Privacy Policy
Last updated: August 4, 2026
Knurdz ("we", "us") operates Sonar IDE through sonar.knurdz.org. We are committed to protecting your privacy. This Privacy Policy explains what personal information we collect when you visit our website, register a host account, pay for a subscription, download the Sonar Code Editor, or participate in a supervised session, and how we use and safeguard that information. By using our services, you consent to the practices described here.
1. Information we collect
Depending on how you use Sonar IDE, we may collect:
- Account and profile data: Name, email address, organization name, role, and authentication identifiers when you sign up or sign in (including email/password, Google, or GitHub OAuth via our auth provider).
- Billing and payment-related data: Subscription plan, transaction references, and payment status. Card and wallet details are collected and processed by PayHere; we do not store your full payment card number on our servers.
- Host and event data: Hackathon or event names, settings, invite links, restriction preferences, and telemetry aggregated for dashboards you access as a host.
- Participant monitoring data (desktop app): When participants use the Sonar Code Editor in a supervised context, the app may record activity signals such as window focus, keyboard activity metrics, clipboard events, active file paths, and session heartbeats. Authorized hosts can view this data in the admin portal or export reports. Much of this data is transmitted to our cloud backend (Appwrite) when online; local logs may also exist on the participant device.
- Website and support data: Messages you send through our Contact form, support emails, and basic technical logs (IP address, browser type, pages visited) used for security and service improvement.
- Cookies and local storage: Session cookies for authentication, theme preferences, and similar functional storage in your browser.
2. How we use your information
- Provide, maintain, and secure the website, host portal, and subscription services.
- Process payments and manage Pro and Enterprise billing through PayHere and related systems.
- Authenticate users and enforce event restrictions configured by hosts.
- Display live and historical monitoring dashboards, risk scores, and reports to authorized hosts.
- Respond to support requests and communicate about service changes, security, or billing.
- Detect fraud, abuse, and unauthorized access attempts.
- Improve Sonar IDE features and reliability using aggregated, non-identifying analytics where possible.
3. Legal bases and host responsibilities
Hosts who collect participant monitoring data are responsible for informing participants about supervision, obtaining any required consent, and complying with applicable laws (including education and employment rules in Sri Lanka and other jurisdictions where events are held).
We process host account and payment data to perform our contract with you and to meet legal obligations. We process monitoring telemetry as a data processor on instructions from the host organizing the event.
4. Information sharing
We do not sell your personal information. We may share data only:
- Service providers: Trusted vendors that help us operate Sonar IDE, such as cloud hosting (Appwrite), email delivery, and PayHere for payment processing. They may use data only to perform services for us under confidentiality obligations.
- Authorized hosts: Participant session data visible in the host dashboard is shared with the host account that created or manages the relevant event.
- Legal requirements: When required by law, court order, or to protect rights, safety, and security of users and the public.
- Business transfers: In connection with a merger, acquisition, or sale of assets, with notice where required by law.
5. Data retention and security
We retain account, billing, and event data for as long as your account is active and as needed for legal, accounting, and dispute-resolution purposes. Monitoring logs and reports may be retained according to plan limits and operational backups.
We use industry-standard technical and organizational measures to protect data, including encryption in transit (HTTPS), access controls on host accounts, and secure payment handling via PayHere. No online system is completely secure; please use strong passwords and notify us promptly of suspected unauthorized access.
6. Desktop app permissions
The Sonar Code Editor may request permissions necessary for supervised use:
- Network access: For authentication, cloud sync, collaboration (Yjs), and sending monitoring heartbeats when configured for hosted events.
- Activity monitoring: To log focus changes, typing metrics, and related signals during supervised sessions, as described in our documentation.
Participants should review event rules set by their host. Without required permissions, some supervised features may not function.
7. Your choices and rights
Depending on your location, you may have the right to:
- Access, correct, or delete personal data we hold about you (subject to legal exceptions).
- Object to or restrict certain processing, or withdraw consent where processing is consent-based.
- Request a copy of your data in a portable format where applicable.
To exercise these rights, contact contact@knurdz.org. Hosts may delete events and manage retention through the dashboard where available.
8. Third-party links
Our website may link to third-party sites (for example GitHub, Knurdz community pages, or documentation). We are not responsible for the privacy practices of those sites. Review their policies before providing personal information.
9. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top will change when we do. Significant changes may be communicated by email or a notice on the website. Continued use after updates constitutes acceptance of the revised policy.
10. Contact us
For privacy questions or requests, use our Contact page, email contact@knurdz.org, or call +94741175199. Related policies: Terms and Conditions and Return & Refund Policy.