Política de
Privacidad
Privacy
Policy
Vigente desde Mayo 2026 · Actualizada Octubre 2026 · Ley 8968 (CR) · RGPD (UE) · terrasonum.io Effective May 2026 · Updated October 2026 · Law 8968 (CR) · GDPR (EU) · terrasonum.io
Tu huella de voz, bajo tu control Your voice fingerprint, under your control
VoiceGuard procesa y almacena los siguientes datos biométricos de voz, únicamente con tu consentimiento explícito:
- Fuente de captura: micrófono del dispositivo del usuario, activado desde el navegador web. Terrasonum nunca accede al micrófono sin interacción activa del usuario.
- Vector de embedding de 256 dimensiones: representación matemática asociada a la voz registrada.
- Métricas acústicas auxiliares: análisis espectral MFCC (40 coeficientes) y varianza de spectral bandwidth. Se usan para evaluación y calibración del sistema; por sí solas no constituyen una detección de síntesis por IA.
- Marca de tiempo de registro, hash SHA-256 del audio y metadatos del archivo (duración, formato, sample rate).
Pila de procesamiento: El audio se procesa en un pipeline de IA que genera el embedding de voz y calcula métricas acústicas auxiliares. Todo el procesamiento ocurre en Azure East US 2 (la región de Azure geográficamente más próxima a Costa Rica, ubicada entre las latitudes −10° y +15°). El pipeline opera como un microservicio aislado en Azure Container Apps.
El audio no persiste. Inmediatamente tras la extracción del embedding, el buffer de audio se libera y destruye en memoria — nunca se escribe en disco ni en Azure Blob Storage. Solo el vector matemático de 256 dimensiones queda almacenado. Este proceso es técnicamente irreversible: el audio original no puede reconstruirse desde el embedding.
Los vectores biométricos no se comparten con terceros, no se usan para entrenar modelos de IA ajenos a Terrasonum, y no se transfieren fuera del entorno de Azure (región East US 2). Se clasifican como datos de categoría especial bajo el artículo 9 del RGPD y el artículo 4 de la Ley 8968 de Costa Rica.
Organizaciones a las que te vinculas como vocero. Una organización cliente de VoiceGuard puede invitarte a vincularte como vocero. Solo ocurre si aceptas tú, con tu propia cuenta, después de leer qué verá y qué no. Desde que aceptas, esa organización recibe tu nombre, tu correo, la fecha en que aceptaste y, si registraste tu voz, el identificador de tu certificado, su fecha y si está sellado, con sello de tiempo y firmado: lo mismo que ya muestra la página pública del certificado. Nunca recibe tu vector biométrico, ningún audio ni las verificaciones hechas contra tu certificado. Si la organización lo configura, esos mismos datos se envían también a sus propios sistemas, en un aviso firmado, cuando aceptas, registras o borras tu voz, o te retiras: no son datos distintos, sino los mismos, entregados sin que tenga que consultarlos. Puedes retirar el vínculo cuando quieras desde Mi panel, sin pedir permiso a la organización; desde ese momento deja de recibir esos datos (recibe un último aviso de que te retiraste). Guardamos la fecha en que aceptaste, la versión del texto que aceptaste y la fecha en que lo retiraste, como constancia del consentimiento.
Acceso del usuario: puedes descargar tu certificado biométrico, consultar los metadatos asociados (fecha de registro, duración, hash), y eliminar tu huella de voz en cualquier momento desde Mi panel → Mi Voz → «Eliminar mi huella de voz». También puedes pedirlo escribiendo a privacidad@terrasonum.io desde el correo de tu cuenta, y lo atendemos en el plazo indicado en «Tus derechos sobre tus datos».
Qué se borra y qué queda. Se borran tu vector biométrico, el hash de tu grabación, el sello de tiempo, la firma del certificado y las verificaciones hechas contra tus certificados. El certificado queda revocado: su enlace sigue abriendo y dice que fue revocado y cuándo, para que nadie que tenga una copia lo tome por vigente. Para eso guardamos solo el identificador del certificado, su fecha de emisión, la de revocación y el motivo, sin tu nombre ni ningún dato de tu voz. Las organizaciones de las que seas vocero verán «certificado revocado» y la fecha. Lo borrado sigue en las copias de seguridad de la base de datos hasta 7 días, y los registros de acceso (logs) pueden contener fragmentos del hash o el identificador del certificado durante su plazo de retención. El sello de tiempo lo emite una autoridad externa, la del Banco Central de Costa Rica, que puede conservar su propio registro de lo que selló: como mucho el hash de tu grabación, nunca el audio ni tu nombre.
