Summary
Sonar collects personal data as part of its Services, a personal wellbeing coaching service for youth that provides text coaching, identifies moments of distress, and helps navigate the process of finding support, often in partnership with school districts, healthcare providers, clinics, and other organizations supporting youth wellbeing. Given the nature of our Services, your privacy and the privacy of all our users and stakeholders are very important to us. Please read this Privacy Policy to learn how we treat your personal data.
By using or accessing our Services in any manner, you acknowledge that you accept the practices and policies outlined below, and you consent that we will collect, use, and share your information as described in this Privacy Policy. Remember that your use of the Services is at all times subject to our Terms of Use, which incorporates this Privacy Policy. Any terms we use in this Privacy Policy without defining them have the definitions given to them in the Terms of Use.
What This Privacy Policy Covers
This Privacy Policy covers how we treat Personal Data that we collect from or about Participating Youth, parents or legal guardians of Participating Youth, Wellbeing Allies, and other related parties or partner organizations, including school districts, healthcare providers, and clinics. “Personal Data” means any information that identifies or relates to a particular individual and includes information referred to as “personally identifiable information” or “personal information” under applicable data privacy laws or regulations. This Privacy Policy does not cover the practices of Third-Party Services. This Privacy Policy addresses our compliance with the Health Insurance Portability and Accountability Act (“HIPAA”), where applicable; the Family Educational Rights and Privacy Act (“FERPA”); the Children’s Online Privacy Protection Rule (“COPPA”); the Student Online Personal Protection Act (“SOPPA”), where applicable.
When you access Sonar through a school district, certain information may be considered an education record or student data. In these instances, our use and disclosure of your data is governed by applicable student privacy laws, including FERPA and SOPPA where applicable.
When you access Sonar through a healthcare provider (like a doctor or clinic), the information we collect is considered medical privacy data. In these instances, our use and disclosure of your data is strictly governed by medical privacy laws like HIPAA to ensure your information remains secure and confidential.
Personal Data
Categories of Personal Data We Collect
Below are the categories of Personal Data that we collect and have collected over the past 12 months and the categories of parties to whom we have disclosed this Personal Data:
| Type of Personal Data | Who We Disclose Personal Data To |
|---|---|
| Sensitive Health Information |
|
| Profile or Contact Data |
|
| Online Identifiers |
|
| Web and App Analytics |
|
| Other Information that You Voluntarily Choose to Provide |
|
Sensitive Health Information. Full chat transcripts with Sonny are not shared with your provider except when required by law (e.g., immediate safety concerns). However, by using Sonar through a healthcare provider, you consent to our sharing summaries, key insights, topics discussed, or relevant portions of your conversations with that provider for assessment, evaluation, or support. For school partnerships, information is shared with authorized school officials only as permitted by applicable law, our agreement with the school district, or when necessary to prevent harm.
Sources of Personal Data
We collect your Personal Data from the following sources:
Information You Provide Us. We collect Personal Data that you provide when you directly interact with us or our Services, such as when you register or communicate with us.
Information Other People Provide Us. For Participating Youth, we collect Personal Data about you that your Wellbeing Allies, our Wellbeing Coaches, and partner organizations provide when they directly interact with our Services.
Information We Collect Automatically. For Participating Youth, we collect Personal Data automatically from data analytics providers about your interactions with our Services, the devices that you use with our Services, your use of those devices in connection with our Services (including your interactions with Third-Party Services), and survey responses that you provide directly to us or data analytics providers. For Wellbeing Ally users, we collect Personal Data automatically from data analytics providers about your interactions with our Services.
Purposes for Collecting, Using, and Disclosing Personal Data
We collect, use, and disclose your Personal Data for the following business purposes:
Providing the Services. We collect, use, and disclose your Personal Data to provide the Services that you requested, including creating your account, authenticating your log-ins, providing customer service, communicating with you, analyzing your use of the Services and Third-Party Services, generating Notifications, and processing payments. Third-party vendors perform some of these services for us. For the avoidance of doubt, the user data collected is used solely for these purposes and not for any other unauthorized activities. When partnering with a healthcare provider, we only use your data to support the care they provide to you.
