Privacy Policy
The Scott-Morgan Foundation
Version 2.2 · Published 20 May 2026
Sections:
4. Lawful basis for processing
5. How we use your information
6. How we share your information
11. Personal-data breach notification
12. Voice clones — additional protections
13. Other categories of data subject
1. Who we are
The Scott-Morgan Foundation is a UK charity working on accessible communication technology for people with dysarthric speech and other communication impairments resulting from disease or disability.
The Scott-Morgan Foundation (UK), a charity registered in England and Wales (charity number 1187386), with its registered office at 5 Plantation Way, Primrose Hill, Torquay, Devon TQ2 7SR, United Kingdom. The UK entity is the data controller for the processing described in this policy.
SMF Labs (France), an Association Loi 1901 (SIREN 104729181) headquartered at 28 rue du Colonel Pierre Avia, 75015 Paris, France, is an affiliated entity that supports the CANDOR research programme. A commercial subsidiary (SAS) is planned but is not yet registered.
The Scott-Morgan Foundation, Inc. (United States) is a non-profit in formation. Once registered, this policy will be updated to reflect its role and any associated data flows.
Together we are referred to in this policy as "SMF", "we", or "us". CANDOR is the research programme name; VoxAI is the product name. Where the distinction matters, this policy says so.
2. Scope of this policy
This policy applies to three categories of person.
2.1 VoxAI users
Individuals who hold or are setting up a VoxAI account, including beta testers and users who have created a voice clone or stored other personal data within the Product.
2.2 Research participants
Individuals who participate in the CANDOR research programme. Participation in CANDOR is by enrolment through a clinical partner site under a study-specific consent form. The CANDOR Recorder application, including any open beta period, is restricted to participants enrolled through a clinical partner site. The first clinical partner site is TecSalud (Monterrey, Mexico). Additional clinical partner sites will be named in the study-specific consent documentation provided to you at enrolment as they become active.
2.3 Website visitors, correspondents, donors, employees and contractors
Individuals who visit our websites, contact us by email, donate, or work for or with us. Section 13 covers these categories briefly; the bulk of this policy concerns categories 2.1 and 2.2.
This policy does not cover personal data processed by third parties under their own privacy policies, for example clinical sites that collect data under their own institutional consents, or third-party app stores that distribute our software. Where data flows from such a third party to SMF, this policy governs the SMF-side processing once data reaches us.
3. Information we collect
3.1 VoxAI account and product data (Product users)
When you create a VoxAI account we collect identifying and contact information that allows the account to function: your name, email address, password (stored as a salted bcrypt hash), preferred language, communication needs, and where you tell us, the underlying neurological condition affecting your speech (for example amyotrophic lateral sclerosis, Parkinson's disease, cerebral palsy, post-stroke dysarthria, or other).
When you record audio in VoxAI for the purpose of building a voice clone or improving the model that supports you, we collect those audio recordings together with associated quality-assurance metadata.
When you use VoxAI to communicate we collect the conversation transcripts you generate within the Product, the response suggestions presented to you, the response you selected or typed, and the context in which the conversation occurred to the extent you choose to share it.
When you use the application we collect usage and technical metrics: device type, operating system, application version, crash reports, response latency, feature-use counts, and similar data needed to keep the service working.
We do not currently take payment through VoxAI. If and when paid plans launch, payment processing will be handled by a payment processor under its own privacy policy, and this policy will be updated.
3.2 Voice recordings and clinical data (Research participants)
For research participants who join the CANDOR programme through a clinical site, we process:
-
voice recordings made under the CANDOR clinical protocol;
-
clinical severity ratings recorded by a qualified clinician, including ALSFRS-R speech scores, GRBAS ratings, intelligibility percentages, and listener effort ratings;
-
limited identifying information necessary to administer the study and respect your rights, including your name, date of birth, contact details, carer or next-of-kin contact information where applicable, and a pseudonymous participant code (for example ALS017) that identifies you in the research corpus;
-
derived acoustic and phonological features computed from your recordings;
-
session metadata including recording dates, the device used, microphone source, signal-to-noise ratio, and quality-assurance grades;
-
transcripts of your recordings, including a ground-truth reference (the prompt sentence) and an automatic-speech-recognition transcript;
-
voice notes recorded by your clinician describing your speech;
-
timestamped consent records, including the type of consent given, the version of the consent form, and any subsequent revocation.
