Privacy

Privacy is everything to us.

Sophia is HIPAA/PHIPA compliant, and every optional switch starts off.

Effective August 18, 2026Qull · Canada

In plain language

A parent or guardian creates the account. Sophia asks for a practice nickname and an age range, not a birth date. The parent decides whether a transcript may be saved, whether an eligible session may help improve Sophia, and whether anything may later be shared with an SLP. Those choices start off.

Sophia is AI practice support. She does not diagnose, provide treatment or replace a speech-language pathologist.

What we collect

We collect the parent account details needed to sign in and manage the plan. For the child we collect a practice nickname, an age range, practice direction, interests, topics to avoid and the minimum memory needed for a future call.

We also store call timing, activities shown, a short parent summary, safety flags and billing entitlement. A readable transcript is stored only when the parent turns that choice on.

Payment card details are collected and handled by Stripe. Qull does not receive the full card number.

What happens on a call

The browser asks for microphone permission only when a call begins. Audio must be sent to the voice and avatar providers so Sophia can listen and respond. Qull does not retain raw call audio by default.

Sophia identifies herself as AI. Anyone may pause, skip, ask for a grown up or end the call. Safety-related sessions are kept out of product improvement use.

Parent choices

The parent can change family settings, turn optional transcript storage and improvement use off, correct the child profile and end a call at any time. SLP sharing remains off unless the parent later connects an SLP and chooses a limited set of information to share.

A parent can download or delete practice data inside the family account. Qull can also help with access, correction, export or deletion at the address below. Qull may need to verify the account holder before completing a request.

Service providers

Qull uses Netlify for hosting, Supabase for accounts and protected data, ElevenLabs for the live voice conversation, HeyGen for the optional live avatar and Stripe for payments. These providers process only the information needed to deliver their part of Sophia.

Provider configuration and contracts may change as Qull improves reliability. Qull does not sell child information or use it for advertising.

Retention and deletion

Family profile data and session summaries remain in the parent account until the parent deletes them or asks Qull to do so, unless Qull must retain a limited record for security, billing, legal or dispute purposes. Revoked permission records may be retained as an audit record.

When a deletion request is completed, Qull deletes or deidentifies the covered data from active systems and allows protected backups to expire through their normal cycle.

Security and changes

Qull uses signed accounts, server-held provider keys, restricted database access and signed payment webhooks. No online service can promise perfect security. If a material incident affects a family, Qull will respond and provide notice as required.

If this notice changes in a way that requires new permission, Sophia will not begin another call until the parent reviews the new choice.

Contact Qull

Privacy questions and family data requests can be sent to wasiq@qull.io.

Qull is based in Canada.