PRIVACY
Privacy Policy
Effective as of 2026-08-04
Nouron Labs, Inc. [LEGAL ENTITY BEING FORMED — proposed Delaware, USA C-Corporation; update with the final name and jurisdiction before publishing] ("Nouron Labs", "we") operates a marketplace for multimodal AI training data. We collect voice, image, video, and document recordings from individuals ("Contributors") in exchange for payment, and license/sell certified datasets to companies that train AI models ("Buyers"). This policy explains, without euphemism, what data we collect, why, who we share it with — including that we sell it — and what rights you have. It applies to our website, mobile apps, and any data you process through our services.
1. What data we collect
Identity and account data: full name, email, country, age, languages and proficiency levels, gender (optional). Verification (KYC) data: an official ID document (front and back) and a selfie to confirm you are the person on the document — this is biometric data under most privacy laws (see Section 3). Payment data: method (Venezuelan pago móvil or Binance Pay) and the details needed to pay you (national ID number, bank, and phone for pago móvil; Binance ID for Binance Pay) — we never store passwords or wallet private keys. Device data: model, operating system, screen resolution. Task content: depending on the vertical you complete, this includes recordings of your voice reading a script or conversing, first-person video of your surroundings (including narration audio and motion sensor/IMU data), photos of yourself or of objects/spaces, personal documents you upload, or computer-interaction data. Some audio or in-person conversation verticals may capture the voice of another person physically present with you — in that case we also collect their explicit consent and minimal identifying data (name, role in the conversation, age range) before recording. Technical metadata for every submission: duration, resolution, date, and time.
2. Why we use your data and on what legal basis
We use your identity and KYC data to verify you are a real person, 18 or older, and to prevent fraud — legal basis: performance of our contract with you and, where applicable, explicit consent for biometric data. We use your task content (voice, image, video, documents) to build, certify, and sell AI training datasets — legal basis: your explicit consent given when you complete each task, plus the license you grant us in our Terms of Service. We use your payment data solely to pay you — legal basis: contract performance. We use technical metadata and device data for quality control and abuse prevention — legal basis: legitimate interest. We do not use your data for targeted advertising or share it for third-party advertising purposes.
3. Biometric data — heightened treatment
Your voice and face may constitute "biometric data" or "sensitive information" under laws like the European GDPR, the Illinois Biometric Information Privacy Act (BIPA) in the US, Brazil's LGPD, or Colombia's Law 1581, when technically processed to uniquely identify you (for example, a voiceprint or a face-geometry scan). Our commitment: (a) we ask for your explicit, separate consent before collecting any such data — never implied by continuing to use the app; (b) we never sell or profit from raw biometric identifiers (a "voiceprint" or "face geometry scan") as such — our anonymization pipeline (Section 5) transforms content before any sale; (c) we retain data classifiable as biometric for a maximum of 3 years from your last interaction with the platform, or until you request deletion, whichever comes first; (d) you may request a copy of this retention policy or deletion of this specific data at any time by writing to data@nouronlabs.com.
4. Who we share your data with — and yes, we sell it
We sell and license datasets containing your recorded content and an anonymous demographic snapshot ("country, age, gender, language, accent, whether you have a quiet environment and headphones") to AI companies that purchase our certified datasets ("Buyers"). Buyers receive content only after it passes through our anonymization pipeline — they never receive your ID document, verification selfie, payment data, or your full name or email. We use infrastructure providers that process your data on our behalf ("subprocessors"): Supabase (authentication and database), Cloudflare R2 (storage of audio/video/image/document files), Modal.com (compute for anonymization, transcription, and quality control — this provider processes your content BEFORE anonymization, so it may have transient technical access to raw data), Resend (transactional email delivery), and Vercel (web application hosting). We do not sell your identity, KYC, or payment data to anyone, under any circumstances.
5. How we anonymize your content before selling it
Before any Buyer receives your content, we run an automated pipeline based on the vertical: we strip the GPS location embedded in photos and video (which your camera adds automatically); we blur, with solid fill —not pixelation, which can be reversed— the faces of people other than you who appear in the background of photos and video; we bleep audio segments where third parties' names, numbers, or other personal information are mentioned; and we visually mask personal information detected in scanned documents. A final independent re-verification step confirms no identifiable third-party personal information remains before approving content for sale; if it fails, the content goes to human review before continuing. This pipeline anonymizes third parties who appear incidentally in your content — it does not anonymize your own voice or image when you are the subject of the task, because that is the nature of the service you agreed to provide.
