Sonant is made by Penumbreal, a one-person software business in the Netherlands, under its Soluneal trade name. We don't run analytics, we don't drop cookies, we don't fingerprint your browser, and we don't sell anything about you to anyone. This page exists to tell you exactly what does get stored when you interact with us, why, and how to make it go away.
1. Who we are
Soluneal is the trade name under which Penumbreal publishes its macOS apps. Penumbreal is a sole proprietorship (eenmanszaak) registered in the Netherlands under KvK number 42159345, at De Nieuwe Erven 3, Unit 15248, 5431 NV Cuijk, The Netherlands, and it is the data controller for everything described on this page. Contact: [email protected]. There is no data protection officer because we are too small to be required to appoint one. Emails go to a real human who reads them.
2. What we collect when you visit this site
Nothing. sonant.soluneal.com runs no analytics, no tag managers, no advertising pixels, no session replay, no heatmaps, and no cookies. Your IP address is processed by Cloudflare's edge to deliver the page to you, but we never see it and it isn't logged for our use.
3. Who else sees it
Nobody who shouldn't. We do not sell, rent, share, license, or otherwise hand your data to advertising networks, data brokers, social platforms, or AI training companies. We run no user database of our own; the only customer records that exist live with the two services below.
- Cloudflare serves this website and the app's update feed. Its processing is governed by its privacy policy and its EU/UK data processing addendum; it acts as a data processor under our instructions and does not use your data for its own marketing.
- Lemon Squeezy runs the store, the license service, and our product-update emails. It holds your order and, if you subscribed, your email address, as described in the next two sections, under its privacy policy.
The app itself also talks directly to a few services for lyrics, artwork, updates, and (if you connect it) your Spotify queue. Those requests carry information about the track, not about you, and each one is described in its own section below.
4. When you buy Sonant
Purchases go through Lemon Squeezy, which sells Sonant as the Merchant of Record. At checkout it collects your name, email address, billing country, and payment details, plus a VAT ID if you enter one. Payment details stay with Lemon Squeezy and its payment providers; we never see a card number.
What we do see, in our Lemon Squeezy dashboard, is your name, email, country, the order, and your license key with its activations. We use it to deliver and activate the license, answer support and refund requests, and keep the bookkeeping Dutch tax law requires, which is also why purchase records are kept for seven years after the sale. Legal basis: performance of the contract with you, and our legal obligations for the records.
When you activate Sonant, the app sends your license key and your Mac's name (the one shown in System Settings, for example "Ayşe's MacBook Air") to Lemon Squeezy's license service so activations can be counted against the five your license allows. Deactivating a Mac, from Settings or by emailing us, removes that entry.
5. Product-update emails
Order confirmations and license emails are transactional and go to every buyer. Beyond that we only email you if you chose it: the checkout has a box for product updates, and you can also subscribe later. That list is hosted and sent through Lemon Squeezy's email tool. Emails are occasional (launches, significant updates), every one carries an unsubscribe link, and opting out never affects your license. Legal basis: your consent, which you can withdraw at any time by unsubscribing or by emailing [email protected].
6. Your rights
If the GDPR (EU/UK) or a similar data-protection law applies to you, you have the right to:
- Access the data we hold about you.
- Correct it if it's wrong.
- Delete it (right to erasure / right to be forgotten).
- Withdraw your consent at any time.
- Receive a copy in a portable format.
- Object to or restrict our processing.
- Lodge a complaint with your local supervisory authority. Ours is the Dutch Autoriteit Persoonsgegevens.
To exercise any of these, just email [email protected]. Because we're small, we usually act on the request the same day. We will not ask you to "verify your identity" by sending us an ID card, your request from the email address on file is sufficient. Deletion has one limit: the purchase records Dutch tax law requires us to keep stay until that period ends, and the payment records themselves are held by Lemon Squeezy, which handles requests about them under its own policy.
7. Cookies and tracking
None. We don't use cookies, localStorage, sessionStorage, or any other client-side persistence on the marketing sites. No analytics scripts, no Google Analytics, no Facebook Pixel, no Plausible, nothing.
8. The live visualizer (optional, opt-in)
Sonant includes an optional live visualizer that makes the menu bar bars react to the actual audio coming out of Music or Spotify. It is off by default and only turns on when you explicitly choose "Allow", either during first-run setup or by enabling Live audio capture under Settings → General → Audio Analysis.
When enabled, Sonant uses macOS's CoreAudio process tap (macOS 14.2+) to read the audio output of Music and Spotify in real time. macOS gates this API behind the standard Microphone privacy permission, which is why your Mac asks for it. No audio is recorded, written to disk, or sent over the network. Samples flow into a 1024-point FFT, get reduced to four band-amplitude numbers, drive the bars, and are then immediately discarded. Music continues to play normally through your speakers. The tap is a read-only branch of the signal.
You can turn the live visualizer off at any time from Settings → General → Audio Analysis. When off, Sonant makes no audio capture calls and the bars revert to a synthetic animation.
9. Lyrics
When you open the Now Playing preview or enable the Current lyric line toggle on the widget, Sonant fetches synced lyrics from lrclib.net, a free no-auth lyrics catalog. The request includes the track title, artist, and album of whatever's currently playing. We do not send your install ID, IP (other than the standard TCP header), or any account information. lrclib.net's response is cached in memory only , it isn't written to disk and disappears when you quit Sonant. If you never open the preview and never enable the widget's lyric row, Sonant never contacts lrclib.net.
10. Album artwork
Music and Spotify normally hand Sonant the artwork of the current track directly. When Music doesn't, Sonant looks the track up on Apple's public iTunes Search API using the artist and title, and shows the cover it returns. When Spotify is playing, the cover is downloaded from the artwork link Spotify provides. Those requests carry the track's artist and title (Apple) or the artwork link (Spotify) and nothing else, no install ID, no account information. Artwork is kept in memory only.
11. Software updates
Sonant checks for updates by fetching a signed update feed
from sonant.soluneal.com (via the open-source
Sparkle framework). That is a plain request for a file; it
carries no install ID, no account information, and no system
profile. Cloudflare's edge sees the request the same way it
sees a visit to this website.
12. Streaming-service account connections (optional)
If you click Settings → Accounts → Connect Spotify,
Sonant runs the standard Spotify OAuth flow with PKCE. You
sign in on Spotify's website (not Sonant) and grant the
user-read-playback-state scope. Spotify
returns an access token + refresh token to a loopback
listener on your machine; we store both in macOS's
Keychain under your user account, scoped
to Sonant's bundle identifier. We use the access token
only to fetch your upcoming-queue list when Spotify is
the active player so we can populate Sonant's
Up Next submenu. We never see your password, and
the tokens never leave your Mac (other than being sent
directly back to Spotify on each API call). Disconnecting
from the same settings panel deletes both tokens from
Keychain immediately.
13. Children
Our products are not directed at children under 16. We don't knowingly collect data from anyone in that age range. If you believe we have, email us and we'll delete it immediately.
14. International transfers
Cloudflare operates a global edge network and Lemon Squeezy is based in the United States, so your data may be processed outside the EU/EEA. Both rely on Standard Contractual Clauses or an equivalent transfer mechanism under GDPR Chapter V.
15. Changes to this page
If we change anything about how we handle your data, we'll update the "Last updated" date at the top of this page and, for material changes, post a notice here and in Sonant's release notes before the new policy takes effect.
16. Questions
Anything unclear, anything missing, anything you want changed? Email [email protected]. A real person will write you back.