On this page
SonaPin does not intentionally send your badge profile, QR payload, or VRM file to us or Sentry. Sentry-enabled builds send crash, hang, and related device diagnostics to Sentry for app functionality; Sentry may infer an approximate location from the network connection. SonaPin does not request device location or use this approximate location for app features, advertising, or tracking. The TestFlight build 1 released September 22, 2026, does not include Sentry. Apple separately processes App Store, backup, crash, and diagnostic information under its policies. TestFlight crash reports are shared with the developer automatically; App Store crash reports depend on your diagnostics-sharing choice.
1. Who we are
SonaPin is operated by MrDemonWolf, Inc., 645 3rd St, Beloit, Wisconsin 53511, United States. For privacy questions or requests, email legal@mrdemonwolf.com.
This policy covers the SonaPin iOS app, this documentation website, and information you choose to send to SonaPin support.
2. Data the app processes on your device
SonaPin processes the following information locally to create and display your badge:
| Local data | Why SonaPin uses it |
|---|---|
| Badge profile | Display name, pronouns, species or character type, and an optional tagline appear on your badge. |
| QR content | Your selected website, social link, contact link, or custom text is converted into a QR code on your device. |
| Avatar | An optional VRM file is copied into SonaPin’s private app storage. SonaPin reads model, author, license, rig, expression, animation, and checksum metadata to validate and render it. |
| Preferences | Theme, contrast, haptics, motion, interaction, display, and onboarding choices keep the app working as you configured it. |
Badge information is not intentionally uploaded to MrDemonWolf, Inc. or Sentry. SonaPin does not open your QR destination, remotely load avatar resources, or send profile or model files to an analytics service.
Crash and hang diagnostics
In Sentry-enabled builds, the app sends crash reports, hang reports, and related diagnostic details to Sentry so we can investigate and fix failures. These reports may include a device-level identifier, a stack trace, app version, device model, operating-system version, and the time of the failure. SonaPin has no account system and does not associate that identifier with your badge profile or other identifying details. Sentry may also infer approximate location from the network IP address; SonaPin does not request device location or use this information for app features, advertising, or tracking. The SDK is configured without screenshots, screen recordings, automatic breadcrumbs, session tracking, product analytics, or default personal identifiers. We do not add your profile, QR content, or avatar file to reports. An unexpected error message may still contain information involved in that failure, so please avoid placing sensitive information in a support report.
We use diagnostic data to maintain app functionality and security, based on our legitimate interests where applicable (GDPR and UK GDPR Article 6(1)(f)). Sentry processes reports for us under its retention and security settings. Email legal@mrdemonwolf.com to ask about a diagnostic report or request deletion where applicable. The older TestFlight build 1 uses Apple's crash reporting only.
Legal basis, choices, and automated decisions
Where the GDPR or UK GDPR applies, local processing is necessary to provide the app functions you request and to perform our agreement with you, or to take steps at your request before that agreement (Article 6(1)(b)). A display name and valid QR payload are required to create a working badge; the avatar, pronouns, character details, tagline, and preference choices are optional. If you do not provide required badge information, SonaPin cannot create that badge.
MrDemonWolf, Inc. does not receive this on-device badge information, and the app has no automated decision-making or profiling that produces legal or similarly significant effects.
3. Information you choose to make visible
SonaPin is a digital badge. People nearby can read, scan, photograph, or screenshot the profile and QR information you display. A QR code may contain personal information or lead to a third-party service. Add only information you intend to share. SonaPin cannot revoke copies made by another person or control what a destination website does after someone opens it.
4. Avatar files and Files providers
When you select a VRM, Apple’s document picker gives SonaPin temporary access to that file. SonaPin validates it, makes an app-managed local copy, and releases access to the selected source. Removing an avatar or deleting SonaPin data removes the app-managed copy, not the original file in Files, iCloud Drive, or another provider.
Your Files provider handles its own storage and may process information under its own privacy policy. SonaPin does not persist access to the source file.
5. Retention and deletion
Local data remains in SonaPin’s Application Support directory until you edit or replace it, remove the imported avatar, choose Delete All Local Data in Settings, or uninstall the app. Delete All Local Data removes SonaPin’s saved profile, QR settings, preferences, onboarding state, app-managed avatar, and local recovery or temporary files from the app’s data directory.
