Legal & Compliance

Privacy Policy

Last updated: March 27, 2026  ·  Effective: March 27, 2026

← Back to sarahconsults.com
Hill Trade LLC — Operator of sarahconsults.com and the Sarah.AI mobile application Contact: privacy@sarahconsults.com

Summary: We collect only what we need to provide our services. We do not sell your personal data. You have the right to access, correct, or delete your data at any time. This policy applies to our website, the Sarah.AI mobile app, and all related services.

Table of Contents

  1. Who We Are
  2. Data We Collect
  3. How We Use Your Data
  4. Legal Basis for Processing
  5. Data Sharing & Sub-processors
  6. Data Retention
  7. Your Rights (GDPR)
  8. California Residents (CCPA)
  9. Children's Privacy
  10. Cookies & Tracking
  11. Data Security
  12. International Transfers
  13. Mobile App Permissions
  14. Changes to This Policy
  15. Contact & Complaints

1. Who We Are

This Privacy Policy applies to all products and services operated by Hill Trade LLC ("we," "our," or "us"), including:

Hill Trade LLC is a business entity registered in the United States and is the data controller for personal information we process.

2. Data We Collect

We collect data in three ways: information you provide directly, information collected automatically, and information from third parties.

2.1 Information You Provide

Data Type Examples When Collected
Contact information Name, email address, phone number Consultation booking, contact form
Business information Company name, industry, business challenges Consultation intake, chat
Chat messages Questions and responses in the AI chat App and website chat feature
Communications Email content, feedback, support requests Any time you contact us

2.2 Information Collected Automatically

Data Type Examples Purpose
Device information Device model, OS version, app version App functionality, crash reports
Usage data Pages visited, features used, session duration Service improvement
Log data IP address, browser type, timestamps Security, fraud prevention
Location data Approximate location derived from IP address only Localized services, compliance

2.3 Information We Do NOT Collect

3. How We Use Your Data

We use your personal data only for the following purposes:

We do not sell, rent, or trade your personal information to any third party for their marketing purposes.

4. Legal Basis for Processing GDPR

For users in the European Economic Area (EEA), United Kingdom, and Switzerland, we process your personal data under the following legal bases as required by GDPR Article 6:

5. Data Sharing & Sub-processors

We share data only with trusted service providers ("sub-processors") who are contractually bound to protect it. We do not share data with advertisers.

Provider Purpose Data Shared Location
Anthropic (Claude) AI chat responses Chat messages (no name/email) USA
OpenAI (GPT-4o) AI fallback responses Chat messages (no name/email) USA
Google (Gemini) AI fallback responses Chat messages (no name/email) USA / EU
Stripe Payment processing Name, email, billing address USA / EU
IONOS (server hosting) Infrastructure hosting All data stored on server USA / EU
ElevenLabs Voice synthesis Text content only USA / EU
SendGrid / IONOS Mail Transactional email delivery Email address, message content USA
Firebase (Google) App analytics, notifications Device ID, usage events USA / EU
Expo (EAS) Mobile app distribution Device token for push notifications USA

We may also disclose personal data to law enforcement or government authorities when required by law, court order, or to protect the safety of our users or the public.

6. Data Retention

We retain your personal data only as long as necessary for the purposes described in this policy, or as required by law.

Data TypeRetention PeriodReason
AI chat messages 90 days Service quality; deleted on rolling basis
Contact form submissions 3 years Business correspondence
Consultation records 5 years Business and legal requirements
Payment records 7 years Tax and financial compliance (IRS)
Server logs (IP address) 30 days Security monitoring
Marketing preferences Until opt-out or account deletion Consent management

After the retention period, data is securely deleted or anonymized. You may request earlier deletion at any time (see Section 7 and 8).

7. Your Rights (EU / UK / EEA) GDPR

If you are located in the European Economic Area, United Kingdom, or Switzerland, you have the following rights under the General Data Protection Regulation (GDPR) and UK GDPR:

Right of Access (Art. 15)

Request a copy of all personal data we hold about you.

Right to Rectification (Art. 16)

Correct inaccurate or incomplete data about you.

Right to Erasure (Art. 17)

Request deletion of your data ("right to be forgotten").

Right to Restrict Processing (Art. 18)

Pause processing of your data in certain circumstances.

Right to Data Portability (Art. 20)

Receive your data in a structured, machine-readable format.

Right to Object (Art. 21)

Object to processing based on legitimate interests or marketing.

Right to Withdraw Consent

Withdraw consent at any time without affecting prior processing.

Right to Lodge a Complaint

File a complaint with your national data protection authority.

To exercise any of these rights, contact us at privacy@sarahconsults.com. We will respond within 30 days (extendable to 90 days for complex requests). We do not charge a fee for reasonable requests.

If you are in the EU, you may also file a complaint with your local supervisory authority. A list of EU supervisory authorities is available at edpb.europa.eu.