Ensuring Security and Integrity. We collect, use, and disclose your Personal Data to detect security incidents that may compromise Personal Data, prevent fraudulent or other illegal activity, and identify Acute Risks to youth users or third parties.
Debugging. We collect, use, and disclose your Personal Data to identify and repair errors that impair the Services’ existing intended functionality.
Undertaking Research. We collect, use, and disclose your Personal Data to undertake internal research for technological development and demonstration. We may also disclose deidentified or aggregated data to trusted partners for research purposes.
Verifying and Maintaining the Services’ Quality and Safety. We collect, use, and disclose your Personal Data to verify and maintain the Services’ quality and safety.
Improving the Services. We may de-identify Customer Data and PHI in accordance with applicable law and contractual requirements, including the HIPAA Privacy Rule safe harbor standards (45 CFR § 164.514(b)(2)) where applicable, to improve and enhance our Platform. We may use only this fully de-identified or aggregated data to train our artificial intelligence or machine learning models. We never use raw or identifiable PHI to train artificial intelligence or machine learning models.
We use and disclose sensitive personal information for the purposes listed above, which includes purposes other than those specified under Cal. Civ. Code § 1798.121(a).
Sale and Sharing of Personal Data
We do not sell your Personal Data, and we do not share it for marketing, advertising, or cross-context behavioral advertising purposes. However, as part of our partnership with a school district, healthcare provider, or other partner organization, certain information (for example, usage metrics, risk indicators, escalation details, and referral information) may be shared with that organization as permitted under applicable privacy laws to provide the Services, support a Participating Youth, or support ongoing care.
Personal Data Retention
We retain each category of your Personal Data for as long as you have an open account with us or as otherwise reasonably necessary to provide you with our Services. If you access Sonar through a school district, we will securely delete or return your data in accordance with applicable law and our agreement with the school district. If you access Sonar through a healthcare provider, we will securely delete or return your data within 30 days of the end of our partnership with your provider, or sooner if requested by your provider.
We may retain Personal Data for longer if doing so is necessary to comply with our legal obligations or if we need it for other legitimate purposes, such as to prevent harm and promote safety, security, and integrity; investigate possible violations of our Terms of Use; or protect ourselves, including our rights, property, or services. In that case, we will retain only the amount of Personal Data that is required to fulfill such purpose, and only for as long as is reasonably necessary to fulfill such purpose. If no such requirements exist, we will only retain data for 30 calendar days following the request.
In order to securely delete or destroy Personal Data when it is no longer needed, we will follow established procedures, including secure deletion from devices, encryption of stored data, and the physical destruction or shredding of paper records and storage media. We will also assess third-party vendors to ensure their compliance with secure disposal practices.
Business Transfers
Your Personal Data that we collect may be transferred to a third party if we undergo a merger, acquisition, bankruptcy, or other transaction in which that third party assumes control of our business (in whole or in part). Should one of these events occur, we will make reasonable efforts to notify you before your information becomes subject to different privacy and security policies and practices.
Deidentified or Aggregated Data
We may create deidentified or aggregated data from the Personal Data we collect, including by removing information that makes the data personally identifiable to a particular user. We may use such deidentified or aggregated data and disclose it to third parties for lawful purposes, including to analyze, build, and improve the Services. We will maintain and use deidentified data in deidentified form only and not attempt to reidentify deidentified data, except for the purpose of determining whether our deidentification process is sufficient. For student data, we will deidentify information in accordance with applicable law and our agreements with school districts. For healthcare data, we will only de-identify information in strict accordance with the HIPAA Privacy Rule safe harbor standards (45 CFR § 164.514(b)(2)).