Audios que certificas como tuyos. Con tu voz registrada puedes certificar audios que vas a publicar (Mi panel → Mis audios certificados). No guardamos el audio: guardamos su hash SHA-256, su tamaño, el título que le pones, tu nombre tal como aparece en tu cuenta, la fecha, el sello de tiempo y la firma. Guardamos también una huella de su sonido: un resumen numérico de cómo cambia la energía del audio en el tiempo (32 bits cada 8 milisegundos), que no contiene el audio. Sirve para encontrar copias del audio que cambiaron de formato (por ejemplo, al subirlo a una red social); no forma parte de lo firmado y no es pública. Ese certificado es público: cualquiera con el enlace, o con una copia exacta del archivo, ve el título, tu nombre y la fecha. La página de comprobación calcula el hash en el navegador de quien comprueba; a nosotros solo nos llega el hash, nunca su audio. Si el archivo no coincide byte a byte, el navegador calcula también la huella del sonido de su primer minuto y solo nos envía esa huella, para buscar un audio certificado que se le parezca; no la guardamos. Puedes revocar cada certificado cuando quieras; si borras tu huella de voz, se revocan todos. Al revocar se borran el título, tu nombre, el sello, la firma y la huella de su sonido, y quedan el identificador, el hash, las fechas y el motivo.
Licencias de uso de tu voz. Una organización puede proponerte usar tu voz con IA (Mi panel → Licencias de mi voz); para eso necesita el identificador de tu certificado de voz, que solo tú le das. Si firmas, con tu verificación en dos pasos, guardamos los términos (usos, territorios, idiomas, periodo, modalidad de pago, revocación), tu nombre tal como aparece en tu cuenta, el nombre de la organización, la fecha, el sello de tiempo y la firma. La licencia es pública para quien tenga su identificador: cualquiera ve quién la firmó, para quién y para qué. El importe y las condiciones de pago no se publican: los guardamos cifrados y solo los ven tú y la organización; la firma cubre solo su hash. La organización recibe un aviso cuando firmas o revocas. Si borras tu huella de voz, tus licencias se revocan al instante y se borran tu nombre, la firma, el sello y las condiciones de pago; quedan el identificador, los términos públicos, las fechas y el motivo.
Credenciales de uso de tu voz. Cada vez que la organización genera un audio con tu voz bajo una licencia, pide una credencial: guardamos el uso, el territorio y el idioma que declara, la huella (SHA-256) del audio y su duración, la fecha y la firma, con tu nombre. No guardamos el audio. La credencial va dentro del audio generado y es pública para quien la tenga: dice que tú autorizaste ese uso, y que lo declaró esa organización. Tú y la organización ven cuántas se emitieron. Si pactaste aprobar cada uso, ves cada petición en tu panel y decides. Si borras tu huella de voz, las credenciales se anulan: se borran tu nombre y la firma. Las copias que ya circulen dentro de audios siguen existiendo, pero nuestra página dirá que están anuladas.
VoiceGuard processes and stores the following voice biometric data, only with your explicit consent:
- Capture source: the user's device microphone, activated from the web browser. Terrasonum never accesses the microphone without active user interaction.
- 256-dimension embedding vector: a mathematical representation associated with the registered voice.
- Auxiliary acoustic metrics: MFCC spectral analysis (40 coefficients) and spectral bandwidth variance. They are used to evaluate and calibrate the system; on their own, they do not detect AI-generated speech.
- Registration timestamp, SHA-256 hash of the audio, and file metadata (duration, format, sample rate).
Processing stack: Audio is processed through an AI pipeline that generates the voice embedding and calculates auxiliary acoustic metrics. All processing occurs in Azure East US 2 (the Azure region geographically closest to Costa Rica, between latitudes −10° and +15°). The pipeline runs as an isolated microservice on Azure Container Apps.
Audio does not persist. Immediately after embedding extraction, the audio buffer is released and destroyed in memory — it is never written to disk or to Azure Blob Storage. Only the 256-dimension mathematical vector is stored. This process is technically irreversible: the original audio cannot be reconstructed from the embedding.
Biometric vectors are not shared with third parties, not used to train AI models external to Terrasonum, and not transferred outside the Azure environment (East US 2 region). They are classified as special category data under Article 9 of the GDPR and Article 4 of Costa Rican Law 8968.
