Privacy Policy

What we collect, how the AI drafts in your inbox, and how to delete your account.

Plain-English summary of how RentaraAI handles your account, your guests' messages, and your data. Effective: 2026-09-11.

Business identity

Who you’re contracting with

The contracting entity for RentaraAI is Steadwright LLC, an Indiana limited liability company, with its registered office at 2120 W Washington St, Suite 200, Indianapolis, IN 46222, United States. The entity governs itself under the laws of the State of Indiana, United States.

Data controller

Steadwright LLC (the entity above) decides why and how your personal data is processed when you use RentaraAI.

Contact channels

  • support@rentaraai.com

    General questions, demos, partnerships, media.

    Acknowledgement: within one business day

    Delivered to the Steadwright inbox via Polsia email proxy; the visible sender identity matches the address you wrote to.

  • billing@rentaraai.com

    Refunds, invoices, subscription changes, terms disputes.

    Acknowledgement: within one business day

    Delivered to the Steadwright billing desk via Polsia email proxy; one business-day acknowledgement window.

  • privacy@rentaraai.com

    Privacy questions and complaints.

    General privacy questions and complaints:

    Response within one business day.

    Formal access, deletion, export, portability, or correction requests:

    Acknowledgement and identity verification within two business days.

    Fulfilment within 30 days. See /rights.

    Delivered to the Steadwright privacy desk via Polsia email proxy; rights requests are tracked from receipt to fulfilment.

  • security@rentaraai.com

    Security disclosures, vulnerability reports, incident coordination.

    Acknowledgement: within two business days

    Delivered to the Steadwright security desk via Polsia email proxy; see /security-incidents for the disclosure timeline.

Third-party subprocessors: OpenAI — API, Polsia, Inc. — R2 object storage, Polsia, Inc. — Email proxy, Stripe, Inc., Render (hosting) + Cloudflare (edge).

Internal components (not shared with any third party): better-auth (local Postgres account store). Full table — categories, locations, retention, links — on /subprocessors.

What we collect

We collect the basics you give us at signup (your name and email) plus billing details when you add a payment method for your subscription. To do the work of the product we also store the guest message threads read from the booking platforms you have connected (we only call out to the platforms you have explicitly connected, and only for the data the draft requires), the property metadata you fill out during onboarding (address, operational house rules, photos, recent reservations), and any compliance filings you create or ask us to draft. We do not collect guest credit-card numbers or government IDs, and we do not read mail delivered to your own inbox outside the connected platforms.

How AI-generated guest replies work

Drafts to your guests are produced through our AI proxy and surfaced to you in the messages inbox. Nothing is sent without your explicit approval — every AI-drafted reply waits behind an "Approve & send" gate in your messages view, and the AI never sends on its own. Each new draft is regenerated from your currently-saved style profile combined with the message context — we do not carry forward prior drafts or your edits, and we never feed your portfolio into model training. We store the guest conversation threads we have read from your connected booking platforms and the AI-drafted replies that have awaited your approval. The AI never sends outbound messages without a human in your account clicking "Approve & send" first. Each call is narrowed to the data it needs — see the canonical scope on /privacy and the per-call-site table on /subprocessors. Operational house rules (per property) always travel into the prompt; the host style block (tone preset, style notes, signature) is sent only when you have the personalization toggle on. Your style profile is on /profile, where you can switch "Use saved style preferences when generating drafts" off (drafts then render without your saved tone preset, style notes, or signature) and reset every saved style field with the "Clear saved style preferences" button below the toggle.

Data retention and deletion

RentaraAI app records (account row, message threads, property metadata, compliance filings, consent ledger) are retained while your account is active. If you cancel and ask us to delete your account, those app records are purged within 30 days; RentaraAI app backups roll off on the same 30-day cycle. We hold billing records for the period required by tax law (typically seven years) but those records contain only the transaction, not your message content. Third-party processor logs (OpenAI API, Polsia email proxy, Stripe, Cloudflare, Render) persist independently per the retention row on /subprocessors — the 30-day window above applies to RentaraAI app records only.

Your controls

You can export your data, edit your property metadata, and delete individual messages from inside the app at any time. On /profile you can switch "Use saved style preferences when generating drafts" off — drafts then generate without your saved tone preset, style notes, or signature. The "Clear saved style preferences" button on the same card resets every saved style field to the default; the underlying drafts already produced are unchanged. Switching the personalization toggle off does NOT drop the property's operational house rules from the prompt — those are per-property data — the rules each host configures for that property — and always sent. To request account deletion or a full data export, open /contact?category=privacy (or email privacy@rentaraai.com — same privacy desk either way); we acknowledge within two business days and complete the request within 30.

