Skip to content

Host AI · Legal

Privacy Policy

What information Host AI uses, when it leaves your device, and how you can control it.

Effective:

Last updated:

1. Introduction

This Privacy Policy explains how LHL GLOBAL LLC (“LHL GLOBAL,” “we,” “us,” or “our”) collects, uses, and protects information when you use the Host AI website and dashboard, the Host AI Chrome extension, and the Host AI iOS app and keyboard (together, the “Service”). Host AI helps hosts draft replies to guest messages. This Policy describes our data practices; it does not replace any consent required for a particular feature or use of your information.

2. Information We Collect

We collect the following categories of information:

  • Account and contact information you provide when you sign up, join the beta waitlist, or contact support.
  • Content you connect or provide for reply generation, including guest messages from a connected Gmail account and conversation text shown on supported host pages when you use the Chrome extension.
  • Host preferences, vehicle or property details, locations, knowledge, and reusable Quick Inserts you choose to save.
  • Generated drafts, replies you save or edit through Host AI, feedback, and actions such as copying or inserting a draft. An inserted draft is not confirmation that a message was sent.
  • Text submitted for AI writing or grammar assistance, and search terms or context submitted for network-backed features.
  • Subscription status, billing identifiers, and transaction records.
  • Account-linked device and installation identifiers used to connect and secure the iOS app and keyboard, including a stored hash of the keyboard installation identifier. RevenueCat also receives Apple’s identifier for vendor (IDFV) from its iOS SDK.
  • Technical and usage information needed to operate the Service, such as AI usage metrics (for example model and token counts), feature actions, request timing, success or failure codes, and basic operational logs. Our hosting and security providers may also process network information such as IP address, request time, and device or browser information.

3. Account Information

Authentication and account management are provided through our authentication provider, Clerk. We use your name, email address, account identifiers, and available profile details to sign you in, identify your account, and display your Host AI profile.

When you choose Sign in with Apple, we receive the information Apple makes available through Clerk. This may include your name and email address. If you choose Hide My Email, we receive Apple’s private relay email address instead of your personal email address. Apple may not provide your name again on later sign-ins.

We use an available name to initialize your Host AI display name. You can edit it in the iOS app under Account → Name. This updates your Host AI display name; it does not change your Apple Account name, sign-in email address, or hosting business name.

4. Gmail / Google Account Data

If you choose to connect Gmail, Host AI requests read-only access to Gmail (the gmail.readonly scope) and your Google account email address (the userinfo.email scope). Host AI does not request permission to send, delete, or modify email through Gmail.

What we access and why. Host AI searches for supported hosting-related email, currently Turo-related messages, including matching sent messages needed to distinguish your replies from guest messages. This can include message bodies, subjects, senders, recipients, timestamps, and thread identifiers. Gmail’s read-only permission technically allows mailbox-wide reading; Host AI uses targeted searches to find relevant messages. Connected sync can process messages and prepare drafts in the background.

What we store. To provide these features, Host AI stores guest message content and related metadata (such as sender, message and thread identifiers, and AI-generated summaries and classifications), together with the OAuth tokens needed to maintain your connection. Host AI uses mailbox notifications and background jobs to check for new messages, renew watches, and refresh access tokens. If authorization expires or is revoked, you may need to reconnect Gmail.

Disconnecting and revoking access. You can disconnect Gmail at any time from your dashboard, which removes the stored access and refresh tokens and disables the connection for future syncs. Work already in progress may still finish. You may also revoke Host AI’s access directly from Google Account connections. Disconnecting stops future access but does not by itself delete messages already synced to your Host AI account. See Account and Data Deletion to request their removal.

Host AI’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Gmail data for advertising, sell it, or use it to train generalized AI models. Access by people is limited to your affirmative permission for specific data, security investigations, legal obligations, or aggregated internal operations as allowed by that policy. Transfers of Google data, including any business transfer, remain subject to its Limited Use requirements.

