Privacy
The plain-language version of how your information is handled.
Last updated 19 September 2026
What we collect
We collect the details you provide in chat, your name and email, and any files you attach so a specialist can help and you can return to your account. The details you type during intake are also processed by an AI service, as described in the next section. When a paid session is created, we save a short technical description reported by the browser: device category, operating system, browser and browser engine when known, plus the country indicated by the internet connection. We do not save the raw IP address or full user-agent string in this session description. If you choose phone verification, we also process your phone number. We may also use the country reported with your internet connection to suggest a calling code; you can always change it.
Grace and the AI service
Expert Helpline uses an assistant called Grace to gather the details of your question before a specialist joins. Grace is automated, not a person. To work out what to ask next, the text you type during intake is sent to our AI provider, an external service provider. Files you attach are not sent there; only the text is. Our AI provider does not use this text to train its models. It keeps the text for a limited period to check for misuse, and may keep it longer where the law requires that or a safety review needs it. We do not need your passwords, card numbers or one-time security codes, and you should not share them in the chat. A specialist may guide you while you enter sensitive details directly into the relevant service yourself.
Conversations before payment
On the live website, we save the messages you submit to Grace and the replies returned by Grace, even if you do not pay or finish your question. Only authorized administrators can review these temporary records to understand questions, improve intake quality and see where people have difficulty continuing. We keep this review copy for 15 days after the last recorded message, then remove it automatically; deletion may take longer if a cleanup attempt must be retried. Expired records are unavailable for review. The record includes message times, the entry surface and, when confirmed, whether payment followed. A random reference groups messages without using advertising identifiers. Signed-in records and records connected to a completed payment are linked to the customer account for access and deletion controls. Unpaid anonymous chats do not create an account or a paid question. We do not send this review copy to advertisers, website analytics or notification services. Your browser may also keep your unfinished chat locally for up to 24 hours so you can continue. If you pay, the separate paid conversation follows the account-retention rules below. Contact us with a privacy request if you want help accessing or deleting your information.
Account and phone verification
Our authentication service provider handles account sign-in, email verification and optional SMS phone verification. When a first payment creates an account, we ask our authentication service provider to send a sign-in email to the address provided at checkout. Opening that link verifies access to the address and can return you to the paid chat. You can choose to create a password separately from your account profile. When you verify a phone number, our authentication service provider receives and stores the number and uses verification and abuse-prevention information, including automated abuse-prevention signals. A phone number is saved as verified only after our authentication service provider confirms the code.
Reply reminder emails
When reply reminders are enabled, we use an email service provider to send a short service reminder if an expert's reply in your paid conversation remains unread. Our email service provider receives your current account email address and generic email content, including a link to the specific conversation and a public link to My Account. The conversation link contains its identifier but does not grant access; account sign-in and conversation access checks still apply. We do not include your name, conversation content, attachments or sign-in token. Our email service provider measures delivery, approximate email opens and clicks on email links so we can understand how useful our reminders are and whether people follow links back to the service. It uses a small tracking image and redirects clicked email links to their intended destination. Image loading and automated email checks can affect these measurements; an open or click does not prove that a person read a reply or used the service. You can turn reminders off in My Account. Reading or answering the reply, closing the conversation or closing your account stops pending reminders, although an email already being sent may still arrive. Local reminder delivery records are removed after seven days of no new eligible replies, and are removed with a purged session. Our email service provider maintains its own delivery and suppression records to operate the email service. Sign-in, password-reset and verification emails continue to use our authentication service provider. Our service emails display a static Expert Helpline logo without recipient-specific image URLs.
Specialist welcome emails
When an administrator creates a specialist account and onboarding emails are enabled, our authentication service provider generates a secure, one-use password-setup link. Our email service provider delivers it in a welcome email with dashboard and app installation instructions. Our email service provider receives the specialist's account email address, name and setup link, but never their password. We do not store the setup link in local delivery records. Our email service provider measures welcome-email delivery, approximate opens and email-link clicks using a tracking image and link redirects, helping us understand whether specialists receive and use the onboarding instructions. These measurements do not prove that account setup was completed. Local welcome delivery records are removed after seven days. Specialists can request another password-reset email from specialist sign-in.
Payments
Payments are handled by a payment service provider. Card details are entered only in that provider's secure checkout and do not touch our forms or servers. We keep limited payment records such as the amount, currency, provider status and relevant refund or dispute references for receipts, tax, refunds and payment disputes.
