Last updated: April 25, 2026
David Labs ("we", "us", "our") operates Sophia, an AI-powered tutoring platform. This Privacy Policy describes how we collect, use, store, and protect your information when you use our Service. We are committed to protecting the privacy of all users, especially children.
We collect only the information necessary to provide and improve the Service:
Credit card and payment details are collected and processed exclusively by Stripe, our third-party payment processor. David Labs does not store, access, or process your credit card numbers or banking information. Please review Stripe's Privacy Policy for details on their data handling practices.
Your voice is NOT recorded. Audio from your microphone is streamed in real-time to Google Cloud's Gemini API (Vertex AI) for processing. The audio stream exists only in-memory during your active session. No audio files, recordings, or voice samples are saved — not on our servers, not on Google's servers, not anywhere.
We use Google Cloud's Vertex AI (enterprise tier), which is contractually distinct from consumer Google products. Google does not use Vertex AI customer data to train or improve their models. Your conversations are processed, not retained by Google.
Text transcripts of voice conversations are generated during the session and may be retained for quality improvement and service operation purposes. These transcripts contain the text content of what was said, not the audio itself.
Sophia uses voice enrollment to recognise returning learners and prevent abuse of the free service. For anonymous users (those who have not signed in with Google), voice enrollment is required to use the Service. Signed-in users are not required to enroll.
Sophia asks for your consent conversationally during your first session. The question is asked verbally by Sophia in plain language (e.g., "I'd save a small voice signature of yours. No recordings, just a fingerprint of how you sound. Is that okay?"). You respond verbally with a clear yes or no. You have up to 5 minutes to make your decision.
If you decline voice consent or do not respond within the decision window, Sophia will end the session. No audio is retained and no voice signature is created. You may still use Sophia by signing in with Google — signed-in users are not required to provide voice consent.
To demonstrate that consent was meaningfully obtained, we record the following for every consent interaction:
This audit trail exists so we can prove to regulators and to you that consent was asked for properly, answered clearly, and recorded accurately. It cannot be used to reconstruct your voice.
Voice signatures prevent the same person from creating multiple free accounts, keeping fair access for everyone. They also let Sophia greet you by name and track your progress across sessions without requiring sign-in. Voice is both the identity mechanism and the abuse prevention gate — without it, we have no way to ensure fair use of the free anonymous service.
If you clear browser storage and lose access to your enrollment session, email privacy@davidlabs.ca to request deletion — we can locate records using reasonable efforts based on any identifiers you provide.
We do not sell, rent, or share your personal information with third parties for their marketing purposes. We do not use your data to train or fine-tune AI models.
Your data is stored in Google Cloud Firestore, hosted in the United States (us-central1 region). All data is encrypted at rest (AES-256) and in transit (TLS 1.2+). We follow Google Cloud's security best practices, including identity and access management, audit logging, and network security controls.
Access to user data is restricted to authorized David Labs personnel on a need-to-know basis. We do not provide direct database access to third parties.
We use the following third-party services to operate Sophia:
Each of these services has its own privacy policy. We encourage you to review them. We select third-party providers that meet enterprise-grade security and privacy standards.
Session data and transcripts: Retained for up to 90 days after the session date for quality improvement, then automatically deleted unless the session has been safety-flagged (see Section 7).
Account information: Retained as long as your account is active. Upon account deletion, personal information is removed within 30 days.
Payment records: Transaction records are retained as required by applicable tax and financial regulations.
Aggregated analytics: De-identified, aggregated data may be retained indefinitely as it cannot be linked back to individual users.
Sophia includes automated safety protocols designed to protect users, particularly minors. If the system detects indicators of distress, harm, or crisis during a session, the following occurs:
Safety-flagged session records are retained indefinitely as a safeguarding measure. This data is encrypted, access-restricted, and reviewable only by designated safety personnel.
Important: Sophia is not a crisis counselor, therapist, or emergency service. Safety protocols are designed to connect users with qualified human support services. Sophia does not investigate, diagnose, or provide therapeutic advice.
David Labs is committed to complying with the Children's Online Privacy Protection Act (COPPA) and equivalent international regulations governing children's data.
We do not knowingly collect personal information from children under 13 without verifiable parental consent. If a user indicates they are under 13 during account creation, the signup process is halted and a parental consent flow is initiated. Without completed parental consent, no account is created and no data is retained.
Users between 13 and 17 may create accounts with reduced data collection. Credit purchases require a payment method belonging to a parent or legal guardian, serving as implicit parental authorization. We apply enhanced privacy protections to minor accounts, including data minimization and restricted retention periods.
Parents and legal guardians have the right to:
To exercise these rights, contact us at parents@davidlabs.ca with proof of identity and relationship to the minor. We will respond within 30 days.
Session data from safety-flagged sessions (see Section 7) cannot be deleted, even at the request of a parent or guardian. This is a safeguarding measure designed to protect the child. Safety-flagged records are encrypted and access-restricted.
Your data is processed and stored in the United States. If you are accessing Sophia from outside the United States, your data will be transferred to and processed in the United States. By using the Service, you consent to this transfer. We rely on Google Cloud's data processing agreements and standard contractual clauses for international data transfers where applicable.
Depending on your jurisdiction, you may have the following rights:
To exercise any of these rights, contact privacy@davidlabs.ca. We will respond within 30 days.
Sophia uses only essential, first-party cookies and local storage for authentication tokens and session state. We do not use third-party tracking cookies, advertising pixels, or analytics trackers. We do not participate in ad networks or sell data to advertisers.
We may update this Privacy Policy from time to time. Material changes will be communicated via email to the address associated with your account at least 14 days before taking effect. The "Last updated" date at the top of this page reflects the most recent revision.
For general privacy questions: privacy@davidlabs.ca
For children's accounts and parental consent: parents@davidlabs.ca
For legal matters: legal@davidlabs.ca