Sume Privacy Policy
Effective Date: January 18, 2026
Sume ("we," "us," or "our") is an AI avatar builder service that allows users to create personalized avatars using uploaded images, voice clips, and personality descriptions. We are committed to protecting your privacy and handling your data responsibly. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website, application, or services (collectively, the "Service"). By using the Service, you agree to the terms of this Privacy Policy.
Please note that this Policy applies only to information we collect through the Service and does not apply to third-party websites or services that you may access through links on our Service. We encourage you to review the privacy policies of those third parties.
If you are a resident of the European Economic Area (EEA), United Kingdom, California, or other jurisdictions with specific data protection laws, additional rights and information may apply to you, as detailed below.
1. Information We Collect
We collect the following types of information:
a. Information You Provide Directly
- Uploaded Content for Avatar Creation: When you create an avatar, you may upload images and voice clips of the persona (which may include biometric data such as facial features or voice patterns) and provide text descriptions of the avatar's personality. We do not require or collect other personal information such as names, ages, or genders unless voluntarily provided.
- Conversation History: If you interact with your avatar (e.g., through voice or video conversations), we collect and store the audio and video recordings of those interactions.
- Account Information: We require Google sign-in for account creation. Through this, we collect information provided by Google, such as your email address, profile name, and any other data you authorize Google to share with us.
- Payment Information: For subscription features (after the initial free tier), we collect billing details through our payment processor (Stripe). We do not store your full payment card information.
- Voluntarily Shared Data: If you explicitly consent to us retaining your uploaded images or voice clips beyond the standard retention period (e.g., for research or improvement purposes), we may store that data as specified.
b. Automatically Collected Information
- Usage Data: When you use the Service, we automatically collect information about your device and interactions, such as IP address, browser type, operating system, access times, pages viewed, and referring URLs.
- Analytics Data: We use tools like Google Analytics and Vercel Analytics to collect data on how you use the Service, including session duration, features accessed, and error logs.
- Cookies and Similar Technologies: We use cookies, web beacons, and similar technologies to enhance your experience, remember preferences, and analyze usage. You can manage cookie preferences through your browser settings.
c. Biometric Information
Images and voice clips you upload may contain biometric identifiers (e.g., facial geometry or voice prints). We treat this as sensitive data and handle it in compliance with applicable laws, such as the Illinois Biometric Information Privacy Act (BIPA), California Consumer Privacy Act (CCPA), and General Data Protection Regulation (GDPR). We obtain your consent for processing biometric data through our terms of service and upload prompts.
We do not collect personal information directly, but uploaded content may incidentally include identifiable details.
2. How We Use Your Information
We use the information we collect for the following purposes:
- Providing and Improving the Service: To generate and host your avatars, enable sharing via private links, and facilitate interactions (e.g., conversations).
- AI Model Training: We use anonymized or aggregated conversation history (including voice audio and video) to globally train and improve our AI models. We do not use your uploaded images or voice clips for training purposes unless you have voluntarily provided them with explicit consent.
- Analytics and Personalization: To understand usage patterns, troubleshoot issues, and enhance features using tools like Google Analytics and Vercel Analytics.
- Billing and Subscriptions: To process payments and manage your subscription tier via Stripe.
- Security and Compliance: To detect and prevent fraud, enforce our terms (including restrictions on inappropriate content), and comply with legal obligations.
- Communications: To send service-related emails (e.g., account updates) or, with your consent, marketing materials.
We do not sell your personal information. Under CCPA and similar laws, certain data sharing may be considered a "sale," but we do not engage in monetary exchanges for data.
3. Sharing Your Information
We share information as follows:
- Service Providers: We share data with third-party vendors for hosting, AI processing, analytics, and payments, including:
- AWS (storage and cloud services)
- OpenAI, Google, xAI, Cartesia, Livekit (AI and machine learning services for avatar interactions)
- Supabase (database management)
- Google Analytics and Vercel Analytics (usage tracking)
- Stripe (payment processing)
- Sharing Features: If you share an avatar via a private link, the recipient can access the avatar hosted on our servers. We do not make avatars publicly available or share them globally.
