Sonic Canvas · Gear Tracker

Privacy Policy

Effective 8 August 2026 · Updated 9 August 2026 · [email protected]

The short version. Gear Tracker requires a free account, and your ledger lives in it — stored on our servers and synced to every device you sign in on, with a working copy in your browser so the app is fast and works offline. We store exactly what sync needs and nothing else: no ad tech, no fingerprinting, no cross-site tracking, one session cookie. The only measuring we do is anonymous and aggregate — cookieless page-view counts and daily totals like "how many people signed up", never profiles of people (section 4). Photos have their hidden location data stripped on your device before upload. Payment details go to Paddle and never touch our servers. Deleting your account really deletes everything, and you can export your whole collection as a file at any time.

1. Who is responsible

The data controller is Ásgeir Þrastarson, Iceland — the individual who builds and runs Gear Tracker (soniccanvas.app) under the Sonic Canvas name. Contact for anything in this policy: [email protected].

2. Where your data lives

Gear Tracker requires an account. Your ledger — items, events, photos, rigs, plus your currency choice and insurance-schedule selections — is stored on our servers (section 3) and synced to every device you sign in on. Losing or replacing a device does not lose your ledger.

Your browser also keeps a complete working copy (in IndexedDB, on your device) so the app opens instantly and works offline. That copy is a cache of your account: it stays on the device until you erase it from the Account page, and changes made offline sync up when the connection returns. Anything logged in this browser before accounts were required is adopted into your account the first time you sign in — never wiped.

3. What we store when you have an account

Account

Your collection

Pages you choose to publish

Operational records

4. What we deliberately don't do

5. Who processes data for us

6. Why we may lawfully do this (GDPR Article 6)

7. How long we keep things

8. Your rights

Under the GDPR (which applies to us as an Iceland-based, EEA-serving service) you have the right to:

For anything not self-serve, email [email protected] and it will be handled within a month, as the GDPR requires. You also have the right to complain to a supervisory authority — in Iceland that is Persónuvernd (personuvernd.is), or the data protection authority of your own country.

9. Security, honestly stated

Traffic is encrypted in transit (TLS). Passwords are stored only as hashes. Sessions are server-side and revocable. The service runs on Cloudflare's infrastructure, and the API refuses requests that don't belong to the signed-in account — every query is filtered by the session's user, never by anything the client claims. No system is breach-proof and we won't pretend this one is; what we can say is that the design keeps the blast radius small: no card data, no location data, no tracking profiles, and the most personal thing on the server is what your gear cost you.

10. Children

Gear Tracker is not directed at children under 13, and we do not knowingly hold accounts for them.

11. Changes

If this policy changes materially, the change will be announced in the app or by email to account holders before it takes effect, and the date above will move. The current version always lives at this address.