Privacy and security
Local operation
Speaker Volume Bridge communicates directly with Sonos devices on the local network. Normal volume synchronization does not require an online account or an Internet connection.
The app does not include advertising, analytics, or publisher telemetry. It does not automatically upload configuration or log files. Recognized releases can make a bounded HTTPS request to the public project update catalog; automatic checks can be disabled in Settings.
Information used by the app
The app accesses only what it needs to discover devices, show status, remember choices, and synchronize controls:
- Sonos device identity, friendly name, local address, volume, mute, and supported settings.
- Selected Windows, macOS, or Ubuntu audio-output identity, volume, and mute.
- Application preferences such as device selection, synchronization direction, mapping, maximum volume, startup behavior, and diagnostic level.
- Update preferences and the last attempt, last successful check, and last-notified edition/version.
It does not intentionally collect names, email addresses, contacts, payment details, precise location, authentication credentials, or audio content.
Local files
Configuration and diagnostic logs are stored in the operating system’s per-user application-data locations. Logs can contain local device or network identifiers needed to diagnose a failure.
Resetting Settings returns the configuration to defaults. Uninstall behavior depends on the platform and distribution. See Updating and uninstalling.
Old-app removal
The app does not inspect running processes to look for the former Sonos Volume Bridge app. Follow Upgrading and remove the old app and its startup entry manually so two installations do not send conflicting controls.
Sharing diagnostics safely
Treat exported diagnostics and logs as private until reviewed. Do not publish raw logs, IP or MAC addresses, device IDs, computer or speaker names, local paths, crash dumps, or screenshots containing those values in a GitHub issue.
For the complete policy, read the v1.6.3 Privacy Policy.
Network protections
The Sonos client accepts only local HTTP device locations using private, loopback, or link-local literal IP addresses. Public addresses and host names from discovery responses are rejected. Protocol responses are bounded and control requests use short deadlines.
Install releases only from the official GitHub repository or an official store listing.
Update catalog requests
Update checks request the public catalog from svb.miguel.ms. They contain no
speaker or configuration data, analytics, advertising data, or persistent
installation identifier. The website host can receive ordinary request metadata
such as the public IP address, time, catalog path, and network headers. The app
accepts only a bounded, valid catalog and approved HTTPS project or Store links.
See Update checks.
Schedules and desktop notifications
The weekly Night schedule and notification preference are stored locally. Scheduling uses the computer’s time zone and selected speaker. Native notification permissions are requested when you opt in; notification denial or desktop suppression does not stop synchronization or scheduling.
Project website and security reports
The desktop app has no publisher analytics. The separate project website offers consent preferences for optional website tracking; these are separate from app settings. See the website privacy policy.
For a suspected vulnerability, follow the Security Policy and use private reporting rather than publishing details in an issue.