Supplément États-Unis

    Version préliminaire en cours de révision juridique

    Version 0.9.0

    Ce document n'est pas encore traduit en français. Il est affiché en anglais : le texte anglais fait foi jusqu'à la publication de la traduction.

    Table of contents

    1. Scope and precedence
    2. Personal information we collect
    3. Sources
    4. Purposes
    5. Disclosures, sale and sharing
    6. Sensitive personal information
    7. Retention
    8. Your rights
    9. How to exercise your rights
    10. Appeals
    11. Consumer health data privacy policy (Washington, Nevada, Connecticut)
    12. Biometric data
    13. Children and teens
    14. AI disclosures
    15. Other state notices
    16. Data breaches
    17. Disputes
    18. Contact

    1. Scope and precedence

    1.1. This Supplement applies to you if you are a resident of the United States. It covers personal information we process as a business or controller: for our website, central registration, accounts, billing, support, marketing, free tools and consumer apps.

    1.2. State laws covered. This Supplement is our notice under the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA) and its regulations, and under the comprehensive privacy laws of the other states that have them, including Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah and Virginia, and of the states whose laws take effect later.

    1.3. Strictest common standard. Many of these laws apply only above size or volume thresholds. We do not track thresholds state by state. We apply this Supplement to residents of every US state, including states without a comprehensive privacy law, such as New York.

    1.4. Data in a customer's System. When a business customer (a school, clinic or company) loads personal information into a System, we act as its service provider or processor. The customer's privacy notice applies, and requests go to the customer. If you send a request to us, we forward it and help the customer answer.

    1.5. This Supplement supplements the Privacy Policy and the other documents of the SonhoLab Legal Center. If it conflicts with them, it prevails for you. Nothing in any SonhoLab document waives or limits rights that cannot be waived or limited under the law that applies to you.

    2. Personal information we collect

    2.1. In the 12 months before the "Last updated" date of this Supplement, we collected the categories of personal information below. We collect only what each service needs; you share much of it only if you use the related service.

    CCPA categoryExamplesServices
    A. IdentifiersName, email address, phone number, account ID, IP address, device IDAccounts, registration, support, marketing, apps
    B. Customer records (Cal. Civ. Code §1798.80(e))Name, address, phone, billing details; payment card data is handled by Stripe, not stored by usBilling
    C. Protected classification characteristicsAge or age range (to confirm you are 18+)Hades, SonhoLab Poker
    D. Commercial informationPlans, purchases, subscription and payment historyBilling, apps
    E. Biometric informationVoice samples and voice modelsHades, only with the voice owner's written consent
    F. Internet or network activityAccess logs, pages visited, feature use; website analytics only with consentWebsite, all services
    G. Geolocation dataApproximate location derived from IP address. We do not collect precise geolocation as a business.All services
    H. Sensory dataAudio recordings (voice samples, voice messages); photos you uploadHades, support
    I. Professional or employment informationBusiness name, job titleAccounts, support
    J. Non-public education informationWe do not collect it as a business. Verita processes it only as a service provider for schools.—
    K. InferencesWe do not create profiles to predict your preferences or characteristics.—
    L. Sensitive personal informationAccount login credentials; voice data (biometric); contents of your Hades conversations and support messages; health information that you reveal in Hades conversationsAccounts, Hades, support

    3. Sources

    3.1. We collect personal information:

    • from you, when you register, use a service, pay, write to us or upload content;
    • from your devices, through logs and, with consent, cookies (see the Cookie Policy);
    • from your organization, when it invites you to its account;
    • from the voice owner, when a person records a consent for their voice to be cloned in Hades;
    • from service providers, such as payment processors (payment status) and app stores (purchase status);
    • from public sources, such as public procurement records in Bidstream.

    4. Purposes

    4.1. We use personal information for these business purposes:

    • providing, maintaining and supporting the services you request;
    • processing payments and keeping financial records;
    • security, fraud and abuse prevention, and debugging;
    • sending service messages and, with your consent, marketing;
    • measuring the use of our website, with your consent;
    • complying with the law and defending legal claims.

