Privacy Policy
Last updated: August 2026
This Privacy Policy explains what Skyhost collects, why, and the choices you have. It covers hosts who use Skyhost and, where relevant, the guests whose messages Skyhost helps answer. We aim to collect only what we need to do our job well — reply to your guests and close bookings.
On this page
Information we collect
Host account details — your name, email, and the login you use to sign in. You can sign in with a password or with an emailed sign-in link. If you set a password, it is stored only as a salted one-way hash by our authentication provider; we never see or store the password itself.
Property information — what you tell Skyhost about your place: rates, availability, house rules, amenities, directions, photos, and the instructions you write for how it should reply.
Connected-channel data — when you connect your Facebook Page, we access the Page's conversations and related details (guest names, message content, and timestamps) so Skyhost can read and answer inquiries.
Guest messages — the content of conversations between your guests and your Page, which Skyhost processes to understand a question and write a reply.
Usage and technical data — basic logs, device and browser information, and analytics about how the host console is used, so we can keep the service reliable.
How we use information
We use the information above to:
- run the service — read guest messages and generate replies on your behalf, check availability, quote rates, and help move bookings forward;
- keep it working — troubleshoot problems, prevent abuse, and improve the product;
- communicate with you — send account, product, and support messages.
We do not sell your data or your guests' data, and we do not use it for advertising.
Third parties we work with
Skyhost relies on a small set of trusted providers, each handling only the part they need:
- Meta Platforms — to receive and send messages through your connected Facebook Page or Instagram account.
- Google (Gemini API) — the AI model that reads a guest's message and drafts the reply. Message content is sent to Google to produce a response; under the API terms it is not used to train their models.
- Supabase — the database that stores your account, your property settings, and your conversation history, and the service that handles sign-in.
- Vercel — hosts the host console and this website.
- Railway — hosts the service that processes messages and generates replies.
- Resend — sends transactional email, such as sign-in links and account notices.
These providers process data under their own terms, only as needed to provide their part of the service, and only for as long as that requires. We name them rather than describing them in categories so you can check each one for yourself.
Data retention
We keep your account and property information while your account is active. We retain conversation history so Skyhost has context for future replies and you have a record of what was said, unless you ask us to delete it.
When you close your account, we delete or de-identify personal data within a reasonable period — except where we need to keep some of it for legal, security, or accounting reasons.
Your rights, and your guests'
Hosts — you can access, correct, export, or delete your account and property data. Just email us and we will help.
Guests — Skyhost processes guest messages on behalf of the host, who is the primary owner of that conversation. If a guest wants their information accessed or deleted, they can contact the host or us, and we will assist.
Depending on where you live, you may have additional rights under laws such as the Philippine Data Privacy Act or the GDPR. We honor those rights where they apply.
Requests from governments and law enforcement
We do not hand over host or guest data on request as a matter of course. When a public authority asks us for personal information, we:
- Review whether the request is lawful and whether it actually reaches us — including whether it is valid in the jurisdiction it comes from, and whether we are the right party to ask.
- Disclose the minimum necessary. We do not volunteer whole conversations, whole accounts, or data about people the request does not name.
- Challenge requests we believe are unlawful, overbroad, or improperly served.
- Keep a record of each request, what we disclosed, and the reasoning — so the decision can be reviewed later.
Where we are legally permitted to tell you that your data was requested, we will.
Security
We use reasonable technical and organizational measures to protect data — encryption in transit, access controls, and trusted infrastructure. No system is perfectly secure, but we work hard to keep your information and your guests' information safe.
Children
Skyhost is a tool for hosts running rentals and is not directed at children. We do not knowingly collect personal information from anyone under 18 as a host account holder.
Changes to this policy
We may update this policy as Skyhost evolves. If a change is material, we will flag it. Continuing to use Skyhost after an update means you accept the revised policy.
Contact
Questions about your privacy or this policy? Email us at hello@tryskyhost.com and a person will get back to you.