SONIX
Privacy Policy
Privacy Policy
Version 3.10
Publication date: August 20, 2026 · Effective date: August 20, 2026
We will never train any AI on your voice, your messages, or your content. Not by default, not with an opt-out buried in settings, not ever — full stop, no exceptions, for any user.
Plain-language summary We’re SONIX SA, the Swiss company behind SONIX (sonix.gg, every subdomain including arena.sonix.gg, and our desktop/mobile apps). Here’s what matters most: • Pulsar voice is never recorded, transcribed, or analysed. • Advertising is limited to one gaming-focused partner, and never reaches institutional/school accounts. • We don’t train any AI on your content, voice, or messages. The rest of this policy is the detail behind those promises.
Table of contents
- Who we are
- Scope of this policy
- Our six privacy commitments
- Personal data we collect
- How we use your data (and our lawful basis)
- Voice in Pulsar — our strongest commitment
- Arena, Orbital, and third parties
- Cookies and similar technologies
- Service providers and sub-processors
- International data transfers
- How long we keep your data
- Security
- Your rights
- Children’s privacy
- Schools and institutional deployments
- Marketing communications
- Automated decisions and profiling
- Data breach notifications
- Changes to this policy
- Contact us and complain
1. Who we are
Plain-language summary SONIX SA, based in Switzerland. We’re the data controller. Any privacy question: privacy@sonix.gg.
SONIX SA (“SONIX”, “we”, “us”), CH-550-1185270-2, Rue de Genève 100, 1004 Lausanne, Switzerland — previously TYXIT SA. We’re the data controller for personal information processed through the Services, except where this policy or a written agreement (like a school’s Institutional Customer Agreement) says otherwise.
Privacy contacts
- Privacy questions: privacy@sonix.gg
- Post: SONIX SA, Rue de Genève 100, 1004 Lausanne, Switzerland
2. Scope of this policy
Plain-language summary Covers everything: our websites, apps, and all four modules (Pulsar, Arena, Orbital, the 3D Avatar Generator), plus Supersonix.
This policy applies to personal information we process through:
- our websites (sonix.gg, all subdomains);
- our desktop and mobile apps;
- our four modules — Pulsar (voice/chat), Arena (tournaments), Orbital (mini-games), and the 3D Avatar Generator;
- Supersonix and any other paid features;
- customer support, developer programs, and institutional offerings.
Specific terms apply on top of this policy in particular contexts — see Section 7 (Arena/Orbital), Section 15 (Schools), and the Cookies Policy.
“Restricted Accounts.” Any account provisioned under an Institutional Customer Agreement (school, university, or esports organisation), resolved automatically from that agreement’s domain list. Restricted Accounts never get targeted advertising, regardless of any consent that might otherwise apply. The 3D Avatar Generator’s photo/webcam option has its own, separate age line — see Section 4.6 — since it involves biometric data and follows BIPA/COPPA biometric requirements rather than general advertising rules.
3. Our six privacy commitments
Plain-language summary These five commitments are what makes SONIX different. They apply to every user, regardless of age, country, or subscription.
Commitment 1 — Voice stays private. Pulsar voice and video are never recorded, transcribed, or analysed being your back. No storage, no voiceprints, no speech recognition, no emotion detection. Real time in, gone when the call ends.
Commitment 2 — No behavioural advertising. No open ad exchanges, and never on a Restricted Account (institutional/school), full stop. Any account meeting SONIX’s standard age eligibility (13+, 16+ in the EEA/UK — Section 2.1 of the Terms of Use) sees ads from gaming-focused ad partners (Nitro/Overwolf) — relevant to you as a gamer, not assembled from a data broker. Haven’t consented to personalised ads? You still see ads, just non-personalised ones, never built from tracking you.
Commitment 3 — Not any AI training on your content. We don’t use your content, voice, messages, or any personal information to train any AI or ML models. Where we use machine learning at all (anti-cheat, voice quality), it’s aggregated, anonymised, non-personal signals only — never your identifiable content.
