The Short Version
Your conversations are yours. Files, memory, and chat history live on your dedicated server, not in a shared Sinora database. When you use an AI, voice, or camera feature, only the content needed to provide that feature is sent to the processors described below.
1. Who We Are
Sinora is operated by WCA Technologies Inc. ("we," "us," "our"). This policy explains what data we collect, what we don't, and how we handle it.
Contact us anytime: care@sinora.ai
2. What We Collect
Account Information
- Email address: used for authentication and account communications
- Payment information: processed and stored by Stripe (we never see your full card number)
Usage Metrics
- Credit consumption and balance
- Message counts and types (Smart, Deep Think, media)
- Session timestamps and feature usage
- Error logs for debugging
- Short-lived session, rate-limit, and billing-retry records for Camera Conversation
These metrics help us improve the platform and monitor system health. They contain no conversation content.
3. What We Do NOT Collect
We do not collect, store, or access your stored chat history.
Every customer gets their own isolated, dedicated server. Your conversations, files, and memory are stored there, not in a shared Sinora database, and our team does not read them unless you explicitly request support that requires access.
AI, Voice & Media Processing
- AI prompts and outputs are processed by our model provider so the assistant can answer
- Voice messages are transcribed locally where supported; live voice calls use the voice processors listed below
- Images, videos, and documents may be sent to the model provider when you use vision, generation, or OCR features
Camera Conversation
This optional beta feature combines a live voice call with approved camera stills. It starts only after you review its disclosure, choose a required task goal and view limit, preview the camera, and tap to begin. While it is active:
- The app sends one initial still when the voice call connects, then still images when you or the assistant requests a new look. A short action look can sample three to six ordered stills over no more than four seconds after you explicitly start it. It does not upload a continuous video stream or create a video file.
- If you start Active Search, you choose an exact limit of 3, 5, or 10 views. Every accepted view contains one overview plus nine detail crops made from that same captured frame. The server enforces the selected limit, and the search stops sooner when the target is verified, you stop it, you change the target, the lease expires, or the camera session ends.
- The task goal, help type, and exact action or search request can travel with a camera request. An Active Search target is temporarily sealed in encrypted request context for no more than five minutes and clears earlier when the target is found, corrected, stopped, expired, or the camera session ends. It is not stored as plain text in camera-session records.
- Microphone audio is not embedded in camera frames. The live voice portion is processed separately by Retell AI and LiveKit under your current Voice settings.
- Device metadata is removed before upload. Sinora does not currently offer automatic redaction inside an image. Voice PII scrubbing and sensitive-text protection do not scan camera images, so you should keep private details out of view.
- Frames pass transiently through Cloudflare to a Z.ai vision endpoint over HTTPS.
- Sinora does not persist raw frame or crop bytes, and does not write frames, goals, help types, action questions, search targets, or vision prompts to Chat or Drive. After the app confirms delivery, one current derived visual description of up to 700 characters can be held for the exact voice call for up to 30 seconds. Up to six receipt-confirmed derived change events can be held for that call for up to 90 seconds. This short-lived text is kept in protected session and private-workstation plugin storage, then expires or clears when the camera session ends. Z.ai's API data processing addendum says customer and end-user API content is processed in real time and is not saved on its servers.
- Retell receives only the receipt-confirmed derived text needed for the voice conversation. It does not receive camera images, crop tiles, bounding boxes, or the vision provider's raw payload. A spoken visual result can still remain in the Voice recording or transcript under your Voice settings.
- Stopping guidance, leaving the screen, or putting the app in the background stops future capture. The session also ends automatically after ten minutes.
- Each successfully delivered and acknowledged view uses one credit, including an Active Search view with nine crops or a short action look containing several stills. Crops are not charged separately. Failed, cancelled, expired, superseded, or undelivered reserved work is refunded to the same credit allocation. Successful usage remains in the account billing ledger.
4. Cookies
We use minimal cookies for:
- Authentication: keeps you logged in
- Preferences: remembers your settings
We do not use advertising or tracking cookies. No third-party analytics scripts run on our platform.
