Sarai not responding? Press here for a new number.
Home

Privacy Policy

Last updated on May 2, 2026

Company: Sarai AI Inc is a Florida company with a principal place of business in Miami, Florida, United States. Mailing address available on request via hey@sarai.solutions.

This Privacy Policy ("Policy") describes how Sarai AI Inc ("Company," "we," "us," or "our") collects, uses, discloses, and safeguards information when you use our website and Sarai AI service (the "Service"). By using the Service, you agree to the practices described in this Policy. If you do not agree, please discontinue use of the Service.

1. Interpretation and Definitions

1.1 Interpretation

Words with initial capital letters have meanings defined in this section. The following definitions apply whether they appear in singular or plural.

1.2 Definitions

2. Information We Collect

2.1 Personal Data

We may collect Personal Data that you provide to us, such as:

2.2 Usage Data

Collected automatically and may include:

3. Tracking Technologies and Cookies

We use Cookies, web beacons, tags, and scripts to track activity and improve the Service.

Cookie Types

4. How We Use Your Information

We may use Personal Data to:

5. How We Share Your Information

We do not sell your Personal Data. We may share information:

6. Service Providers

We engage third-party service providers to operate Sarai AI. Each provider is contractually bound to process your data only as needed to perform its service, under appropriate data-protection terms (DPAs where applicable). For security and competitive reasons, we do not publish information about our infrastructure or specific subprocessors. If you have a legitimate legal, regulatory, or due-diligence need for this information, contact us at the address in Section 12 and we will respond on a case-by-case basis.

7. Analytics, Logs & Advertising Tech

We use analytics and logging tools (e.g., product analytics, performance monitoring, and crash reporting) to understand usage, improve reliability, and secure the Service. These tools may set Cookies or collect pseudonymous identifiers and usage events.

We use third-party advertising and conversion-measurement technologies on our public marketing pages. These technologies may set first-party Cookies and transmit information such as IP address, user agent, page URL, and referral parameters to ad-network providers so that we can measure advertising performance and attribute conversions. These technologies are not loaded on our privacy policy, terms of service, or any signed-in product pages.

We do not "sell" Personal Data for monetary consideration as that term is defined under U.S. state privacy laws. We may "share" Personal Data for cross-context behavioral advertising on our public marketing pages, as that term is defined under applicable U.S. state privacy laws (including, without limitation, California Cal. Civ. Code § 1798.140, the Virginia Consumer Data Protection Act, the Colorado Privacy Act, the Connecticut Data Privacy Act, the Utah Consumer Privacy Act, the Florida Digital Bill of Rights, the Texas Data Privacy and Security Act, the Oregon Consumer Privacy Act, the Montana Consumer Data Privacy Act, the Tennessee Information Protection Act, the Iowa Consumer Data Protection Act, the Indiana Consumer Data Protection Act, the Delaware Personal Data Privacy Act, and the New Jersey Data Privacy Act, as each may be amended). To opt out of such sharing — or to exercise any other state-law right (access, correction, deletion, portability, opt-out of profiling, opt-out of targeted advertising, appeal) — contact us at hey@sarai.solutions with the subject line "Privacy Rights Request" and identify the state in which you reside. We will respond within the timeframe required by your state's law (typically 30–45 days, with a possible extension when permitted).

8. Retention of Personal Data

We retain Personal Data only for as long as necessary to fulfill the purposes described in this Policy, including to comply with legal obligations, resolve disputes, and enforce our agreements.

Usage Data is typically retained for shorter periods of time, unless it is required to maintain the security of the Service, improve functionality, or comply with applicable law. When Personal Data is no longer needed, we will securely delete or anonymize it.

You can wipe all of your conversational data, memory, connections, and reminders at any time using the "Delete all my data" button in your dashboard at https://sarai.solutions/app.

9. International Transfers of Personal Data

Your information, including Personal Data, may be processed and stored at the Company's operating offices and in other jurisdictions where our Service Providers are located. These jurisdictions may have data protection laws that differ from those in your country of residence.

By submitting Personal Data, you consent to its transfer to and processing in jurisdictions outside of your home country. We will take reasonable measures to ensure your Personal Data is treated securely and in accordance with this Privacy Policy, including requiring adequate safeguards where applicable (e.g., Standard Contractual Clauses for transfers from the EEA / UK).

10. Your Rights to Access and Delete Data

You have the right to request access to, correction of, or deletion of your Personal Data that we hold about you.