Apple device or iCloud backups may retain app data according to settings and retention rules you control with Apple. Copies held by your Files provider, QR scanners, screenshots, or other people are outside SonaPin’s control.
Deleting local app data does not automatically remove a diagnostic report already sent to Sentry. Contact us if you want us to locate or delete a report where possible.
6. Website and support information
This static site uses no SonaPin analytics, advertising, account system, contact form, or marketing cookies. GitHub Pages hosts the site and may process request information such as an IP address, browser details, and security logs as an independent controller under GitHub’s Privacy Statement. MrDemonWolf, Inc. does not receive GitHub’s raw request logs for this site.
If you email support or legal, we receive the address, message, and any details or attachments you choose to send. We use that information to answer your request, troubleshoot, prevent abuse, and meet legal obligations. Where European privacy law applies, our basis is performance of our agreement or steps you request (Article 6(1)(b)), our legitimate interests in supporting and securing SonaPin (Article 6(1)(f)), or compliance with law (Article 6(1)(c)). Support information is optional, but without an email address and enough detail we may be unable to respond. We normally delete support correspondence 24 months after the last activity unless an active security, dispute, accounting, or legal need requires a longer period.
7. Providers, sharing, and transfers
- Apple independently distributes the app and processes App Store, purchase, crash, backup, or diagnostic information under its policies. TestFlight crash reports are shared with us automatically; App Store diagnostics depend on your sharing choice.
- Sentry receives crash, hang, and related diagnostic reports from Sentry-enabled builds as our processor. See Sentry’s Privacy Policy.
- GitHub independently hosts this public site and source repository in the United States under its Privacy Statement.
- Email and infrastructure providers act for us to receive, secure, and answer messages you choose to send. We require providers acting on our behalf to protect that information consistently with this policy and applicable law.
- VRMKit runs inside the app to parse and render compatible avatars. It does not receive your model from SonaPin.
We do not sell personal information or share it for cross-context behavioral advertising. Because SonaPin does not track you, Global Privacy Control and Do Not Track signals do not change the app or site’s behavior. Website and support information may be processed in the United States. Apple and GitHub describe safeguards for transfers they control in their own notices. Where MrDemonWolf, Inc. is responsible for an international transfer, we use a lawful transfer mechanism when applicable; contact us for information about the safeguards relevant to your request.
MrDemonWolf, Inc. is established in the United States. If applicable law requires us to appoint a representative in another jurisdiction before covered processing begins there, we will publish that representative’s contact details in this policy.
8. Your privacy rights
Because MrDemonWolf, Inc. cannot access data that exists only inside SonaPin on your device, use the app’s edit, remove, and Delete All Local Data controls to manage it. For information we do hold, such as support correspondence, applicable law may give you rights to access, correct, delete, restrict, object, or receive a portable copy. You may also withdraw consent where consent is the processing basis.
Send requests to legal@mrdemonwolf.com. We may need to verify your identity before acting. EU and UK residents may complain to their local data-protection authority. California residents may request access, correction, or deletion; we do not sell or share personal information and will not discriminate against anyone for exercising privacy rights.
9. Children
SonaPin is a general-audience app and is not directed specifically to children under 13. The local app does not create accounts or send a child’s badge data to MrDemonWolf, Inc. Anyone who is not old enough to accept these terms or provide consent under local law should use SonaPin only with a parent or guardian. Children under 13 should not email support without a parent or guardian. If we learn that we received a child’s personal information through support, a parent or guardian can contact legal@mrdemonwolf.com for a verified deletion request.
10. Security
SonaPin stores its working files in the app’s private iOS container and relies on Apple’s app sandbox, device security, and data-protection features. No storage or transmission method is perfectly secure. Protect your device, review what you place in a QR code, and avoid sending sensitive model or QR data in a support email unless it is necessary.
11. Changes to this policy
If SonaPin adds accounts, cloud sync, product analytics, advertising, or another material data practice, this policy and the App Store privacy disclosure will be updated before that version is released. If a change materially reduces your privacy, we will provide a conspicuous in-app notice before it takes effect and request fresh consent where law requires it. Changes apply prospectively. The effective date at the top shows the latest revision.
12. Contact
MrDemonWolf, Inc.645 3rd St
Beloit, WI 53511
United States
legal@mrdemonwolf.com