    4.2. We do not use your personal information for targeted advertising. We do not use it to train AI models. Our AI providers are contractually barred from training on it. See the AI Transparency Notice.

    5. Disclosures, sale and sharing

    5.1. Disclosures for a business purpose. In the last 12 months we disclosed each category in section 2 to these categories of recipients, only for the purposes in section 4:

    • service providers and processors: hosting (Hetzner, in Finland), payments (Stripe), AI for our website chat and support desk (OpenAI), messaging (Meta WhatsApp Business Platform), push notifications (Google Firebase Cloud Messaging) and website analytics with consent (Google Analytics 4). The complete list is in Subprocessors and International Transfers. Hades, which is not offered to the public, uses the providers listed in its Addendum;
    • independent controllers you use to reach us: Google Play, the Apple App Store and payment card networks;
    • authorities, when the law requires. See Government and Law Enforcement Requests.

    5.2. No sale. No sharing. We do not sell personal information, and we do not share it for cross-context behavioral advertising. We have not done either in the last 12 months. We have no actual knowledge of selling or sharing the personal information of consumers under 16. Google Analytics 4 runs only with consent, with Google Signals and advertising features off.

    5.3. Targeted advertising and profiling. We do not process personal information for targeted advertising.

    6. Sensitive personal information

    6.1. We use sensitive personal information only for the purposes permitted by the CCPA regulations (§7027(m)): to provide the service you request, to secure our services, to prevent fraud and for other permitted purposes. We do not use it to infer characteristics about you. For this reason we do not offer a "Limit the Use of My Sensitive Personal Information" link.

    6.2. In states that require consent before processing sensitive data (such as Colorado, Connecticut, Texas and Virginia), we ask for your opt-in consent before we process it, except where the law allows otherwise.

    7. Retention

    7.1. We keep each category only as long as needed for its purpose, then delete or de-identify it:

    DataRetention
    Account and organization dataLife of the account + 30 days after cancellation
    Free plan inactivePurged after 90 days of inactivity, with 2 prior notices
    Access and application logs6 months; up to 12 months for security investigations
    Billing, invoices and tax records5 years, or longer if the law requires
    Consent and legal-acceptance records5 years after the relationship ends
    Privacy requests and responses24 months
    Support tickets24 months after closure
    Marketing leads and waitlistUntil you unsubscribe, or 24 months without interaction
    Hades voice profiles and recordingsUntil the voice owner or account holder revokes, or account deletion + 30 days; biometric data is never kept more than 3 years after last use
    Hades conversation historyUntil you delete it, or account deletion + 30 days

    7.2. Backups roll off within 30 days. The full schedule is in the Data Retention Schedule.

    8. Your rights

    8.1. Subject to the law of your state, you have the right to:

    • know and access the personal information we collected about you, the categories of sources, purposes and recipients, and the specific pieces of information;
    • delete personal information we collected from you;
    • correct inaccurate personal information;
    • portability: get a copy of your data in a portable, readily usable format. Data export is always available in your account, on every plan;
    • opt out of the sale or sharing of personal information, of targeted advertising, and of profiling in furtherance of decisions with legal or similarly significant effects. We do none of these, but you can still submit an opt-out, and we will record it;
    • limit the use of sensitive personal information (see section 6);
    • obtain a list of third parties to which we disclosed personal information, where your state provides it (for example, Oregon and Minnesota);
    • appeal our decision on your request (section 10);
    • non-discrimination: we will not deny you services, charge you a different price or give you a different quality of service because you exercised your rights.

    9. How to exercise your rights

    9.1. How to ask. Email contacto@sonholab.com with the subject "US privacy request", or use the tools in your account. The full procedure is in Your Privacy Rights and How to Exercise Them.