The Service allows you to update or delete most information directly within your account settings. You may also contact us to request changes or deletions.

To request complete deletion of your Personal Data, email hey@sarai.solutions with the subject line "Delete My Data." We will delete associated Personal Data within 30 days, subject to retention obligations described in Section 8.

Please note that certain information may need to be retained where we have a legal obligation, a legitimate business interest, or to prevent fraud and abuse.

Regional rights. Depending on your location, you may have additional rights under your jurisdiction's privacy laws.

U.S. state rights: If you are a resident of any U.S. state with an applicable consumer privacy law — including California (CCPA/CPRA), Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Florida (FDBR), Texas (TDPSA), Oregon (OCPA), Montana (MCDPA), Tennessee (TIPA), Iowa (ICDPA), Indiana (INCDPA), Delaware (DPDPA), or New Jersey (NJDPA), among others — you may have rights to: (i) confirm whether we process your Personal Data and access a copy; (ii) correct inaccurate Personal Data; (iii) delete Personal Data we collected from you; (iv) obtain a portable copy of Personal Data; (v) opt out of the sale or sharing of Personal Data; (vi) opt out of targeted advertising; (vii) opt out of profiling that produces legal or similarly significant effects; and (viii) appeal a denial of any of the above. We do not discriminate or retaliate against you for exercising these rights.

Additional U.S. federal protections: we comply with the Telephone Consumer Protection Act (TCPA), the CAN-SPAM Act, the Children's Online Privacy Protection Act (COPPA — we do not knowingly collect data from children under 13), Section 5 of the FTC Act, and (where applicable) HIPAA, GLBA, and FERPA. Where state breach-notification laws apply (all 50 states), we will provide notice in accordance with the timeline and method required by your state's law. We comply with New York's SHIELD Act, Massachusetts 201 CMR 17.00, and other applicable state-specific data-security regimes.

EEA / UK rights: If you are in the European Economic Area or United Kingdom, you have rights under the GDPR / UK GDPR, including access, rectification, erasure, restriction, portability, objection, the right not to be subject to solely automated decision-making, and the right to lodge a complaint with your supervisory authority.

Other regions: We make reasonable efforts to honor analogous rights under Canada's PIPEDA, Brazil's LGPD, Australia's Privacy Act, and other comparable regimes.

11. GDPR Legal Bases

Where the GDPR / UK GDPR applies, we process Personal Data on the following legal bases:

  1. Performance of a contract — providing the Service you signed up for.
  2. Legitimate interests — security, fraud prevention, product improvement, and communications about similar services.
  3. Consent — where required (e.g., certain marketing communications, optional connector authorizations).
  4. Legal obligations — tax, accounting, regulatory compliance.

12. Disclosure of Personal Data

Business Transactions

If the Company is involved in a merger, acquisition, financing, or sale of assets, your Personal Data may be transferred as part of that transaction. We will provide notice before your Personal Data is transferred and becomes subject to a different Privacy Policy.

Law Enforcement and Legal Requests

We may disclose Personal Data if required to do so by law or in response to valid requests by public authorities (e.g., courts, regulators, government agencies).

Other Legal Grounds

We may disclose Personal Data where we believe such action is reasonably necessary to:

13. Security of Personal Data

We use commercially reasonable technical and organizational measures to protect your Personal Data, including encryption in transit (TLS) and at rest, scoped OAuth tokens with revocation support, JWT-based session authentication, and audit logging of administrative actions.

However, no method of transmission over the Internet or method of electronic storage is completely secure. Accordingly, while we strive to protect your information, we cannot and do not guarantee the absolute security of Personal Data. You are responsible for maintaining the security of your account credentials (your phone number, your iMessage account, your email) and limiting unauthorized access to your devices.

14. Security Incidents

If we become aware of a security incident that affects your Personal Data, we will investigate and, where required by law, notify you and / or regulators without undue delay, including providing information about steps you can take to mitigate potential harm.

15. Children's Privacy

The Service is intended for users 18 years of age or older and is not directed to minors. We do not knowingly collect Personal Data from anyone under the age of 18. If we become aware that we have collected such data, we will promptly delete it. Parents or guardians who believe their minor child has provided us with information should contact us at the email below so we can remove it.

If you are a parent or guardian and believe your child has provided us with Personal Data, please contact us. Where applicable law requires parental consent for minors, we may request such consent before collecting or using Personal Data.