Third-Party Vendors
We partner with third-party vendors to provide our Services. All vendors are extensively vetted and required to comply with relevant regulations. All third-party vendors who help us provide our Services undergo strict security vetting and are legally bound to protect your information to the same high standards that we do.
Data Security
We seek to protect your Personal Data from unauthorized access, use, and disclosure using appropriate physical, technical, organizational, and administrative security measures based on the type of Personal Data and how we are processing that data. You should also help protect your data by appropriately selecting and protecting your password and/or other sign-on mechanisms; limiting access to your computer or device and browser; and signing off after you have finished accessing your account. Although we work to protect the security of your account and other data that we hold in our records, please be aware that no method of transmitting data over the internet or storing data is completely secure.
Data Protection Measures
Encryption and Access Control. We use industry-standard AES-256 encryption for data at rest and TLS for data in transit. Access to confidential systems is restricted through Role-Based Access Control (RBAC) and multi-factor authentication (MFA), ensuring only authorized personnel access sensitive data.
Vendor and Third-Party Security. All vendors with access to confidential data undergo security assessments aligned with our Third-Party Management Policy. Agreements clearly define responsibilities for protecting data, following standards such as SOC 2 and ISO 27001.
Secure Development and Cloud Protection. Applications follow secure-by-design principles, including least privilege and defense-in-depth. Cloud service providers are continuously evaluated for compliance with our security frameworks to prevent data breaches or service disruptions.
Incident Response and Monitoring. Our Incident Response Plan ensures swift detection, response, and remediation of potential security incidents. Systems are continuously monitored, and incidents are logged and escalated per defined severity levels.
Backup and Data Disposal. Regular backups ensure data availability, and restore tests are performed annually. Personal Data is securely deleted or de-identified when no longer required, following NIST standards for data sanitization.
Employee Training and Awareness. Employees receive security awareness training upon hire and annually thereafter. Access to systems is removed immediately upon termination to prevent unauthorized access.
Compliance with Legal and Regulatory Standards. We follow GDPR, CCPA, and other applicable regulations, ensuring Personal Data is processed lawfully and transparently. Annual policy reviews ensure continued alignment with evolving legal requirements.
Data Breach Notification Procedure
In the event of a data breach or any actual or suspected security incident involving your information, we will immediately take steps to secure our systems. We will notify your partner organization (e.g., school district, healthcare provider) within five (5) business days of discovering the breach, detailing what happened, the data affected, and how we are fixing it. We will work closely with your provider to ensure you are notified and supported in accordance with applicable laws.
Privacy Rights
Under law, individuals and partner organizations (e.g., school districts and healthcare providers), where applicable, have the following privacy rights:
Right to Know. The right to request the following information about how we have collected and used your Personal Data: (i) the categories of Personal Data we collect; (ii) the categories of sources from which we collect your Personal Data; (iii) the business or commercial purpose(s) for collecting your Personal Data; (iv) the categories of third parties to whom we disclose your Personal Data; (v) the categories of third parties to whom we have disclosed your Personal Data; and (vi) the specific pieces of Personal Data we have collected about you in a portable and, where technically feasible, readily usable format that allows you to transmit the data to another entity.
Right to Request Correction. The right to correct inaccurate Personal Data maintained by us.
Right to Request Deletion. The right to request that we delete your Personal Data, subject to certain defined exceptions.
Right to Limit the Use or Disclosure of Sensitive Personal Information. The right to request that we limit our processing of sensitive personal information to the purposes specified under Cal. Civ. Code § 1798.121(a).
Right to Non-Discrimination. The right not to receive discriminatory treatment for exercising your privacy rights.
If you use Sonar through a healthcare provider, your medical records are controlled by that provider. To access, modify, or delete your data, please contact your healthcare provider directly. We will fulfill its instructions regarding your data within ten (10) days of its request.
