Skip to content

Privacy Policy

How we handle your data

This policy explains how HostHours collects, uses, shares, retains, and protects information when you use the HostHours mobile application, website, and support channels.

Effective and last updated August 20, 2026

Overview

HostHours is an account-based recordkeeping tool for US short-term-rental (STR) and long-term-rental (LTR) owners. We do not sell personal information, use it for cross-context behavioral advertising, serve third-party ads, or use advertising or cross-app tracking SDKs.

Questions and privacy requests can be sent to support@hosthours.app.

Data we handle

Account and profile

We process your email address, HostHours user ID, authentication and session data, and the report name you choose. If you use Apple or Google sign-in, we receive the account identifier and profile details that provider makes available based on your choices, such as a name or email address. Apple may provide a private relay address.

Property and activity records

We process the facts you enter or confirm, including property names, STR or LTR strategy, city and state, optional street address and ZIP code, property type, tax year, tracking reference, rental and personal-use days, ownership percentage, and notes. Activity records can include dates, durations, categories, descriptions, contributor names and roles, source information, confirmation times, monthly reviews, reminders, and revision history.

Evidence and files

If you attach optional evidence, we process the image or PDF you selected, its filename, type and size, your label and reference text, upload status, and the related activity and property. Receipts, invoices, screenshots, messages, and photos may contain personal or financial information. Review and redact them before uploading. HostHours does not upload your entire photo library or file collection.

Purchases, diagnostics, analytics, and support

For paid plans, HostHours and RevenueCat process your HostHours user ID, plan and entitlement status, product and offering identifiers, purchase and renewal status, storefront price and currency, and, when available, account email. Apple or Google processes payment credentials; HostHours does not receive your full card number.

Our systems and providers also process technical data needed to operate and protect the Service, such as IP address, platform, app version, request time, authentication events, feature or plan state, categorical completion or failure state, and limited error details. Account-linked product events use approved categorical values and do not include notes, transcripts, calendar titles, addresses, filenames, evidence, or imported rows. If you contact support, we process the email address, message, and attachments you send.

Voice, Calendar, CSV, and location suggestions

Voice AI drafts

Voice AI is an optional Pro feature. When you choose to record, the device and its speech-recognition service turn speech into text. Depending on the device, settings, and language, Apple or Google may process the audio under its own terms. HostHours may temporarily keep a recording in app-managed device storage so transcription can be retried, but HostHours does not send raw audio to its backend or to OpenRouter. You can type instead.

To create an editable draft, HostHours sends the transcript or typed description through an authenticated Supabase Edge Function to OpenRouter, which routes it to the configured AI model provider. The current configuration uses an OpenAI model. The request also includes limited context needed to interpret the description: local date, locale and time zone; selected property; property names, locations and tax years; contributor names and types; and the available categories. The result is a suggestion, and you must review the property, date, duration, contributor, category, and note before an activity is saved.

HostHours requests Zero Data Retention routing and denies provider data collection for each OpenRouter request. OpenRouter may retain non-content request metadata such as model, token count, cost, and latency. HostHours keeps a source hash and limited request metadata for retry, allowance, abuse-prevention, and billing controls; the temporary structured result is scrubbed after about 24 hours. Pending input and the editable draft remain account-scoped on the device until completed, discarded, or removed with account data.

Device Calendar Recall

Calendar Recall is an optional Pro feature. After you choose it and grant permission, HostHours reads only the device calendars you select, including Google calendars that are already synchronized with the device. It can read visible calendar names, event titles, start and end times, all-day status, and time-zone data for the selected date range. HostHours does not edit events or authorize directly with Google Calendar.

Selected calendar identifiers stay account-scoped on the device, and unsaved clues are reviewed there. If you save a clue, the fields you confirm and limited source provenance become a normal synced HostHours activity. An event title or length is a clue, not proof that work occurred.

Reviewed CSV import

A CSV you select is read and validated on the device. HostHours can map date, duration, property, notes, category, contributor, and evidence-reference columns and flag invalid or possible duplicate rows. The raw CSV is not uploaded or retained. If you confirm an import, a file hash and batch identifier are stored with the new activities for duplicate and provenance checks. Existing activities are not overwritten.

Google Places city suggestions

If you use property-location autocomplete, the location text you type is sent through an authenticated HostHours server function to Google Places for US city suggestions. Google receives the query and returns place identifiers and display labels. You can skip autocomplete and enter city and state manually.

How we use data

We use data described in this policy to:

  • create, authenticate, secure, recover, and delete your account;
  • save, sync, isolate, restore, and export your workspace;
  • store and retrieve private evidence and show its upload or deletion status;
  • provide the Voice, Calendar, CSV, and location features you choose;
  • schedule local reminders and route notification actions;
  • verify plans, restore purchases, and reconcile subscription changes;
  • respond to support, privacy, security, and legal requests;
  • measure content-free product operation, troubleshoot failures, and prevent abuse;
  • comply with law and enforce the Terms of Use.

Where applicable law requires a legal basis, we rely on performing the Service you request, your consent for optional permissions or processing, legitimate interests in operating and securing the Service, and legal obligations. You may withdraw an optional permission at any time, but that does not undo processing already completed lawfully.

