Privacy Policy
Last updated: July 2026
1. Introduction
AI Guest Concierge ("we", "us", "our") operates the platform accessible at trymitali.com. This Privacy Policy explains how we collect, use, store, and protect personal data when you use our service as a property host or as a guest interacting with a concierge.
[REVIEW NEEDED] Review with a qualified legal advisor before publishing. Add registered company name and address.
2. Data We Collect
We collect the following categories of personal data:
- Account data: name, email address, and profile photo from your Google account (via Google OAuth).
- Organization data: organization name and settings you configure.
- Property data: property name, address, description, photos, amenities, house rules, and other content you add.
- Knowledge base content: all text and information you add to knowledge base sections.
- Guest session data: messages exchanged between guests and the AI Concierge, session tokens, and language preferences.
- Guest request data: service requests submitted by guests (text and category).
- Payment data: subscription status and plan information. Card details are handled exclusively by Stripe and are never stored on our servers.
- Usage data: session counts, message counts, and timestamps used for analytics and billing limit enforcement.
- API keys (optional): if you provide a BYOK OpenAI API key, it is stored encrypted with AES-256-GCM.
3. How We Use Your Data
- To provide the AI Concierge service to your guests.
- To process your subscription and billing via Stripe.
- To authenticate you via Google OAuth.
- To store and retrieve your property's knowledge base for AI responses.
- To enforce usage limits (messages per month, properties per plan).
- To display usage analytics in your dashboard.
- To respond to support requests.
4. Data Sharing
We share data with the following third-party processors only as necessary to provide the service:
- OpenAI: Guest messages and property knowledge base content are sent to OpenAI to generate AI responses. See OpenAI's privacy policy for their data handling practices.
- Stripe: Payment and subscription data is processed by Stripe.
- AWS: Property images and uploaded assets are stored in private AWS S3 buckets.
- MongoDB Atlas: All application data is stored in MongoDB.
We do not sell personal data. We do not share data with advertisers.
5. Data Retention
- Account and organization data: retained until you delete your account.
- Guest session messages: retained until you delete them or delete the property.
- Uploaded assets: retained in S3 until you delete them or delete the property.
- Stripe event logs: retained for 90 days for webhook idempotency.
[REVIEW NEEDED] Add specific retention periods once confirmed.
6. Cookies
We use session cookies for authentication (managed by Auth.js). No advertising or tracking cookies are used. See our Cookie Policy for details.
7. Your Rights
Depending on your location, you may have rights to access, correct, delete, or export your personal data. To exercise these rights, contact us at [email protected].
[REVIEW NEEDED] Specify applicable law and response timeframes (e.g., GDPR Article 12 requires response within one month).
8. Contact
For privacy questions or requests: [email protected]