- Legal Requirements: We may disclose information if required by law, subpoena, or to protect our rights, users, or the public (e.g., to prevent harm or illegal activities).
- Business Transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred to the new entity.
We do not share biometric data with third parties except as necessary for avatar generation (e.g., with AI providers) and under strict data processing agreements.
4. Data Retention
- Uploaded Images and Voice Clips: We store these temporarily for avatar creation and retain them for up to one (1) month, after which they are automatically deleted. If you voluntarily consent to longer retention (e.g., by opting in), we retain them as specified in your consent.
- Conversation History: We retain audio and video conversation data for as long as your account is active, or longer if needed for model training (in anonymized form) or legal purposes.
- Account and Usage Data: Retained for the duration of your account plus a reasonable period for backups and compliance (typically up to 7 years for financial records).
- Deletion Requests: You can request deletion of your data at any time (see Section 7). We will delete or anonymize it unless retention is required by law.
5. Security
We implement reasonable administrative, technical, and physical safeguards to protect your information, including encryption for data in transit and at rest, access controls, and regular security audits. However, no system is completely secure, and we cannot guarantee absolute security. You are responsible for maintaining the confidentiality of your Google account credentials.
6. Restrictions on Inappropriate Content and Legal Compliance
To ensure the Service is used lawfully and ethically, we prohibit the creation of avatars that:
- Infringe on others' rights (e.g., using someone's likeness without their consent, violating right of publicity laws).
- Contain or promote illegal, harmful, or inappropriate content (e.g., deepfakes for deception, explicit material, hate speech, violence, or child exploitation).
- Violate intellectual property rights or privacy laws.
We use automated filters, content moderation (including AI tools from providers like OpenAI), and human review where necessary to detect and remove violating content. By using the Service, you represent that you have all necessary rights and consents for uploaded materials. We may suspend accounts or delete content that violates our terms. These measures help comply with laws such as state deepfake regulations (e.g., in California, New York, and Texas), GDPR's lawful processing requirements, and federal laws against unlawful content.
If you believe content violates these rules, contact us at support@sumelabs.com
7. Your Rights and Choices
Depending on your location, you may have the following rights:
- Access, Correction, or Deletion: Request access to, correction of, or deletion of your personal information.
- Opt-Out: Opt out of data processing for training, marketing, or certain sharing (e.g., under CCPA, opt-out of "sales").
- Consent Withdrawal: Withdraw consent for biometric processing (which may limit Service use).
- GDPR Rights (EEA/UK Users): Rights to data portability, objection, and restriction.
- CCPA Rights (California Users): Non-discrimination for exercising rights; we do not offer financial incentives tied to data collection.
To exercise these rights, contact us at [privacy@sumelabs.com] or through your account settings. We respond within applicable legal timeframes (e.g., 30 days under GDPR, 45 days under CCPA). We may verify your identity before processing requests.
You can also manage Google sign-in data through Google's privacy controls.
8. Children's Privacy
The Service is not intended for children under 13 (or 16 in some jurisdictions). We do not knowingly collect data from children. If we learn we have collected such data, we will delete it. We restrict creation of avatars depicting minors or inappropriate content involving children to comply with laws like COPPA.
9. International Data Transfers
We are based in US, and your data may be processed in the US or other countries. For EEA/UK users, we use Standard Contractual Clauses or other mechanisms to ensure adequate protection under GDPR.
10. Changes to This Privacy Policy
We may update this Policy periodically. We will notify you of material changes via email or in-app notice. Continued use after changes constitutes acceptance.
11. Contact Us
If you have questions, contact us at:
- Email: support@sumelabs.com
For California users: You may contact us or the California Attorney General for complaints.
This Policy is governed by the laws of California, USA, without regard to conflict of laws principles.