    9.2. Global Privacy Control. We treat a Global Privacy Control (GPC) signal from your browser as a valid request to opt out of the sale and sharing of personal information and of targeted advertising, for that browser and, if you are logged in, for your account. It also counts as a refusal of non-essential cookies. There is no common standard for "Do Not Track" signals; we honor GPC instead.

    9.3. Verification. To protect you, we verify your identity before we act on a request to know, delete or correct. If you are logged in, your login is usually enough. Otherwise, we ask you to confirm information we already hold, such as the email address on the account. For specific pieces of information or sensitive data, we may ask for more. We do not need to verify opt-out requests.

    9.4. Authorized agents. You can use an authorized agent. The agent must provide your signed written permission or a valid power of attorney. Unless the agent has a power of attorney, we may ask you to verify your identity directly and to confirm that you gave the permission.

    9.5. Deadlines. We confirm receipt within 10 business days and answer within 45 days. If we need more time, we can extend by up to another 45 days, and we tell you why within the first 45 days. Opt-out requests are processed as soon as feasible, and within 15 business days.

    9.6. Free of charge. Requests are free, up to two per 12 months for access and portability. We may charge a reasonable fee or refuse a request only if it is manifestly unfounded or excessive.

    9.7. Metrics. The CCPA requires published request metrics only from businesses that handle the personal information of 10 million or more Californians a year. That does not apply to us today. If it does, we will publish them.

    10. Appeals

    10.1. If we decline your request, in whole or in part, you can appeal. Email contacto@sonholab.com with the subject "Privacy appeal" and explain why you disagree.

    10.2. We review the original decision and answer in writing within 45 days, with our reasons.

    10.3. If we deny your appeal, you can contact the Attorney General of your state. California residents can also contact the California Privacy Protection Agency (https://cppa.ca.gov).

    11. Consumer health data privacy policy (Washington, Nevada, Connecticut)

    11.1. Scope. This section is our consumer health data privacy policy under the Washington My Health My Data Act (RCW 19.373), Nevada SB 370 and the consumer health data provisions of the Connecticut Data Privacy Act. These laws apply regardless of company size. This section is published in our Legal Center.

    11.2. Consumer health data we collect as a regulated entity.

    • Hades: voice samples and voice models (biometric data); and health, mental health or emotional information you reveal in conversations, including signals used by the crisis protocol.
    • We do not otherwise collect consumer health data as a regulated entity. Clínicas holds health data only as a processor for the clinic, which is the regulated entity. See the Health Data Addendum (Clínicas).

    11.3. Sources and purposes. We collect this data from you (and, for voices, from the voice owner) only to provide the Hades features you request, to run the crisis protocol and to keep the service secure.

    11.4. Separate consent. We ask for your consent to collect consumer health data separately from any other consent and from the Terms of Service. We ask for a second, separate consent before we share it with any third party other than our processors.

    11.5. Recipients. We disclose this data only to the processors that run Hades, listed in the Hades Addendum: Voice, Biometrics, Memorials and Companion AI, section 14. We do not disclose it to affiliates. We never sell consumer health data.

    11.6. No geofencing. We do not set up geofences around facilities that provide in-person health care services to identify, track or send messages to people.

    11.7. Your rights. You can:

    • confirm whether we collect, share or sell your consumer health data, and access it;
    • get a list of all third parties and affiliates with which we shared it, with their contact information;
    • withdraw your consent;
    • have your consumer health data deleted, including from our processors. Deleted data leaves our backups when they expire.

    11.8. How to exercise them. Sections 9 and 10 apply, including the 45-day deadline and the appeal process.

    12. Biometric data

    12.1. Voice data is processed only in Hades. Before collecting a voiceprint, we give the voice owner written notice of the purpose and retention period and obtain a signed written release (electronic signature). This follows the Illinois Biometric Information Privacy Act (BIPA), the Texas Capture or Use of Biometric Identifier Act (CUBI) and Washington RCW 19.375.