Commitment 4** — Minimal data collection.** We collect what we actually need — nothing more. No special-category data (race, religion, health, sexual orientation, political opinions, etc.), except what you choose to put in your own content, which we obviously can’t filter out — and one narrow, consent-gated exception: the 3D Avatar Generator’s photo/webcam option (Section 4.6), never available to anyone under 18 or to Restricted Accounts.
Commitment 5** — Your rights, made easy.** Delete your account and data whenever you want, from account profile settings. Anything else, email privacy@sonix.gg — 30 days, usually faster.
4. Personal data we collect
Plain-language summary Six categories: account info, technical info, in-app activity, payment info (if you pay), support requests, and — only if you opt in, only for eligible accounts — avatar data. We do NOT collect: precise location; race, religion, sexual orientation, or other sensitive categories; voiceprints; financial info beyond what your payment processor handles; search history; or anything from your device beyond what we need. One narrow exception: temporary biometric data for the optional photo/webcam avatar feature, as the purpose is to actually create a reassembled 3D avatar — see Section 4.6.
4.1 Account information — Email (required); username/pseudo (public); password (salted hash, we never see it); date of birth (not collected as a blanket registration requirement — we ask at specific moments, like an age-restricted tournament or the avatar photo/webcam option); Google/Discord sign-in identifiers if used; avatar and profile picture, if you upload one.
4.2 Network and device information — IP address, used live for low-latency voice routing and coarse regional approximation, not stored as a persistent record outside security investigations; connection-quality signals (ping, jitter, packet loss), aggregated, not used to profile you; device identifier and type, app version, basic performance signals, kept max 60 days.
4.3 In-app activity — Messages and content you send (so that you see your chat history next time you connect); Crew memberships and friend connections; aggregate session metadata; Arena tournament history; Orbital game-launch records; Xcoins balance and history; support-case content.
4.4 Payment information — Handled by Stripe, Apple Pay, or Google Pay. We receive only a confirmation, a transaction reference, and (for tax purposes) your billing country — never your full card number, CVV, or bank details.
4.5 Information we do NOT collect — Voice or video content (Section 6); precise location; special-category data (racial/ethnic origin, religion, health, sexual orientation, political opinions, trade-union membership, genetic data) — with one narrow, consent-gated exception: temporary (we don’t save it) biometric data via the Avatar Generator’s photo/webcam option as the purpose of this feature is to actually create a reassembled 3D avatar! (Section 4.6), never for anyone under 18 or on a Restricted Account; financial info beyond what the processor gives us; in-app search history; your device contacts (we may help you find existing SONIX users among them, with permission, but never store the list).
4.6 Avatar data (3D Avatar Generator) — Two ways to build an avatar:
- Template-based — presets male or female type, sliders, assets. No photo, no scan. Open to everyone, including Restricted Accounts.
- Photo or webcam-based — you upload a photo or use your camera, and we process a facial geometry mapping to build a 3D model. This is biometric data, used solely to make your avatar — not for recognition, ID verification, or matching across accounts. Not retained: the source photo is discarded the moment the model’s built; only the finished avatar sticks around, same as any other avatar image. Requires its own explicit “I consent” action before the camera launches — separate from your general account consent. Never available to anyone under 18.
5. How we use your data (and our lawful basis)
Plain-language summary Every use of your data has a reason and a legal basis under GDPR. Table below.