​
Voice recordings collected in the clinical research context constitute health data under UK and EU GDPR Article 9, because of the dysarthria clinical context, and sensitive personal data under the LFPDPPP. We process them accordingly. See Section 4 for the lawful basis and Section 9 for security.
​
3.3 Information about minors
VoxAI is not directed to children under the age of 13 and we do not knowingly collect personal data from children under 13 through the Product. If you are under 18 and wish to use VoxAI you will be asked to confirm your age and, in some jurisdictions, to provide verifiable parental consent.
In the research programme we occasionally enrol minors whose parents and treating clinicians have determined that participation is in the child's interest. In such cases we obtain explicit written consent from a legal representative, record the child's separate assent, and apply heightened safeguards documented in the relevant study's Data Protection Impact Assessment.
3.4 Information we do not collect
We do not collect special category data we have no use for. We do not intentionally collect data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, data concerning sex life or sexual orientation, criminal conviction data, or financial account information. Clinical records may incidentally contain family history references; where this happens, we treat that data with the same protections that apply to other clinical data.
4. Lawful basis for processing
4.1 VoxAI product use
For account creation, log-in, and core service delivery, we rely on the necessity of processing for performance of a contract with you (UK GDPR Article 6(1)(b)). The contract is your acceptance of the VoxAI Terms of Service.
For processing your voice recordings to build a voice clone, we rely on your explicit consent under Article 9(2)(a), recorded at the moment you create or modify a voice clone.
For analytics and product improvement, we rely on our legitimate interests (Article 6(1)(f)), specifically the interest in making accessibility technology measurably better, balanced against your interest in your data. You can object to this processing at any time. See Section 7.
4.2 Research participation
For your participation in the CANDOR research programme and the processing of your voice recordings and clinical data for research purposes, our Article 6 lawful basis is legitimate interests under Article 6(1)(f), specifically our interest in advancing accessibility technology and clinical understanding of dysarthric speech for people with voice loss. Our Article 9 condition is processing necessary for scientific research purposes under Article 9(2)(j), read with the UK Data Protection Act 2018, Schedule 1, Part 1, paragraph 4, with the safeguards required by Article 89(1) and documented in our Appropriate Policy Document for the relevant study.
Separately, we obtain study-specific informed consent from every research participant as an ethical and clinical research requirement. The consent form is provided to you at enrolment by the clinical partner site. We record consent in four distinct categories so you can give, decline, or withdraw each independently:
-
Study participation, covering enrolment in the CANDOR research programme and the recording sessions described in the study consent form;
-
Voice cloning, covering the creation of a personalised voice model from your recordings;
-
Future research use, covering the use of your pseudonymised recordings in pooled model training and future research beyond the immediate study protocol;
-
Terms and Conditions, covering your acceptance of the CANDOR Recorder application terms of use.
Withdrawal from a study stops future data collection from you and triggers the handling described in Section 7.4.
4.3 Sensitive personal data under LFPDPPP
For research participants in Mexico, processing of sensitive personal data is additionally based on your express written consent under the LFPDPPP, recorded through the consent form of the specific study, and on the international-transfer disclosures and safeguards set out in Section 8.
6. How we share your information
We share personal data only with the parties described below, only for the purposes set out for each, and under the safeguards described in this policy.
6.1 Within SMF and named researchers
We share personal data among SMF and its affiliated entities, and with a defined list of named SMF researchers and SMF Labs collaborators who have a documented research need. The current list of named researchers with access to your personal data is provided to you at enrolment as part of the study-specific consent documentation and is reviewed quarterly.
Some SMF roles, including the role held by the SMF research administrator, are scoped to all clinical partner sites rather than a single site, in order to operate the research programme across countries. The study-specific consent documentation identifies which SMF personnel can access your data and at what scope.
6.2 Clinical sites and partner researchers
For research participants we share personal data with the clinical site that enrolled you, under a written agreement that incorporates the safeguards described in Section 9. The specific clinical site relevant to your participation is named in the study-specific consent documentation provided to you at enrolment. The site administers the clinical aspects of the study under its own institutional governance; SMF processes the recordings for research purposes under this policy and the study-specific consent and Data Processing Agreement.