Organizations you link to as a speaker. A VoiceGuard client organization may invite you to link to it as a speaker. It only happens if you accept, with your own account, after reading what it will and will not see. From the moment you accept, that organization receives your name, your email, the date you accepted and, if you registered your voice, your certificate identifier, its date and whether it is sealed, timestamped and signed: the same information the public certificate page already shows. It never receives your biometric vector, any audio, or the verifications made against your certificate. You can withdraw the link at any time from My dashboard, without asking the organization; from then on it stops receiving that data. We keep the date you accepted, the version of the text you accepted and the date you withdrew, as a record of consent.
User access: you can download your biometric certificate, view associated metadata (registration date, duration, hash), and delete your voice fingerprint at any time from My dashboard → My Voice → “Delete my voice fingerprint”. You can also request it by writing to privacidad@terrasonum.io from your account's email address, and we handle it within the timeframe set out in “Your rights over your data”.
What is deleted and what remains. Your biometric vector, the hash of your recording, the timestamp, the certificate signature and the verifications made against your certificates are deleted. The certificate becomes revoked: its link still opens and says that it was revoked and when, so that no one holding a copy mistakes it for a valid one. For that we keep only the certificate identifier, its issue date, its revocation date and the reason, without your name or any data about your voice. Organizations you are a speaker for will see “certificate revoked” and the date. Deleted data remains in database backups for up to 7 days, and access logs may contain fragments of the hash or the certificate identifier during their retention period. The timestamp is issued by an external authority, that of the Central Bank of Costa Rica, which may keep its own record of what it stamped: at most the hash of your recording, never the audio or your name.
Audio you certify as yours. With your voice registered you can certify audio you are about to publish (My dashboard → My certified audio). We do not store the audio: we store its SHA-256 hash, its size, the title you give it, your name as it appears on your account, the date, the timestamp and the signature. We also store a fingerprint of its sound: a numerical summary of how the audio's energy changes over time (32 bits every 8 milliseconds), which does not contain the audio. It is used to find copies of the audio that changed format (for example, when uploaded to a social network); it is not part of what is signed and it is not public. That certificate is public: anyone with the link, or with an exact copy of the file, sees the title, your name and the date. The verification page computes the hash in the checker's browser; only the hash reaches us, never their audio. If the file does not match byte for byte, the browser also computes the sound fingerprint of its first minute and sends us only that fingerprint, to look for a certified audio that resembles it; we do not store it. You can revoke each certificate at any time; if you delete your voice fingerprint, all of them are revoked. Revoking deletes the title, your name, the timestamp, the signature and the fingerprint of its sound, and keeps the identifier, the hash, the dates and the reason.
Licences to use your voice. An organization can propose to use your voice with AI (My dashboard → Licences of my voice); to do so it needs your voice certificate identifier, which only you give it. If you sign, with your two-step verification, we store the terms (uses, territories, languages, period, payment mode, revocation), your name as it appears in your account, the organization's name, the date, the timestamp and the signature. The licence is public to anyone with its identifier: anyone can see who signed it, for whom and for what. The amount and payment conditions are not published: we store them encrypted and only you and the organization see them; the signature covers only their hash. The organization is notified when you sign or revoke. If you delete your voice fingerprint, your licences are revoked immediately and your name, the signature, the timestamp and the payment conditions are deleted; the identifier, the public terms, the dates and the reason remain.
Credentials for uses of your voice. Each time the organization generates audio with your voice under a licence, it requests a credential: we store the use, territory and language it declares, the fingerprint (SHA-256) of the audio and its duration, the date and the signature, with your name. We do not store the audio. The credential travels inside the generated audio and is public to whoever has it: it says you authorised that use, and that the organization declared it. You and the organization see how many were issued. If you agreed to approve each use, you see every request in your dashboard and decide. If you delete your voice fingerprint, credentials are voided: your name and the signature are deleted. Copies already travelling inside audio files still exist, but our page will say they are voided.
Metadatos geográficos de las grabaciones Geographic metadata of recordings
Los archivos de audio subidos pueden contener metadatos de geolocalización (coordenadas GPS) incrustados por el dispositivo de grabación. Terrasonum puede usar estos datos para enriquecer la taxonomía del sonido con etiquetas geográficas (ej. "Bosque lluvioso · Península de Osa, Costa Rica") y para generar mapas sonoros regionales de acceso público con fines educativos y de conservación.