8. California Residents CCPA / CPRA

If you are a California resident, you have specific rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):

Your California Rights

Categories of Personal Information Collected (CCPA)

CategoryCollected?Sold?Shared?
Identifiers (name, email, IP)YesNoService providers only
Commercial informationYes (if you purchase)NoStripe (payment processor)
Internet / network activityYes (usage logs)NoAnalytics only
Geolocation (approximate)Yes (IP-derived)NoNo
Professional informationYes (if provided)NoNo
Inferences from dataNoNoNo
Sensitive personal informationNoNoNo

How to Submit a CCPA Request

Submit a verifiable consumer request by emailing privacy@sarahconsults.com with subject line "CCPA Privacy Request". We will verify your identity and respond within 45 days. You may designate an authorized agent to submit requests on your behalf.

For California residents, our contact for privacy matters is also available at:
Hill Trade LLC · privacy@sarahconsults.com · Subject: "CCPA Request"

9. Children's Privacy COPPA

Our services are intended for users aged 18 and older. We do not knowingly collect personal information from anyone under the age of 18.

If you are a parent or guardian and believe your child under 18 has provided us with personal information, please contact us at privacy@sarahconsults.com and we will promptly delete that information.

This policy complies with the Children's Online Privacy Protection Act (COPPA, 15 U.S.C. § 6501–6506).

10. Cookies & Tracking Technologies

Our website uses minimal cookies and tracking technologies.

Cookie TypePurposeDurationCan Opt Out?
Essential cookies Session management, security (CSRF tokens) Session / 24 hours No — required for service
Analytics (optional) Understand which pages are most useful Up to 2 years Yes — see below

We do not use third-party advertising cookies or tracking pixels (no Facebook Pixel, Google Ads remarketing, etc.).

You can control cookies through your browser settings. Most browsers allow you to block or delete cookies. Note that disabling essential cookies may affect website functionality.

Do Not Track (DNT): We honor browser DNT signals where technically feasible. When we detect a DNT signal, we disable all optional analytics for that session.

11. Data Security

We implement industry-standard security measures to protect your personal information:

In the event of a data breach that is likely to result in risk to your rights and freedoms, we will notify you and applicable regulatory authorities within 72 hours of becoming aware (as required by GDPR Article 33), and within the timeframes required by applicable US state laws.

12. International Data Transfers GDPR

Hill Trade LLC is based in the United States. If you access our services from the EU, EEA, UK, or other jurisdictions with data protection laws, please be aware that your information may be transferred to and processed in the United States.

For transfers of personal data from the EEA or UK to the United States, we rely on:

Our primary sub-processors (Anthropic, Google, Stripe, IONOS) maintain their own GDPR-compliant data transfer mechanisms. We have Data Processing Agreements in place with all sub-processors that handle EEA data.

13. Mobile App Permissions

The Sarah.AI mobile application (Android and iOS) requests the following device permissions. All permissions are optional unless noted, and you can revoke them in your device settings at any time.

PermissionPlatformWhy It's NeededRequired?
Internet access Android, iOS Connect to AI services and send/receive chat messages Yes
Camera Android, iOS Optional — future video consultation feature No
Microphone Android, iOS Optional — future voice consultation feature No
Push notifications Android, iOS Receive consultation reminders and updates No
Network state Android Detect connectivity to provide offline-aware UX No
Vibrate Android Haptic feedback for notifications No
Receive boot complete Android Schedule local notifications after device restart No
Bluetooth (connect/scan) Android Reserved for future accessibility features No

The app does not use camera or microphone permissions in the current version (1.0.0). These are declared for future use only and will not be activated without explicit in-app notice and consent.

14. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.

When we make material changes, we will:

Your continued use of our services after the effective date of the revised policy constitutes your acceptance of the changes. We encourage you to review this policy periodically.

15. Contact Us & Privacy Complaints

For any privacy questions, requests, or complaints, please contact us:

Hill Trade LLC — Privacy Team

Email: privacy@sarahconsults.com

Website: https://sarahconsults.com

Subject line for requests: "Privacy Request" or "CCPA Request" or "GDPR Request"

We aim to respond to all privacy requests within 30 days. For CCPA requests, the statutory limit is 45 days.

EU/UK Representative

Hill Trade LLC does not currently maintain a formal EU/UK representative office. For EU or UK data subject requests, please contact us directly at privacy@sarahconsults.com. If your concern is not resolved, you have the right to lodge a complaint with your national data protection authority.

California Privacy Requests

California residents may submit requests under CCPA/CPRA to privacy@sarahconsults.com with subject: "CCPA Privacy Request". We will verify your identity before processing. You may also designate an authorized agent.

This Privacy Policy was last updated on March 27, 2026. Hill Trade LLC reserves the right to modify this policy. Prior versions are available upon request. This policy is governed by the laws of the United States. Disputes will be resolved in accordance with our Terms of Service.