← Back to sign in

Privacy Policy

Last updated: April 25, 2026

David Labs ("we", "us", "our") operates Sophia, an AI-powered tutoring platform. This Privacy Policy describes how we collect, use, store, and protect your information when you use our Service. We are committed to protecting the privacy of all users, especially children.

1. Information We Collect

We collect only the information necessary to provide and improve the Service:

Account Information

  • Name and email address (from Google OAuth)
  • Self-declared age range (under 13, 13-17, or 18+)
  • Account creation date

Session Data

  • Session duration, topic, and learner level
  • Exercise results and proficiency assessments
  • Mood and engagement signals (generated by AI, not user-reported)
  • Text transcripts of voice conversations
  • Device type and browser user agent

Payment Information

Credit card and payment details are collected and processed exclusively by Stripe, our third-party payment processor. David Labs does not store, access, or process your credit card numbers or banking information. Please review Stripe's Privacy Policy for details on their data handling practices.

2. Voice and Audio Data

Your voice is NOT recorded. Audio from your microphone is streamed in real-time to Google Cloud's Gemini API (Vertex AI) for processing. The audio stream exists only in-memory during your active session. No audio files, recordings, or voice samples are saved — not on our servers, not on Google's servers, not anywhere.

We use Google Cloud's Vertex AI (enterprise tier), which is contractually distinct from consumer Google products. Google does not use Vertex AI customer data to train or improve their models. Your conversations are processed, not retained by Google.

Text transcripts of voice conversations are generated during the session and may be retained for quality improvement and service operation purposes. These transcripts contain the text content of what was said, not the audio itself.

2A. Voice Enrollment (Biometric Signature)

Sophia uses voice enrollment to recognise returning learners and prevent abuse of the free service. For anonymous users (those who have not signed in with Google), voice enrollment is required to use the Service. Signed-in users are not required to enroll.

How consent is obtained

Sophia asks for your consent conversationally during your first session. The question is asked verbally by Sophia in plain language (e.g., "I'd save a small voice signature of yours. No recordings, just a fingerprint of how you sound. Is that okay?"). You respond verbally with a clear yes or no. You have up to 5 minutes to make your decision.

If you consent

  • We collect: approximately 5–10 seconds of audio during the consent conversation.
  • We derive: a voice signature — a mathematical vector of numbers, not audio.
  • We discard: the raw audio immediately after processing. Processing happens in-memory on our servers. No audio file is written to disk.
  • We store: the voice signature in Google Cloud Firestore (us-central1, Iowa, USA), tied to an anonymous identity record.
  • Retention: 180 days of inactivity, then the record is auto-deleted by a scheduled sweep. Active use extends retention.
  • Legal basis: your explicit verbal consent, given during the conversational enrollment flow, revocable at any time. This constitutes valid consent under GDPR Article 9 (explicit consent for biometric data) and PIPEDA Principle 3 (knowledge and consent).

If you decline

If you decline voice consent or do not respond within the decision window, Sophia will end the session. No audio is retained and no voice signature is created. You may still use Sophia by signing in with Google — signed-in users are not required to provide voice consent.

Consent audit trail

To demonstrate that consent was meaningfully obtained, we record the following for every consent interaction:

  • The version of the consent prompt Sophia used
  • The exact question Sophia asked
  • A text transcript of your verbal reply
  • The consent outcome (affirmative, declined, or equivocal)
  • A SHA-256 hash of the audio clip (a fingerprint proving what audio existed, not the audio itself)
  • Timestamp, session ID, and browser user agent

This audit trail exists so we can prove to regulators and to you that consent was asked for properly, answered clearly, and recorded accurately. It cannot be used to reconstruct your voice.

Deletion and your rights

  • Signed-in users: delete via Settings.
  • Anonymous users: delete via /privacy/me.
  • Email: privacy@davidlabs.ca. Self-serve deletions are processed immediately. Email requests are processed within 30 days.

Why we do this

Voice signatures prevent the same person from creating multiple free accounts, keeping fair access for everyone. They also let Sophia greet you by name and track your progress across sessions without requiring sign-in. Voice is both the identity mechanism and the abuse prevention gate — without it, we have no way to ensure fair use of the free anonymous service.

  • Location: processed in Google Cloud us-central1 (Iowa, USA).
  • Sharing: we never share voice signatures with any third party. Google Cloud provides the infrastructure only — it has no access to interpret the signature.

If you clear browser storage and lose access to your enrollment session, email privacy@davidlabs.ca to request deletion — we can locate records using reasonable efforts based on any identifiers you provide.

3. How We Use Your Information

  • To provide, operate, and improve the tutoring experience
  • To adapt difficulty, teaching style, and content to your level
  • To track usage for billing and credit management
  • To detect and prevent abuse, fraud, and security threats
  • To operate safety protocols that protect users (see Section 7)
  • To generate aggregated, de-identified analytics for service improvement
  • To comply with legal obligations

We do not sell, rent, or share your personal information with third parties for their marketing purposes. We do not use your data to train or fine-tune AI models.

