Skip to main content
Ask Ava →

Cookie and Browser Storage Notice

Legal entity
Human Advisor AI LLC
Privacy requests
privacy@humanadvisor.ai
Compliance and incidents
compliance@humanadvisor.ai

1. Purpose

This notice explains how Human Advisor AI LLC may use cookies, browser storage, session identifiers, and similar technologies on the Human Advisor AI public website and public assistant experiences. It supplements the Website and Public Assistant Privacy Notice.

Cookies and browser storage are not all used for the same purpose. Technologies required to operate or secure a requested service must remain separate from optional analytics, learning, feedback, advertising, or marketing choices.

2. What cookies and browser storage are

Cookies are small data files that a website may ask a browser to store. Browser storage can also include session storage, local storage, or other browser-managed values. These technologies may help a service maintain a requested session, remember a preference, support security, or measure service performance.

The categories in this notice do not establish that every described technology will be used.

3. Current HAA principles

  • Human Advisor AI will not bundle optional analytics, learning, feedback, marketing, or other optional purposes with a required service action.
  • Declining optional storage or analytics must not prevent ordinary Ava chat or an otherwise permitted connection request, except where a strictly necessary technology is required to provide or secure the requested function.
  • The browser cannot authorize conversation learning, durable message retention, destination routing, or server-controlled identity decisions.
  • Strict international and unknown-jurisdiction chat must not create a durable cross-visit advertising identifier.
  • Unsubmitted public-form values remain in browser memory only unless and until the visitor submits the form.
  • Human Advisor AI will provide a practical way to change optional choices when optional technologies are deployed.
  • Production infrastructure for the HAA website and public assistant must use United States processing and storage regions. Provider-controlled logs, backups, and service records follow the provider’s applicable policies and contract; HAA-controlled records follow HAA’s final Privacy Notice and governing control documents.

4. Technology categories

Technology categories, their purpose and their consent treatment
CategoryPurposeConsent treatment
Strictly necessary Operate a requested page, session, form, security control, preference control, load-balancing function, or Ava session state that cannot reasonably work without it Used only as necessary under the applicable legal basis; not repurposed for optional analytics or marketing
Preferences Remember a visitor-selected display or service preference Separate choice where required; refusal must not be treated as marketing refusal or learning refusal
Analytics and performance Measure prose-free service performance, timing, stage, outcome, and error categories Optional where required by the applicable jurisdiction and implementation profile
Feedback Record a visitor’s separate feedback choice or signal Separate from ordinary chat, lead delivery, learning, and marketing
Learning and improvement Support optional HAA learning only under the approved implementation profile Separate optional consent; prohibited for strict international and unknown-jurisdiction chat
Marketing or advertising Measure or support promotional activity Separate optional consent and suppression treatment; not required for ordinary chat or lead delivery

What is in use today. Analytics is off. No analytics provider or browser identifier is approved. No marketing or advertising technology is approved for the initial website release, and no outside cookie-platform provider is in use. This notice describes the categories that may apply and the rules that govern them; it does not state that a technology in any optional category is deployed.

5. Ava sessions and conversation content

Ordinary Ava messages are processed to generate replies. Human Advisor AI does not retain complete conversation transcripts by default. Ephemeral message content remains in active session memory and is destroyed on clear, expiry, session end, or context loss.

Session identifiers expire after 30 days or earlier. Strict international and unknown-jurisdiction message prose may not be written to diagnostics, samples, fixtures, datasets, lead payloads, or summaries.

A connection request remains separate. When a visitor chooses to connect, the structured contact and business information submitted through the connection flow is sent to the disclosed destination, with a labeled AI-generated summary of the conversation when one was disclosed before consent. No conversation transcript is included.

6. Analytics and security information

The approved control schedule permits prose-free structured performance signals, such as timing, stage, outcome, and error categories. It prohibits message text, contact fields, and durable cross-visit advertising identifiers in strict international structured telemetry.

Security and abuse controls may use operational information needed to protect the website and assistant. Any browser-stored security value must be documented with its provider, purpose, United States region, and duration. Security logs should not contain conversation prose by default. Provider-controlled security records follow the provider’s applicable policy and contract.

7. Choices and preference controls

When optional technologies are present, the website should provide choices that are specific to their purpose. A single control must not be used to obtain unrelated permissions.

  • Necessary technologies: explained, but not represented as optional when the requested service cannot run securely without them.
  • Analytics or performance: separate choice where required.
  • Conversation learning: separate optional choice and controlled by the server-selected policy profile.
  • Feedback: separate action initiated by the visitor.
  • Marketing: separate from enquiry delivery and subject to opt-out and suppression controls.
  • Lead delivery: separate affirmative consent after the destination is disclosed; not a cookie or analytics choice.

Optional technologies remain off until the applicable choice is recorded, and visitors can reopen the control to change optional choices. Because no optional technology is currently in use, there is no optional choice to record and no preference control is presented.

8. Third-party technologies

No analytics, advertising, or outside cookie-platform provider is approved for the initial release by this notice.

A third-party service must not be described as necessary, privacy-preserving, non-training, region-bound, or short-lived unless the applicable configuration and contract support that statement. Approved production providers must use United States processing and storage regions. Provider-controlled records follow their applicable policies and contracts, while HAA-controlled records follow HAA’s approved schedule.

9. Browser controls

Visitors may use browser controls to review, remove, or block browser-stored information. Blocking a strictly necessary technology may prevent the related requested function from operating. Browser deletion does not delete server-side consent, lead, delivery, security, or privacy-request records.

10. Retention

Retention periods for HAA-controlled records, including session identifiers, structured telemetry, consent records, submitted leads, delivery receipts and security logs, are set out in the retention section of the Website and Public Assistant Privacy Notice.

11. Contact

Privacy questions and requests may be sent to privacy@humanadvisor.ai. Compliance or incident concerns may be sent to compliance@humanadvisor.ai.