To submit a request to exercise your privacy rights, including to access, review, request corrections, or delete user data, please contact us at support@sonarmentalhealth.com. To submit a request to exercise your right to limit, you can also click “Limit the Use of My Sensitive Personal Information.” If you are under 13, your parent or guardian must make any request to exercise your right to know, request correction, or request deletion.
Please note that, depending on the nature of your request, we may need additional information to verify your identity or, as applicable, the identity of your parent or guardian, including, without limitation, name, address, telephone number, and/or email addresses. We will use any information you submit only to fulfill your request.
You may use an authorized agent to submit a request to exercise your privacy rights. If you would like to designate an authorized agent, we will require you to submit an email or letter confirming that you authorize your agent to submit the request and including information that allows us to verify your identity. This verification process is not necessary if your authorized agent provides documentation showing that the authorized agent has power of attorney to act on your behalf.
If you are a resident of California, Colorado, Nevada, Oregon, or Texas, you may have additional rights with regard to your Personal Data, including the right to opt-out of the sale of your Personal Data. If you have further questions about your privacy rights or would like to exercise your rights, please contact us at support@sonarmentalhealth.com.
Additional Information
Regarding the Privacy of Users 12 Years of Age or Younger
This section contains additional information regarding the privacy of users 12 years of age or younger. We disclose Personal Data collected from users 12 years of age or younger only as described in this Privacy Policy and as permitted by COPPA. This may include disclosure to authorized third-party vendors and subcontractors who are contractually bound to strict privacy and security restrictions; to partner organizations or Wellbeing Allies where authorized by a parent or guardian or necessary to provide the Services; to prevent harm; or as required by law.
The types of Personal Data collected from users 12 years of age or younger, how that Personal Data is collected, the types of third parties that receive that Personal Data, and how we and those third parties use that Personal Data are described in the “Personal Data” section. We do not enable a user 12 years of age or younger to make Personal Data publicly available. Due to the nature of our Services, we do collect a wide variety of Personal Data from Participating Youth, including Participating Youth under 13; however, we will not require a user 12 years of age or younger to disclose more Personal Data than is reasonably necessary to use our Services. A parent or guardian of a user 12 years of age or younger can review that user’s Personal Data, have that user’s Personal Data deleted, or refuse to permit further collection or use of that user’s Personal Data by contacting us at support@sonarmentalhealth.com. We will give the parent or guardian of a user 12 years of age or younger the option to consent to the collection and use of that user’s Personal Data without consenting to the disclosure of the user’s Personal Data to third parties.
Regarding School Partnerships
In order to provide our Services, we often partner with schools and school districts. We enter into a Data Privacy Agreement with each school or district partner that outlines specific data protection obligations and our compliance with applicable student privacy laws, including FERPA and SOPPA where applicable. Partners or regulatory bodies may request an audit to verify our compliance as permitted by applicable law or our agreements.
Regarding Healthcare Partnerships
In order to provide our Services, we often partner with healthcare providers, clinics, and hospitals. We enter into strict, legally binding data protection agreements with every healthcare partner to ensure your medical data is handled with the highest level of security. Partners or regulatory bodies can audit our systems to verify our compliance with healthcare privacy laws. If we ever receive a legal request for your medical data, we will immediately notify your healthcare provider and coordinate our response with them, unless legally prohibited from doing so.
Changes to This Privacy Policy
We are constantly trying to improve our Services, so we may need to change this Privacy Policy from time to time. We will alert you to any such changes by placing a notice on the Sonar website, by sending you an email, and/or by some other means. Please note that if you have opted not to receive legal notice emails from us (or you have not provided us with your email address), those legal notices may not reach you. We encourage you to review this Privacy Policy periodically.
Contact Information
If you have any questions or comments about this Privacy Policy, the ways in which we collect and use your Personal Data or your choices and rights regarding such collection and use, please do not hesitate to contact us at:
- Website
- www.sonarmentalhealth.com
- Address
- 2108 N ST # 9120, Sacramento, CA 95816