6.3 Technology service providers acting as data processors
We engage technology service providers to host, transmit, secure, or process personal data on our behalf. Each processor is bound by a written Data Processing Agreement that limits its processing to the purposes we instruct and requires appropriate security.
Cloud-hosting and audio storage (Google Cloud Platform): the CANDOR Recorder middleware runs on Google Cloud Run in europe-west1 (Belgium). Audio recordings are stored in Google Cloud Storage in the same region, europe-west1 (Belgium). Google acts as a processor under its Cloud Data Processing Addendum.
Database (Supabase): clinical metadata, pseudonymous participant codes, consent records, severity ratings, and audit logs are stored in a managed PostgreSQL database operated by Supabase, Inc. Our Supabase database instance is hosted in Ireland, within the European Economic Area. Supabase acts as a processor under its Data Processing Addendum.
6.4 Voice cloning through your own ElevenLabs account
When you receive a voice clone, the clone is created and held in your own personal ElevenLabs account, set up under the ElevenLabs Impact Program. ElevenLabs, not SMF, is the data controller for your voice clone and for the recordings used to create it through that account, under ElevenLabs' own privacy policy and terms of service.
SMF facilitates your access to the ElevenLabs Impact Program. SMF does not host your voice clone on its own infrastructure and does not receive a copy of the recordings you make through your ElevenLabs account. CANDOR research recordings are kept separate from ElevenLabs and are not transferred to ElevenLabs.
6.5 Disclosures required by law
We disclose personal data to the extent required by applicable law, court order, regulatory request, or to protect the safety of a data subject or another person. Where we receive such a request, we apply the highest available legal protections, including resisting overbroad requests, requiring formal process where the law permits, and notifying you of the request where we are legally able to do so.
6.6 In the event of a corporate transaction
If SMF ever undergoes a merger, acquisition, or asset transfer, your personal data may be transferred as part of that transaction. We would notify you of any such transfer and your rights regarding it. As a registered charity in the UK, the form of any such transaction is constrained by charitable-trust law.
5. How we use your information
5.1 To deliver the VoxAI product to you
We use your account information, voice recordings, conversation transcripts, and selected responses to provide you with the personalised communication-assistance features you have signed up for. This includes generating contextually appropriate response suggestions, training the components of the model specific to your communication style, and providing technical support. The lawful basis is contract performance under Article 6(1)(b).
5.2 To advance CANDOR research
We use voice recordings and clinical data contributed under the CANDOR research programme to build a multi-language corpus of speech from people with dysarthria, to develop and validate AI models that recognise and respond to dysarthric speech, to study how speech changes over the course of progressive conditions such as ALS, and to publish aggregated scientific results that advance the field. The lawful basis is legitimate interests under Article 6(1)(f) and scientific research under Article 9(2)(j).
For research participants we always work from pseudonymised data once your recordings enter the research corpus. Direct identifiers are stripped and replaced with an opaque participant code (for example ALS017 for an ALS patient or CTL005 for a healthy control). The link between the participant code and your identity is held in a separate, more tightly controlled part of our database. Pseudonymised data remains personal data under UK and EU GDPR, and continues to be protected by the safeguards described in this policy.
The aggregated results we publish do not name you and do not include any data that could reasonably re-identify you. If we ever want to describe your case by name, for example as an illustrative case study in a paper or fundraising material, we ask you for separate written permission specific to the intended use.
5.3 To keep our products and services secure and reliable
We use technical metrics, audit logs, security telemetry, and similar data to detect and respond to security incidents, prevent fraudulent or abusive use of our services, and meet our legal obligations. We maintain an append-only audit log of access to personal data, including every time an authorised staff member accesses your identifying information. The lawful basis is legitimate interests under Article 6(1)(f) and legal obligation under Article 6(1)(c).
5.4 To communicate with you
We use your contact information to send you transactional communications about your account, for example password resets, security notices, and study-related updates, and to respond when you contact us. We send marketing or fundraising communications only where you have separately opted in. The lawful basis is contract performance and, for marketing and fundraising, consent under Article 6(1)(a).
5.5 To meet our legal and regulatory obligations
We use your information as required by applicable law, including to respond to lawful requests from supervisory authorities, to comply with tax and charity-regulation obligations, to defend ourselves in legal proceedings, and to meet our record-keeping obligations under research law. The lawful basis is legal obligation under Article 6(1)(c).