5. Chrome Extension and Host Page Context

The Host AI Chrome extension runs on supported host conversation pages (currently Turo) and on Gmail. When you use the extension on a supported page, it reads available conversation text and identifying page context, such as the guest name and conversation identifiers. When you request a draft, or when Auto-draft is enabled and a relevant chat is detected, that context is sent to Host AI for processing. Depending on your settings, drafts may be inserted into the reply box for review. The extension does not click Send for you.

The production extension requests only the permissions it needs to do this: access to the current tab and scripting on its supported host pages (host-ai.app, turo.com, and mail.google.com), local storage for your settings, the clipboard for the copy action, and identity for sign-in. Quick Inserts you save are stored with your account so they are available across your devices.

6. iOS App and Keyboard Data

The Host AI iOS app lets you sign in and manage your account. Ordinary typing, local spelling suggestions, predictions, and swipe decoding run on your device. These local features do not upload a keystroke stream or swipe paths. Local personalization may keep learned words on your device. Full Access enables the keyboard’s network-backed features; it is not needed for ordinary typing.

Native AI Write and AI Grammar are not enabled in the 1.0 keyboard. On surfaces where these tools are available, explicitly requesting them sends the selected text or draft context needed for the action to Host AI and its AI provider. AI Write uses the text you submit, not your Gmail conversations or host knowledge. Host Reply retrieves conversations and drafts already associated with your account and may trigger a background refresh of your connected Gmail mailbox. Opening or refreshing Quick Inserts loads your saved snippets from Host AI. Searching those loaded snippets in the Quick Insert panel happens on your device: ordinary typing does not send the current word or surrounding text to Host AI for Quick Insert searches. Saving a new Quick Insert sends the content you explicitly choose to save. These features may use temporary caches.

You can turn off Full Access or remove the keyboard in iOS Settings. Doing so stops keyboard network features but does not delete information already saved in your Host AI account.

7. AI Processing

To generate drafts and suggestions, Host AI sends the relevant content (such as the guest conversation and your provided context) to a third-party AI service provider (OpenAI) for processing. Host AI stores conversation drafts and replies you save or edit through Host AI, along with feedback, to provide reply history and improve suggestions for your account. This is distinct from training a general-purpose AI model. AI providers may retain request information according to their service terms and the configuration used for the feature. AI-generated content may contain errors and is provided for your review.

8. How We Use Information

  • To provide, maintain, and secure the Service.
  • To read guest messages and generate and improve draft replies.
  • To sync supported Gmail messages and maintain authorized connections.
  • To operate your subscription and provide support.
  • To monitor reliability and control operating costs.

9. Service Providers

We share information with service providers as needed for the features you use. These include:

  • Clerk for sign-in and account management.
  • Supabase for database and storage services.
  • Google for the Gmail connection you authorize and mailbox notifications.
  • OpenAI for AI processing, such as classification, draft generation, and writing assistance.
  • Stripe for web payments and subscription management.
  • Apple for Sign in with Apple when you choose that sign-in method, App Store distribution, and any purchases made through your Apple account.
  • RevenueCat for in-app subscription processing in the Host AI iOS app. RevenueCat receives your Host AI app user identifier, App Store purchase and subscription information, and technical information from its SDK, including Apple’s identifier for vendor (IDFV), app and operating-system versions. Purchase information supports plan verification and subscription analytics. IDFV is a device-level identifier distinct from Apple’s advertising identifier (IDFA). Host AI does not use these identifiers for advertising or cross-app advertising tracking, and does not send RevenueCat your messages, drafts, or Gmail data.
  • Vercel for hosting and operational logs, and Inngest for background processing.
  • Email services for routing and handling messages you send to support.

Each provider receives information needed for its role. Providers may process information under their own applicable terms and privacy practices. Google data remains subject to the Limited Use restrictions described above.

10. Payments

Web subscription payments are processed by Stripe. If you purchase a subscription through Apple, Apple processes that purchase under its own terms, and RevenueCat relays the purchase and subscription status to Host AI. We receive billing identifiers and subscription status to manage your access. Host AI does not collect or store your full payment card number; that information is handled by the payment provider under its own terms and security.

