Skip to content

Your data

Privacy Policy

This policy explains, in plain language, how HostHours handles account details, STR and LTR work records, assisted drafts, selected calendar clues, private evidence, purchases, and support messages.

Scope and overview

This Privacy Policy applies to the HostHours mobile application, the hosthours.app website, and support communications (collectively, the “Service”). “HostHours,” “we,” “us,” and “our” refer to the operator of the HostHours Service.

HostHours is an account-based factual recordkeeping service for US short-term-rental (STR) and long-term-rental (LTR) owners. Workspace records are scoped to the signed-in account. We do not sell personal information, serve third-party advertising, or use advertising or cross-app tracking SDKs. The current app uses content-free product events for reliability and rollout decisions, not a third-party product-analytics SDK.

Launch and document status

This page describes the current repository candidate and intended production data flows. It is not proof that HostHours is publicly available in the App Store or Google Play, or that every paid or provider-backed feature is enabled. Signed-device tests, current store and RevenueCat evidence, the production evidence-limit migration, Voice AI operational controls, public HTTPS endpoints, and support-mailbox delivery still require final owner verification.

The legal operator/data-controller identity, mailing address, final effective date, and production SMTP provider have not been supplied for this draft and must not be guessed. The responsible owner or adviser must add and approve those details, the subscription language, provider settings, and data-retention language before public launch.

Data we process

Account and profile data

We process your email address, internal user ID, authentication and session information, and any owner name you provide. If you choose Apple or Google sign-in, we receive the account identifier and profile details that provider makes available based on your choices, such as a name or email address. Apple may provide a private relay address.

Workspace and rental records

We process information you enter to use the Service: property names, STR or LTR strategy, city/state location, optional street address and ZIP code, tax year, tracking reference, rental and personal-use days, ownership percentage, and notes; activity dates, durations, categories, descriptions, contributor names and roles; monthly reviews, reminders, source and revision context, and report/export history.

Private evidence and files

When you attach evidence, we process the selected image or PDF, filename, MIME type and size, evidence label/type, reference text, upload and deletion status, and related activity/property identifiers. Receipts, invoices, screenshots, messages, and photos may contain personal or financial information, so review and redact them before uploading. Camera, photo-library, or file access is requested only when you start the relevant action; HostHours does not upload an entire library.

The release-candidate rules allow zero new evidence files on Free, up to one image or PDF per activity on Essential, and up to five on Pro. These are new-action limits and do not silently delete existing evidence after a downgrade. The compatible server migration and signed app still require production release verification.

Voice AI input and editable drafts

Voice AI is a Pro capability. A new Voice task on Free or Essential should reach the plan choice before HostHours requests microphone permission or collects content. In the current client, operating-system speech recognition first creates text. HostHours does not send the raw recording to OpenRouter; depending on the device, language, and system capabilities, Apple or Google may process speech under the platform's own speech-recognition terms. You can type instead.

To create an editable draft, the authenticated HostHours Edge Function sends the transcript or typed description to OpenRouter together with limited grounding context: local date, locale and time zone; selected property ID; property IDs, names, locations, and tax years; contributor names and types; and available activity categories. OpenRouter returns a structured suggestion. The server validates it, and you review the property, date, duration, contributor, category, and factual note before anything is saved as an activity.

The request is configured to require OpenRouter Zero Data Retention routing and deny provider data collection. HostHours logs categorical status, request identifiers, latency, token/usage units, and estimated cost without transcript, note, address, evidence, filename, or imported-row content. Supabase temporarily stores a source hash, request/provider metadata, and validated structured result for retry and idempotency; the result is designed to be scrubbed after about 24 hours. Pending text and editable draft state are stored account-scoped on the device until completed, discarded, or removed with account data.

Device Calendar Recall

Calendar Recall is a Pro capability. After you choose it and grant operating-system calendar access, HostHours uses that access only to read calendars you select on the device, including Google calendars already synchronized through the device calendar account. It reads visible event titles, calendar names, start/end times, all-day status, and time-zone data for the selected date range. HostHours does not edit the calendar, create events, or use direct Google Calendar authorization.

Selected calendar identifiers are stored account-scoped on the device. Unsaved clues are generated and reviewed on the device. A timed event's length can seed an editable duration, but it is not treated as proof of participation. If you save a reviewed clue, the confirmed activity fields plus limited source provenance, such as a derived identifier and source time, become a normal synced HostHours record.

Reviewed CSV import

A selected CSV is read and parsed on the device. HostHours processes its header and rows to detect and map date, duration, property, notes, category, contributor, and optional evidence-reference columns; it also checks invalid rows, duplicates, and locked months. The raw CSV is not uploaded or retained. A SHA-256 file hash and batch identifier are attached to confirmed imported activities for duplicate and provenance checks. Free and Essential can inspect the local mapping/validation preview; Pro is required to append selected reviewed rows. Existing activities are not overwritten.

