This Privacy Policy explains how Human Frontier Labs Inc.(“Sontara,” “we,” or “us”) handles personal information when you use sontara.ai, our mobile applications, and related services (the “Service”). We’ve tried to write this in plain English. If anything is unclear, email privacy@sontara.ai.
1. The short version
- We collect what we need to run your account and your AI agents, and nothing more.
- We don’t sell your data, train AI models on your conversations, or run third-party advertising.
- Your agent’s AI processing runs on Google Cloud’s Vertex AI under enterprise terms that prohibit Google from using your data to train models.
- Your agent keeps a persistent memory so it can work for you across sessions — it’s yours, it’s isolated to your account, and it’s deleted when you delete your account.
- You can delete your account at any time from inside the app or by emailing us; see sontara.ai/data-deletion for exactly what gets removed.
2. Information we collect
2.1 Information you give us
- Account information.When you sign in with Google or Apple, we receive your email address and name from your authentication provider. If you sign in with Apple and choose “Hide My Email,” we receive only Apple’s private relay address.
- Subscription information. If you subscribe to a paid plan, we receive a customer reference and subscription status from our payment processor. We do not receive or store your card number, CVC, or full billing address.
- Agent configuration.The names you give your agents, your plan’s model configuration, the autonomy policy you set, and the channels you connect.
- Channel and integration credentials.When you connect external services (e.g. Telegram, Slack, Discord, WhatsApp, Google Workspace), you provide tokens or OAuth credentials so your agent can interact with those platforms. We store them in encrypted form and use them only to operate the connections you set up.
2.2 Information generated by your use of the Service
- Conversations and files. Messages between you and your agent, and any files you upload, are stored alongside your agent so it can remember context across sessions.
- Usage metrics.Aggregate metrics about your agent’s activity (such as message counts and credits consumed) for billing and capacity planning.
- Diagnostic logs. Standard server logs we use for troubleshooting and security. We do not intentionally log message content. Logs are retained for a limited period and then deleted (see Section 8).
2.3 Mobile-app specifics
- On-device data. Your sign-in token is stored in iOS Keychain or Android Keystore (encrypted by the operating system). The app remembers basic UI state.
- Microphone & speech recognition.Voice input is transcribed by your device’s built-in speech recognizer. When an offline language model is installed it stays on your device; otherwise your operating system’s speech recognizer (Apple or Google) transcribes it, subject to that provider’s terms. Sontara does not record, store, or receive your raw audio — only the resulting text is sent to your agent.
- No advertising or analytics SDKs. The mobile app does not embed third-party analytics or ad-tracking.
3. Agent memory
Your Sontara agent maintains a persistent memory across your conversations. This includes a chronological record of your messages and the agent’s responses, a store of facts the agent has captured, and relationships derived from those facts. Together these enable your agent to remember context, preferences, and prior decisions.
Agent memory is stored in an isolated runtime environment and a cloud storage bucket dedicated to your account, encrypted at rest. It is never shared across customers, never used to train AI models, and is treated as a distinct category of personal information for access, correction, and deletion requests. Deleting your account deletes your agent’s memory (see Section 8).
4. Cookies & attribution
We use a small number of first-party cookies: session cookies for sign-in, and — if you arrive through a referral or campaign link — a first-touch attribution cookie that records the referral source (such as a partner code or campaign tag) for up to 90 days so we can credit the referral if you subscribe. Attribution data is stored with your account after signup and used for partner commissions and understanding how people find Sontara.
We do not use third-party advertising cookies or cross-site tracking. Our web analytics are privacy-preserving and cookieless (aggregate page views and referrers, no individual behavioral profiles).
5. How we use information
We use the information described above to:
- Operate, maintain, and improve the Service;
- Authenticate you and protect your account;
- Process payments, manage subscriptions, and pay partner referral commissions;
- Provide your agent with the credentials it needs to operate the channels and services you have connected;
- Detect, investigate, and prevent fraud, abuse, and security incidents;
- Communicate with you about service updates, billing issues, and support requests;
- Comply with legal obligations and enforce our Terms of Service.
We do not use your conversations, files, or agent memory to train AI models, profile you for advertising, or share with data brokers.
6. Service providers
We engage third parties to help operate the Service. Their roles fall into a small number of categories:
- Authentication. A third-party identity provider handles sign-in (Apple, Google) and session management.
- Payments.PCI-compliant payment processors handle all card data and billing — on the web, and separately for app-store purchases made through Apple or Google. We never see card numbers. Partner referral payouts run through a regulated payment platform that also handles partner identity verification and tax documentation.
- Cloud infrastructure.Reputable cloud providers host our application, database, and your agent’s runtime environment. All data is encrypted in transit and at rest.
- AI inference.Your agent’s AI processing runs on Google Cloud’s Vertex AI. Under Google Cloud’s enterprise terms, your prompts, responses, and content are not used to train Google’s models.
- Email. A transactional email provider delivers account and billing emails.
- Analytics. Privacy-preserving, cookieless web analytics (aggregate page views and referrers only).