| Purpose | Lawful basis | What this means |
|---|---|---|
| Run the Service (accounts, voice, chat, tournaments, games, subscriptions) | Terms of Use | Basic account, session, content data — can’t run SONIX without it. |
| Authenticate you, keep your account secure | ToU + Legitimate interests | Password hashing, suspicious-login detection, anti-fraud. |
| Customer support, bug investigation | ToU + Legitimate interests | Using what you tell us to actually help you. |
| Aggregate analytics for improvement | Legitimate interests | Aggregated, anonymised — not used to profile or target ads. |
| Abuse prevention, anti-cheat, moderation | Legitimate interests + Legal obligation | Stopping breaches of the Terms, Guidelines, and the law. |
| Legal obligations (tax, accounting, AML, law enforcement) | Legal obligation | Limited records, kept for the periods the law requires. |
| Service emails | ToU + Legitimate interests | Necessary to operate the Service — can’t opt out, but can close your account. |
| Marketing emails (opted in) | Consent | Always opt-in, unsubscribe anytime. |
| Supersonix payments | ToU + Legal obligation | Processor gives us a confirmation and tax data, nothing more. |
| Legal claims (investigate, defend, assert) | Legitimate interests | Disputes, regulatory inquiries, litigation. |
| Swiss telecoms law (BÜPF/VÜPF), where it applies | Legal obligation | Limited connection-metadata retention if required. |
| Advertising, our gaming-focused partner (eligible accounts) | Consent (personalised) / Legitimate interests (contextual) | Available to any account meeting SONIX’s standard age eligibility; never Restricted Accounts (institutional/school). No consent → contextual ads, not no ads. |
| 3D avatar from photo/webcam | Explicit consent (Art. 9(2)(a) GDPR / Art. 6(2) FADP) | Only if you choose it. Never under 18, never Restricted Accounts. |
6. Voice in Pulsar — our strongest commitment
Plain-language summary Your voice is private. In the background we don’t record it, transcribe it, store it, analyse it, or use it for anything beyond delivering the call. This is the single biggest difference between SONIX and every other gaming-comms platform.
- No recording. No SONIX-controlled recording feature. No server-side archive. Except obviously if you choose yourself to activate such a feature.
- No transcription. Real time or after the fact. Except obviously if you choose yourself to activate such a feature.
- No AI analysis. No speech-to-text, sentiment analysis, emotion detection, voiceprint extraction.
- No advertising profiling from voice. Ever, for any commercial purpose.
- No biometric data. No voiceprints, faceprints, or speaker-ID vectors from Pulsar.
- Encrypted in transit.
- Ephemeral. Passes through our infrastructure for real-time delivery only — not retained.
- Aggregate signals only (packet loss, jitter) for quality and abuse prevention — never the content of your calls.
The same biometric-data protections apply to the facial-geometry data in the Avatar Generator’s photo/webcam option — Section 4.6.
If you record your own session using third-party tools, that’s outside our control — you’re responsible for complying with recording, wiretap, and consent laws in your jurisdiction. Bypassing our no-recording architecture with third-party tools isn’t allowed (Terms of Use Section 7, Community Guidelines Section 12).
7. Arena, Orbital, and third parties
Plain-language summary Arena: we provide the platform, Organisers run their own tournaments. Orbital: third-party games get only your username/pseudo, eventually skins and avatar — nothing else. Their own privacy notices cover what happens inside.
7.1 Arena. We’re the controller for your Arena participation data (matches, results, leaderboards). Enter a tournament and the Organiser may collect more — contact info for prize delivery, ID for eligibility, tax info for prize reporting — as an independent controller under their own privacy notice, shown to you at entry. We only pass the Organiser what they need to run the tournament: typically your username, results, and (for prize delivery) contact info you’ve chosen to give.
7.2 Orbital. Launch a Third-Party Game and the developer gets exactly two things: your username/pseudo and your avatar, so you show up as yourself. Nothing else — no real name, email, DOB, IP, contacts, payment info, message history, or voice. Inside the game, they can collect game-specific data (score, choices) under their own privacy notice, as an independent controller. Every developer signs our Developer Agreement: minimal data collection, a clear privacy notice, explicit consent for any advertising or AI training, and they indemnify us if it goes wrong. If needed we can pull any games that breaches the Agreement.
8. Cookies and similar technologies
Plain-language summary A small number of cookies, mostly to keep you logged in and remember your settings. Advertising cookies run for any account meeting our standard age eligibility, through one gaming-focused partner — never institutional/school accounts, never open ad exchanges. Full inventory in our Cookies Policy.
Categories: Strictly necessary (session cookies, auth tokens, security, your consent cookie via Nitro CMP) — can’t be disabled. Analytics (Google Analytics 4, privacy-hardened settings, loads only with consent). Advertising, for any account meeting our standard age eligibility, through Nitro/Overwolf — consented, TCF-governed personalised ads, or non-personalised contextual ones if you decline — through that same Nitro CMP consent tool. Never open exchanges, never data brokers, never institutional/school accounts.