6. International transfers
Our infrastructure and most of our Buyers are located in the United States. If you reside in the European Union, the European Economic Area, or any country whose data protection law regulates international transfers, your data may be transferred outside your country of residence to the United States or other countries where our subprocessors or Buyers operate. We use, as applicable, the EU-US Data Privacy Framework adequacy mechanism (where the recipient is certified) and Standard Contractual Clauses as an additional safeguard. You may request a copy of the safeguards applicable to your case by writing to data@nouronlabs.com.
7. How long we keep your data
Account and identity data: while your account is active, and up to 30 days after you request deletion (see Section 9). Biometric data (selfie, ID document, and any data classifiable as biometric): a maximum of 3 years from your last interaction with the platform, or sooner if you request it. Task content already sold/licensed to Buyers: retained indefinitely within datasets already delivered, because — as explained in Section 9 — we cannot retroactively revoke a Buyer's access to data we already legitimately sold them. Audit and consent records: kept permanently as evidence that we met our legal obligations, even after you delete your account.
8. Your rights
Depending on your country of residence, you may have the right to: access the data we hold about you; correct inaccurate data; request deletion of your account and personal data (see Section 9 for its limits); request a portable copy of your data; object to certain uses of your data; withdraw your consent at any time (without affecting the lawfulness of prior processing); and, if you are a California resident, specifically opt out of the sale or sharing of your personal information, and limit the use of your sensitive personal information. To exercise any of these rights, write to us at data@nouronlabs.com — we respond within a reasonable period under the law applicable to your case, typically no more than 30 days.
9. What actually happens when you delete your account
When you request account deletion, we flag your account for removal with a 30-day grace period (in case you change your mind). After that period: we irreversibly anonymize your name, email, selfie, ID document, and payment data; we deliberately retain non-identifying demographic data (country, age, gender, language) because it is already embedded as anonymous metadata in sold datasets, and removing it would break the integrity of those datasets without providing any additional protection of your identity (those fields never identify who you are). Content already sold to a Buyer before your deletion request is NOT retroactively removed from the Buyer's systems — we notify them of your request, but Nouron Labs has no legal authority to force deletion in third-party systems that already received the data under license. This limitation is standard in the AI training dataset industry (applied, for example, by Mozilla Common Voice and comparable platforms) and is why we ask for your explicit consent BEFORE you record, not after.
10. Minors
Nouron Labs is prohibited for anyone under 18, no exceptions. Unlike most platforms, we don't rely solely on a self-declaration checkbox: we verify your age against your official ID document as part of the KYC process. If we detect that a user is a minor, we immediately suspend the account and delete their data.
11. Security
We apply role-based access controls, encryption in transit and at rest for data stored in our infrastructure, and strict separation between operational data (KYC, payment) and data included in sale manifests — our code never exposes payment data, ID documents, or selfies in files delivered to Buyers. No system is perfectly secure; if a breach affecting you occurs, we will notify you as required by applicable law.
12. Changes to this policy
We may update this policy. Cosmetic changes (clarifications, reordering) are published with only a new effective date. Material changes — such as adding a new use of your data, a new type of Buyer, or changing how we treat biometric data — require your new affirmative acceptance: the next time you log in, you'll see a blocking notice asking you to review and accept the updated version before continuing to use the platform. We never apply material changes retroactively without your consent.
13. Contact
For any question about this policy or to exercise your rights: data@nouronlabs.com.
14. Jurisdiction-specific notes
If you reside in California (US): under the CCPA/CPRA, you have the right to know what personal information we sell and to opt out of that sale, and to limit the use of your sensitive personal information — contact us to exercise this. If you reside in the EU/EEA: we process your data based on your explicit consent (GDPR Art. 9 for biometric data) and you have the right to lodge a complaint with your local data protection authority. If you reside in Brazil: under the LGPD, we treat biometric data as "dado sensível" with specific, highlighted consent, and you can exercise your data subject rights by contacting the email in Section 13. If you reside in Colombia: under Law 1581 of 2012, your authorization for processing sensitive data (including biometrics) is always voluntary and you may refuse it without unjustified exclusion from the service, unless the data is strictly necessary to provide it (as with KYC verification). If you reside in Illinois, Texas, or Washington (US): you receive the same heightened standard of informed written consent and public retention policy that we apply globally to biometric data (Section 3), regardless of whether your state legally requires it.
Questions about this document? Write to us at data@nouronlabs.com
v1.0.0-2026-08-04