old sentence standing. It is why access
to stored files is limited to administrators and every access is recorded.
8. Children
Souna is for adults only and is not directed at anyone under 18. We do not knowingly collect
data from minors. If you believe a minor has created an account, write to us and we will remove
it.
9. International transfers
Our servers and our providers are located outside your country, so using the Service means your
account data is transferred internationally. We use providers that offer appropriate safeguards
for such transfers.
10. Changes
We may update this policy. Material changes are posted here with a new date. The English
version is the authoritative one.
11. Contact
Write to privacy@souna.si. See also our
Terms of Service.
← Back