5.6 We do not sell your personal data
We do not sell your personal data. We do not share your personal data with third parties for their independent marketing purposes.
5.7 AI training
Your CANDOR research recordings will be used to train AI models that are part of our research output, where you have given consent for future research use under Section 4.2. Specifically, general dysarthric speech recognition and synthesis models are trained on pooled, pseudonymised recordings from many participants. We do not use your data to train third-party general-purpose AI models, we do not allow third parties to do so, and we do not allow training on your data for any purpose other than dysarthric-speech research and accessibility-technology development.
Voice recordings may not be used for biometric authentication, individual identification outside the clinical research context, commercial voice synthesis not authorised by you, or any purpose not described in this policy.
7. Your rights
Wherever you are located, you have meaningful rights over your personal data. The exact scope of those rights depends on the law that protects you. You can exercise any right by contacting us at the address in Section 14.
7.1 Rights under UK and EU GDPR
If you are a UK or EEA resident, you have the right of access to your personal data; the right to rectification of inaccurate or incomplete data; the right to erasure ("right to be forgotten") in defined circumstances; the right to restriction of processing in defined circumstances; the right to data portability for data you have provided to us under consent or contract; the right to object to processing based on our legitimate interests; the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects; and the right to withdraw consent at any time without affecting the lawfulness of prior processing.
You also have the right to lodge a complaint with a supervisory authority. In the United Kingdom the lead authority is the Information Commissioner's Office (ico.org.uk). In your country of residence, the local data-protection authority may also be available to you.
7.2 Rights under California law
Where applicable, California residents may have rights of access, deletion, correction, and portability over their personal information; the right to know what categories of personal information are collected and how they are used; the right to opt out of sales or sharing of personal information (we do not engage in either); the right to limit the use and disclosure of sensitive personal information; and the right to non-discrimination for exercising any of these rights. To exercise these rights, contact us at the address in Section 14 and identify your request as a California privacy request.
7.3 Rights under Mexican law (LFPDPPP)
If you are a Mexican resident, you have the ARCO rights of access, rectification, cancellation, and opposition; the right to withdraw consent; and, where the data subject is deceased, the right of legal heirs to request cancellation of your personal data under the LFPDPPP.
To exercise LFPDPPP rights, contact us at the address in Section 14. For research participants enrolled through TecSalud or another Mexican clinical site you can also contact the site directly; the site will forward your request to us within 72 hours.
7.4 Right to withdraw participation in research
If you participate in CANDOR research, you can withdraw your participation at any time, without giving a reason, by writing to us at the address in Section 14 or by contacting the clinical site that enrolled you. On withdrawal we will:
-
stop collecting new data from you within 24 hours of receipt of the request;
-
delete your raw voice recordings within 30 days, and confirm deletion in writing;
-
delete your voice clone (if one was generated for you) within 30 days, unless you have specified a different disposition for that clone in your consent form;
-
continue to retain derived, pseudonymised features and any results already published, unless retention is itself contrary to the law that applies to you.
Where applicable law requires us to retain certain clinical-research data for a specified period (for example UK clinical-research retention requirements or Mexican NOM-024 retention), that legal retention obligation takes precedence over the 30-day deletion timeline. In those cases we restrict access to your data rather than deleting it, and we explain this to you in writing when we confirm receipt of your withdrawal request.
​
7.5 Posthumous data
VoxAI and the CANDOR research programme both serve people with progressive conditions where end-of-life data handling is a real question. In both contexts we offer you, at the point of consent, three options for what happens to your data after you pass away:
-
A. Continued use of your data within the programme for the full duration of the relevant study or product lifetime.
-
B. Continued use for a defined period after your death, after which all raw recordings are deleted, while derived features may continue to be used.
-
C. Deletion of all raw recordings within 30 days, and your voice clone, where applicable, within 30 days of notification of death.
You can change your election at any time during your lifetime by contacting us. The treatment of your data after death is also governed by the law of your country of residence; for French residents in particular, additional rights to issue directives regarding personal data after death may apply under national law.
