Privacy Policy
Last updated: November 11, 2025
1. Introduction
SINK ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application, website, and browser extension (collectively, the "Service").
2. Information We Collect
2.1 Information You Provide
- Account information (username, email address, profile picture)
- Comments and reactions you post
- Room creation and participation data
- Payment information (processed securely through Stripe)
2.2 Audio Data
IMPORTANT: SINK never stores your raw audio recordings.
- We use your device's microphone for auto-sync functionality (ASR/ACR)
- Audio is processed in real-time to generate short audio fingerprints (6-10 seconds)
- Only fingerprints are sent to our servers, not raw audio
- Audio samples are discarded immediately after matching
- No audio recordings are stored on our servers
2.3 Automatically Collected Information
- Device information (platform, OS version, device model)
- Usage data (features used, session duration, interactions)
- Analytics data (via PostHog, anonymized where possible)
- Technical logs (errors, performance metrics)
3. How We Use Your Information
- Provide and maintain the Service
- Enable time-coded comment synchronization
- Process payments and manage subscriptions
- Moderate content for safety and compliance
- Send notifications and updates
- Improve our services through analytics
- Comply with legal obligations
4. Third-Party Services
We use the following third-party services:
- Supabase: Authentication, database, and real-time features
- Stripe: Payment processing
- PostHog: Analytics and product insights
- TMDB: Movie and TV show metadata (see Attribution page)
- OpenSubtitles: Subtitle data for sync (see Attribution page)
These services have their own privacy policies. We encourage you to review them.
5. Data Retention
- Raw audio buffers: Never persisted (ephemeral, in-memory only)
- Audio fingerprints: Retained for 30 days for sync functionality
- Comments: Retained until you delete them or your account
- Account data: Retained until account deletion
- Logs: Retained for 90 days (sanitized, PII removed)
6. Your Rights
Depending on your location, you may have the following rights:
- Access: Request a copy of your personal data
- Deletion: Delete your account and associated data
- Correction: Update or correct your information
- Portability: Export your data in a machine-readable format
- Opt-out: Disable analytics tracking (EEA users)
- Objection: Object to processing of your data
To exercise these rights, contact us at privacy@sink.chat or use the account deletion feature in Settings.
7. Data Security
We implement industry-standard security measures:
- TLS encryption for all data in transit
- Encryption at rest for stored data
- Row-level security (RLS) policies on user data
- Regular security audits and updates
- Least-privilege access controls
8. Children's Privacy
Our Service is not intended for users under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe we have collected information from a child under 13, please contact us immediately.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date.
10. Contact Us
If you have questions about this Privacy Policy, please contact us at:
Email: privacy@sink.chat
Support: support@sink.chat