Sonavera Service Provider Disclosure
Version: 2026-08-05 revision 4
North Star Software Inc. operates the Sonavera hosted biometric service. In this disclosure, “Sonavera,” “we,” “us,” and “our” refer to North Star Software Inc. as operator of the Sonavera service.
8. Service providers and international processing
The current-flow consent screen names every disclosed provider and gives immediate access to the purposes and material retention terms below through an inline expandable section.
Sonavera uses the following service providers:
| Provider | Information, purpose, and material retention |
|---|---|
| AWS | Hosts Sonavera compute, application, consent and evidence records, encrypted reusable face and voice templates or resolver vectors when a flow creates them, databases, backups, keys, logs, and operational infrastructure. Application, capture, and RDS logs use a 30-day period. Automated RDS backups use a seven-day period. Sonavera does not send ceremony content to a separate AWS biometric or model-training API. |
| Cloudflare | Delivers and protects the Demo and hosted application and processes request, consent, legal, OIDC/API Redirect, coarse-location, abuse-prevention, and security data. Demo correlation and deletion state has bounded expiry; provider and security logs follow Cloudflare’s plan and configuration. Cloudflare states that it does not train on Customer Content without consent, although bounded traffic signals may support threat and security systems. Participant deletion does not fan out to provider security logs. No reusable biometric template is transferred. |
| LiveKit | Transports live camera, microphone, AI audio, and room metadata. The Public Demo does not use LiveKit Agents, recording, egress, or model training. Ordinary User Data is deleted after delivery. Separately generated observability data may remain for 30 days plus encrypted-backup time, and operational metrics may remain longer. Ending the session closes transport. No reusable biometric identifier is transferred. |
| OpenAI | Processes participant audio, automatic low-detail visual context, conversation, system and tool context, a hashed safety identifier, a ceremony identifier, and ceremony state for AI session assistance. It is not used for face matching, liveness scoring, or biometric identity decisions. Realtime has no application-state retention; standard abuse-monitoring logs may retain content for up to 30 days. Content submitted while Sonavera’s current training opt-out applies is not used for model training. Sonavera has no participant-correlated deletion dispatch for those logs. No reusable Sonavera biometric template or vector is sent. |
| ElevenLabs | Processes microphone audio and returns transcript text. The integration does not add a tenant, handshake, face, or template identifier and does not use Enterprise Zero Retention Mode. Ordinary history, debugging, moderation, deletion, and backup rules apply; deleted database items may remain in backups for up to 30 days. Audio and transcripts submitted while Sonavera’s current model-improvement opt-out applies are not used for training. Sonavera has no participant-correlated provider deletion dispatch. No reusable biometric identifier is transferred. |
| Aurigin | Processes one locally speech-trimmed 16 kHz WAV and limited request information for voice-authenticity and audio anti-spoofing analysis. Sonavera adds no participant or ceremony identifier. Aurigin states that raw audio is deleted immediately after analysis, is never stored, and is not used for training. That statement does not cover uncorrelated operational records. No reusable voiceprint or identity template is sent or returned. |
| Sentry | Processes scrubbed browser errors, stack traces, breadcrumbs, release and runtime metadata, and selected diagnostics for reliability monitoring. Replay, profiles, Logs, and tracing are not enabled. Events follow Sentry project retention; storage is in the United States, IP scrubbing is enabled, and aggregated identifying-data use is disabled. Participant deletion does not fan out to Sentry. No raw media or reusable biometric template is intended to be sent. |
Provider-held information follows the verified provider agreement, Sonavera account configuration, and provider retention settings. Provider-held information may have a different retention period from Sonavera-held application records.
Deletion through the requesting service applies to associated Sonavera-held active-system data. It does not selectively delete unexpired backup, security, abuse-monitoring, or uncorrelated operational records held under the provider practices described above.
Some service providers process personal information outside Canada, including in the United States, the European Economic Area, Australia, Brazil, Costa Rica, Egypt, Hong Kong, India, Indonesia, Israel, Japan, Malaysia, Mexico, the Philippines, Saudi Arabia, Singapore, South Africa, South Korea, Switzerland, Taiwan, the United Arab Emirates, and the United Kingdom. For Aurigin and its safeguarded service providers, processing in other countries cannot be entirely excluded.
Information processed in another country may be subject to that country’s laws and may be accessible to its courts, law-enforcement agencies, or national-security authorities.
The Privacy Officer can answer questions about service-provider processing outside Canada.