SUN
Create newSearchMy spaceCatalogBlogSUN API
Recent

Nothing yet

Log in
© 2026 Blue Energy People, Inc.PrivacyTerms & ServiceContact usCareers

Privacy Policy

Last updated August 5, 2026

What SUN collects when you make a course, why we collect it, and what you can ask us to delete.

On this page

  1. 1. Who we are
  2. 2. Information we collect
  3. 3. How we use it
  4. 4. How generation works
  5. 5. Service providers
  6. 6. How long we keep it
  7. 7. Your choices
  8. 8. Security
  9. 9. Children
  10. 10. International transfers
  11. 11. Changes to this policy

1. Who we are

Blue Energy People, Inc. builds and operates SUN. This policy explains how we handle personal information across the SUN web app, the mobile app, and the Sun Public API. It applies to everyone who signs in, and to the small amount of data we collect from visitors who do not.

2. Information we collect

  • Account information

    Your email address, and the display name and avatar you choose. If you sign in with a third-party provider, we receive the basic profile that provider returns and nothing more. We never see your password.

  • Prompts and source material

    The topic you type into the composer, and any text you paste or upload as source material for a course. This is the raw input to generation, so we store it alongside the course it produced.

  • Generated courses and audio

    The scripts, chapter structure, cover art, and audio files that generation produces, plus the settings you chose (format, voice, length).

  • Voice recordings

    If you create a cloned voice, we store the sample recordings you submit and the resulting voice model. We only ever create a clone from a recording you deliberately upload for that purpose.

  • Listening and usage activity

    Which courses you play, how far through them you get, what you search for, and which features you use. This is what powers your library, your recents rail, and resume-where-you-left-off.

  • Technical data

    IP address, browser and device type, and timestamped logs of requests to our servers. We use these for security, abuse prevention, and debugging.

  • API tokens

    If you use the Sun Public API, we store a hash of each personal token you create along with its label and last-used time. We do not retain the token secret itself after you first see it.

3. How we use it

We use the information above to:

  • Generate the courses you ask for and deliver the finished audio to you.
  • Keep your library, playback position, and preferences in sync across devices.
  • Authenticate you, enforce quotas, and protect accounts from abuse.
  • Diagnose failures (a generation job that errors is much easier to fix when we can see the prompt that produced it).
  • Understand which features get used, in aggregate, so we know what to build next.
  • Send you service messages, such as a notice that a long-running generation has finished.

We do not sell personal information, and we do not use your prompts, uploads, or voice recordings to train our own general-purpose models.

4. How generation works

Creating a course sends your prompt and any source material you provided to our generation service, which in turn calls third-party language and text-to-speech models to write the script and voice it. Those providers process the content to return a result and are contractually barred from using it to train their models.

Generated audio is stored in our object storage so you can play it again later. Courses are private to your account unless you explicitly share one, at which point anyone holding the share link can listen to it.

5. Service providers

We keep the list of companies that touch your data deliberately short. Today it is:

  • Supabase

    Authentication, our primary database, and file storage for audio and images.

  • Language and speech model providers

    Generate course scripts, synthesize narration, and host cloned voices.

  • Mixpanel

    Product analytics. We send it pseudonymous event data, meaning which screens and features were used, and deliberately do not send it prompt text, course content, or voice recordings.

  • Cloud hosting and CDN providers

    Run our servers and deliver audio files to your device.

We may also disclose information when the law requires it, or when we need to investigate fraud, abuse, or a threat to someone's safety. If we are ever party to a merger or acquisition, personal information may transfer as part of that transaction, and this policy travels with it.

6. How long we keep it

  • Courses, prompts, and audio stay until you delete them, or until you delete your account.
  • Cloned voices stay until you delete the voice. Deleting a voice removes both the sample recordings and the derived model.
  • Analytics events are retained in aggregated form and are not tied to your account after deletion.
  • Server logs are kept for a short operational window, on the order of weeks, and then discarded.

When you delete your account we remove your personal data from our production systems. Backups roll off on their own schedule, so a copy can persist there for a short period before it is overwritten.

7. Your choices

  • Delete any course, or any cloned voice, from within the app at any time.
  • Request a copy of the personal data we hold about you.
  • Ask us to correct information that is wrong.
  • Ask us to delete your account and the data attached to it.
  • Opt out of non-essential analytics by emailing us.

Depending on where you live you may have additional rights under laws such as the GDPR or the CCPA, including the right to object to certain processing and the right to lodge a complaint with your local data protection authority. Write to us and we will honor these requests regardless of where you are.

8. Security

Data is encrypted in transit and at rest. Access to production data is limited to the people who need it to operate the service, and row-level security rules in our database keep one account's content from being readable by another. No system is perfect, but we treat prompts and voice recordings as sensitive by default.

9. Children

SUN is not directed at children under 13, and we do not knowingly collect their personal information. If you believe a child has given us personal data, contact us and we will delete it.

10. International transfers

We operate from the United States and our providers may process data there and in other countries. Where required, we rely on standard contractual clauses or an equivalent safeguard to cover those transfers.

11. Changes to this policy

We will update this page when our practices change and move the date at the top. If a change materially affects how we use your information, we will tell you in the app or by email before it takes effect.

Questions about your data, or want to make a request? Reach us at hello@sunapp.ai.