Terms of Service
These terms govern your use of Sonela. They are written in plain language on purpose — you should be able to read them once and know what you are agreeing to. Where a term carries a real consequence, it says so in the same sentence rather than in a schedule somewhere else.
1. Who these terms are between
"Sonela", "we" and "us" mean the operator of the Sonela service. "You" means the organisation that opens a workspace, and anyone using that workspace. If you accept these terms for an organisation, you confirm you are authorised to do so.
Sonela is operated from Albania and is currently in early access with no paid subscriptions. The full company registration details — legal entity name, registration number and registered address — are published on this page before the service accepts payment.
2. What the service is
Sonela is an AI assistant you embed in your own web application with a script tag. It answers questions from your own operational data, using an AI model — either one you supply a key for, or one we run on your behalf under section 7.
- Read-only. There is no code path in the service that writes to your data. This is enforced by a query validator that admits only a single read query, guards the engine applies while it runs — a statement timeout, a row cap and, on PostgreSQL and MySQL, a read-only transaction — and a rollback rather than a commit. The security brief describes each layer and names the file that implements it.
- Where it runs. Your data is reached in one of two ways, and you choose which when you connect it. Through the Sonela Gateway: one small service you run on one server inside your own network, which connects outward to us — we do not dial into it, nothing is installed on staff machines, and what it needs to sign in to your database stays on your side. Or through a direct connection: you give us what your database expects at sign-in, and we hold those details on our infrastructure — encrypted with AES-256-GCM and bound to your workspace — to open the connection ourselves.
- Grounded in a schema you approve. Nothing is queried until you have reviewed the schema the gateway reads and reports back, and approved it. What you hide stays hidden.
- Not a system of record. Sonela reads your data to answer a question. It is not a backup, an archive, or a place to keep anything.
3. Your account and your keys
You are responsible for what happens in your workspace, including the acts of anyone you invite into it. Keep sign-in details, widget keys, gateway keys and any API key you supply confidential, and tell us promptly if you believe one has been exposed.
If you run the gateway, you decide how much of your data it is able to read. That configuration is made inside your network and stays there: it is not sent to us, and we cannot inspect it. If you connect directly instead, the sign-in details you give us decide the same thing, and we hold them as section 5 describes. Either way, if you give Sonela more reach than the assistant needs, the additional exposure is yours, not ours.
4. Acceptable use
You agree not to use Sonela to:
- break the law, or infringe anyone's rights;
- access data you are not entitled to access, including by attempting to defeat the tenant isolation the service applies to every query;
- probe, scan or attack the service or its infrastructure, except that we welcome good-faith security research reported to us before it is published;
- resell or expose the service to third parties as a standalone product rather than as an assistant embedded in your own application;
- circumvent quotas, or use automated means to generate questions at a volume the service is not priced for.
5. Your data, and our role
You own your data. We do not acquire any right to it beyond what is needed to run the service for you.
For personal data inside your database, you are the controller and we are a processor: we act on your instructions. That relationship is set out in the data processing agreement, which forms part of these terms once you are on a paid plan.
- Questions and the rows that answer them pass through our service, and reach one AI provider — the one you selected if you supplied a key, otherwise the one we run. They are not written to our storage.
- Chat transcripts are held in the end user's browser for the length of the conversation. We keep none.
- Our usage records store counts, timings and token totals — never the text of a question, an answer, or a query.
- Written material you upload to ground the assistant — procedures, product notes, policies — is stored in your workspace, because that is what it is for, and is sent to the AI provider with the question it helps answer. It is readable only by your workspace, and deleting it, or the workspace, removes it.
- An AI provider key you supply is encrypted at rest and decrypted only in memory to serve a request; no API we expose returns it. On a gateway connection, what the gateway needs in order to read your data is configured inside your network and is not sent to us. On a direct connection, the database sign-in details you give us are held on our infrastructure, encrypted with AES-256-GCM and bound to your workspace and data source; no API we expose returns them, and deleting the data source or the workspace removes them.