Google Places city autocomplete

When you edit a property location and type at least three characters, HostHours may send that search text through an authenticated Supabase Edge Function to Google Places for US city suggestions. Google receives the query and returns place IDs and display labels. HostHours applies per-user request limits. Manual city/state entry remains available, and the autocomplete does not send the rest of your workspace.

Plans and purchases

Free has no store purchase. For Essential and Pro, we process the HostHours account identifier, resolved plan and entitlement status, product and offering identifiers, purchase/renewal history, storefront pricing and currency, and, when available, your account email through RevenueCat. Apple or Google processes payment credentials; HostHours does not receive your full card number.

Device, network, reminder, analytics, and support data

Our infrastructure and providers may process ordinary technical data needed to operate and protect the Service, such as IP address, platform/device type, app version, request time, authentication events, feature/plan state, categorical completion or failure state, and error metadata. Content-free product events can include coarse count buckets, but not transcripts, notes, calendar titles, filenames, addresses, or CSV rows. If you contact support, we process the email address, message, and attachments you send.

Reminder preferences are part of the synced workspace. Reminder delivery is scheduled locally by the operating system. HostHours does not currently register a push token or send these reminders through a HostHours push server. Notification permission remains controlled in device settings.

How we use data

We use the data described above to:

  • create, authenticate, secure, recover, and delete your account;
  • save, sync, isolate, and restore your account-scoped workspace;
  • store and retrieve private evidence and show upload/deletion status;
  • create editable Voice suggestions and validate them before review;
  • show read-only clues from device calendars you selected;
  • map and validate local CSV rows, then append only confirmed Pro imports;
  • return US city suggestions for the location text you enter;
  • generate the plan-appropriate preview, CSV, PDF, and portable JSON exports;
  • schedule local reminders and route notification taps;
  • verify Essential or Pro entitlements, restore purchases, and reconcile plan changes;
  • respond to support, privacy, security, and legal requests;
  • maintain reliability, enforce limits, prevent abuse, and troubleshoot failures; and
  • comply with applicable law and enforce our Terms.

The final operator-approved policy must identify the legal bases that apply to the operator and each relevant jurisdiction before launch. Depending on applicable law and the purpose, those bases may include providing the Service you request, consent for optional permissions or content, service security and operation, and legal obligations. Withdrawing an optional permission prevents future access through that permission but does not automatically undo processing that already lawfully occurred.

When data reaches other services

We disclose data only as needed to operate the Service, at your direction, or as required by law. Current or release-candidate providers include:

  • Supabase — authentication, account email flow, workspace database, private evidence Storage, Edge Functions, feature/allowance enforcement, limited product events, and account deletion. See the Supabase Privacy Policy.
  • OpenRouter and an eligible model endpoint — Pro Voice draft processing using the text and grounding context described above. Requests are designed to require Zero Data Retention routing and deny provider data collection; OpenRouter may retain non-content request metadata. See OpenRouter Privacy and its Zero Data Retention documentation.
  • Google Maps Platform / Places — authenticated US city autocomplete for the location text you type. See the Google Privacy Policy.
  • RevenueCat — Essential/Pro entitlement and purchase lifecycle, associated with the HostHours user ID and, when available, email. RevenueCat may also receive platform and store-transaction information. See the RevenueCat Privacy Policy.
  • Apple and Google — sign-in if selected, store purchase/payment processing, and platform speech recognition where the device cannot perform it entirely on-device. Calendar Recall uses the operating-system calendar store; it does not authorize HostHours directly with Google Calendar. See Apple Privacy and Google Privacy.
  • Backblaze B2— a private, self-managed offsite recovery copy of logical database archives and private Supabase evidence objects. It is not the application's live database or file backend. See the Backblaze Privacy Policy.

A production SMTP provider has not been selected and is therefore not named here. If another provider will process confirmation or password-recovery email, this policy must be updated before relying on it in production.

We may also disclose information to professional advisers or authorities when reasonably necessary to comply with law, protect users or the Service, investigate fraud/security issues, or establish legal claims. If the Service is involved in a merger, financing, acquisition, or sale, data may transfer as part of that transaction, subject to applicable law and notice where required.

When you export or share through the device share sheet, the recipient and destination app receive that file at your direction. Their practices are outside HostHours' control.

Storage, backups, transfers, and security

HostHours keeps a user-ID-scoped offline workspace cache and app-managed evidence copies on your device. Local account state can also include a pending Voice input or editable draft, selected device-calendar identifiers, import review state while its screen remains open, timers, queues, and generated reports. Authentication session data uses device-protected storage where supported. Protect the device with a passcode and take care when exporting or sharing files.

Signed-in workspace data is synced to Supabase. Uploaded evidence is stored in a non-public Supabase Storage bucket with account-prefixed access policies and is opened through time-limited signed links. A link already issued may work until it expires, even after metadata is removed and while physical file cleanup completes.

