Privacy Policy
For the Guardian Sarah consumer app. Last updated August 2026.
1. Guardian Sarah is not a HIPAA service
People ask, because the app talks to older adults. Guardian Sarah is not a health-care provider, a health plan, or a business associate of one, and HIPAA does not apply to us. We are a companionship and entertainment app that you buy directly.
That does not mean nobody regulates this data. Because what you say to Sarah can touch on your health, we treat the Service as a health app under the Federal Trade Commission's Health Breach Notification Rule (16 C.F.R. Part 318) and we follow that Rule's notification duties. Section 9 says what that means for you.
2. What we collect
You give us
- Your name, phone number, and email.
- What you want Sarah to know: things you like to talk about, your language, the music and reading you enjoy, when you want her to call, and any reminders you ask her to give you.
- The family members you invite, by name and email or phone.
- Payment information — handled by Apple, Google, or our payment processor. We never see or store your card number.
You create by using it
- What you and Sarah say to each other during a scheduled visit, turned into text so Sarah can understand you and reply.
- Audio recordings — only if you turn recording on. Off by default. See Section 4.
- A written summary of each visit, and Story Vault entries built from the stories you tell.
- Notes your family sends you and Sarah reads aloud.
We collect automatically
- Device type, operating system, app version, and language.
- Crash and error reports, scrubbed of the content of your conversations.
- When calls happened, how long they lasted, and whether they connected.
We do not collect
- No video. No cameras. Ever.
- No location tracking. We do not follow where you are.
- No always-on listening. Sarah's microphone is open only during a visit you scheduled or started. She cannot hear your room between calls.
- No contact-list scraping, no reading your other apps, no advertising identifiers.
3. Why we use it
| What we do | Why |
|---|---|
| Run the visits, understand your speech, produce Sarah's reply | To provide the Service you bought |
| Remember earlier conversations | So Sarah can pick up where you left off — the core of the product |
| Write the summary your family reads | You asked us to, by inviting them |
| Bill you, answer support requests | Contract and legitimate business need |
| Fix bugs, keep the Service secure and available | Legitimate interest in a working, safe product |
We do not use your information for advertising, for profiling, for automated decisions with legal or similarly significant effects, or to build a marketing list from what you told Sarah.
4. Voice, recordings, and consent
Your voice is the most sensitive thing this app touches. Here is precisely what happens to it.
During a visit. Your speech is streamed to a speech-to-text service, converted to text, and discarded as audio unless you turned recording on. The text is sent to an AI language model that produces Sarah's reply, and the reply is turned back into speech.
Transcripts. We keep the text of your visits so Sarah can remember you and so your summary can be written. See Section 8.
Recordings are OFF unless you chose them at signup. To turn recording on or off afterwards, email support@guardiansarah.com and we change it for you. When recording is on:
- Sarah says so out loud at the start of every call, before anything else. That announcement cannot be disabled.
- Sarah cannot stop a recording once a call has begun. She will tell you so if you ask her to. You can end the call at any time, and email us to turn recording off so nothing further is saved — but a call that ends early keeps the audio recorded up to that point.
- You and your invited family can play the recording back in the app.
- Everyday call recordings are deleted automatically after 30 days. Keepsakes you save to the Story Vault are kept until you delete them, one at a time, in the app. To have all saved audio for a person deleted at once, email support@guardiansarah.com — deleted means permanently deleted.
Why she announces it every time. Some states require every person on a call to consent to being recorded, not just the person who owns the app. Announcing it on every recorded call is how we make that true for everyone, everywhere, without asking you to know your own state's rule.
We do not create a voiceprint. We do not perform speaker recognition, voice authentication, or biometric identification of any kind, and we do not build a template of your voice. We do not sell, license, or trade voice data.
5. Who sees your information
The family members you invited. They see your visit summaries, your Story Vault entries, and — if recording is on — your recordings. They cannot listen to a live call. You choose them, and you can have any of them removed at any time — ask us and their access is cut the same day. Removal goes through us on purpose, so nobody in the circle can quietly remove anyone else.
Nobody else, unless one of these applies:
- Service providers who make the app work, under contract, only to provide their service to us: the AI model provider that generates Sarah's replies and writes your summary; the services that carry live call audio and convert speech to and from text; our database, file storage, email, and crash-reporting providers; and the app stores or payment processor that bill you. None of them may train their models on your conversations.
- If the law requires it — a valid subpoena, warrant, or court order. We will tell you unless we are legally barred from doing so.
- To prevent serious harm, where we believe in good faith it is necessary to prevent death or serious physical injury. This is not a promise to intervene, and it is not a safety feature. Sarah does not summon help. In an emergency, call 911.
- A change of business. If we are acquired or merged, your information may transfer. We will email you first, and this policy continues to apply until we give you notice of a new one.
We have never sold personal information and we do not plan to. We do not share it for cross-context behavioral advertising.
6. AI model training
We do not use your conversations, recordings, transcripts, or Story Vault to train AI models — not ours, not our providers'. Our agreements with the AI providers in Section 5 prohibit it. If we ever want to change that, we will ask you first, in plain words, and it will be off unless you say yes.
7. Marketing email
We email you about your account and your subscription. We email you about Guardian Sarah news only if you opted in, and every one of those has an unsubscribe link that works on the first click. We never use anything Sarah learned about you to target marketing.