5. Third Parties
We work with a limited number of trusted providers:
- Stripe: payment processing. Stripe handles your billing data under their own privacy policy.
- Supabase: authentication, account records, and usage or billing ledgers. Stored conversation content does not touch Supabase.
- Cloudflare: secure web delivery and our API edge. Cloudflare processes request, security, and limited session metadata; camera frames pass through transiently.
- OVHcloud: dedicated VPS hosting. Servers can be provisioned in supported regions for data-residency needs.
- Z.ai: AI model provider. Prompts, uploaded media, generated-media prompts, document content, and sampled live-camera frames needed for AI responses are processed under Z.ai's API terms and data processing addendum. Z.ai states that API customer data is generally processed in Singapore.
- Retell AI and LiveKit: provide optional live voice calls and process the audio and connection data needed for a call.
- Resend: delivers account and service emails.
We do not sell or rent your data. We share data only with the providers listed here, services you connect, or when required by law.
6. Data Retention
- Account data: retained while your account is active, deleted within 72 hours of account closure
- Chat data: stored on your dedicated server; deleted when your server is deprovisioned (within 72 hours of cancellation)
- Payment records: retained as required by law (typically 7 years for tax purposes)
- Usage metrics: aggregated and anonymized after 90 days
- Sinora Voice: recordings, transcripts, summaries, and sanitized call records are retained for up to 30 days when Voice recording and transcript storage is enabled. A spoken Camera Conversation result can be included. Accounts configured for basic call attributes do not retain provider recordings or transcripts
- Camera Conversation raw frames and crops: request-scoped bytes are not persisted by Sinora's API; Z.ai's API data processing addendum says customer and end-user API content is processed in real time and is not saved on its servers
- Camera Conversation visual context: one receipt-confirmed current description of up to 700 characters can remain for no more than 30 seconds, and up to six receipt-confirmed derived change events can remain for no more than 90 seconds, in protected session and private-workstation plugin storage for the exact bound voice call
- Active Search target: sealed search context expires within five minutes and clears earlier when the search is found, corrected, stopped, expired, or the camera session ends
- Camera Conversation coordination records: camera-session state expires within 10 minutes; account-linked billing-retry records containing session and request IDs, frame sequence, status, and timestamps can remain for up to 24 hours; successful credit usage remains in the billing ledger
7. Security
The Sinora app connects to our API over HTTPS, and Camera Conversation keeps frames on HTTPS connections through its processing path. Account access is authenticated, private workstations are isolated by customer, and Camera Conversation has strict size, time, frequency, and spending limits.
No system is perfectly secure. If you believe your account or data may be at risk, contact care@sinora.ai right away.
8. Your Rights
You have the right to:
- Access your personal data
- Correct inaccurate information
- Delete your account and all associated data
- Export your data in a portable format
- Object to data processing where applicable
To exercise any of these rights, email care@sinora.ai. We'll respond within 30 days.
9. Compliance
WCA Technologies Inc. is a Canadian company and handles account data under the Personal Information Protection and Electronic Documents Act (PIPEDA).
Your dedicated server region can support data-residency needs, but it is not a blanket regulatory certification for every workflow:
- Canada: available for Canadian data-residency needs
- Europe: available for customers who need EU server residency review
- United States: not currently available for HIPAA or PHI workflows
Sinora does not currently support HIPAA-regulated PHI workflows. Do not send protected health information through the service unless we have a signed, workflow-specific agreement with eligible subprocessors in place.
You have the right to access, correct, or delete the personal information we hold about you. To exercise these rights or file a complaint, contact us at care@sinora.ai or the Office of the Privacy Commissioner of Canada.
10. Children's Privacy
Sinora is not intended for anyone under 18. We do not knowingly collect information from minors. If you believe a minor has created an account, please contact us and we'll remove it promptly.
11. Changes to This Policy
We may update this policy as our service evolves. When we make significant changes, we'll notify you via email and update the effective date. Continued use after changes constitutes acceptance.
12. Contact
Questions or concerns about your privacy? We're here to help.
Email: care@sinora.ai
Company: WCA Technologies Inc.