16. Use of Google User Data and Artificial Intelligence

We use Google Workspace APIs (Gmail, Google Drive, Google Calendar) solely to provide features directly requested by users. Any personal data accessed from these APIs is only processed as needed to complete that request and is never used to develop, train, or improve any machine learning or artificial intelligence (AI) model — whether our own or any third party's.

Sarai AI complies with the Google Workspace API User Data and Developer Policy. We affirm that:

You may revoke access to Google services at any time via your Google Account permissions page or from your dashboard at https://sarai.solutions/app.

17. Apple HealthKit and Wearable Data

If you connect Strava, Oura, or (in a future release) Apple HealthKit, Sarai AI may collect health and fitness data such as activity, sleep, recovery, and heart rate data. This data is used solely to personalize your experience within the Service (e.g., reminders to recover after a poor sleep night).

We do not sell your health data. Health data is not used to serve advertising. You may disconnect any health connector at any time from the Integrations tab of your dashboard, after which we will no longer collect new health data and will purge stored health metrics within 30 days.

18. Automated Voice and SMS Communications

Sarai AI provides salon, spa, dental, fitness, and other service-business owners ("Business Customers") with tools to send automated SMS messages and place automated voice calls (including AI-generated voice) to their own clients. This section explains how those communications work, what consent we require, and how recipients can opt out.

What this covers. Automated voice calls placed through the Service include appointment confirmations, reminders, schedule changes ("running 15 minutes late"), follow-ups, and (where the Business Customer has obtained separate written consent) promotional messages. Voice calls may use an artificial or AI-generated voice and are governed by the federal Telephone Consumer Protection Act (TCPA, 47 U.S.C. § 227), the FCC's February 8, 2024 Declaratory Ruling treating AI-generated voices as "artificial or prerecorded voice," the Florida Telephone Solicitation Act (Fla. Stat. § 501.059), and applicable state analogues.

Consent we require. Before any automated SMS or voice call is placed to a recipient through the Service, we require an affirmative consent record on file. Consent is captured at the public booking page, intake form, or owner-confirmed enrollment, and the exact text of the consent shown to the recipient is stored alongside the timestamp, IP address, and user agent for evidence purposes. Consent is not a condition of receiving in-person service from the Business Customer — recipients who decline consent may still book by contacting the Business directly.

Per-call disclosures. Every automated voice call placed through the Service opens with an audible disclosure naming the Business Customer and identifying the call as automated, followed by an opt-out option (press 9). This disclosure runs before any other content of the call.

Quiet hours. Automated voice calls and non-transactional SMS messages are gated to the hours of 8:00 a.m. to 9:00 p.m. in the recipient's local time zone. Time-sensitive transactional SMS (e.g., "your stylist is running 30 minutes late") may fall outside this window under TCPA's transactional carve-out; automated voice calls are gated regardless of intent.

How to opt out. Recipients have multiple opt-out paths and we honor each immediately:

Marketing vs. transactional. The Service distinguishes between transactional communications (confirmations, reminders, schedule changes, follow-ups) and marketing communications (promotions, win-back campaigns). Marketing voice calls and SMS require prior express written consent separately captured for the marketing purpose, and Business Customers must scrub against the National Do-Not-Call Registry before any marketing voice campaign. We do not initiate marketing voice calls to numbers the recipient has not specifically opted into for marketing.

Caller ID. Automated voice calls are placed using the Business Customer's verified outbound number (or, where unavailable, a Sarai AI Inc-issued number registered to the Business). We do not spoof caller ID or use neighbor-spoofing tactics. Our voice provider participates in STIR/SHAKEN attestation as required by 47 C.F.R. § 64.6301.

Florida residents. If you are a Florida resident, you have additional protections under the Florida Telephone Solicitation Act, including a private right of action for autodialed calls placed without prior express written consent. We treat Florida-resident phone numbers under the strictest standard available; opt-outs are honored as global suppressions.

Records and audits. We maintain consent records and call-attempt logs for each Business Customer for a minimum of four (4) years to support TCPA litigation defense and regulatory inquiries. Recipients may request a copy of the consent record on file by emailing hey@sarai.solutions.

19. Changes to this Privacy Policy

We may update this Privacy Policy at any time. Any updates will be posted on this page with the "Last updated" date revised accordingly. For material changes, we will also notify you via iMessage or email at least 7 days before the change takes effect. Your continued use of the Service after changes take effect indicates your acceptance.

20. Contact Us

If you have any questions about this Privacy Policy, you can contact us at hey@sarai.solutions.