We bind each provider by contract to confidentiality and appropriate security. A current list of subprocessors with specifics is available to enterprise customers, regulators, and auditors on request via privacy@sontara.ai.
7. Google Workspace data and Limited Use
When you connect a Google account, Sontara requests access to Gmail, Google Calendar, Google Drive, Docs, Sheets, and Slides so your agent can read, draft, send, and organize on your behalf. We request the following Google API scopes and use each only for the features you connect it for:
- Gmail (read, compose, send, modify). Read, search, draft, send, reply to, and organize the messages your agent acts on at your direction.
- Google Calendar. Read and manage the calendar events you ask your agent to handle.
- Google Drive. Find, read, create, and update the files your agent works with.
- Docs, Sheets, and Slides. Read and edit the documents, spreadsheets, and presentations your agent works with.
- Account email. Identify which Google account is connected.
Limited Use commitment.Sontara’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We use Google Workspace data only to provide and improve the user-facing features you connected it for.
- We do not transfer or sell Google Workspace data, except as necessary to provide or improve those features, to comply with applicable law, or as part of a merger or acquisition with appropriate notice.
- We do not use Google Workspace data for advertising.
- We do not allow humans to read your Google Workspace data unless (a) you give explicit consent for specific messages or files, (b) it is necessary for security purposes such as investigating abuse, (c) we are required to by applicable law, or (d) the data has been aggregated and anonymized for internal operations.
- Google Workspace data is never used to train or improve generalized AI or machine-learning models. Your agent uses it only in the moment, to perform the task you asked for, inside your isolated agent instance.
You can revoke Sontara’s access at any time at myaccount.google.com/permissions or by disconnecting the integration in the app. Revoking access invalidates and deletes the stored authorization token.
8. Data retention
We retain your personal information for as long as your account is active or as needed to provide the Service. Specific retention periods by category:
- Account information (email, name, identity record): retained until account deletion, then deleted within 30 days.
- Agent configuration and channel credentials: deleted within 30 days of account deletion; stored secrets are purged at the same time.
- Agent memory, conversations, and files: stored in your agent’s isolated environment and dedicated storage bucket; deleted within 30 days of account deletion when we destroy that environment and its storage. In practice, deletion of your agent’s environment begins immediately.
- Usage metrics and billing records: retained for up to 7 years in anonymized or aggregate form to satisfy tax, accounting, and compliance obligations. Payment records are also retained by our payment processor per its legal obligations.
- Diagnostic logs: retained for 90 days, then deleted.
After you delete your account, we complete the full data purge within 30 days, except for records subject to legal retention obligations (billing records, breach-disclosure obligations, court orders). See sontara.ai/data-deletion for the step-by-step description.
9. International data transfers
Sontara is operated from the United States. If you access the Service from outside the U.S., your information will be transferred to and processed in the U.S. and other jurisdictions where our service providers operate. By using the Service, you consent to this transfer.
10. Your privacy rights
Depending on where you live, you may have rights under applicable privacy law. We honor all of the following regardless of your location:
- Access: Request the categories and specific pieces of personal information we hold about you.
- Correction: Request that we correct inaccurate information.
- Deletion:Request deletion of your personal information, including your agent’s memory, conversation history, and all stored credentials.
- Portability: Request an export of your data in a machine-readable format.
- Opt-out of sale or sharing: We do not sell or share your personal information for advertising or cross-context behavioral targeting. No opt-out action is required, but you may contact us to confirm.
California residents (CCPA/CPRA): You have the rights listed above plus the right to limit use of sensitive personal information and the right to non-discrimination for exercising your rights. We fulfill requests within 45 days (extendable to 90 days with notice). To exercise rights, email privacy@sontara.ai; we will verify your identity before processing.
Texas (TDPSA), Virginia (CDPA), Florida (FDBR), Connecticut (CTDPA), Colorado (CPA), and other state residents: You have equivalent rights under your state law. We process requests from residents of all US states under the same standards described above.
EEA, UK, and Swiss residents have rights under the GDPR and its UK equivalent, including the right to lodge a complaint with your data-protection authority.
Data breach notification: If a data breach affects your personal information, we will notify you as required by applicable breach notification laws, generally within 30 to 60 days of discovery.
11. Children
Sontara is not directed to children under 13, and we do not knowingly collect personal information from anyone under 13. If you believe a child has provided us with personal information, contact privacy@sontara.ai and we will delete it.
12. Security
We use industry-standard practices to protect your information, including encryption in transit and at rest, isolation of your agent’s runtime from other customers’, access controls on internal systems, and the principle of least privilege for engineering access. No system is perfectly secure; if you become aware of a vulnerability, please report it to privacy@sontara.ai.
13. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes we will notify you by email or in-app notice and update the “Last updated” date above. Continued use of the Service after a change indicates your acceptance.
14. Contact
Questions, concerns, or requests under this policy should go to privacy@sontara.ai.
Human Frontier Labs Inc., a Delaware corporation.