Estos datos de ubicación nunca se venden ni se comparten con anunciantes ni con terceros comerciales.
Puedes eliminar los metadatos GPS del archivo antes de subirlo usando herramientas como ExifTool o la app de Fotos de tu dispositivo. También puedes solicitar la eliminación de cualquier dato de ubicación ya asociado a tus archivos escribiendo a privacidad@terrasonum.io; procesamos la solicitud dentro de los 30 días hábiles siguientes.
Uploaded audio files may contain geolocation metadata (GPS coordinates) embedded by the recording device. Terrasonum may use this data to enrich the sound taxonomy with geographic tags (e.g., "Rainforest · Osa Peninsula, Costa Rica") and to generate publicly accessible regional sound maps for educational and conservation purposes.
This location data is never sold or shared with advertisers or commercial third parties.
You can remove GPS metadata from the file before uploading using tools such as ExifTool or your device's Photos app. You may also request deletion of any location data already associated with your files by emailing privacidad@terrasonum.io; we process requests within 30 business days.
Tus derechos sobre tus datos Your rights over your data
Bajo la Ley de Protección de la Persona frente al Tratamiento de sus Datos Personales (Ley 8968, Costa Rica) y el Reglamento General de Protección de Datos (RGPD, Unión Europea), tienes los siguientes derechos:
- Acceso: solicitar un resumen completo de todos los datos personales que almacenamos sobre ti.
- Rectificación: corregir información inexacta o incompleta.
- Supresión ("derecho al olvido"): solicitar la eliminación total de tus datos, incluyendo vectores biométricos y grabaciones.
- Oposición: oponerte al tratamiento de tus datos para fines de marketing, investigación o elaboración de perfiles.
- Portabilidad: recibir tus datos en formato estructurado y de uso común (JSON, CSV).
- Limitación: solicitar que el tratamiento se restrinja mientras se resuelve una disputa o reclamación.
- Retirada del consentimiento: retirar en cualquier momento cualquier consentimiento que hayas otorgado, sin afectar la licitud del tratamiento previo.
Para ejercer cualquiera de estos derechos, contacta a privacidad@terrasonum.io. Respondemos en un máximo de 30 días hábiles. Si la solicitud es compleja, podemos extender el plazo 60 días adicionales, notificándote dentro del primer mes.
Under the Law on Protection of Individuals against the Processing of Personal Data (Law 8968, Costa Rica) and the General Data Protection Regulation (GDPR, European Union), you have the following rights:
- Access: request a complete summary of all personal data we store about you.
- Rectification: correct inaccurate or incomplete information.
- Erasure ("right to be forgotten"): request complete deletion of your data, including biometric vectors and recordings.
- Objection: object to the processing of your data for marketing, research or profiling purposes.
- Portability: receive your data in a structured, commonly used format (JSON, CSV).
- Restriction: request that processing be restricted while a dispute or claim is being resolved.
- Withdrawal of consent: withdraw any consent you have given at any time, without affecting the lawfulness of prior processing.
To exercise any of these rights, contact privacidad@terrasonum.io. We respond within a maximum of 30 business days. For complex requests, we may extend this by 60 additional days, notifying you within the first month.
Cuánto tiempo conservamos tus datos How long we keep your data
| Tipo de dato | Período de retención |
|---|---|
| Uploads sin procesar | 30 días desde la carga |
| Datos de cuenta activa | Vigencia de la cuenta + 90 días tras eliminación |
| Vectores biométricos (VoiceGuard) | Hasta que los eliminas; copias de seguridad hasta 7 días más |
| Certificados de audios publicados (VoiceGuard) | Hasta que los revocas o borras tu huella de voz (la huella de su sonido se borra en ese momento); después queda solo la lápida (identificador, hash, fechas y motivo) |
| Datos de transacciones | 5 años (obligación fiscal, Ministerio de Hacienda CR) |
| Registros de acceso (logs) | 90 días |
| Datos de ubicación GPS | Vinculados al archivo; se eliminan junto con él |
Los datos de menores de 18 años no son recolectados deliberadamente. Si Terrasonum detecta datos de menores, los elimina de inmediato y notifica al responsable legal.
| Data type | Retention period |
|---|---|
| Unprocessed uploads | 30 days from upload |
| Active account data | Account lifetime + 90 days after deletion |
| Biometric vectors (VoiceGuard) | Until you delete them; backups up to 7 more days |
| Published audio certificates (VoiceGuard) | Until you revoke them or delete your voice fingerprint (the fingerprint of their sound is deleted at that moment); afterwards only the tombstone remains (identifier, hash, dates and reason) |
| Transaction data | 5 years (tax obligation, Costa Rican Ministry of Finance) |
| Access logs | 90 days |
| GPS location data | Linked to the file; deleted together with it |
Data from individuals under 18 is not deliberately collected. If Terrasonum detects data from minors, it is deleted immediately and the legal guardian is notified.
