Last updated: March 27, 2026 · Effective: March 27, 2026
Summary: We collect only what we need to provide our services. We do not sell your personal data. You have the right to access, correct, or delete your data at any time. This policy applies to our website, the Sarah.AI mobile app, and all related services.
This Privacy Policy applies to all products and services operated by Hill Trade LLC ("we," "our," or "us"), including:
Hill Trade LLC is a business entity registered in the United States and is the data controller for personal information we process.
We collect data in three ways: information you provide directly, information collected automatically, and information from third parties.
| Data Type | Examples | When Collected |
|---|---|---|
| Contact information | Name, email address, phone number | Consultation booking, contact form |
| Business information | Company name, industry, business challenges | Consultation intake, chat |
| Chat messages | Questions and responses in the AI chat | App and website chat feature |
| Communications | Email content, feedback, support requests | Any time you contact us |
| Data Type | Examples | Purpose |
|---|---|---|
| Device information | Device model, OS version, app version | App functionality, crash reports |
| Usage data | Pages visited, features used, session duration | Service improvement |
| Log data | IP address, browser type, timestamps | Security, fraud prevention |
| Location data | Approximate location derived from IP address only | Localized services, compliance |
We use your personal data only for the following purposes:
We do not sell, rent, or trade your personal information to any third party for their marketing purposes.
For users in the European Economic Area (EEA), United Kingdom, and Switzerland, we process your personal data under the following legal bases as required by GDPR Article 6:
We share data only with trusted service providers ("sub-processors") who are contractually bound to protect it. We do not share data with advertisers.
| Provider | Purpose | Data Shared | Location |
|---|---|---|---|
| Anthropic (Claude) | AI chat responses | Chat messages (no name/email) | USA |
| OpenAI (GPT-4o) | AI fallback responses | Chat messages (no name/email) | USA |
| Google (Gemini) | AI fallback responses | Chat messages (no name/email) | USA / EU |
| Stripe | Payment processing | Name, email, billing address | USA / EU |
| IONOS (server hosting) | Infrastructure hosting | All data stored on server | USA / EU |
| ElevenLabs | Voice synthesis | Text content only | USA / EU |
| SendGrid / IONOS Mail | Transactional email delivery | Email address, message content | USA |
| Firebase (Google) | App analytics, notifications | Device ID, usage events | USA / EU |
| Expo (EAS) | Mobile app distribution | Device token for push notifications | USA |
We may also disclose personal data to law enforcement or government authorities when required by law, court order, or to protect the safety of our users or the public.
We retain your personal data only as long as necessary for the purposes described in this policy, or as required by law.
| Data Type | Retention Period | Reason |
|---|---|---|
| AI chat messages | 90 days | Service quality; deleted on rolling basis |
| Contact form submissions | 3 years | Business correspondence |
| Consultation records | 5 years | Business and legal requirements |
| Payment records | 7 years | Tax and financial compliance (IRS) |
| Server logs (IP address) | 30 days | Security monitoring |
| Marketing preferences | Until opt-out or account deletion | Consent management |
After the retention period, data is securely deleted or anonymized. You may request earlier deletion at any time (see Section 7 and 8).
If you are located in the European Economic Area, United Kingdom, or Switzerland, you have the following rights under the General Data Protection Regulation (GDPR) and UK GDPR:
Request a copy of all personal data we hold about you.
Correct inaccurate or incomplete data about you.
Request deletion of your data ("right to be forgotten").
Pause processing of your data in certain circumstances.
Receive your data in a structured, machine-readable format.
Object to processing based on legitimate interests or marketing.
Withdraw consent at any time without affecting prior processing.
File a complaint with your national data protection authority.
To exercise any of these rights, contact us at privacy@sarahconsults.com. We will respond within 30 days (extendable to 90 days for complex requests). We do not charge a fee for reasonable requests.
If you are in the EU, you may also file a complaint with your local supervisory authority. A list of EU supervisory authorities is available at edpb.europa.eu.
If you are a California resident, you have specific rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
| Category | Collected? | Sold? | Shared? |
|---|---|---|---|
| Identifiers (name, email, IP) | Yes | No | Service providers only |
| Commercial information | Yes (if you purchase) | No | Stripe (payment processor) |
| Internet / network activity | Yes (usage logs) | No | Analytics only |
| Geolocation (approximate) | Yes (IP-derived) | No | No |
| Professional information | Yes (if provided) | No | No |
| Inferences from data | No | No | No |
| Sensitive personal information | No | No | No |
Submit a verifiable consumer request by emailing privacy@sarahconsults.com with subject line "CCPA Privacy Request". We will verify your identity and respond within 45 days. You may designate an authorized agent to submit requests on your behalf.
