Legal centerPrivacy Policy
Privacy Policy
This policy explains what Sifrhost does with personal data — the host's, and the guest's. It describes what the system actually does, not what a privacy policy usually says. The person responsible is ANASS RAHMOUNI, a registered self-employed operator (auto-entrepreneur) in Morocco, trading as Sifrhost.
Who we are and what this covers
Sifrhost is a WhatsApp assistant for accommodation hosts. A host puts their property details into a dashboard; their guests message a WhatsApp number and the assistant answers from those details.
Identity of the person responsible: ANASS RAHMOUNI, registered self-employed operator (auto-entrepreneur), registration number 003980944000115, tax identifier 73080496, registered activity: IT consulting, hosting and development. Address: Avenue Sidi Ahmed Louafi, Qu Sebbanine, Chefchaouen 91000, Morocco. Email for everything in this policy: contact@sifrhost.com.
This covers two different people. The host, who has an account and signs in. And the guest, who has no account and never visits this website — the guest only ever sees WhatsApp. Where the two are treated differently, this policy says so.
There is no guest login and no guest portal. If you are a guest and you want to know what is held about you, or want it deleted, email contact@sifrhost.com. A person reads that address.
What we hold
From the host
- Account: name, email address, WhatsApp number, a hashed password (we never see the password itself), interface language, and whether the account is verified.
- Property: address, Google Maps link, Wi-Fi network name and password, door codes and key locations, house rules, check-in and check-out times, FAQs, an emergency phone number, and photos you upload.
- Local services you add: the business name and the contact number you type in, including the WhatsApp number the assistant uses to reach them.
- Billing: your billing name, tax identifier and address, your token balance, and invoices.
- Use of the dashboard: settings, and an audit record of sensitive actions such as approving a payment or erasing someone's data.
From the guest, over WhatsApp
- The phone number and the profile name WhatsApp gives us.
- The text of messages sent to the assistant, and the replies.
- Whatever the guest writes into a request — a pickup point, an address, an order, a time.
- The language we detect the guest is writing in.
- Where the guest appears to be in their stay — arrived in the city, entered the property, checked out. This is inferred from what the guest writes; nobody enters it by hand.
What we do NOT keep, even though it passes through
- Voice notes. A voice note is transcribed so the assistant can answer it, and the transcript is used for that reply and then discarded. The message record says only "[Audio Message]". The audio itself stays on WhatsApp's servers; we never copy it.
- Photos. A photo sent by a guest stays on WhatsApp's servers. We send the link to an AI service to describe what is in it, and we keep the link and the description — not the image.
- A guest's IP address or device. Guests reach us through WhatsApp, so we never see either.
Collected automatically, from this website only
- IP address, browser and device information, and timestamps — for visitors to this website and hosts signed in to the dashboard. Used for security, rate-limiting and abuse detection.
- Product analytics events. See the Cookie & Tracking Notice for exactly what is and is not recorded.
The record the host keeps about the guest
This one is easy to miss, so it gets its own section.
When a host prepares for a guest, they create a record about that guest in their dashboard: the guest's name, phone number, booking reference, and the dates of the stay. There is also a notes field on that record, for the host's own remarks. The guest never sees any of it.
Separately, the system keeps a timeline of where the guest is in their stay — arrived, in the property, checked out — worked out from the guest's own messages. Today nothing in the product displays that timeline; it is used to decide what the assistant should say next and when a message may be sent. It is still a record about a person, so it is described here.
The host, not Sifrhost, decides what goes in that record and whether it is fair or accurate. A guest can ask what is held about them, and ask for it to be corrected or deleted, at contact@sifrhost.com.
Why we process it
To run host accounts, to let the assistant answer a guest from the host's own details, to pass a guest's request to a local business and translate it, to bill hosts, to stop abuse, and to comply with the law.
- To perform a contract — running the dashboard and the assistant for a host, and passing on requests the guest asked us to pass on.
- Legitimate interests — keeping the service secure, detecting abuse, fixing faults, and understanding how the product is used. We limit this: analytics obeys your browser's "Do Not Track" setting, and session recordings mask all text before it leaves your browser.
- Legal obligation — invoices, tax records, and responding to lawful requests.
We do not ask for cookie consent, and this policy does not claim consent as a basis for analytics. Nothing is set before you act, no advertising or cross-site tracking is used, and the controls described in the Cookie & Tracking Notice apply automatically.