Marco legal que nos vincula Legal framework that binds us
Terrasonum trata datos biométricos de voz, que constituyen datos de categoría especial bajo múltiples marcos regulatorios. Cumplimos con:
- Ley 8968 — Costa Rica (Ley de Protección de la Persona frente al Tratamiento de sus Datos Personales): base legal de operación. Los datos biométricos se clasifican como datos sensibles bajo el artículo 4. El usuario tiene derecho de acceso, rectificación, supresión y oposición. La autoridad de control es la PRODHAB (prodhab.go.cr).
- RGPD Art. 9 — Unión Europea (Reglamento General de Protección de Datos): los datos biométricos para identificación inequívoca son categoría especial bajo el Art. 9. El tratamiento requiere consentimiento explícito (Art. 9.2.a). El usuario tiene derecho de acceso (Art. 15), rectificación (Art. 16), supresión (Art. 17), portabilidad (Art. 20) y oposición (Art. 21). Base legal: consentimiento explícito e interés legítimo en proteger la identidad del usuario.
- CCPA — California Consumer Privacy Act (USA): para usuarios ubicados en California, aplicamos los derechos CCPA: derecho a saber qué datos personales se recopilan, derecho a eliminar datos personales, derecho a no discriminación por ejercer estos derechos. Terrasonum no vende datos personales ni biométricos a terceros (opt-out no aplicable). Las solicitudes CCPA pueden enviarse a privacidad@terrasonum.io.
Para datos biométricos, la base legal aplicada es el consentimiento explícito e informado del usuario, otorgado antes de activar el micrófono por primera vez. Este consentimiento puede retirarse en cualquier momento, sin afectar la licitud del tratamiento previo.
Terrasonum processes voice biometric data, which constitutes special category data under multiple regulatory frameworks. We comply with:
- Law 8968 — Costa Rica (Law on Protection of Individuals against the Processing of Personal Data): the primary legal basis for operations. Biometric data is classified as sensitive data under Article 4. Users have rights of access, rectification, deletion and objection. The supervisory authority is PRODHAB (prodhab.go.cr).
- GDPR Art. 9 — European Union (General Data Protection Regulation): biometric data for unique identification is special category under Art. 9. Processing requires explicit consent (Art. 9.2.a). Users have rights of access (Art. 15), rectification (Art. 16), erasure (Art. 17), portability (Art. 20) and objection (Art. 21). Legal basis: explicit consent and legitimate interest in protecting the user's identity.
- CCPA — California Consumer Privacy Act (USA): for users located in California, we apply CCPA rights: the right to know what personal information is collected, the right to delete personal information, and the right to non-discrimination for exercising these rights. Terrasonum does not sell personal or biometric data to third parties (opt-out not applicable). CCPA requests can be sent to privacidad@terrasonum.io.
For biometric data, the applicable legal basis is the user's explicit and informed consent, obtained before activating the microphone for the first time. This consent can be withdrawn at any time, without affecting the lawfulness of prior processing.
¿Preguntas sobre tus datos? Questions about your data?
Si tienes dudas sobre esta política o quieres ejercer algún derecho, escríbenos.
Responsable del tratamiento: Terrasonum S.A. (en constitución), San José, Costa Rica.
Correo de privacidad: privacidad@terrasonum.io
Autoridad de control (Costa Rica): Agencia de Protección de Datos de los Habitantes — prodhab.go.cr
Autoridad de control (UE): La autoridad de supervisión competente del Estado miembro donde resides.
If you have questions about this policy or wish to exercise any right, write to us.
Data controller: Terrasonum S.A. (in formation), San José, Costa Rica.
Privacy email: privacidad@terrasonum.io
Supervisory authority (Costa Rica): Agency for the Protection of the Rights of Inhabitants — prodhab.go.cr
Supervisory authority (EU): The competent supervisory authority of the Member State where you reside.