Terms of Service & Privacy Policy
Effective date: 2026/02/02
Last updated: 2026/02/02
This document governs access to and use of Sonde and explains how personal data is processed in connection with the hosted Sonde SaaS.
By creating an account or using the hosted service, you agree to this document in full.
1. About Sonde
Sonde is an open-source and hosted software service that tracks how brands appear in AI-generated responses.
It allows users to:
- define and schedule prompts
- run those prompts against large language models (LLMs)
- optionally enable web search
- score and analyze responses over time
Sonde acts as an orchestration and analysis layer and does not operate its own AI models.
2. Architecture and Third-Party Services
The hosted Sonde service uses:
- Supabase (self-hosted): authentication, database, scheduling
- Next.js: frontend
- OpenRouter: third-party API gateway to LLMs and optional web search
- Stripe: billing and subscriptions
All LLM requests are executed using Sonde’s system API key. Users do not provide their own model API keys.
3. Open Source and Deployment Model
Sonde is available as:
- an open-source, self-hosted project, and
- a managed hosted SaaS operated by us
This document applies only to the hosted SaaS.
Self-hosted deployments are governed by the applicable open-source license.
4. Accounts and Eligibility
You must:
- be at least 18 years old
- provide accurate account information
- be authorized to act on behalf of any organization you represent
You are responsible for all activity under your account.
5. Subscription Plans and Credits
5.1 Plans
Sonde offers Free, Pro and Enterprise plans with different credit limits and model access.
- 1 credit = 1 execution run
- Automated scoring (“Judge”) executions do not consume credits
Plan details are displayed throughout the application and on the Sonde website and may change.
5.2 Billing
Paid plans are billed via Stripe. Subscription lifecycle events (renewal, cancellation, invoices) are handled through Stripe’s systems.
6. Acceptable Use
You agree not to:
- submit unlawful, infringing, or abusive content
- bypass plan or credit limits
- interfere with service operation
- use Sonde for high-risk or regulated decision-making (e.g. medical, legal, credit decisions)
You are responsible for the prompts you submit.
7. User Content and AI Outputs
7.1 Ownership
You retain ownership of:
- prompts
- configurations
- results and analyses generated for your account
7.2 Processing
By using Sonde, you authorize us to:
- process prompts
- send prompts to third-party AI providers via OpenRouter
- store responses and scores for display and analysis
Sonde does not use prompts to train AI models.
7.3 Limitations
AI-generated outputs:
- may be inaccurate or incomplete
- are produced by third-party models outside Sonde’s control
- must not be relied upon as factual or authoritative
8. Availability and Termination
We aim to provide a reliable service but do not guarantee uninterrupted availability.
You may stop using Sonde at any time.
We may suspend or terminate access for material breaches of this document.
9. Privacy and Data Protection
9.1 Controller
Data Controller:
Compiuta S.r.l.
Via Tiziano Vecellio, 169B, 35132 Padova, Italy
info@compiuta.com
9.2 Categories of Personal Data
We process the following categories:
Account Data
- email address
- user ID
- subscription and plan information
Usage Data
- prompts submitted by users
- execution schedules
- AI responses
- evaluation scores and reasoning
Technical Data
- timestamps
- request identifiers
- token usage and cost metadata
Users should not include sensitive or special-category personal data in prompts.
9.3 Purposes of Processing
Personal data is processed to:
- provide and operate the service
- execute scheduled prompts
- display results and analytics
- manage subscriptions and credits
- ensure security and prevent abuse
- comply with legal obligations
9.4 Legal Bases
Processing is based on:
- Contract (Article 6(1)(b) GDPR)
- Legitimate interests (Article 6(1)(f)) for security and service operation
- Legal obligations (Article 6(1)(c))
9.5 AI Models and OpenRouter
Sonde does not operate its own AI models.
When executing prompts, Sonde sends prompt text and limited technical metadata to OpenRouter, which routes requests to selected AI model providers.
- Prompts are used solely for inference
- Prompts are not used by Sonde to train models
- Processing is governed by OpenRouter’s Data Processing Agreement
9.6 International Data Transfers
OpenRouter and its sub-processors may process data outside the EU, including in the United States.
Transfers are safeguarded using:
- Standard Contractual Clauses (SCCs) adopted under Commission Decision (EU) 2021/914
- supplementary technical and organisational measures
9.7 Sub-Processors
We use sub-processors for:
- cloud hosting and infrastructure
- authentication and databases
- billing and payments
- monitoring and logging
- AI model providers (via OpenRouter)
An up-to-date list is available upon request at info@compiuta.com.
9.8 Data Retention
Personal data is retained only as long as necessary for:
- service operation
- legal and contractual obligations
Users may request deletion of their data, subject to applicable retention requirements.
9.9 Security
We implement appropriate technical and organisational measures, including:
- encryption in transit
- access controls and least privilege
- incident response procedures
- regular security reviews
9.10 Your Rights
Under GDPR, you have the right to:
- access
- rectification
- erasure
- restriction
- data portability
- objection
Requests can be sent to: info@compiuta.com
You also have the right to lodge a complaint with your local data protection authority.
10. Cookies
Sonde uses only essential cookies required for authentication and session management. No advertising cookies are used.
11. Limitation of Liability
To the maximum extent permitted by law:
- the service is provided “as is”
- we are not liable for indirect or consequential damages
- total liability is limited to amounts paid by you in the preceding 12 months
12. Governing Law
This document is governed by the laws of Italy, without regard to conflict-of-law principles.
13. Changes
We may update this document from time to time. Material changes will be communicated via the service or website.
14. Contact
Legal & Privacy Contact:
Compiuta S.r.l.
Via Tiziano Vecellio, 169B, 35132 Padova, Italy
info@compiuta.com