- We do not train any model on your data, and we do not use it to improve the service for anyone else.
You may ask us to export your configuration or delete your workspace at any time by emailing hello@sonela.ai, and we will action it. Deleting a workspace removes its configuration and any key it held; usage counters are retained in aggregate for billing and accounting records.
6. AI answers, and what they are worth
This is the clause worth reading twice. Sonela composes answers using an AI model. The service is designed to answer only from query results and to say when it cannot — but no AI system is correct every time, and an answer that reads confidently can still be wrong.
Answers are informational. Do not use them as the sole basis for a decision with financial, legal, medical, safety or regulatory consequences without checking the underlying data. You remain responsible for decisions made in reliance on an answer.
7. The AI provider: your key, or ours
Each paid plan is sold two ways, and which one you choose decides both the price and the number of answered questions included. The difference is not only commercial, so it is set out here in full.
- Your own key. Your relationship with that provider is directly with them, under their terms and their data processing agreement. We pass your questions and query results to the endpoint you configured and nowhere else. What you pay them is separate from what you pay us.
- Our key. We send your questions and query results to a provider we contract with, under our agreement with them, and we choose the model — we select for cost as well as quality, and we may change the model. Trials always run this way. If you need to know or to fix which provider and model your data reaches, ask us, or bring your own key.
Either way we do not train on your data and do not pass it to any other provider. We are not responsible for a provider's availability, pricing or model changes, nor for what a provider you chose does with data under the agreement you hold with them. If a provider changes in a way that breaks the service, we will tell you what we know.
8. Trials
A trial workspace runs for 14 days or 200 answered questions, whichever comes first. No card is required to start one, and it runs on an AI key we supply, so there is nothing for you to obtain before you begin.
When a trial ends the workspace pauses: the assistant stops answering, and everything you configured — schema approvals, grounding context, uploaded material, settings — is preserved and resumes the moment you choose a plan. We will email you when this happens. If you do not choose a plan, we may delete a paused workspace after 90 days, with notice first.
9. Fees, billing and taxes
- Subscription fees are as shown on our pricing page at the time you subscribe, in USD, excluding VAT and any other applicable tax.
- Payments are processed by Paddle, who act as merchant of record and whose terms cover the payment itself. Your invoice comes from them.
- Subscriptions renew automatically for the same period until cancelled. You can cancel at any time from your dashboard, effective at the end of the period you have paid for.
- Fees already paid are not refunded pro rata when you cancel, except where the law gives you a refund right or where we have failed to provide the service. Our refund policy sets out how to ask and what happens next.
- On a plan where you bring your own AI key, what you pay that provider is separate, is billed by them, and does not pass through us. On a plan where we supply the key, the model cost is ours and is included in the fee, which is why those plans cost more and include fewer answered questions. Either way our fee is flat and does not move when your usage does.
- We may change prices with at least 30 days' notice before the change applies to your next renewal.
10. Availability and support
We aim to keep the service available and will give reasonable notice of planned maintenance. During early access we do not offer a service level agreement, and you should not build a process that cannot tolerate the assistant being briefly unavailable.
Support is by email at the address in section 16, at the level shown for your plan.
11. Changes to the service
The product is actively developed and will change. We will not remove a capability you rely on, or make a change that materially reduces the service, without at least 30 days' notice. If such a change is unacceptable to you, you may cancel and we will refund the unused part of the period you have paid for.
12. Suspension and termination
You may stop using the service and close your workspace at any time. We may suspend or terminate a workspace if you materially breach these terms, if fees go unpaid after notice, or if continuing would expose us or others to legal risk or a security threat. Except where the risk requires acting immediately, we will tell you first and give you a chance to put it right.