What your browser stores
Your browser keeps sign-in state, unfinished intake and the information needed to recover an interrupted checkout. Where analytics is permitted, analytics tools may store random browser identifiers and advertising-attribution cookies for up to 90 days. These identifiers are not your account ID. An explicit cookie choice is saved for 90 days; an opt-out is also retained in browser storage until you change it or clear site data, with a server-readable opt-out cookie lasting up to one year. Internal browsers have a separate exclusion marker. A content-free local ledger prevents duplicate funnel events for up to 24 hours; its code never leaves the browser. A secure paid-session handoff expires after 30 minutes. Card details are never stored by our app. Clearing site data removes these saved browser preferences and may cause us to ask again where consent is required.
Analytics and operational journey alerts
We use analytics tools on the live website to understand public page visits, how people start intake and whether they continue through fee disclosure, checkout and payment. Eligibility is worldwide. Where prior consent is required, analytics stays off until you choose Accept All; Essential Only lets you continue without analytics. Elsewhere, eligible visits use analytics by default and you can opt out using the control below. Missing or invalid location signals, development and Preview sites, signed-in specialists and administrators, internal browsers, and browser privacy opt-outs are excluded. We infer the applicable consent setting from the hosting request-country signal, not your language. Networks, travel and VPNs can affect that signal. Funnel events use fixed stage labels, limited technical information and approximate location. Content-free interaction events distinguish a visible input, a first edit, submission and a displayed reply; failures and response times use fixed categories. Approved advertising identifiers may appear in the initial public landing-page measurement. They are not copied into chat, account or payment records or sent as message content. Private conversation pages and hosted payment screens are excluded from browser analytics. Verified purchase reporting uses the recorded charge amount and currency and a one-way transaction reference. Automatic enhanced measurement is disabled. Event-level analytics data is retained for 2 months and user-level data for 14 months, with the user-data period renewed by activity; aggregated reports may remain longer. We do not enable ad personalization or remarketing. Separate operational alerts contain only a temporary visit code, fixed journey labels, an allowlisted public path, source category and approximate country; they contain no chat text, identity or payment details.
Landing-page interaction analytics
On the home page and pages under /ask, analytics tools may record public page structure, clicks, scrolling and pointer movement. Grace’s header, static greeting, assistant replies, buttons and loading indicators can appear in these recordings. Text entered by customers, customer message bubbles, unsent drafts and the checkout email field are masked. Grace may repeat details from your question in an assistant reply, so a recording of that reply may contain those details. Do not share passwords, payment-card details or one-time security codes with Grace. Recording pauses while hosted checkout is open and stops before a private conversation opens. Fixed event labels indicate input focus, a first edit, intake start, fee disclosure, checkout opening and payment confirmation, without field values or additional identifiers. These observations are best effort and are not the authoritative payment record. The analytics control below stops future recording and removes accessible analytics cookies where the browser permits.
Advertising purchase measurement
When enabled, we use our advertising service provider to measure whether an ad leads to a paid session. This follows its own eligibility rules on the live website and the internal-browser exclusions, analytics opt-out and Global Privacy Control rules described above. We do not load an advertising script or pixel in your browser. On the public home or business-support landing page, our own code can capture one length- and format-checked ad-click reference called oppref before it is removed from the page address. The reference is a pseudonymous advertising identifier; it is not anonymous, and its format alone cannot prove who supplied it. We keep it in an encrypted, secure cookie for at most 24 hours, bound to this browser and our advertising data source. It is not saved in browser app storage. For an eligible verified Live payment, checkout records an encrypted copy for delivery and our server sends the advertising service provider the original click reference, a one-way event code to prevent duplicate counting, the time we finalized the paid record, the purchase amount and currency, and our public home-page address. We also mark the event as a website purchase and set the provider’s opt-out setting to request exclusion from future user personalization. We do not send the advertising service provider names, email addresses or their hashes, phone numbers, our account or session identifiers, raw payment identifiers, private page addresses, customer IP or device details, or chat content as part of this reporting. An already-queued event may be retried after the browser closes. The same event code is reused, and a successful HTTP response confirms receipt rather than proving the purchase has been attributed or shown in Ads Manager. This reporting does not add refund reporting or measure the content of a conversation.
Temporary analytics records
The protected cleanup job retries queued measurements and removes expired temporary data in bounded batches. Purchase reporting stops after 48 hours for the primary analytics provider and six days for the advertising provider. Successful delivery removes the temporary client identifier or encrypted click reference. The paid-session handoff becomes unusable after 30 minutes and is removed by cleanup. Cleanup runs about every ten minutes once released; outages and backlog can delay physical removal. It never deletes the underlying payment or conversation records.
