Account privacy
The account service connects your Sonderr installs and records your current plan. Your local workspace stays on your device.
Stored by the account service
- Your email address, account ID, salted password hash, plan, paid-through date, grant reason, and account creation date.
- Hashed browser and device session tokens, session expiry and sign-in timestamps, basic client labels, device-code digests, plan-request status, and plan-grant history.
- Authenticator secrets are encrypted at rest; recovery codes are stored as hashes and shown only once during setup.
- Your hourly AI request count and the hour it belongs to, used to enforce and display your plan limit. The counter resets each hour; prompts and generated content are not stored by the account service.
- Hashed, short-lived rate-limit identifiers; raw IP addresses are not written to the account database by the app.
Kept on your device
Chat history, workspace files, provider keys, and the app’s account token remain in Sonderr’s local data directory. The account service does not receive chat prompts, file contents, or provider keys.
Sign-in and plan requests
Passwords are stored as salted scrypt hashes. Browser sessions use an HTTP-only secure cookie. You can review active sessions, sign out other sessions, and change your password in account security settings. Device codes expire after ten minutes and can be approved once. Pro and Max requests are reviewed manually; PayPal payments are not automatically verified here. Paid access does not auto-renew.
Account access
Email verification and password-reset emails are not available yet. Use a unique password you can retain safely. If you lose access, contact Sonderr support and include your Sonderr ID. Do not email your password or one-time device code.