AI, and what is sent to AI companies
The assistant is built on AI models run by other companies. To answer a guest, we send them the guest's message and the context the assistant needs. Concretely, on every turn of a conversation that is: the guest's message text, the recent messages in that conversation, and the host's property details — including the address, the Google Maps link, and the Wi-Fi network name and password.
AI is also used to transcribe voice notes, to describe photos, to translate between languages, to work out what a guest is asking for, and to detect abusive messages.
We do not use conversations to train any model of our own — we do not have one. What each AI company does with the text we send them is governed by their own terms, which we do not control and therefore do not restate here. The companies are named in the next section so you can read those terms yourself.
The assistant tells a guest it is an assistant before it answers, in the guest's own language. It answers from the host's saved details, and it can still get things wrong. Do not rely on it for anything medical, legal, financial or urgent.
WhatsApp is not ours
WhatsApp is run by Meta, and Meta decides what happens to your messages on their side. We are a separate company from Meta and we cannot reach into their systems.
That has one consequence worth stating plainly: when we delete a conversation, we delete our copy. The guest's own copy stays in WhatsApp on their phone, and whatever Meta holds on its servers stays there under Meta's policies, not ours.
The same is true of voice notes and photos a guest sends. They live on Meta's servers. We hold a link, not the file. If you want your copy dealt with, that is a request to Meta — see WhatsApp's own privacy policy and in-app settings.
Companies that handle data for us
This is the whole list. Each one is here because the product cannot run without it.
- Neon — the database. Everything persistent is here: accounts, properties, conversations, billing.
- Vercel — hosting for this website and the dashboard.
- Meta Platforms (WhatsApp Cloud API) — carries every message to and from guests. See the section above.
- OpenAI — the main assistant model, voice transcription, photo description, translation, and the search that matches a guest's question to a host's saved answer.
- Anthropic — used for abuse detection and for working out what a guest is asking for.
- Inngest — runs work in the background, such as sending a scheduled message or handing a question to a host. This is worth naming precisely: it is not just a scheduler. Message text, phone numbers, guest names, locations and a host's replies all pass through it.
- Upstash — short-lived cache and rate-limiting. Guest phone numbers and visitor IP addresses appear here as keys, for minutes at a time.
- Cloudinary — stores photos and files that a host uploads. Guest photos are not here; they stay with Meta.
- Resend — sends email to hosts: verification, password reset, invoices, notifications.
- PostHog — product analytics and error reports for this website and the dashboard, never for guest conversations.
One more service, which receives no personal data
The assistant can convert currencies for a guest. To do that our server asks exchangerate-api.com for the day's rates. It is a request for a rate table: no guest, host or message data is sent, and the request comes from our server, not from anyone's browser or phone. It is listed here for completeness, not because it processes personal data.
Where the data goes
Most of the companies above are based in the United States and store data there or in the European Union. Sifrhost is operated from Morocco. So personal data does leave Morocco, and for a guest in the EU it may leave the EU.
The legal instrument that should cover those transfers — a CNDP authorisation on the Moroccan side, and the corresponding contractual clauses on the European side — is being put in place. Until it is recorded here, this policy does not claim it exists. See the next section.
How long we keep things
These are the periods the system actually enforces. A nightly job applies them.
Guest data
- A conversation and its messages: deleted 30 days after the last message. Deleting the conversation deletes its messages, abuse warnings and captured request details with it.
- There is a second, shorter rule: if a guest writes again after more than 24 hours of silence, the previous conversation is deleted first and a new one starts. So a returning guest's older conversation usually goes sooner than 30 days.
- A question the assistant could not answer, which becomes a task for the host: 90 days. A conversation holding one of these is kept until the question goes.
- The host's record about the guest — name, phone, booking reference, dates, notes: 90 days after check-out.
- A block a host placed on a guest: expires after 30 days by itself, and the record of it is removed 90 days after that.
Technical records about guest conversations
- Records of which AI model answered, and clipped extracts of what was sent: 30 days.
- Questions asked of the local-knowledge search, and photo-recognition records including the photo link: 90 days.
- Translation cache: 180 days from the last time that phrase was needed. See the warning below.
Host data
- Your account and your properties: kept while the account is open. Email contact@sifrhost.com to close it and have it erased.
- Half-finished forms saved automatically as you type: deleted 7 days after you last touch them.
- Notifications: 30 days once read, 180 days if never read.
- Token usage records: 365 days.
- Sign-in tokens and password-reset links: deleted shortly after they expire.