8. International transfers
SMF operates from the United Kingdom and works with clinical partners and processors in several countries. Wherever your personal data is transferred outside the jurisdiction where you reside, we apply a transfer mechanism recognised by applicable law.
8.1 UK to EEA and EEA to UK
Personal data flows between the United Kingdom and the European Economic Area are covered by the European Commission's adequacy decision concerning the United Kingdom and the United Kingdom's reciprocal adequacy regulations for the EEA. These jointly authorise the flow of personal data in both directions without additional safeguards. The processing infrastructure for the CANDOR Recorder, including Google Cloud Storage in Belgium and our Supabase database in Ireland, sits within the EEA and is covered by this adequacy framework.
8.2 UK to Mexico and Mexico to UK
Personal data transferred between the United Kingdom and Mexico, including data collected from research participants enrolled through Mexican clinical partner sites, is safeguarded by the UK International Data Transfer Agreement executed between the relevant SMF entity and the clinical partner site, complemented on the Mexican side by the express consent and notification provisions of the LFPDPPP.
For transfers under the UK International Data Transfer Agreement, SMF maintains a transfer risk assessment covering destination-country law, public-authority access risks, and supplementary technical measures including encryption in transit and at rest, pseudonymisation of clinical recordings, and role-based access controls.
8.3 Other transfers
No personal data is transferred to the United States by SMF at this time. When SMF USA is registered as a non-profit, this policy will be updated to disclose the transfer mechanism and the recipient. For any other cross-border flow not described above, for example, future deployments in additional countries, we will identify and document the applicable transfer mechanism before commencing the flow, and update this policy accordingly.
9. Security
We protect your personal data with technical and organisational measures appropriate to its sensitivity. The principal measures are:
-
Encryption in transit using TLS 1.3 for all transmissions between your device, our infrastructure, and our processors.
-
Encryption at rest is applied by our cloud-storage and database providers using industry-standard algorithms.
-
Password storage using bcrypt hashing for all clinical staff accounts.
-
Short-lived authentication tokens (30-minute access tokens, 7-day refresh tokens with single-use rotation).
-
Role-based access control with multi-factor authentication available for privileged accounts.
-
Separation of personally identifying information from research and analytic data, with elevated access controls on the personally identifying information.
-
Append-only audit logging of all access to personal data, with logs reviewed quarterly.
-
Server-side audio verification on every recording uploaded to the CANDOR Recorder, to catch corrupted or non-audio files before they enter the research corpus.
-
Write-once storage for committed research recordings, so that the original audio file cannot be altered after quality-assurance commit.
-
Rate limiting on authentication and data-access endpoints to prevent abuse.
-
Annual review of our technical and organisational measures, with summary findings provided to clinical-site partners on request.
-
An incident response procedure with a 24-hour notification commitment to clinical-site partners, and a 72-hour Article 33 notification commitment to the Information Commissioner's Office and equivalent foreign authorities, for any personal-data breach meeting the relevant threshold.
​
For research participants whose data is processed under a study-specific Data Processing Agreement, additional study-specific measures are documented in that agreement.
No system is ever completely secure. If we become aware of a personal-data breach that creates a meaningful risk to your rights and freedoms, we will notify you in accordance with the law that applies to you.
10. Retention
We keep personal data only for as long as we need it for the purposes set out in this policy or as required by law.
10.1 VoxAI user data
We keep your VoxAI account data for the duration of your active account, plus an additional period (currently up to 24 months) to support reactivation if you return to the service. If your account is dormant for longer than 24 months without communication from you, we will email you, and absent a response we will delete the account.
Conversation transcripts are retained for 90 days unless you ask us to delete them earlier.
10.2 Research-participant data
For research participants, raw voice recordings and clinical data are retained for the duration of the relevant research study plus any applicable statutory clinical-research retention period in the participating site's jurisdiction. Derived features and aggregate model outputs may be retained beyond that point where adequate pseudonymisation measures are in place. You can override this with a withdrawal request under Section 7.4, subject to any legal-hold obligations described in that section.
10.3 Other categories
Email correspondence is retained for up to 7 years for record-keeping purposes. Audit logs are retained for 3 years. Employment and contractor records are retained per the law of the employment jurisdiction. Marketing and fundraising contact lists are deleted on request and reviewed annually.
