Terms of Service
These terms govern your use of Sonela. They are written in plain language on purpose — you should be able to read them once and know what you are agreeing to. Where a term carries a real consequence, it says so in the same sentence rather than in a schedule somewhere else.
1. Who these terms are between
"Sonela", "we" and "us" mean the operator of the Sonela service. "You" means the organisation that opens a workspace, and anyone using that workspace. If you accept these terms for an organisation, you confirm you are authorised to do so.
Sonela is operated from Albania and is currently in private beta with no paid subscriptions. The full company registration details — legal entity name, registration number and registered address — are published on this page before the service leaves private beta and accepts payment.
2. What the service is
Sonela is an AI assistant you embed in your own web application with a script tag. It answers questions by reading data from a database you connect, using an AI model you supply the key for.
- Read-only. There is no code path in the service that writes to your database. This is enforced by a query validator, a read-only transaction and the database role you create. The security one-pager describes each layer and names the file that implements it.
- Grounded in a schema you approve. Nothing is queried until you have reviewed the schema we introspect and approved it. What you hide stays hidden.
- Not a system of record. Sonela reads your data to answer a question. It is not a backup, an archive, or a place to keep anything.
3. Your account and your credentials
You are responsible for what happens in your workspace, including the acts of anyone you invite into it. Keep sign-in credentials, widget keys and API keys confidential, and tell us promptly if you believe one has been exposed.
You choose the database credentials you give us. We ask for a least-privilege, SELECT-only role and provide the script that creates one; if you supply a more privileged credential instead, the additional exposure is yours, not ours.
4. Acceptable use
You agree not to use Sonela to:
- break the law, or infringe anyone's rights;
- access data you are not entitled to access, including by attempting to defeat the tenant isolation the service applies to every query;
- probe, scan or attack the service or its infrastructure, except that we welcome good-faith security research reported to us before it is published;
- resell or expose the service to third parties as a standalone product rather than as an assistant embedded in your own application;
- circumvent quotas, or use automated means to generate questions at a volume the service is not priced for.
5. Your data, and our role
You own your data. We do not acquire any right to it beyond what is needed to run the service for you.
For personal data inside your database, you are the controller and we are a processor: we act on your instructions. That relationship is set out in the data processing agreement, which forms part of these terms once you are on a paid plan.
- Questions and the rows that answer them pass through our service, and reach the AI provider you selected. They are not written to our storage.
- Chat transcripts are held in the end user's browser for the length of the conversation. We keep none.
- Our usage records store counts, timings and token totals — never the text of a question, an answer, or a query.
- Your database credentials and provider keys are encrypted at rest and decrypted only in memory to serve a request. No API we expose returns them.
- We do not train any model on your data, and we do not use it to improve the service for anyone else.
You may export your configuration and delete your workspace at any time. Deleting a workspace removes its configuration and credentials; usage counters are retained in aggregate for billing and accounting records.
6. AI answers, and what they are worth
This is the clause worth reading twice. Sonela composes answers using an AI model. The service is designed to answer only from query results and to say when it cannot — but no AI system is correct every time, and an answer that reads confidently can still be wrong.
Answers are informational. Do not use them as the sole basis for a decision with financial, legal, medical, safety or regulatory consequences without checking the underlying data. You remain responsible for decisions made in reliance on an answer.
7. Your AI provider
You bring your own key for the AI provider you choose. Your relationship with that provider is directly with them, under their terms and their data processing agreement. We pass your questions and query results to the endpoint you configured and nowhere else.
We are not responsible for a provider's availability, pricing, model changes, or what they do with data under the agreement you hold with them. If a provider changes in a way that breaks the service, we will tell you what we know.
8. Trials
A trial workspace runs for 14 days or 200 answered questions, whichever comes first. No card is required to start one.
When a trial ends the workspace pauses: the assistant stops answering, and everything you configured — schema approvals, provider keys, branding, grounding context — is preserved and resumes the moment you choose a plan. We will email you before and when this happens. If you do not choose a plan, we may delete a paused workspace after 90 days, with notice first.
9. Fees, billing and taxes
- Subscription fees are as shown on our pricing page at the time you subscribe, in USD, excluding VAT and any other applicable tax.
- Payments are processed by Paddle, who act as merchant of record and whose terms cover the payment itself. Your invoice comes from them.
- Subscriptions renew automatically for the same period until cancelled. You can cancel at any time from your dashboard, effective at the end of the period you have paid for.
- Fees already paid are not refunded pro rata when you cancel, except where the law gives you a refund right or where we have failed to provide the service.
- What you pay your AI provider is separate, is billed by them, and does not pass through us — which is why our price does not move when your usage does.
- We may change prices with at least 30 days' notice before the change applies to your next renewal.
10. Availability and support
We aim to keep the service available and will give reasonable notice of planned maintenance. During the private beta we do not offer a service level agreement, and you should not build a process that cannot tolerate the assistant being briefly unavailable.
Support is by email at the address in section 16, at the level shown for your plan.
11. Changes to the service
The product is actively developed and will change. We will not remove a capability you rely on, or make a change that materially reduces the service, without at least 30 days' notice. If such a change is unacceptable to you, you may cancel and we will refund the unused part of the period you have paid for.
12. Suspension and termination
You may stop using the service and close your workspace at any time. We may suspend or terminate a workspace if you materially breach these terms, if fees go unpaid after notice, or if continuing would expose us or others to legal risk or a security threat. Except where the risk requires acting immediately, we will tell you first and give you a chance to put it right.
13. Intellectual property
We own the service, its software and its brand. You own your data, your schema configuration, and anything you author in the product. Nothing here transfers ownership either way. You may not copy, reverse engineer or create derivative works from the service, except where the law says you may despite this clause, and except for the components we publish under an open source licence — which are governed by that licence.
If you send us feedback, we may use it to improve the product without owing you anything for it.
14. Warranties and liability
The service is provided "as is". Beyond what these terms say and what the law requires, we do not give warranties — including that the service will be uninterrupted, error-free, or that any particular answer will be accurate.
Neither party is liable for indirect or consequential loss, or for lost profits, revenue, goodwill or anticipated savings. Our total liability arising out of or in connection with these terms is limited to the fees you paid us in the 12 months before the event giving rise to the claim — or, if you are on a free trial and have paid us nothing, to EUR 100.
Nothing in these terms limits liability that cannot lawfully be limited, including for death or personal injury caused by negligence, or for fraud.
15. Changes to these terms, and governing law
We may update these terms. For a material change we will give at least 30 days' notice by email and update the version and date at the top of this page; continuing to use the service after the change takes effect means you accept it. If you do not accept it, you may cancel before it takes effect.
These terms are governed by the law of Albania, and the courts of Tirana have jurisdiction — except that if you are a consumer, you keep the protections and the forum that the mandatory law of your country of residence gives you.
If any clause turns out to be unenforceable, the rest of these terms continue to apply. These terms, together with the data processing agreement once it applies, are the whole agreement between us about the service.
16. Contact
Questions about these terms, about a security issue, or about anything else: hello@sonela.cloud. We answer.
Plain terms, on purpose.
If a clause here is unclear, that is a defect in the writing and we would like to know. The same principle governs the security one-pager: a document nobody can check is not a commitment.