Subprocessors
Who we share data with, and how long each piece stays.
One row per processor. Purpose, location, data shared, retention, and a link so you can verify the processor’s own posture. Updated when an addition or removal lands.
OpenAI — API
Location: OpenAI-operated infrastructure; processing location depends on the account and applicable data-residency configuration.
Processes AI text calls sent directly from RentaraAI’s server through the OpenAI API — guest-reply drafts, pilot demo drafts, nightly-rate suggestions, maintenance triage, and the streaming chat relay. Each call is narrowed to the data that call needs; we never send a host’s full portfolio.
- Data shared
- OpenAI API call-site scoped payloads only: (1) inbox/pilot demo drafts — the latest 5 turns of the guest thread + the property’s operational house rules + your saved tone preset, style notes, and signature block when personalization is ON. (2) messages lazy drafts (guest-reply) — the guest name + message body only. (3) nightly-rate suggestions — address / city / bedrooms, three scalar fields. (4) maintenance triage — the host-supplied description only. (5) narrow chat relay — auth-gated streaming chat scoped per call site (public-hero-demo for anonymous visitors, host-assistant for signed-in hosts, ops-console for admins): the server prepends a per-site system prompt, accepts ≤ 20 turns of `{role, content}` messages (4,000 chars each, 64 KiB total), rejects unknown top-level keys, and excludes payment details, stripe session IDs, credentials, session tokens, password strings, API keys, SSN / tax IDs, payout and banking info, host-payout details, uploaded IDs, and cross-tenant portfolio data. Operational house rules are always sent when the route loads a property; the host/style/signature block is gated by the per-user personalization toggle.
- Retention
- OpenAI states that API inputs and outputs are not used to train its models by default unless the API customer explicitly opts in. Standard API abuse-monitoring logs may retain prompts, responses, and related metadata for up to 30 days by default, subject to documented exceptions and account-level data controls. Chat Completions has no application-state retention by default. Per-call-site returns (ReplyDraft, Message.aiDraft, MaintenanceRequest.triage, Listing rate suggestion) are stored separately in RentaraAI’s database for the durations listed in § 2 of the Privacy Policy.
- Last reviewed
- 2026-09-30
Polsia, Inc. — R2 object storage
Location: United States (Cloudflare R2, Polsia-proxied)
Stores property photos and permit PDFs the host uploads.
- Data shared
- Image bytes and filenames only. No message content.
- Retention
- Until the host deletes the file or closes the account (30 days post-cancellation).
- Last reviewed
- 2026-08-06
Polsia, Inc. — Email proxy
Location: United States (Polsia-operated)
Delivers outbound messages when the host clicks "Approve & send".
- Data shared
- Sender address, recipient address, subject, body. No attachments by design.
- Retention
- Platform-managed delivery logs; retention is provider-controlled and governed by Polsia — consult https://polsia.com/privacy for the current window. Suppresses duplicates at the recipient. Underlying mail routing is governed by Polsia.
- Last reviewed
- 2026-08-06
Stripe, Inc.
Location: Stripe-default US/EU processing
Subscription billing and (where applicable) host-side payouts via Stripe Connect.
- Data shared
- Name, email, billing address, plan amount, payout bank details where payouts are enabled. We never see card numbers.
- Retention
- Billing records only — no message content. Per Stripe own data retention policy (typically seven years for tax records).
- Last reviewed
- 2026-08-06
Render (hosting) + Cloudflare (edge)
Location: United States (Render default region) + Cloudflare global edge
Runs the application runtime, terminates TLS, serves static assets.
- Data shared
- Standard HTTP request metadata (IP, user-agent, referer) for the app’s own routes.
- Retention
- Render platform logs (90 days rolling). Cloudflare access logs governed by Cloudflare own retention.
- Last reviewed
- 2026-08-06
Notice of additions or removals is sent to active account owners at least 30 days before the change takes effect — see /rights for the request workflow.
Effective: 2026-09-11 · v2026-08-06
What runs locally on our side.
These components handle data inside our own runtime (no third-party handoff). They are not subprocessors in the GDPR/PIPEDA sense and never receive customer data as an external service.
better-auth (local Postgres account store)
Location: United States (this app's Postgres)
Holds local session cookies, password hashes, and account metadata in the app database.
- Data handled
- Account row only — never any message content or guest data.
- Last reviewed
- 2026-08-06
No customer data is sent to this component as an external service.