What Sonar is
Sonar projects the credit utilization each of your cards is on course to report to the credit bureaus when its statement closes, and tells you before it happens.
Sonar does not pull your credit report or your credit score, does not move money, and is not a lender, a bank, a credit bureau, or a credit repair service.
Information we collect
Grouped by where it comes from. This is the complete list.
| Source | What we receive |
|---|---|
| Sign in with Apple | Apple's opaque identifier for you, and your name and email address only if you chose to share them when you signed in. If you used Apple's Hide My Email, we only ever see the relay address. |
| Your bank or card issuer, through Plaid | Account balances, credit limits, statement issue dates, payment due dates, minimum payments, interest rates (APRs), the account name and the last few digits of the account number, the institution's name, and card transactions — merchant, amount, date, whether the charge is still pending, and Plaid's spending category for it. |
| Apple Card, through Apple Wallet | Balance, credit limit and statement dates. Your iPhone reads these from Apple Wallet with your permission and sends them to our servers, where they are stored alongside your other cards so that alerts can be composed and sent whether or not your phone is awake. |
| Your device | Your Apple push notification token, and your device's time zone — so that an alert arrives at 11am where you actually are. |
| What you type | Your alert thresholds, how many days of warning you want, and any credit limit or card name you enter by hand. |
| The sonar.cards waitlist | Your email address, if you sent it to us through the form on our website. We use it once, to tell you Sonar has launched. |
We never see or store your bank username, password, or security codes. Plaid handles those directly with your bank and passes us only the account data listed above. We do not store your full account number — only the last few digits your bank provides.
How we use your information
Only for these things:
- to work out when each card's statement closes and project what it will report at that moment;
- to find recurring charges — subscriptions and bills likely to post before a statement closes — so the projection counts them. This is the only reason we receive your transactions;
- to send the alerts you asked for, when you asked for them;
- to keep your bank connections working, and to sign you in;
- to answer you when you write to us;
- to keep the service secure and to meet our legal obligations.
That is the entire list. We do not use your information for advertising. We do not sell it, and we do not share it for anyone's marketing. We do not use it to train machine-learning models. The Sonar app contains no analytics tools, no advertising identifiers, and no third-party trackers.
Our website counts page views using Plausible Analytics, which sets no cookies, collects no personal information, and is not used in the app.
What our notifications show
Sonar's alerts carry the card's name, its balance, and its projected utilization — for example, "Platinum closes in 3d · $5,364 at last sync, +$180 committed → 15.8% projected to report." Payment reminders name the statement balance and the minimum payment.
These appear on your lock screen unless you turn previews off in iOS Settings › Notifications › Sonar › Show Previews. Notifications are optional, and Sonar works without them.
How we protect your information
- Everything between the app and our servers travels over an encrypted TLS connection.
- The key that lets us read your bank data — Plaid's access token — is encrypted with AES-256-GCM before it is written to our database.
- Your sign-in credential is never stored in a usable form: the app holds a short-lived token, and the long-lived one is kept only as a one-way hash, rotated every time it is used.
- Access to production systems is limited to the one person who operates Sonar, over multi-factor authentication.
- We keep a written information security program covering these practices, our vendors, and how data is disposed of, and we review it as Sonar changes.
No service can promise perfect security, and we will not pretend otherwise. If your information is involved in a security incident, we will notify you and the appropriate authorities as required by law, without undue delay.
Where your information is stored
Your information is stored on servers we rent from Railway. Sonar is built and operated from Mexico City, and your information may be accessed from there.
Keeping, deleting, and disconnecting
Disconnecting one bank
Open Sonar, tap the card, then the ⋯ menu, and choose Disconnect bank. That removes the connection at Plaid as well as here, and deletes the cards, transactions and history that came from it. A bank that shared no card at all appears under Settings › Banks without cards, with the same Disconnect.
Deleting your account
Open Sonar, go to Settings and tap Delete account. This is a deletion, not a deactivation.
When you do, we immediately delete your account record, your cards, your transactions, your statement and balance history, your settings and your notification tokens from our database, and we cancel every bank connection with Plaid. If a bank connection cannot be cancelled at that moment — because Plaid is unreachable, say — we keep only the encrypted key needed to cancel it, and nothing else about you, and we keep retrying until the cancellation goes through or, if it cannot be completed automatically, until we resolve it by hand. Deleting your account does not require you to contact us, and it is never blocked by a failure on our side.
How long we keep things otherwise
We keep your information while your account is open, and delete data we no longer need to provide the service — and in any event no later than two years after we last used it to provide the service to you — unless we are required to keep it by law, or disposal is not reasonably feasible for the way the information is stored.
After a deletion request we retain information solely to the extent required by applicable law.
Your choices
- Disconnect any bank, at any time, from the card's ⋯ menu.
- Delete your account, at any time, in Settings.
- Turn notifications off — in Sonar's settings, or entirely in iOS Settings › Notifications › Sonar.
- Change your thresholds, lead days, credit limits and card names whenever you like.
- Email [email protected] to ask what we hold about you, to correct it, or to have it deleted. We offer this to everyone, wherever you live.
Nevada residents may direct us not to sell their covered information. We do not sell it and have no plans to; if you want that instruction on the record anyway, write to [email protected] and we will confirm receipt.
Sonar does not track you across other companies' apps or websites, so we do not respond differently to Do Not Track signals. We are not aware of any third party collecting personally identifiable information about you across sites or apps through Sonar.
Children
Sonar is for adults aged 18 and over. We do not knowingly collect information from anyone under 18.
Changes to this policy
If we change this policy in a way that matters, we will tell you in the app before the change takes effect, and we will update the effective date and version at the top of this page. Continuing to use Sonar after that date means you accept the updated policy. If a change would involve sharing your information in a way this policy does not already describe, we will give you notice — and where the law requires it, a choice — before that sharing begins.
Contact us
Sonar is operated by Half Moon Labs LLC. Write to [email protected] with any question about this policy or about your information, and a person will answer.