4. Data Storage and Security

Your data is stored in Google Cloud Firestore, hosted in the United States (us-central1 region). All data is encrypted at rest (AES-256) and in transit (TLS 1.2+). We follow Google Cloud's security best practices, including identity and access management, audit logging, and network security controls.

Access to user data is restricted to authorized David Labs personnel on a need-to-know basis. We do not provide direct database access to third parties.

5. Third-Party Services

We use the following third-party services to operate Sophia:

  • Google Cloud Platform — Infrastructure, database (Firestore), and compute (Cloud Run)
  • Google Vertex AI (Gemini) — AI-powered tutoring and real-time voice interaction
  • Google OAuth — User authentication
  • Stripe — Payment processing for credit purchases
  • GitHub — Internal issue tracking for safety and bug reports (no user data is shared — only session metadata)

Each of these services has its own privacy policy. We encourage you to review them. We select third-party providers that meet enterprise-grade security and privacy standards.

6. Data Retention

Session data and transcripts: Retained for up to 90 days after the session date for quality improvement, then automatically deleted unless the session has been safety-flagged (see Section 7).

Account information: Retained as long as your account is active. Upon account deletion, personal information is removed within 30 days.

Payment records: Transaction records are retained as required by applicable tax and financial regulations.

Aggregated analytics: De-identified, aggregated data may be retained indefinitely as it cannot be linked back to individual users.

7. Safety Protocols and Immutable Records

Sophia includes automated safety protocols designed to protect users, particularly minors. If the system detects indicators of distress, harm, or crisis during a session, the following occurs:

  • Crisis intervention resources are displayed on screen
  • The session is flagged internally for safety review
  • Session data from safety-flagged sessions becomes an immutable record — it cannot be deleted or modified by the user, David Labs staff, or automated systems
  • An internal review ticket is created containing only session metadata (session ID, timestamp, user type) — no disclosure content is included in the ticket

Safety-flagged session records are retained indefinitely as a safeguarding measure. This data is encrypted, access-restricted, and reviewable only by designated safety personnel.

Important: Sophia is not a crisis counselor, therapist, or emergency service. Safety protocols are designed to connect users with qualified human support services. Sophia does not investigate, diagnose, or provide therapeutic advice.

8. Children's Privacy (COPPA Compliance)

David Labs is committed to complying with the Children's Online Privacy Protection Act (COPPA) and equivalent international regulations governing children's data.

Users Under 13

We do not knowingly collect personal information from children under 13 without verifiable parental consent. If a user indicates they are under 13 during account creation, the signup process is halted and a parental consent flow is initiated. Without completed parental consent, no account is created and no data is retained.

Users Aged 13 to 17

Users between 13 and 17 may create accounts with reduced data collection. Credit purchases require a payment method belonging to a parent or legal guardian, serving as implicit parental authorization. We apply enhanced privacy protections to minor accounts, including data minimization and restricted retention periods.

Parental Rights

Parents and legal guardians have the right to:

  • Review the personal information we have collected from their child
  • Request deletion of their child's personal information
  • Refuse to permit further collection of their child's information
  • Receive a copy of their child's data in a machine-readable format

To exercise these rights, contact us at parents@davidlabs.ca with proof of identity and relationship to the minor. We will respond within 30 days.

Exception: Safety-Flagged Records

Session data from safety-flagged sessions (see Section 7) cannot be deleted, even at the request of a parent or guardian. This is a safeguarding measure designed to protect the child. Safety-flagged records are encrypted and access-restricted.

9. International Data Transfers

Your data is processed and stored in the United States. If you are accessing Sophia from outside the United States, your data will be transferred to and processed in the United States. By using the Service, you consent to this transfer. We rely on Google Cloud's data processing agreements and standard contractual clauses for international data transfers where applicable.

10. Your Rights

Depending on your jurisdiction, you may have the following rights:

  • Access: Request a copy of the personal data we hold about you
  • Correction: Request correction of inaccurate or incomplete data
  • Deletion: Request deletion of your personal data (subject to legal retention requirements and safety-flagged record exceptions)
  • Portability: Request your data in a structured, machine-readable format
  • Withdrawal of consent: Close your account at any time
  • Objection: Object to processing of your data in certain circumstances

To exercise any of these rights, contact privacy@davidlabs.ca. We will respond within 30 days.

11. Cookies and Tracking

Sophia uses only essential, first-party cookies and local storage for authentication tokens and session state. We do not use third-party tracking cookies, advertising pixels, or analytics trackers. We do not participate in ad networks or sell data to advertisers.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email to the address associated with your account at least 14 days before taking effect. The "Last updated" date at the top of this page reflects the most recent revision.

13. Contact

For general privacy questions: privacy@davidlabs.ca

For children's accounts and parental consent: parents@davidlabs.ca

For legal matters: legal@davidlabs.ca