Privacy
What Sonlit knows about you
Almost nothing. The tools run in your browser, so your audio never reaches me unless you choose to send it.
Last updated
In your browser
Audio you open in Sonlit is decoded and trimmed by your own browser. It is not uploaded. Drafts, settings and anything the tools remember between visits are stored in your browser and never sent to me.
The features that would upload a file — save to an account, email me a copy, send to my phone — are not built yet.
Cookies and tracking
Sonlit sets one cookie, on every page: the session cookie that keeps a signed-in account signed in and protects the forms from cross-site posts. It holds a random identifier and nothing else.
No analytics, no advertising pixel, no session recorder, no tag manager. The fonts and images are files on this domain, so no third party is told which pages you read.
If you make an account
An account is an email address that has proved it can receive mail. There is no password. It holds:
- Your email address.
- When the account was created, confirmed and last used.
- That you confirmed you are 16 or older, and which version of the terms you agreed to.
- The creations you save. Nothing saves into an account yet.
Before you confirm, the unconfirmed registration also holds a salted hash of the address you registered from. It goes when the registration does. The account itself keeps no form of your IP address.
Every sign-in is a fresh link emailed to you, good once and good for 15 minutes. Only a hash of it is stored.
If you write to me
The contact form keeps three things: the name you give it, your email address and what you wrote. They become a conversation in my inbox at keocodes.com, which is where I read it and answer.
The receipt emails you a private link to that conversation. The link is the key: anyone who has it can read the thread and add to it, and it does not expire. Keep it to yourself.
I keep the thread until I delete it. Nothing removes it on a schedule, and asking me to delete it is enough.
How long I keep things
- Unconfirmed registrations
- 7 days, then deleted.
- Sign-in link records
- Dead after 15 minutes; the record is removed a week later.
- Accounts and saved creations
- While the account exists. An account unused for 12 months may be deleted, after an email at 11 months.
- Messages you send me
- Until I delete the thread. The private link in your receipt works for as long as it exists.
- Daily allowance counters
- A salted hash of your connection and a count. 3 days.
- Rate-limit records
- The times of your recent requests, filed under a hash of your connection. Kept until I clear them.
- Files you email yourself or send to your phone
- 24 hours, then deleted. Not built yet.
- Operations log
- Account events with the time, a hashed fragment of the connection and your address masked. Rotates on size.
The operations log is the one thing the erase button does not reach. It holds no raw IP address and no readable email address.
Erasing it
The delete button on your account page removes the account, its creations and any live sign-in link immediately. There is no cooling-off period and no reactivation.
You can do the same without signing in, through the data request tool on the privacy page at keocodes.com. That sweep reaches Sonlit too, and it deletes any conversation filed under your email address, private link and all.
Copies you have already downloaded are yours and are untouched. Anything I emailed you is in your inbox, outside my reach — delete it there.
Who runs this
Sonlit is run by Derrick Keo under the name KeoCodes, and is part of keocodes.com. Questions about this page go to keocodes.com/contact.php.
The site-wide statement, your rights and the data request tool are at keocodes.com/privacy.php. Copyright complaints go to keocodes.com/dmca, where the registered agent and the form are. The terms for these tools are here.