    12.2. We do not sell, lease, trade or otherwise profit from biometric data. The shared voice library is not available to users in the United States.

    12.3. We destroy voice data when the purpose is fulfilled or the voice owner revokes consent, and never later than 3 years after its last use. When the voice owner revokes consent, the voice is removed for everyone and deleted from all our systems automatically. Hades is not currently offered to the public; access is limited to invited testers.

    12.4. The full rules, including consent from the voice owner and the procedure for deceased persons, are in the Hades Addendum: Voice, Biometrics, Memorials and Companion AI.

    13. Children and teens

    13.1. COPPA. Our consumer apps and website are not directed to children under 13, and we do not knowingly collect their personal information. Hades and SonhoLab Poker are for adults (18+). If we learn that we collected personal information from a child under 13 without verifiable parental consent, we delete it.

    13.2. Schools. In Verita, the school authorizes collection for educational purposes only, in place of the parent, as the FTC allows. Commercial use is prohibited. See the Children and Student Data Addendum (Verita).

    13.3. Under-16 opt-in (California). California law requires opt-in consent before selling or sharing the personal information of consumers under 16. We do not sell or share anyone's personal information.

    14. AI disclosures

    14.1. Our AI assistants tell you at the start that you are talking to an AI system. On request, they confirm it again, as the Utah Artificial Intelligence Policy Act requires.

    14.2. Hades is a companion chatbot under California SB 243 and New York General Business Law Article 47. It reminds you it is an AI at the start of each session and every 3 hours, and it follows a published crisis protocol. See the Hades Addendum and the AI Transparency Notice.

    14.3. Colorado and other states. Colorado's law on automated decision-making technology (SB 26-189) takes effect on 1 January 2027. Where any AI feature is used to make or substantially support a consequential decision about you, we will give the required disclosures before use.

    14.4. Messages. Our AI agents do not send automated marketing messages to US phone numbers without prior express written consent.

    15. Other state notices

    15.1. California "Shine the Light" (Cal. Civ. Code §1798.83). We do not disclose personal information to third parties for their own direct marketing purposes.

    15.2. California automatic renewal. The terms of our automatic renewals, your consent and online cancellation are in the Terms of Service.

    15.3. California online services (Cal. Civ. Code §1789.3). California residents can contact the Complaint Assistance Unit of the Division of Consumer Services of the California Department of Consumer Affairs, through www.dca.ca.gov.

    15.4. New York. New York residents have the same rights as residents of other states under this Supplement. For schools in New York, the Parents' Bill of Rights for Data Privacy and Security is attached to the Children and Student Data Addendum (Verita).

    15.5. Washington. SonhoLab Poker is not available in Washington State.

    16. Data breaches

    16.1. If a breach affects your personal information, we notify you, and any state authority the law requires, within the deadline of the law of the state where you live. See Security and Incident Response.

    17. Disputes

    17.1. The Terms of Service contain an arbitration agreement and class-action waiver for US users, with a 30-day opt-out, a small-claims carve-out and a mass-arbitration protocol. They do not waive public injunctive relief. Read the dispute resolution section of the Terms of Service.

    18. Contact

    18.1. Privacy requests, appeals and questions: contacto@sonholab.com.

    18.2. L. M. PEREZ MONTANA (SonhoLab), CNPJ 61.620.014/0001-00, Rua Fausto Cabral, 871, Casa A, Vicente Pinzon, Fortaleza-CE, 60181-227, Brazil. Phone +55 85 99412-2292.


    Version 0.9.0 (preliminary) · Effective 26 September 2026 · © L. M. PEREZ MONTANA (SonhoLab), CNPJ 61.620.014/0001-00. This version is under legal review; we will notify material changes as described in these documents.

    Version préliminaire en cours de révision juridique

    Version 0.9.0

    Empreinte SHA-256 de ce texte: d6f5ae221092513375669e4a814d12221d51ef20f5073019c79e83f75e2c1659

    Retour au Centre juridique