For California residents, our contact for privacy matters is also available at:
Hill Trade LLC · privacy@sarahconsults.com · Subject: "CCPA Request"
Our services are intended for users aged 18 and older. We do not knowingly collect personal information from anyone under the age of 18.
If you are a parent or guardian and believe your child under 18 has provided us with personal information, please contact us at privacy@sarahconsults.com and we will promptly delete that information.
This policy complies with the Children's Online Privacy Protection Act (COPPA, 15 U.S.C. § 6501–6506).
Our website uses minimal cookies and tracking technologies.
| Cookie Type | Purpose | Duration | Can Opt Out? |
|---|---|---|---|
| Essential cookies | Session management, security (CSRF tokens) | Session / 24 hours | No — required for service |
| Analytics (optional) | Understand which pages are most useful | Up to 2 years | Yes — see below |
We do not use third-party advertising cookies or tracking pixels (no Facebook Pixel, Google Ads remarketing, etc.).
You can control cookies through your browser settings. Most browsers allow you to block or delete cookies. Note that disabling essential cookies may affect website functionality.
Do Not Track (DNT): We honor browser DNT signals where technically feasible. When we detect a DNT signal, we disable all optional analytics for that session.
We implement industry-standard security measures to protect your personal information:
In the event of a data breach that is likely to result in risk to your rights and freedoms, we will notify you and applicable regulatory authorities within 72 hours of becoming aware (as required by GDPR Article 33), and within the timeframes required by applicable US state laws.
Hill Trade LLC is based in the United States. If you access our services from the EU, EEA, UK, or other jurisdictions with data protection laws, please be aware that your information may be transferred to and processed in the United States.
For transfers of personal data from the EEA or UK to the United States, we rely on:
Our primary sub-processors (Anthropic, Google, Stripe, IONOS) maintain their own GDPR-compliant data transfer mechanisms. We have Data Processing Agreements in place with all sub-processors that handle EEA data.
The Sarah.AI mobile application (Android and iOS) requests the following device permissions. All permissions are optional unless noted, and you can revoke them in your device settings at any time.
| Permission | Platform | Why It's Needed | Required? |
|---|---|---|---|
| Internet access | Android, iOS | Connect to AI services and send/receive chat messages | Yes |
| Camera | Android, iOS | Optional — future video consultation feature | No |
| Microphone | Android, iOS | Optional — future voice consultation feature | No |
| Push notifications | Android, iOS | Receive consultation reminders and updates | No |
| Network state | Android | Detect connectivity to provide offline-aware UX | No |
| Vibrate | Android | Haptic feedback for notifications | No |
| Receive boot complete | Android | Schedule local notifications after device restart | No |
| Bluetooth (connect/scan) | Android | Reserved for future accessibility features | No |
The app does not use camera or microphone permissions in the current version (1.0.0). These are declared for future use only and will not be activated without explicit in-app notice and consent.
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.
When we make material changes, we will:
Your continued use of our services after the effective date of the revised policy constitutes your acceptance of the changes. We encourage you to review this policy periodically.
For any privacy questions, requests, or complaints, please contact us:
Hill Trade LLC — Privacy Team
Email: privacy@sarahconsults.com
Website: https://sarahconsults.com
Subject line for requests: "Privacy Request" or "CCPA Request" or "GDPR Request"
We aim to respond to all privacy requests within 30 days. For CCPA requests, the statutory limit is 45 days.
Hill Trade LLC does not currently maintain a formal EU/UK representative office. For EU or UK data subject requests, please contact us directly at privacy@sarahconsults.com. If your concern is not resolved, you have the right to lodge a complaint with your national data protection authority.
California residents may submit requests under CCPA/CPRA to privacy@sarahconsults.com with subject: "CCPA Privacy Request". We will verify your identity before processing. You may also designate an authorized agent.
This Privacy Policy was last updated on March 27, 2026. Hill Trade LLC reserves the right to modify this policy. Prior versions are available upon request. This policy is governed by the laws of the United States. Disputes will be resolved in accordance with our Terms of Service.