Nitro/Overwolf runs our consent banner (Nitro CMP) as our data processor for consent management, alongside its role as our advertising partner — both listed at sonix.gg/subprocessors. Manage preferences through the banner or your browser; full detail in the cookies document on sonix.gg footer. [SONIX Legal — 20 Aug 2026: this replaces the prior CookieYes processor reference; confirm Nitro/Overwolf’s DPA covers the consent-management function specifically, not only advertising, since the two are now the same vendor performing two roles.]
9. Service providers and sub-processors
Plain-language summary A small number of trusted providers — hosting, payments, verification, support, and one gaming-focused ad partner for eligible accounts. All under written contracts. Up-to-date list: sonix.gg/subprocessors.
We use written Art. 28-compliant DPAs with every provider, holding them to our own security standard. Categories: hosting and infrastructure; payment processing; transactional email; customer support (Google Workspace); anti-abuse and security; age/identity verification, only when needed and only for that specific check; and cookie consent management and advertising, both now performed by Nitro/Overwolf (never institutional/school accounts for advertising, and the sole ad and consent-management sub-processor we use). [SONIX Legal — 20 Aug 2026: Nitro/Overwolf now covers two previously separate sub-processor categories (cookie consent management and advertising). This reduces the sub-processor headcount by one entry — flagging this against the “six EU-heavy sub-processors” figure used as a documented differentiator elsewhere (sales materials, institutional pitches); that figure needs revisiting or reconfirming at five, or a like-for-like replacement noted, before it’s repeated externally.]
We don’t use open ad exchanges, general-purpose tracking SDKs, or AI-training providers as sub-processors, full stop. Full list, with country and purpose, at sonix.gg/subprocessors — institutional customers get advance notice of changes.
10. International data transfers
Plain-language summary *Some providers are outside Switzerland. Data leaving the EEA/Switzerland travels under Standard Contractual Clauses or equivalent safeguards**.*
We’re based in Switzerland and host most data within the EEA/Switzerland. Where a provider sits outside without an adequacy decision, we rely on the European Commission’s revised Standard Contractual Clauses, the UK’s International Data Transfer Addendum, or the Swiss FDPIC’s equivalent clauses — plus supplementary measures like encryption where needed. GDPR Article 49 derogations only where strictly necessary (your explicit consent, or contract performance). Where relevant, we also lean on the Swiss-U.S./EU-U.S. Data Privacy Framework for certified providers. We do not transfer personal data to Russia, Belarus, or any jurisdiction under comprehensive sanctions, whatever the mechanism.
Outside the EEA, UK, and Switzerland: we apply this policy’s protections as a single global baseline, not a reduced standard elsewhere. Questions: privacy@sonix.gg.
11. How long we keep your data
Plain-language summary We keep data only following laws and standards.
Principles: keep it only as long as it’s needed; delete or anonymise once it isn’t; retain longer only where the law or a legitimate interest (like defending a legal claim) genuinely requires it.
| Category | Retention period | Why |
|---|---|---|
| Account data (email, username, password hash, DOB) | Active + 30 days after deletion | A short recovery window, then it’s gone. |
| Inactive account (no activity 3 years) | Deleted, 1-month notice first | Section 3.4 of the Terms of Use. |
| Pulsar messages, images, files (Crews/DMs) | While the Crew exists, message undeleted; gone within 30 days of account closure | Keep chat history usable while you’re active. |
| Biometric facial-geometry data (avatar) | Not retained — gone right after model generation | Transient processing only. |
| Advertising consent/ID data (eligible accounts) | Consent duration + up to 13 months | Standard IAB TCF convention. |
| Pulsar voice and video | Not stored — ephemeral | Section 6. |
| Device IDs, performance signals | Max 60 days | Minimised, for multi-device support and crash debugging. |
| Full IP address | Not persistent | Minimisation, legitimate security interest. |
| Connection-quality signals | Aggregated within 30 days | Service-quality improvement. |
| Support cases (incl. bug reports) | 24 months from closure | Quality assurance, follow-up. |
| Arena tournament records | Active + 3 years | Competitive history, dispute resolution. |
| Xcoins balance and history | While active | Service operation. |
| Supersonix payment records | 10 years | Swiss Code of Obligations Art. 958f. |
| Moderation and abuse records | 5 years | Legal defence, repeat-offender tracking, transparency. |
| Marketing opt-in/out preferences | Indefinite | So we keep honouring your choice. |
| BÜPF/VÜPF connection metadata (Switzerland) | Under review | Pulsar rides on users’ own internet connections rather than providing them, which Swiss case law generally treats as a lighter obligation than a telecom’s; smaller providers are often exempt from retention duties entirely. We’re watching this area of law as it evolves. |
| Data subject request records | 3 years from completion | Shows GDPR Art. 12 compliance. |
We may hold limited information longer where the law, a legal defence, or a binding court order requires it.