11. Personal-data breach notification
If we become aware of a personal-data breach affecting you we will notify the appropriate supervisory authority within 72 hours where required, and notify you without undue delay where the breach is likely to result in a high risk to your rights and freedoms. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures we are taking to address the breach.
For research participants, our clinical-site partners are contractually required to notify us of any breach affecting personal data they process on our behalf within 24 hours of becoming aware.
12. Voice clones — additional protections
Where you receive a voice clone through the ElevenLabs Impact Program facilitated by SMF, we commit to the following:
-
The voice clone is created and held in your own ElevenLabs account, not on SMF infrastructure. You control your ElevenLabs account, including deletion of the clone, under ElevenLabs' own terms.
-
SMF does not use voice recordings or voice clones for biometric authentication or for identifying you outside the research or product context you consented to.
-
SMF does not use voice clones for commercial voice synthesis or for any other purpose not described in this policy or in the consent you provided.
-
SMF does not allow any third party with whom we share research data to use voice recordings or voice clones for any unauthorised purpose, and our processor contracts impose the same restriction.
13. Other categories of data subject
13.1 Website visitors
When you visit scottmorganfoundation.org or related sites we collect basic technical information including IP address, browser type, page views, and referring URL, for security and analytics purposes. We do not use third-party advertising cookies. We use a small number of first-party cookies to remember your preferences; you can disable cookies in your browser without affecting the core functionality of the site.
13.2 Donors
If you donate to The Scott-Morgan Foundation we process your contact information and donation history for the purposes of issuing receipts, complying with charity-regulation requirements, and (with your separate opt-in) sending you updates about our work. We do not share donor data with other charities. Donation payment is processed by a payment processor under its own privacy policy.
13.3 Correspondents
If you write to us, we process your message and contact details solely to respond to you and, where relevant, to keep a record of the interaction. We do not add you to mailing lists without your separate consent.
13.4 Employees and contractors
If you work for or with SMF, separate privacy notices apply to your employment- or engagement-related data. Please refer to your contract or contact the People and Operations team.
14. How to contact us
For privacy questions, to exercise any of the rights described in Section 7, to report a suspected breach, or to ask anything else about how we process your personal data, please contact:
The Scott-Morgan Foundation
Email: info@scottmorganfoundation.org
Postal: 5 Plantation Way, Primrose Hill, Torquay, Devon TQ2 7SR, United Kingdom
If your inquiry concerns research participation at a clinical partner site, you can also contact that site's Institutional Privacy Office at the address provided in your study consent form.
We will acknowledge your request within 7 days and respond substantively within the period required by the law that applies to you (typically one month under UK and EU GDPR, 20 days under LFPDPPP). We may extend this period if the request is complex, in which case we will tell you within the original period why we need more time.
15. Automated decisions and profiling
We do not subject you to decisions based solely on automated processing that produce legal or similarly significant effects.
Some features of VoxAI and the CANDOR research pipeline use automated processing, for example, the model that generates response suggestions in the VoxAI conversation interface, or the AI severity pre-screening that informs (but never replaces) a clinician's severity rating in the CANDOR study. The CANDOR severity workflow enforces a blind-rating protocol: the clinician records their independent severity rating before the model prediction is shown to them. These automated outputs are always advisory; a human, whether you, your clinician, or a member of the SMF research team, makes the decision that matters.
16. Data Protection Officer
SMF processes special category personal data through the CANDOR research programme. At our current processing scale, with research participation restricted to enrolled clinical-site participants, we have determined that the formal appointment of a Data Protection Officer under UK GDPR Article 37 is not yet required, and privacy inquiries are handled through the contact details in Section 14. We intend to appoint an independent Data Protection Officer before the public launch of the VoxAI product, with a current target of Q4 2026, and this policy will be updated at that time.
17. Changes to this policy
We may update this policy from time to time, including to reflect changes in our processing, changes in the law, or feedback from users, research participants, or supervisory authorities. When we make a material change, we will notify you in advance, through the CANDOR Recorder application, the VoxAI Product, the consent renewal flow for active research participants, or email, where we have your address on file, and where the change requires fresh consent we will request it before continuing.
The current version is shown at the top of this policy. Earlier versions are archived and available on request.
​
The Scott-Morgan Foundation · UK Registered Charity 1187386 · scottmorganfoundation.org
.png)