We collect
- Semantic actions
- Parametrized routes
- Small state probes
- Release identifiers
Most analytics vendors ask you to trust controls around a complete recording. Sonder starts by subtracting it: no session video, screenshots, DOM capture, input values, or raw HTML.
Contact securityA masked semantic event stream: for example, clicked “Save changes” (button) in Billing on /settings/:id. Friction events can include whether an error, spinner, disabled control, or empty state was visible.
Routes are parametrized before transport. Consecutive repeats collapse to one event with a count.
Emails, phone numbers, card numbers, SSNs, long digit runs, and sensitive property keys are replaced with [masked] in the browser. Ingest applies the same rules again before storage.
The session ID is a random per-tab value in sessionStorage. Sonder does not use third-party cookies or cross-site tracking.
Traffic uses TLS and providers encrypt at rest. EU residency is not offered during beta.
Frontend write keys can submit events and read nothing. Server/API keys are hashed, scoped, and revocable. Control-plane access is workspace isolated; owner-only operations include retention, deletion, keys, and billing.
Default retention is 90 days. Derived records for a deletion request are removed immediately; residual masked raw events age out within the configured retention window.
Diagnosis sends masked, aggregated friction ribbons to the DeepSeek API—never input values or screenshots. The provider is named so customers can evaluate it, and the model endpoint is configurable for customers who bring their own.
Sonder does not yet have a SOC 2 report, EU region, or multi-region availability. Draft privacy, terms, and DPA documents are published and visibly marked pending counsel review.
A security.txt is available for responsible disclosure.
Review the exact event contract, masking rules, and data model before connecting anything.