11. Cookies and Analytics

Host AI uses cookies and similar technologies as needed to keep you signed in and to operate the Service. The application does not include advertising trackers. Authentication, hosting, and payment providers may use their own cookies or collect operational information to deliver and secure their services.

12. Data Retention

We retain your account information and the content associated with your account (including synced guest messages and generated and final replies) for as long as your account is active and as needed to provide the Service, and thereafter as required to meet legal, security, or operational needs. You can delete your account in the iOS app or ask support for help. The time needed to remove data may vary between active systems, backups, and providers. Some records may be retained where required by law or to resolve disputes.

Account deletion does not remove every provider or support record. We retain Stripe customer records used to check prior free-trial eligibility and prevent repeated trials. Support correspondence may remain after its link to your Host AI account is removed, including the contact information and content you supplied, for support, security, or dispute-resolution purposes. You can contact us about these records through the privacy-request options below.

13. Data Security

We use administrative and technical safeguards designed to protect information, including access controls and encrypted connections. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

14. Data Sharing

We do not sell your personal information. We share information only with the service providers listed above to operate the Service, when required by law or legal process, to protect rights and safety, or in connection with a business transfer. AI processing is performed by the provider described in “AI Processing.” Google data remains subject to the additional restrictions described in the Gmail section above.

15. Your Choices and Controls

  • Connect or disconnect Gmail from your dashboard at any time.
  • Revoke Host AI’s Google access from your Google Account settings.
  • Review drafts before they are sent — Host AI never sends for you.
  • Turn off keyboard Full Access or disable extension Auto-draft.
  • Edit your Host AI display name in the iOS app under Account → Name.
  • Depending on applicable law, request access, correction, deletion, or a portable copy of your personal information, or object to or restrict certain processing. Contact us to make a request; we may need to verify your identity.

16. Gmail Disconnect / Google Authorization Revocation

You control the Gmail connection. Disconnecting from your dashboard removes Host AI’s stored tokens, and revoking access in your Google Account settings removes Host AI’s authorization at Google. Disconnecting disables future syncs; revoking access prevents further authorized access through that Google connection. Work already in progress may finish. Neither action deletes previously synced messages. To remove those records, submit a deletion request below.

17. Account and Data Deletion

If your account uses Sign in with Apple, deletion attempts to revoke its Apple authorization before removing your sign-in identity. The OAuth token is used only for that server-side request, not written to Host AI logs or retained in our database. If a token cannot be recovered or Apple revocation cannot be confirmed, your account can still be deleted and the app explains how to remove the authorization in your Apple Account. This does not cancel an App Store subscription.

In the Host AI iOS app, open Account → Settings → Delete Account to delete your account and associated Host AI data, including synced guest messages, drafts, knowledge, and device access. The flow cancels a linked web subscription. Deleting your Host AI account does not cancel an Apple subscription: Apple billing continues until you cancel it in Apple’s subscription settings. The deletion screen provides access to Manage Apple Subscriptions.

For help with deletion or another privacy request, email support@host-ai.app from the address associated with your account. Signed-in hosts can also submit a support request. We will verify and process your request and explain any information we must retain. Disconnecting Gmail or uninstalling the extension or app does not delete your Host AI account. A support request alone does not confirm deletion or cancel billing. Some provider, backup, security, and legally required records may remain subject to the retention terms above.

18. Children’s Privacy

The Service is intended for hosts operating a business and is not directed to children. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.

19. International Processing

LHL GLOBAL and our service providers may process and store information in the United States and in other locations where those providers operate. Where required, we rely on appropriate safeguards for such transfers.

20. Changes to This Policy

We may update this Policy from time to time. When we do, we will revise the date above and, where required, provide notice or obtain consent before making a material change to how we use information.

21. Contact

LHL GLOBAL LLC
Email: support@host-ai.app

Contact us with questions about this Policy or your data. See also our Terms of Service and Support page.