When data reaches other services

We disclose data only as needed to operate the Service, follow your direction, protect the Service or users, complete a business transaction subject to applicable law, or comply with a valid legal request. We do not authorize service providers to use your data for their own advertising. Providers used by the Service, depending on the feature and production configuration, include:

  • Supabase — authentication, account email flows, workspace database, private evidence Storage, Edge Functions, plan enforcement, product events, and account deletion. See Supabase Privacy.
  • OpenRouter and the configured AI model provider, currently OpenAI — processing the text and limited context described above to create a Voice draft using a Zero Data Retention route. See OpenRouter Privacy and Zero Data Retention, plus OpenAI Privacy.
  • RevenueCat — paid-plan entitlement and purchase lifecycle. See RevenueCat Privacy.
  • Google Maps Platform / Places — US city autocomplete for text you enter. See Google Privacy.
  • Apple and Google — sign-in when selected, store purchases and payments, platform speech recognition, and other operating-system services. See Apple Privacy and Google Privacy.
  • Sentry — if crash reporting is enabled, scrubbed JavaScript error reports containing app, release, platform, error type, and stack frames. HostHours disables user data, messages, requests, breadcrumbs, screenshots, replay, performance traces, native crash handling, and automatic sessions. Network systems may still process an IP address. See Sentry Privacy.
  • Backblaze B2 — restricted recovery copies of database archives and private evidence objects; it is not the live app backend. See Backblaze Privacy.

When you export or share a file through the device share sheet, the destination you choose receives that file at your direction. Its privacy and retention practices then apply.

Device permissions and local features

  • Microphone and speech recognition: requested only when you start Voice capture; typed input remains available.
  • Calendar: requested only when you open Calendar Recall; access is read-only and limited to calendars you select.
  • Camera, photos, and files: used only when you choose optional evidence to attach.
  • Notifications: used for reminders and active-timer visibility. Reminder delivery is scheduled locally; HostHours does not register a push token for those reminders.

You can change permissions in device settings. Withdrawing permission stops future access through that permission but does not delete records or evidence you already chose to save.

Storage, transfers, and security

HostHours keeps an account-scoped offline workspace cache and app-managed evidence copies on your device. Local state may also include a pending Voice input, selected calendar identifiers, an import preview while you review it, timers, sync queues, and generated exports. Authentication sessions use device-protected storage where supported.

Signed-in workspace data is synchronized to Supabase. Uploaded evidence is stored in a non-public bucket with account-scoped access rules and opened through short-lived signed links. Recovery copies are stored separately in restricted Backblaze storage. We use encrypted network transport, access controls, data minimization, and deletion fences, but no device, transmission, AI, or storage system can be guaranteed completely secure. Protect your device and exported files with appropriate access controls.

Providers may process data in the United States or other countries where they operate. When required, transfers are handled under the provider's applicable contractual or legal safeguards.

Retention and account deletion

We keep your active account, workspace, revisions, and live evidence while needed to provide the Service or until you delete them. A completed Voice draft result is scrubbed after about 24 hours; limited request, allowance, and cost metadata may be kept longer for retry, abuse prevention, billing, and reliability. The raw CSV is not retained. Content-free product events are retained for up to 400 days. Support, security, entitlement, and transaction records are kept only as long as reasonably needed for the relevant purpose or legal obligation.

In the app, open Settings → Profile & account → Delete account. The deletion flow permanently removes the live HostHours authentication account, cloud workspace, private evidence, related metadata, RevenueCat customer profile, and account-scoped local data. If a step fails, the app will ask you to retry or contact support rather than treating a partial request as complete.

If you cannot use the app, request deletion from the account-deletion section of Support or email support@hosthours.app from the address associated with your account. We may verify ownership before completing the request.

Short-lived signed links may continue to work until they expire. Restricted recovery copies may remain after live deletion until they are separately purged from recovery storage. Provider backups, security logs, and Apple or Google transaction records may also remain under the provider's process or where law requires retention. They are not used as an active account and are protected from ordinary product access.

Deleting a HostHours account does not cancel an App Store or Google Play subscription. Cancel renewal separately through the store. Canceling a subscription also does not delete your HostHours account or records.

Your choices and privacy rights

  • Review and correct: edit profile, property, activity, contributor, evidence, category, and reminder data in the app.
  • Export: Export my data is available on every plan. The portable JSON includes records and evidence metadata, not original evidence files.
  • Delete content: delete individual activities, evidence, properties, or the entire account through the relevant in-app controls.
  • Voice: type instead, edit every suggested field, or discard pending local input without saving an activity.
  • Calendar: choose or remove calendars in HostHours, or withdraw Calendar permission in device settings.
  • CSV and location: deselect import rows, discard a preview, or enter city and state without autocomplete.
  • Connected accounts: manage Apple or Google account access with that provider.

Depending on where you live, you may also have rights to access, correct, delete, restrict, object to, or receive a portable copy of personal data, and to appeal or complain to a data-protection authority. Email support@hosthours.app. We may verify your identity, and legal exceptions may limit a request.

Children, website data, and recordkeeping

Children

HostHours is intended for adults managing rental records and is not directed to children. We do not knowingly collect personal information from children. Contact us if you believe a child supplied data.

Website

The public website uses Google Analytics to measure page visits and interactions. Google Analytics uses cookies and processes usage, browser, and device information. See Google’s Privacy Policyfor information about how Google handles data. Hosting and network systems may process basic request data needed to deliver and secure the site.

Rental recordkeeping

HostHours is a factual recordkeeping tool, not tax, legal, accounting, or financial advice. You are responsible for record accuracy, your own retention obligations, and preserving any source files you need. Export important data before deleting it.

Changes to this policy

We may update this policy when the Service, providers, or legal requirements change. The date above will change, and we will provide additional notice when required for a material change.

Contact us

Email support@hosthours.app for privacy questions, requests, or account-deletion help. Do not include passwords, full payment-card details, tax identification numbers, Voice transcripts, or unredacted sensitive documents in email.