8. How long we keep things
| Data | Kept for |
|---|---|
| Account details | While your account is open |
| Visit transcripts and summaries | 12 months, then deleted automatically |
| Audio recordings (if you turned recording on) | 30 days, unless you saved it to the Story Vault |
| Story Vault entries you saved | Until you delete them, or 90 days after you close your account |
| Billing records | As long as tax and accounting law requires |
| Crash and error logs | Held by Sentry, the company that reports errors to us, for 30 days. They are scrubbed of the content of your conversations before they are sent. |
When you close your account we delete your personal information within 90 days, except what we must keep for law or accounting. Backups are purged on their own cycle, within 90 days. See how to delete your account — from the app or by email, no sign-in required to make the request.
9. If there is a breach
We treat Guardian Sarah as a health app under 16 C.F.R. Part 318. If your unsecured personally identifiable health information is acquired without your authorization — including by a service provider, and including a disclosure we did not intend — then:
- We will notify you by email and in the app without unreasonable delay and no later than 60 calendar days after we discover it.
- The notice will say what happened, when, what information was involved, what we are doing, and what you can do.
- We will notify the Federal Trade Commission within the Rule's deadlines — within 60 days, or within 10 business days if 500 or more people are affected.
- If 500 or more people in one state are affected, we will notify prominent media in that state.
State breach-notification laws apply on top of this, and we follow those too.
10. Your rights
Everyone who uses Guardian Sarah gets these, regardless of where you live. We do not think privacy rights should depend on your zip code.
- See it. Ask for a copy of what we hold about you.
- Correct it. Fix anything wrong.
- Delete it. A Story Vault entry, all saved audio for a person, or your whole account. Story Vault entries are in-app, done by the family admin. Account deletion is in-app on both apps, and each person closes their own: on the senior's phone, she closes her own account from the gear icon, typing her own first name to confirm; in the family app, the family admin closes the family account, typing their email to confirm. Everyday call recordings delete themselves after 30 days, and email or phone will delete anything sooner — including for someone who no longer has the phone. Details: how to delete an account.
- Take it with you. Export your Story Vault and summaries in a readable format.
- Have recording turned off, at any time — ask us, and nothing else you have is lost.
- Have a family member removed from your circle — ask us, access cut the same day. This one always goes through us, so nobody in the circle can quietly remove anyone else.
- Opt out of marketing email.
- Not be punished for using any of these. We will not degrade the Service or charge you more.
How. Email support@guardiansarah.com. We respond within 45 days and will tell you if we need another 45. Free, unless a request is genuinely excessive.
Someone acting for you. An agent with your written permission may make a request for you. We will confirm with you directly before acting — that check is deliberate, and it is there to protect you.
If you live in California
Under the CCPA/CPRA you also have the right to know the categories of personal information we collect, the purposes, and the categories of third parties we disclose to — all listed in Sections 2, 3, and 5. We do not sell or share personal information as those terms are defined, and we have not in the preceding 12 months. We collect information that may be sensitive personal information (health-adjacent content of conversations, and the contents of communications). We use it only to provide the Service, which is a permitted purpose, so no "Limit the Use of My Sensitive Personal Information" link is required — but you may still ask us to stop, and we will. We do not knowingly collect information from anyone under 16.
If you live in Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, Delaware, or another state with a privacy law
You have the same access, correction, deletion, portability, and opt-out rights listed above, and the right to appeal if we refuse a request. To appeal, reply to our decision or email us with "Appeal" in the subject; we respond within 45 days, and if we deny the appeal we will tell you how to contact your state Attorney General.
Sensitive data consent. Where your state requires opt-in consent before processing sensitive data, the consent you give at signup is that consent, and you can withdraw it by turning recording off or closing your account.
If you live in Washington or Nevada
Washington's My Health My Data Act and Nevada's SB 370 give you specific rights over consumer health data, including the right to withdraw consent and the right to have it deleted. Guardian Sarah does not sell consumer health data. Exercise your rights at support@guardiansarah.com.
11. Security
Encrypted in transit and at rest. Access limited to the few people who need it, and logged. Secrets managed centrally. Family access is enforced at the database, not just in the app, so a bug in the app cannot open your visits to someone you did not invite. Backups are encrypted and stored separately.
No system is perfect and we will not claim otherwise. If something happens, Section 9 says what we do.
12. Children
Guardian Sarah is for adults. We do not knowingly collect information from anyone under 18. If we learn we have, we delete it.
13. Changes
If we change this policy in a way that matters, we will email you and show it in the app at least 30 days before it takes effect, and we will summarize what changed at the top. We will not apply a materially different use to information we already collected without asking you first.
14. Legal terms that also apply
This Privacy Policy is part of our Terms of Service, which also govern any claim about your data. To the fullest extent permitted by law, our total liability for any claim arising out of or relating to this Policy or your information is limited as described in the Terms of Service §11, and any such claim is subject to the arbitration agreement, class-action waiver, and one-year filing deadline in the Terms of Service §12. If any part of this Policy is found unenforceable, the rest stays in effect.
15. Contact
Guardian Sarah LLC, Madison, Wisconsin
support@guardiansarah.com