While production remains on Supabase Free, a daily self-managed workflow creates a logical database archive and incrementally copies private evidence to private Backblaze B2 storage without mirroring source deletions. B2 copies may therefore remain after live content is deleted until the operator's configured retention or rotation process removes them; that production configuration still requires final verification. This is not Supabase-managed backup or point-in-time recovery, and database archives do not by themselves restore binary evidence files. The complete disposable restore and sample-object recovery drill remains unverified, so no recovery point or recovery time is guaranteed.

Providers may process data in the United States or other countries where they operate. Their transfer mechanisms and policies apply; the responsible operator must verify any safeguards required by applicable law before launch. We use reasonable administrative and technical controls, but no device, transmission, AI, backup, or storage system can be guaranteed completely secure. HostHours does not claim a compliance certification in this draft.

Your choices and privacy rights

  • Review and correct: edit profile, property, activity, evidence, people/category, and reminder data in the app.
  • Voice: type instead of speaking, edit every suggested field, or discard the pending local input/draft without saving an activity.
  • Calendar: choose calendars in HostHours, remove a selected source, or withdraw Calendar permission in device settings.
  • CSV: review and deselect rows; the raw file is not uploaded or retained by HostHours.
  • Location: ignore autocomplete and enter city/state manually.
  • Export: use Export My Data on every plan. The JSON contains evidence metadata, not original binary files.
  • Plan exports: Essential includes the standard activity CSV; Pro includes the full PDF and CPA CSV packet.
  • Delete individual content: remove entries or evidence in the app. Some deletions have an Undo window or asynchronous remote cleanup.
  • Permissions: change microphone, speech-recognition, camera, photo/file, calendar, and notification permissions in device settings.
  • Provider access: manage Apple or Google connected-account permissions with that provider.
  • Account deletion: use Settings → Profile & account to export data and then permanently delete the account.

Depending on where you live, you may also have rights to access, correct, delete, restrict, object to, or receive a portable copy of personal data, and to appeal or complain to a data-protection authority. To make a request, email support@hosthours.app. We may verify your identity and will not discriminate against you for exercising a privacy right. Rights can be limited by applicable exceptions.

Retention and account deletion

We retain the active account and synced workspace as needed to provide the Service. You control how long you keep activity records and live evidence. Pending Voice input and draft state remain on the device until completed, discarded, or cleared. The server-side Voice idempotency result is designed to expire after about 24 hours; content-free allowance, request, and cost metadata can be retained longer for abuse, billing, and reliability controls. CSV raw files are not retained by HostHours.

Support correspondence and limited security, transaction, entitlement, feature, and request records may be kept as reasonably necessary to resolve requests, prevent abuse, comply with legal duties, reconcile billing, or establish legal claims.

In-app account deletion first removes the RevenueCat customer profile, attempts any applicable Apple-token revocation, fences new workspace writes, and removes live private evidence objects before deleting the Supabase authentication user and cascading cloud workspace/metadata. The app then attempts to clear the account-scoped local workspace, evidence, queues, Voice draft, calendar-source selection, billing state, and session data. Failures can require a retry or manual Apple-disconnect step; follow the in-app status instead of assuming a partial request completed.

Backblaze recovery copies, provider backups, security logs, and Apple or Google store transaction records may remain under the relevant retention schedule or where law requires them. Because the self-managed B2 copy does not mirror live deletion, it is not erased synchronously with account deletion. It is intended only for restricted recovery use; removal follows the operator's configured retention/rotation process, which must be verified before launch.

Deleting a HostHours account does not cancel an App Store or Google Play subscription. Cancel separately with the store. Canceling a subscription also does not delete the HostHours account or its existing records.

US rental recordkeeping disclaimer

HostHours is an STR/LTR recordkeeping tool, not tax software and not a tax, legal, accounting, or financial adviser. Information stored in HostHours may be relevant to a US tax discussion, but HostHours does not determine material participation, deduction eligibility, tax classification, audit acceptance, or whether any specific record or evidence is sufficient. Hour comparisons, Calendar clues, Voice/CSV drafts, and quality indicators are organizational aids only.

This policy does not tell you how long tax records must be retained. You are responsible for record accuracy and preservation and for reviewing your facts with a qualified CPA or tax professional. Export anything you need before deleting content or the account; deletion is not a substitute for your retention obligations.

Children, website use, and changes

Children

HostHours is intended for adults managing rental records and is not directed to children under 13. We do not knowingly collect personal information from children under 13. Contact us if you believe a child provided data so it can be reviewed.

Website and cookies

The current public website candidate does not use advertising or product-analytics cookies. Essential hosting and network systems may process basic request data for delivery, reliability, and security. If this changes materially, we will update this policy and any consent controls required by law.

Policy changes

We may update this policy when the Service, providers, plan rules, or legal requirements change. The final production policy must display an approved effective date and operator identity. Later revisions will show a new date and provide additional notice when a material change requires it.

Contact us

The intended address for questions, privacy requests, and account-deletion help is support@hosthours.app. Delivery and reply capability must be verified before public launch. Do not include passwords, full payment-card details, tax identification numbers, Voice transcripts, or unredacted sensitive documents in email.