13. Intellectual property
We own the service, its software and its brand. You own your data, your schema configuration, and anything you author in the product. Nothing here transfers ownership either way. You may not copy, reverse engineer or create derivative works from the service, except where the law says you may despite this clause, and except for the components we publish under an open source licence — which are governed by that licence.
If you send us feedback, we may use it to improve the product without owing you anything for it.
14. Warranties and liability
The service is provided "as is". Beyond what these terms say and what the law requires, we do not give warranties — including that the service will be uninterrupted, error-free, or that any particular answer will be accurate.
Neither party is liable for indirect or consequential loss, or for lost profits, revenue, goodwill or anticipated savings. Our total liability arising out of or in connection with these terms is limited to the fees you paid us in the 12 months before the event giving rise to the claim — or, if you are on a free trial and have paid us nothing, to EUR 100.
Nothing in these terms limits liability that cannot lawfully be limited, including for death or personal injury caused by negligence, or for fraud.
15. Changes to these terms, and governing law
We may update these terms. For a material change we will give at least 30 days' notice by email and update the version and date at the top of this page; continuing to use the service after the change takes effect means you accept it. If you do not accept it, you may cancel before it takes effect.
These terms are governed by the law of Albania, and the courts of Tirana have jurisdiction — except that if you are a consumer, you keep the protections and the forum that the mandatory law of your country of residence gives you.
If any clause turns out to be unenforceable, the rest of these terms continue to apply. These terms, together with the data processing agreement once it applies, are the whole agreement between us about the service.
16. Contact
Questions about these terms, about a security problem, or about anything else: hello@sonela.ai. We answer.
Privacy note for this website
This website is static pages. It sets no cookies and loads nothing from anyone else's servers: the assistant in the corner comes from our own API, and it is the only thing on the page that is not part of the page. The site keeps one thing in your browser: one flag, set when you close, finish or decline the Meet Sonela tour, so the tour does not open by itself again — it holds nothing about you, goes nowhere, and clearing your browser's data for this site removes it. It counts page views, and counts them in a way that records nothing about you — set out below. There is nothing to consent to, which is why no banner asked you. You can verify every word of that in your browser's developer tools, on this tab, right now.
What it does process: serving you these pages means our hosting edge receives your requests, and — like every request on the web — each one carries your IP address, which appears in ordinary server logs. Beyond the pages and their own assets, the site's script makes four requests of its own accord, all to our own API at api.sonela.ai: one for the live price list the pricing section shows, one for the gateway download's current version and checksum, one that counts this page view, and one that asks how the assistant in the corner should appear here. Three of those four carry nothing about you. The counting one carries the path of the page you opened and nothing else — no cookie, no identifier, nothing that could pick you out of the total it joins. The country it came from is worked out on our own server from the address, in memory, and the address is then discarded rather than written down; it goes to nobody else. A fifth goes to that same API only when you send the contact form, and it carries what you put into it — your email address, your message, and one file if you chose to attach one — which are stored with us and emailed to the person who answers you. The file is deleted as soon as that email goes out, and dropped unsent if it never can. The same first-party logging applies to all of them. We use those logs to serve the site and keep it secure — our legitimate interest — and for nothing else.
The assistant in the corner is this product, answering for itself. Nothing you type reaches us until you send it. When you do, your question goes to our API and on to one AI provider so that it can be answered — and it is answered from what this website publishes, never from any customer's records, which it cannot reach. The conversation lives in this browser tab and is gone when you close it: no transcript is kept. What is kept is counts and timings, never your words. If you use the microphone, the recording is sent once to be turned into the text in the box, and neither the recording nor that text is kept afterwards. It asks for no account and nothing about you; please do not type anything into it you would not put in an email to a stranger.
That is the whole story until you create an account. From that point you are in the product, whose data handling section 5 above and our privacy policy both cover. Questions about any of it: hello@sonela.ai.
Plain terms, on purpose.
If a clause here is unclear, that is a defect in the writing and we would like to know. The same principle governs the security brief: a document nobody can check is not a commitment.