Contact

For general privacy questions or to lodge a complaint, email privacy@rentaraai.com — we respond within one business day. For formal access, deletion, export, or correction requests, open /contact?category=privacy (or email privacy@rentaraai.com — the routed form also records your request to the privacy desk); we acknowledge and verify identity within two business days, and fulfil the verified request within 30 days. Full workflow on /rights.

Third-party processors we share with

We share narrow slices of data with the processors that make the product work — none of them train a model on your portfolio. The full table on /subprocessors (locations, retention, verification links) is the same registry that powers every other legal surface on this site.

  • OpenAI — API

    OpenAI-operated infrastructure; processing location depends on the account and applicable data-residency configuration.

    Purpose: Processes AI text calls sent directly from RentaraAI’s server through the OpenAI API — guest-reply drafts, pilot demo drafts, nightly-rate suggestions, maintenance triage, and the streaming chat relay. Each call is narrowed to the data that call needs; we never send a host’s full portfolio.

    Data shared: OpenAI API call-site scoped payloads only: (1) inbox/pilot demo drafts — the latest 5 turns of the guest thread + the property’s operational house rules + your saved tone preset, style notes, and signature block when personalization is ON. (2) messages lazy drafts (guest-reply) — the guest name + message body only. (3) nightly-rate suggestions — address / city / bedrooms, three scalar fields. (4) maintenance triage — the host-supplied description only. (5) narrow chat relay — auth-gated streaming chat scoped per call site (public-hero-demo for anonymous visitors, host-assistant for signed-in hosts, ops-console for admins): the server prepends a per-site system prompt, accepts ≤ 20 turns of `{role, content}` messages (4,000 chars each, 64 KiB total), rejects unknown top-level keys, and excludes payment details, stripe session IDs, credentials, session tokens, password strings, API keys, SSN / tax IDs, payout and banking info, host-payout details, uploaded IDs, and cross-tenant portfolio data. Operational house rules are always sent when the route loads a property; the host/style/signature block is gated by the per-user personalization toggle.

    Retention: OpenAI states that API inputs and outputs are not used to train its models by default unless the API customer explicitly opts in. Standard API abuse-monitoring logs may retain prompts, responses, and related metadata for up to 30 days by default, subject to documented exceptions and account-level data controls. Chat Completions has no application-state retention by default. Per-call-site returns (ReplyDraft, Message.aiDraft, MaintenanceRequest.triage, Listing rate suggestion) are stored separately in RentaraAI’s database for the durations listed in § 2 of the Privacy Policy.

  • Polsia, Inc. — R2 object storage

    United States (Cloudflare R2, Polsia-proxied)

    Purpose: Stores property photos and permit PDFs the host uploads.

    Data shared: Image bytes and filenames only. No message content.

    Retention: Until the host deletes the file or closes the account (30 days post-cancellation).

  • Polsia, Inc. — Email proxy

    United States (Polsia-operated)

    Purpose: Delivers outbound messages when the host clicks "Approve & send".

    Data shared: Sender address, recipient address, subject, body. No attachments by design.

    Retention: Platform-managed delivery logs; retention is provider-controlled and governed by Polsia — consult https://polsia.com/privacy for the current window. Suppresses duplicates at the recipient. Underlying mail routing is governed by Polsia.

  • Stripe, Inc.

    Stripe-default US/EU processing

    Purpose: Subscription billing and (where applicable) host-side payouts via Stripe Connect.

    Data shared: Name, email, billing address, plan amount, payout bank details where payouts are enabled. We never see card numbers.

    Retention: Billing records only — no message content. Per Stripe own data retention policy (typically seven years for tax records).

  • Render (hosting) + Cloudflare (edge)

    United States (Render default region) + Cloudflare global edge

    Purpose: Runs the application runtime, terminates TLS, serves static assets.

    Data shared: Standard HTTP request metadata (IP, user-agent, referer) for the app’s own routes.

    Retention: Render platform logs (90 days rolling). Cloudflare access logs governed by Cloudflare own retention.

Internal components (no third party)

better-auth (local Postgres account store): Holds local session cookies, password hashes, and account metadata in the app database. (full table).

No customer data is sent to this component as an external service.

We do not sell or rent your data, and we do not share it with advertising networks.

Effective: 2026-09-11 · v2026-08-06

We will email you before any material change to this policy and re-prompt acceptance on your next sign-in.

Read our Terms →