Legal
Privacy Policy
Effective 26 August 2026 · Version 2026-08-26
Resona uses account information, your private workspace, and AI requests to provide the features you choose. It uses essential session technology, does not sell personal information, and does not use behavioral advertising.
1. Scope and responsible party
This Policy explains how the maintainers of this Resona deployment process personal information when you use the hosted Service. The open-source code can be operated by other people; independently operated deployments have their own privacy responsibilities and may follow different practices.
2. Information we process
- Account information: username, display name, email address and verification status, password hash, account status, and timestamps.
- Exabyte identity information: immutable Exabyte subject, verified email, name, preferred username, locale, time zone, avatar, profile revision, connection state, and account lifecycle status. Resona does not retain Exabyte access or refresh tokens after sign-in.
- Your workspace and activity: interface files, saved settings, audio configurations, playback history, uploaded files, AI prompts, generated results, run status, and short operational summaries.
- Security and service data: server logs, session identifiers, CAPTCHA redemption records, request timing, error information, and information needed to detect abuse and maintain availability.
- Communications: verification, password-reset, and service emails, plus information you choose to send when requesting support.
3. Audio and microphone behavior
Ambient synthesis and audio parameter changes run primarily in your browser. Resona does not upload the generated audio stream merely because you listen. If you use voice input, your browser’s speech-recognition feature may process audio under the browser or operating-system provider’s terms. Resona receives the resulting transcript as an AI prompt; it does not intentionally store the raw microphone recording.
4. Why we process information
We process information to create and authenticate accounts; verify email; synchronize Exabyte profiles; provide audio, storage, AI, and personalization features; preserve requested settings and history; prevent fraud and abuse; enforce account controls; send transactional messages; diagnose failures; comply with law; and protect users and the Service.
Depending on applicable law, these activities rely on performing the service you request, your consent, legitimate interests in security and reliable operation, and compliance with legal obligations. You may withdraw consent where consent is the applicable basis, without affecting earlier lawful processing.
5. Service providers and disclosures
Information is disclosed only as needed to operate requested features:
- OpenAI-compatible AI provider configured by Resona: receives prompts and the limited workspace context needed to perform an AI request.
- Exabyte Accounts: authenticates linked users and sends signed profile or lifecycle updates.
- Resend: delivers verification, password-reset, and account emails when configured.
- Hosting and infrastructure providers: store or transmit the application, database, session data, backups, and logs.
- Legal or safety recipients: information may be disclosed when reasonably necessary to comply with law, protect rights and safety, investigate abuse, or respond to valid legal process.
CapJS human verification is hosted by Resona. We do not sell personal information, share it for cross-context behavioral advertising, or use third-party advertising cookies.
6. Cookies and sessions
Resona uses an essential, HttpOnly session cookie to keep you signed in, protect forms, and retain short-lived authentication transactions. Session contents are stored server-side, using Redis in production. The Service does not currently use analytics or advertising cookies.
7. Retention
Account information, workspace files, playback history, and AI history are generally kept while the account exists or until removed through an available control. Verification and reset records expire according to their security purpose. Operational logs and security records are kept only as long as reasonably needed for security, debugging, legal compliance, and service integrity.
When Exabyte marks an account anonymized, Resona blocks access immediately and schedules deletion of the local account, workspace, history, and avatar after seven days. A final administrator may be retained in a blocked state until another administrator exists so the deployment is not left unmanaged. Backups may retain limited copies temporarily until their normal rotation completes.
8. International processing
Resona, Exabyte Accounts, email delivery, AI providers, and hosting providers may process information in different countries or regions. Where applicable law requires it, the operator should use appropriate contractual, organizational, or legal safeguards and obtain required consent before transferring personal information across borders.
9. Security
Resona uses measures including HTTPS, password hashing, server-side sessions, CSRF protection, CAPTCHA checks, protected user workspaces, encrypted administrative secrets, signed webhook validation, file limits, and restricted AI file access. No system is completely secure, so we cannot guarantee absolute security.
10. Your choices and rights
Depending on your location, you may have rights to access, correct, delete, restrict, or obtain a copy of personal information; object to certain processing; withdraw consent; or complain to a data-protection authority. You can edit available local profile fields, manage linked Exabyte information through Exabyte Accounts, unlink Exabyte where a working local password remains, or request account deletion. We may need to verify your identity before completing a request.
11. Children
Resona is not directed to children under 14 and does not knowingly permit them to create or independently use an account. A minor who is otherwise permitted to use the Service must have any consent or guardian authorization required by applicable law. Contact us if you believe a child’s information was provided improperly.
12. Demo privacy
The Demo is shared and should be treated as public demonstration space. Do not submit personal, confidential, medical, financial, or otherwise sensitive information. Demo content can be reset remotely and is not intended for lasting storage.
13. Policy changes
We may update this Policy when data practices, providers, or legal requirements change. The current effective date and version appear above. Material changes will receive reasonable notice and may require renewed acknowledgement.
14. Contact
For privacy questions or requests, contact the Resona maintainers through Resona GitHub Issues. Because issues are public, do not include passwords, API keys, health information, identification documents, or other sensitive personal information. Ask the maintainers to provide a private contact channel when sensitive information is required to verify or complete a request.