12. Security
Plain-language summary Encryption, access controls, monitoring, a written Information Security Program with a named coordinator.
TLS in transit, encrypted storage at rest; passwords as salted hashes, never plain text; least-privilege, role-based access with audit logs; regular vulnerability scanning and third-party testing; a documented breach-response plan; a written Information Security Program under top management or delegate, with regular risk review. Your part: keep your password to yourself, use 2FA, report anything odd to security@sonix.gg. No system is bulletproof, but we hold ourselves to the standard a privacy-first platform should.
13. Your rights
Plain-language summary See it, fix it, delete it, object to it. Most of this lives in your account settings; everything else, email privacy@sonix.gg.
Access, delation, withdrawing consent, and the right not to be subject to a purely automated decision with legal effect (Art. 15–22 GDPR / FADP equivalents) — see Section 17 for automation specifically, Section 18 for complaints.
How: email privacy@sonix.gg. Handled manually, one month per GDPR Art. 12(3) (extendable by two more for complex requests, with notice). We may verify your identity first. Free, unless a request is manifestly unfounded or excessive — then we may charge a reasonable fee or decline, and tell you why.
14. Children’s privacy
Plain-language summary SONIX is for 13+ (16+ in the EEA/UK). We don’t knowingly collect data from anyone younger. Find an underage account, we delete it. Advertising eligibility follows the same age line as the rest of the platform — no separate, extra restriction. The photo/webcam avatar option and AI training stay off-limits for anyone under 18, regardless of consent.
14.1 Minimum age. Not directed at under-13s (under-16s in the EEA/UK). We don’t knowingly collect their personal information without verifiable parental consent.
14.2 Age screening. We ask for your actual date of birth only at specific moments — an age-restricted tournament, the avatar photo/webcam option — not as a blanket requirement. Learn later that a registered user is underage? We suspend the account, delete the personal data (subject to narrow legal-retention exceptions), and offer parents a manual reinstatement review via privacy@sonix.gg.
14.3 Reports. Suspect an underage user? moderation@sonix.gg — we investigate and act within 24 hours of confirmation.
14.4 COPPA (United States). SONIX is built for gamers, not directed at under-13s, and we don’t knowingly collect their information without verifiable parental consent. A US school may authorise collection from under-13 students for educational purposes under FTC guidance. Where verifiable parental consent is needed: a Supersonix purchase’s payment transaction itself counts, where the card belongs to a parent (FTC’s accepted online-payment method); other moments use a signed consent form or similar. We don’t share a child’s information with third parties without separate consent, beyond COPPA’s narrow internal-operations exception. Parents can review, delete, or object to further collection, or (under the 2025 amendments) control third-party disclosure requiring separate consent — privacy@sonix.gg.
14.5 Voice and biometric data for minors. No recording, transcription, storage, or analysis of any user’s voice — minors included. No voiceprints, no biometric identifiers, full stop.
14.6 No AI training or sale of minors’ data. Advertising to a user under 18 follows the same rules as any other eligible account — SONIX’s standard age eligibility (13+, 16+ EEA/UK) is the line, with no additional age restriction beyond that. The photo/webcam avatar option remains off-limits under 18 (template-only for them), since it involves biometric data and follows BIPA/COPPA’s biometric-specific requirements rather than general advertising rules. No training AI/ML on a minor’s content, voice, or data. No sale, rental, or licensing of a minor’s data. No sharing a minor’s data with third parties beyond what’s strictly necessary to run the Service or what the law requires.
