Subprocessors

Who we share data with, and how long each piece stays.

One row per processor. Purpose, location, data shared, retention, and a link so you can verify the processor’s own posture. Updated when an addition or removal lands.

AI / model inference

OpenAI — API

Location: OpenAI-operated infrastructure; processing location depends on the account and applicable data-residency configuration.

Processes AI text calls sent directly from RentaraAI’s server through the OpenAI API — guest-reply drafts, pilot demo drafts, nightly-rate suggestions, maintenance triage, and the streaming chat relay. Each call is narrowed to the data that call needs; we never send a host’s full portfolio.

Data shared
OpenAI API call-site scoped payloads only: (1) inbox/pilot demo drafts — the latest 5 turns of the guest thread + the property’s operational house rules + your saved tone preset, style notes, and signature block when personalization is ON. (2) messages lazy drafts (guest-reply) — the guest name + message body only. (3) nightly-rate suggestions — address / city / bedrooms, three scalar fields. (4) maintenance triage — the host-supplied description only. (5) narrow chat relay — auth-gated streaming chat scoped per call site (public-hero-demo for anonymous visitors, host-assistant for signed-in hosts, ops-console for admins): the server prepends a per-site system prompt, accepts ≤ 20 turns of `{role, content}` messages (4,000 chars each, 64 KiB total), rejects unknown top-level keys, and excludes payment details, stripe session IDs, credentials, session tokens, password strings, API keys, SSN / tax IDs, payout and banking info, host-payout details, uploaded IDs, and cross-tenant portfolio data. Operational house rules are always sent when the route loads a property; the host/style/signature block is gated by the per-user personalization toggle.
Retention
OpenAI states that API inputs and outputs are not used to train its models by default unless the API customer explicitly opts in. Standard API abuse-monitoring logs may retain prompts, responses, and related metadata for up to 30 days by default, subject to documented exceptions and account-level data controls. Chat Completions has no application-state retention by default. Per-call-site returns (ReplyDraft, Message.aiDraft, MaintenanceRequest.triage, Listing rate suggestion) are stored separately in RentaraAI’s database for the durations listed in § 2 of the Privacy Policy.
Last reviewed
2026-09-30
Processor privacy page →
Object storage

Polsia, Inc. — R2 object storage

Location: United States (Cloudflare R2, Polsia-proxied)

Stores property photos and permit PDFs the host uploads.

Data shared
Image bytes and filenames only. No message content.
Retention
Until the host deletes the file or closes the account (30 days post-cancellation).
Last reviewed
2026-08-06
Processor privacy page →
Email deliverability

Polsia, Inc. — Email proxy

Location: United States (Polsia-operated)

Delivers outbound messages when the host clicks "Approve & send".

Data shared
Sender address, recipient address, subject, body. No attachments by design.
Retention
Platform-managed delivery logs; retention is provider-controlled and governed by Polsia — consult https://polsia.com/privacy for the current window. Suppresses duplicates at the recipient. Underlying mail routing is governed by Polsia.
Last reviewed
2026-08-06
Processor privacy page →
Payments

Stripe, Inc.

Location: Stripe-default US/EU processing

Subscription billing and (where applicable) host-side payouts via Stripe Connect.

Data shared
Name, email, billing address, plan amount, payout bank details where payouts are enabled. We never see card numbers.
Retention
Billing records only — no message content. Per Stripe own data retention policy (typically seven years for tax records).
Last reviewed
2026-08-06
Processor privacy page →
Infrastructure

Render (hosting) + Cloudflare (edge)

Location: United States (Render default region) + Cloudflare global edge

Runs the application runtime, terminates TLS, serves static assets.

Data shared
Standard HTTP request metadata (IP, user-agent, referer) for the app’s own routes.
Retention
Render platform logs (90 days rolling). Cloudflare access logs governed by Cloudflare own retention.
Last reviewed
2026-08-06
Processor privacy page →

Notice of additions or removals is sent to active account owners at least 30 days before the change takes effect — see /rights for the request workflow.

Effective: 2026-09-11 · v2026-08-06

Internal components — not third-party subprocessors

What runs locally on our side.

These components handle data inside our own runtime (no third-party handoff). They are not subprocessors in the GDPR/PIPEDA sense and never receive customer data as an external service.

better-auth (local Postgres account store)

Location: United States (this app's Postgres)

Holds local session cookies, password hashes, and account metadata in the app database.

Data handled
Account row only — never any message content or guest data.
Last reviewed
2026-08-06

No customer data is sent to this component as an external service.