What analytics never receives
Our funnel and purchase event builders do not accept names, emails, phone numbers, raw account/session/payment IDs, private page addresses, error text, attachments or conversation content. These event restrictions are separate from landing-page recordings: assistant replies can be visible as described above, including details repeated from a question. Customer input, customer message bubbles, drafts and email fields are masked. Hosted checkout and private conversation pages are excluded. Advertising references are confined to the separately described attribution and purchase-measurement paths.
How conversations and attachments are used
Apart from the AI intake described above, the conversation collected by Grace may be viewed by specialists deciding whether they can help with your question, the specialist assigned to it, and the people who operate the service as needed to provide support, manage payments and review quality. Attachments are available only to you, the assigned specialist and the people who operate the service when necessary. Conversations and attachments are not published, sold or used for unrelated purposes.
Who else handles your information
We use service providers for AI intake, authentication, account emails, database and file storage, hosting, payment processing, service email delivery and engagement measurement, analytics tools and content-free operational notifications. Each receives the information needed for its role, as described in this policy. Analytics tools may receive the visible assistant replies described above; they do not receive our private conversation archive or attachments. Notification providers receive no conversation content or attachments.
Where your information goes
Your information may be stored or processed by our service providers in a country other than the one you live in, under privacy laws that differ from your own. Where required, we use safeguards for international transfers in accordance with applicable data-protection law.
Closing your account
Closing your account signs you out, restricts your data and suspends any active conversation. You can restore the account by signing in within 30 days. After that period, your profile, conversation content and attachments are scheduled for permanent deletion on or shortly after the deadline; deletion runs in batches and may be delayed while a failed step is safely retried. After sign-in data is deleted, a content-free security marker prevents an older session from recreating the account. It becomes eligible for removal after two hours and may be removed later by the scheduled expiry process.
Records kept after deletion
We do not keep your conversation text. Our AI provider's misuse-checking period, described above, runs on its own schedule. We may keep a limited de-identified session summary for specialist reporting, including the assigned specialist, dates, category and outcome, plus allowlisted payment and minimal audit records for legal, tax, refund, dispute and security needs. These records have customer links and free-form text removed, but we do not describe them as anonymous because correlation may still be possible from external records.
What we don't do
We do not sell your personal information, use analytics for ad personalization or remarketing, or send private paid conversations or attachments to advertisers, analytics tools, notification providers or data brokers. Landing-page recordings may show Grace’s replies as described above. Bounded advertising identifiers measure whether approved ads lead to public funnel stages and purchases; our event payloads do not combine them with what you type, your account details or private conversation records.
Your choices
You can update your profile, close and recover your account, or contact us at support@experthelpline.com with a privacy request. When analytics is eligible, you can turn it off or back on for this browser with the control below. We also treat an enabled Global Privacy Control browser signal as an analytics opt-out and save that choice in this browser; analytics cannot be re-enabled while the signal continues. Turning analytics off disables future browser collection, removes browser-accessible analytics identifiers where possible, asks our server to clear the encrypted advertising attribution cookie, and prevents new server purchase measurements from being queued for this browser. It cannot cancel a purchase already queued or retract information already sent or included in aggregated reports. The choice is shared across tabs in this browser. Clearing site data removes the saved opt-out, but an enabled Global Privacy Control signal applies again on the next eligible request. Some financial or security records may need to be retained for the purposes described above.
Your privacy rights
Depending on applicable law, you may have rights to access, correct, delete or receive a portable copy of your information, and to restrict or object to processing. Contact support@experthelpline.com to exercise a privacy right; we respond within the period required by applicable law. We handle information to provide the service and take payment, meet legal obligations, and operate the service securely and prevent misuse. Where we rely on consent, you can withdraw it at any time. You may also complain to your local data protection authority.
Children
Expert Helpline is not intended for children under 13, and we do not knowingly collect their information. If you believe a child under 13 has given us information, email support@experthelpline.com and we will delete it.
Changes to this policy
If we change how we handle your information, we will update this page and change the date at the top. If a change is significant, we will say so here rather than leaving you to spot it.
Who we are
Expert Helpline is an independent service available at experthelpline.com, operated by Digital Consultancy, 6E9 RC Vyas Colony, Bhilwara, Rajasthan, PIN 311001, India. Questions about this policy are welcome at support@experthelpline.com or via the contact page.