15. Schools and institutional deployments
Plain-language summary A school using SONIX is the data controller for its workspace. In the US, we act as a “school official” under FERPA, processing student data only on the school’s instructions.
Advertising and the photo/webcam avatar option are both fully excluded from institutional/school accounts, based on the domain list in each school’s Institutional Customer Agreement — neither feature is enabled for, or receives any data from, a School workspace.
Where a school, university, or esports club uses SONIX under an Institutional Customer Agreement, that Organisation is the controller for its members’ data; SONIX acts as processor (or “school official,” in FERPA terms) on its instructions.
15.1 FERPA (US schools). We’re a “school official” with a “legitimate educational interest” (34 CFR § 99.31(a)(1)(i)(B)), performing a service the School would otherwise handle in-house, under the School’s direct control, using student data only for purposes the School authorises — never redisclosed except as directed or legally required. No advertising, profiling, sale, AI training, or other commercial use of student data — ever. We don’t collect academic records (grades, transcripts, attendance) unless the School specifically asks. Students and parents: contact your School to access, correct, or delete education records; we’ll support the School’s request.
15.2 US state student-data laws. Where a deployment triggers state law (NY Ed. Law § 2-d, California SOPIPA, Colorado SB 188, Illinois SOPPA, Connecticut Public Act 16-189, Florida’s student-data laws), we add a state-specific addendum to the Institutional Customer Agreement.
15.3 GDPR/FADP (EU and Swiss schools). The Institutional Customer Agreement includes an Art. 28 DPA (or FADP equivalent), plus SCCs for international transfers where applicable.
16. Marketing communications
Plain-language summary Marketing emails only if you’ve opted in. Unsubscribe anytime.
Service emails — confirmations, resets, security alerts, terms updates, receipts — necessary to run your account, can’t opt out while active. Marketing emails — opt-in only, unsubscribe anytime from the footer. A “soft opt-in” for a similar feature you’ve already used applies only where lawful, always with a clear unsubscribe.
17. Automated decisions and profiling
Plain-language summary We don’t let a computer alone decide something that significantly affects you. A human reviews anything that does.
Art. 22 GDPR (and the FADP equivalent) gives you the right not to be subject to a purely automated decision with legal or similarly significant effect. In practice: anti-cheat and abuse systems can flag an account automatically, but a human reviews any suspension or termination; content filters can reduce visibility automatically, but a human reviews removal; we never use profiling to set your Supersonix price or any other feature’s price. Where automation contributes to a moderation decision, our statement of reasons (ToU Section 13) says so, and you can appeal.
18. Data breach notifications
Plain-language summary If we’re ever breached in a way that affects you, we notify the authority (typically within 72 hours under GDPR) and notify you if the risk to you is high.
We maintain a written breach-response plan. If it happens: the competent authority within 72 hours where Art. 33 GDPR requires it; the Swiss FDPIC as soon as possible where Art. 24 FADP requires it (high-risk breaches); affected users without undue delay where the risk to you is high (Art. 34 GDPR); schools and other Organisations within 48 hours for anything touching their workspace. You’ll get the nature of the breach, roughly how many people are affected, the likely consequences, and what we’re doing about it.
19. Changes to this policy
Plain-language summary We may update this. Material changes affecting your rights get at least 14 days’ notice by app and email before they apply.
Effective date’s at the top. Material changes that hurt your rights get 14 days’ notice, in-app and by email. Keep using the Services after that and you’ve accepted the update; don’t agree, close your account first.
20. Contact us and complain
Plain-language summary privacy@sonix.gg for anything privacy-related. You can also complain to your local data protection authority — details below.
- Privacy: privacy@sonix.gg
- Post: SONIX SA, Rue de Genève 100, 1004 Lausanne, Switzerland
Complaints: Switzerland — FDPIC, Feldeggweg 1, 3003 Bern, edoeb.admin.ch. EEA — your country’s data protection authority (list at edpb.europa.eu), or your workplace’s, or where the alleged issue happened. UK — ICO, ico.org.uk. US (COPPA) — FTC, ftc.gov/complaint. We’d genuinely appreciate the chance to sort it out first — privacy@sonix.gg.
— End of Privacy Policy —