Trust · Data Protection

How we protect your data

Structured personal data is removed before any AI ever sees it.

Raw message

Sure — email me at ‹EMAIL_1› or call ‹PHONE_1›.

Vault
AI model
receives tokens
0 raw0 tokenized
Detected, tokenized, then sent to AI — your team still sees the real values.

What we redact

Before your conversation reaches our coaching AI, we automatically detect and tokenize structured personal data: email addresses, phone numbers, payment-card numbers, IBANs, BICs, postal codes, and URLs.

This runs wherever SonicR1's coaching AI processes your conversation — live coaching in real time and post-call debriefs.

How it works

Detected values are replaced with neutral tokens in memory before the request leaves our systems, so the coaching AI receives tokens in place of raw structured personal data.

Your team sees the real values in the product; the coaching model works from tokens.

Encryption

Identifying values are encrypted at rest with AES-256-GCM. The encryption key is held in an isolated secrets vault, separate from application credentials.

All data is encrypted in transit with TLS 1.3.

No model training

Your conversations are never used to train AI models. We use production AI endpoints that do not learn from your data.

Your data rights

You can request erasure of identifying data at any time under GDPR Article 17. We acknowledge within 48 hours and complete within 14 days.

Email privacy@sonicr1.com to start a request.

Retention & anonymization

Retention is configurable per workspace. After the retention window, the tokens generated during analysis can no longer be re-linked to their original values, while aggregate analytics remain available.

Audit integrity

Every redaction event is written to an append-only, tamper-evident audit trail that cannot be altered or deleted.

Data residency

Primary data storage is located in Frankfurt, Germany (eu-central-1). Your data is isolated per organization and never shared across tenants.

Learn more

See our Privacy Policy and Data Processing Agreement for full detail, or our Security overview for infrastructure and tenancy.