Privacy Policy
Last updated: August 2026
1. Introduction
This Privacy Policy explains how we collect, use, store, and protect personal data when you use this platform — either as the host managing properties or as a guest interacting with the AI Concierge.
[REVIEW NEEDED] Review with a qualified legal advisor before publishing. Add registered company name and address.
2. Data We Collect
We collect the following categories of personal data:
- Host account data: name, email address, and profile photo from your Google account (via Google OAuth).
- Property data: property name, address, description, photos, amenities, house rules, and other content the host adds.
- Knowledge base content: all text and information added to knowledge base sections.
- Guest session data: messages exchanged between guests and the AI Concierge, session tokens, and language preferences.
- Guest request data: service requests submitted by guests (text and category).
- Usage data: session counts, message counts, and timestamps used for analytics.
- OpenAI API key (optional): if the host provides a BYOK key, it is stored encrypted with AES-256-GCM.
3. How We Use Your Data
- To provide the AI Concierge service to guests.
- To authenticate the host via Google OAuth.
- To store and retrieve property knowledge base content for AI responses.
- To display usage analytics in the host dashboard.
- To respond to support requests.
4. Data Sharing
We share data with the following third-party processors only as necessary to provide the service:
- OpenAI: Guest messages and property knowledge base content are sent to OpenAI to generate AI responses. See OpenAI's privacy policy for their data handling practices.
- Cloudinary: Property images and uploaded assets are stored via Cloudinary. Public assets (property images, logos) are delivered via Cloudinary's CDN. Verification images are stored as private authenticated assets and are never publicly accessible.
- MongoDB Atlas: All application data is stored in MongoDB.
- Google: Authentication is handled via Google OAuth.
We do not sell personal data. We do not share data with advertisers.
5. Data Retention
- Host account data: retained until the account is deleted.
- Guest session messages: retained until deleted by the host or when the property is deleted.
- Uploaded assets: retained in Cloudinary until deleted by the host.
[REVIEW NEEDED] Add specific retention periods once confirmed.
6. Cookies
We use session cookies for host authentication (managed by Auth.js). No advertising or tracking cookies are used. The guest concierge uses localStorage on the guest's device — no cookies. See our Cookie Policy for details.
7. Your Rights
Depending on your location, you may have rights to access, correct, delete, or export your personal data. To exercise these rights, contact us at [email protected].