Legal
Privacy Policy
Last updated June 6, 2026
Sonder is an add-in for Microsoft Outlook that surfaces a Rock RMS person’s profile and an AI briefing alongside the email you’re reading. This policy explains what information Sonder processes, why, and the choices available to you. It applies to the Sonder website, the Outlook add-in, and the admin dashboard (together, the “Service”).
1. Who we are
The Service is provided by FifteenTwentyTwo (“Sonder,” “we,” “us”). You can reach us at privacy@fifteentwentytwo.co.
2. Our role — controller vs. processor
Sonder is sold to churches and ministry organizations (each, an “Organization”) that use Rock RMS. The Organization decides what data lives in its Rock instance and who may access it. For that congregant and staff data, the Organization is the data controller and Sonder acts as a data processor, processing it only on the Organization’s behalf and instructions to provide the Service.
Sonder is the controller only for the limited account and operational data we collect directly — for example, an administrator’s login details and our diagnostic logs. Where an Organization requires a Data Processing Addendum (DPA), contact us at the address above.
3. Information we process
Account & administrator data
When an Organization is set up, we store the administrator’s name, email address, role, and the Organization’s name and Rock connection settings. An Organization’s Rock API credentials and AI provider keys are encrypted at rest.
Rock RMS profile data
To show you the person behind an email, Sonder reads data from your Organization’s Rock RMS instance, which can include: names and contact details; family and household relationships; group and ministry involvement; event registrations; and registration payment / giving status. This data may reveal religious affiliation and may relate to children. We process it only to present profiles and briefings to authorized staff of the same Organization, never to build a cross-Organization profile.
Outlook message data
While you have the add-in open on a message, Sonder reads the message’s sender and recipient addresses and display names, its subject, and its body text, plus your own mailbox address and name (to tell “you” apart from the sender). This is used to match the correspondent to a Rock person and to generate the AI briefing for the message in front of you.
Microsoft identity
Inside Outlook, Sonder verifies your identity through Microsoft Entra (Nested App Authentication). We receive your work email, display name, and tenant identifier from the Microsoft-issued token so we can enforce that only authorized staff of your Organization see Rock data.
AI processing data
When the AI briefing or chat is used, the relevant email content and the matched Rock profile are sent to the Azure OpenAI (Microsoft Foundry) deployment that your Organization configured with its own key. That request is processed under Microsoft’s enterprise terms for Azure OpenAI, which provide that prompts and outputs are not used to train Microsoft or OpenAI foundation models. Sonder does not use your content to train any model.
Diagnostics & session replay
We collect technical logs (for example, a build-version beacon and authorization events) to operate and secure the Service. We also use LogRocket session replay to record how the add-in is used — interactions, console and network metadata, device and browser information. Depending on configuration, replays may also capture content displayed on screen, which can include personal information. Authentication tokens are stripped from recorded network traffic. Sessions are attributed to the signed-in user and Organization. If your Organization does not want this content captured, contact us — masking can be tightened or session replay disabled.
Cookies & local storage
We use strictly necessary cookies and browser storage to keep you signed in and remember preferences (such as light/dark theme). We do not use advertising or cross-site tracking cookies.
4. How we use information
- To provide the Service — match correspondents to Rock people and generate briefings.
- To authenticate users and enforce per-Organization, per-user access.
- To secure, monitor, debug, and improve the Service.
- To communicate about the account, including administrator invitations.
- To comply with legal obligations.
5. Automated processing
The AI briefing and chat generate text to assist staff. Output can be inaccurate or incomplete and is intended as a starting point — staff should verify it before relying on or acting on it. Sonder does not make automated decisions that produce legal or similarly significant effects about any individual.
6. Subprocessors & third parties
We share information with service providers who process it on our behalf under contract, and with the providers your Organization connects:
| Provider | Purpose | Location |
|---|---|---|
| Microsoft (Entra, Outlook/Office, Azure OpenAI) | Identity verification; in-mailbox add-in runtime; AI processing on your Organization’s own Azure resource | Per your Microsoft tenant |
| Railway | Application hosting and managed PostgreSQL / Redis databases | United States |
| LogRocket | Product analytics and session replay | United States |
| Resend | Transactional email (e.g. administrator invitations) | United States |
Your Organization’s Rock RMS instance is operated by your Organization, not by Sonder. We do not sell personal information, and we do not share it for cross-context behavioral advertising.
7. International transfers
Sonder is operated from the United States and information is processed there. If your Organization or its data subjects are located outside the United States, transfers are made under an appropriate safeguard such as the Standard Contractual Clauses. [Confirm transfer mechanism with counsel for your target markets.]
8. Data retention
Email and profile data read to render a briefing are processed transiently to answer your request and are not stored as a standing copy by Sonder beyond what is needed to operate the Service. Account data is retained for the life of the Organization’s account; diagnostic and session-replay data are retained for a limited period and then deleted in the ordinary course. On account termination we delete or return Organization data as described in the Terms and any applicable DPA.
9. Security
We protect information with measures including encryption in transit (TLS), encryption at rest for stored Organization secrets, verified per-user identity inside Outlook, and access controls that fail closed when authorization cannot be confirmed. No method of transmission or storage is perfectly secure, but we work to protect your information and to limit access to those who need it to operate the Service.
10. Your rights
Depending on where you live, you may have rights to access, correct, delete, or restrict the use of your personal information, to data portability, and to withdraw consent. Because most personal information in Sonder belongs to an Organization’s Rock instance (for which the Organization is the controller), requests from congregants or staff should be directed to the relevant Organization; we will assist the Organization in responding. For data for which Sonder is the controller, contact privacy@fifteentwentytwo.co.
11. Children’s data
Sonder is a tool for Organization staff and is not directed to children. An Organization’s Rock data may include information about minors (for example, children registered for events). Sonder processes that data only on the Organization’s instruction; the Organization is responsible, as controller, for any consents or notices required for minors’ data under applicable law.
12. U.S. state privacy rights
We do not sell or share personal information as those terms are defined under the California Consumer Privacy Act (as amended) or comparable U.S. state laws. Residents of states with applicable privacy laws may exercise the rights described in Section 10. We will not discriminate against you for exercising your rights.
13. EU/UK data protection
Where the EU or UK GDPR applies, Sonder generally acts as a processor on the Organization’s behalf; the Organization determines the legal basis for processing congregant and staff data. Where Sonder is a controller (account and diagnostic data), our legal bases are performance of a contract and our legitimate interests in operating and securing the Service. A DPA incorporating the Standard Contractual Clauses is available to Organizations on request.
14. Changes to this policy
We may update this policy from time to time. Material changes will be reflected by updating the “Last updated” date above and, where appropriate, by notifying Organization administrators.
15. Contact us
Questions about this policy or our data practices? Email privacy@fifteentwentytwo.co.