Legal centerGuest Data & Consent Notice
Guest Data & Consent Notice
This is for guests who message a host's assistant on WhatsApp. It explains what the assistant collects, why, how it connects you to local services, and what you can ask for. The first time you write, the assistant tells you in the chat that it is automated and acting for your host. This is the longer version of that line.
Who you're messaging
You are talking to an automated assistant — a bot — operated by Sifrhost (ANASS RAHMOUNI) on behalf of your host. It answers from information your host wrote down, and it can connect you to local services when you ask.
It is not a person and it is not an emergency service. In an emergency, call your local emergency number directly.
What we collect
- Your WhatsApp number, and the profile name WhatsApp gives to whoever you message.
- What you send: text, voice notes, and photos.
- Details you give us so we can help — a pickup point, a destination, an order, what you need.
- The language you write in, detected automatically, and where you are in the conversation.
What we don't keep
Voice notes are transcribed and the recording is discarded. We do not store your audio — the conversation shows only that an audio message arrived.
Photos stay on WhatsApp's servers. We keep the link and a short written description of what was in the picture, not the picture itself.
We do not collect your IP address, your device details, or your location beyond what you type.
It is processed by AI
Your messages are sent to AI providers — currently OpenAI and Anthropic — to be understood, transcribed, translated, and answered. Photos you send are analysed by AI to work out what you are asking about.
To answer you, the assistant sends the AI provider what it needs from your host's information. Depending on your question that can include the property address, its Google Maps link, and the Wi-Fi network name and password.
Automated answers can be wrong. Check anything that matters, and do not rely on the assistant for medical, legal, safety, or emergency decisions.
Connecting you to local services
If you ask for a taxi, a delivery, or a table, the assistant passes your request to that provider and translates between you, without giving either side the other's phone number. It shares what the provider needs — a pickup point, an order, a time.
Those providers are independent businesses arranged or recommended by your host, not by Sifrhost. We connect and translate. We do not provide the service, and we cannot stand behind it. If something goes wrong with the service itself, that is between you, your host, and the provider.
What your host can see about you
Your host sees more than your messages. They also keep a private record about you that you cannot see.
It holds their own notes about you, and a timeline of your stay — when you arrived in the city, when you reached the property, when you left. It is the host's record, kept in their dashboard, and it is not shown to you anywhere in the chat.
We are telling you because you should know it exists. If you want to know what it says about you, or want something in it corrected or removed, ask your host — it is theirs, not ours. Write to us at contact@sifrhost.com if you cannot reach them and we will help you get to them.
WhatsApp keeps its own copy
The conversation happens on WhatsApp, which is Meta's service, not ours. Meta holds its own copy of these messages under its own terms and privacy policy, and so does your own phone.
That matters if you ask us to delete your data: we can delete what is on our side, but we cannot reach the copy on Meta's servers or the one in your phone. To deal with those, use WhatsApp's own settings and Meta's own privacy tools.
Who else sees your data
We do not sell your data and we do not use it for advertising. It reaches these companies only because they run parts of the service:
- Meta (WhatsApp Business Platform) — carries the messages.
- OpenAI and Anthropic — the AI that reads, transcribes, translates, and answers.
- Neon — the database where the conversation is stored.
- Upstash — short-term cache; your phone number is used as a key there.
- Inngest — runs scheduled work, and message content passes through it.
- Cloudinary — stores files your host uploads.
- Resend — sends email to your host, not to you.
- PostHog — usage analytics for the host dashboard.
- Vercel — hosts the service.
Some of these are outside Morocco, so your data crosses borders to reach them.
One service receives nothing about you: we call exchangerate-api.com to convert currencies. It gets an amount and two currency codes. No name, no number, no message.
How long we keep it
Your conversation is kept for up to 30 days after your last message. There is also a shorter rule: if you go quiet for 24 hours, the conversation is closed and its contents removed the next time anything touches it. So for most guests the real answer is 24 hours; 30 days is the limit for a conversation that is never returned to.
A question the assistant could not answer is kept for 90 days so your host can improve the answers. A request passed to a driver or a restaurant is kept for 180 days, so there is a record if the service is disputed.
If your host reports abuse from your number, that report is kept for one year.
One thing we cannot delete
Translating the same sentence twice costs money for no reason, so translations are cached and shared across the platform.
The cache is keyed by a fingerprint of the text itself. It holds no name, no number, and no link back to you or to any conversation. That is what makes it safe to share — and it is also why we cannot find your entries in it to delete them. Nothing in it identifies you, so there is nothing to look up.
Entries expire on their own after 30 days. That is the only control there is, and we would rather say so than let you think a deletion request reaches further than it does.
If your host blocks you
A host can stop the assistant replying to your number. It is their decision and it only affects their own properties — no other host is affected, and nothing about you is shared with anyone else.
Nothing is automated: no system decides on its own to block you. A person does, and a person can undo it.
A block lifts on its own after 30 days. If you think it was a mistake, write to contact@sifrhost.com and a person will look at it.
What you can ask for
You can stop messaging the assistant at any time, and you do not have to give it anything you would rather not.
Where the law gives you the right, you can ask for a copy of your data, ask for it to be corrected, or ask for it to be deleted. Write to contact@sifrhost.com. There is no button for this — a person reads your request and does it by hand, so tell us the WhatsApp number you used.
Two limits, stated plainly: we cannot reach the copy WhatsApp and your phone hold, and we cannot reach the translation cache described above. Everything else on our side, we can.
To turn the assistant off for your conversation, ask your host — they can do it from their dashboard. The assistant cannot switch itself off, so asking it in the chat will not work.
Normal WhatsApp charges, and Meta's own terms and privacy policy, apply to your use of WhatsApp.
Contact
Questions about your data go to contact@sifrhost.com. The operator is ANASS RAHMOUNI, Chefchaouen, Morocco. The full details are in the Privacy Policy.
Questions about these documents?
These are drafts pending legal review. For anything time-sensitive, reach the team directly.
Contact us