Records we keep on purpose
- Invoices and payment records. Tax law requires these and a privacy right does not override that.
- The audit trail of sensitive actions — who approved a payment, who erased whose data — for two years. Deleting it would defeat its purpose.
- Technical logs: 30 days for incoming message logs, 90 days for system logs.
The translation cache, and why erasure cannot reach it
This is a real limit on erasure and we would rather write it down than let you discover it.
When a message is translated, we save the result so the same sentence never has to be paid for twice. That saved entry is filed under a fingerprint of the text itself — not under anyone's name, number, or account. It has no link to a person by design, and it is shared across all hosts.
The consequence: if you ask us to erase your data, we can find and delete everything filed under you, but we cannot find your sentences in that cache, because nothing there says they were yours. Nobody can look up what you said either — the only way to get an entry out is to already know the exact sentence.
An entry is deleted 180 days after the last time it was needed. A phrase that keeps being used keeps being refreshed, so a common sentence — "what is the wifi password" — may stay indefinitely. A sentence particular to you falls out.
Your rights, and how to use them
You can ask for a copy of your data, ask us to correct it, ask us to delete it, object to some processing, or ask us to restrict it.
A host can change most of it directly: properties, services, FAQs and photos are all editable in the dashboard.
For anything else — a copy, a correction, deletion, or closing an account — email contact@sifrhost.com. There is no self-service delete button. A request goes to an administrator, who looks up everything held for that phone number or email and erases it. We check who you are before we act, and we reply within the period the law allows.
What erasure does not reach
- The translation cache, for the reason above.
- Your own WhatsApp messages, which are yours and Meta's, not ours.
- Invoices and the audit trail, which we are required to keep. We remove what identifies you where we can and keep the record itself.
If a host blocks you
A host can stop the assistant replying to a particular guest. It is a decision a person makes; nothing blocks anyone automatically.
A block only covers that host's properties, and it lifts by itself after 30 days. If you think it was wrong, email contact@sifrhost.com and a person will look at it.
Separately, if a conversation is flagged as abusive the assistant may stop replying and alert the host. That also does not block anyone; it pauses the conversation.
Morocco — Law 09-08 and the CNDP
Moroccan Law No. 09-08 on the protection of individuals with regard to the processing of personal data applies to this service. Under it, processing must be declared to the Commission Nationale de contrôle de la protection des Données à caractère Personnel (CNDP), and transferring personal data outside Morocco needs the CNDP's authorisation.
A declaration of this processing has been filed with the CNDP under Law 09-08, together with a separate request for authorisation to transfer personal data outside Morocco. Neither has been decided yet: the CNDP has not issued a declaration number, and the transfer authorisation has not been granted. Both references will be published here as soon as the CNDP issues them.
People in Morocco can exercise the rights above by emailing contact@sifrhost.com, and can also complain to the CNDP directly.
Guests in the EU
If you are in the EU, the GDPR gives you the rights described above, and you can complain to the data protection authority in your own country.
We have not appointed a representative in the EU under Article 27 GDPR. Write to contact@sifrhost.com; that address reaches the person responsible, not a queue.
The instrument covering transfers out of the EU is the open item described in the section above.
Security
Traffic is encrypted in transit. Passwords are hashed and never stored in a readable form. Access to the dashboard is restricted to the account that owns the data, and administrator actions are recorded.
Half-finished forms are encrypted before they are written to the database. That matters because the guest-link form holds a real guest's name and phone number while the host is still typing.
Beyond that, data in the database is protected by the hosting provider's own encryption and access controls, not by a second layer of our own. No system is perfectly secure. If something goes wrong and the law requires us to tell you, we will.
Age
You must be at least 18 to open a host account. We do not verify age — we do not ask for identity documents — so this is a condition of using the service, not a check we perform.
The assistant serves the guests of a host's accommodation and is not aimed at children. If you believe a child's data has reached us, email contact@sifrhost.com and we will remove it.
Changes
We may update this policy. If a change is significant we will tell hosts through the dashboard or by email. The version and effective date of what you are reading are shown at the top of this page.
Contact
Email contact@sifrhost.com — for support, privacy questions, a copy of your data, erasure, or to appeal a block.
We have not appointed a Data Protection Officer. Sifrhost is run by one person and that address reaches them.
ANASS RAHMOUNI, Avenue Sidi Ahmed Louafi, Qu Sebbanine, Chefchaouen 91000, Morocco.
Questions about these documents?
These are drafts pending legal review. For anything time-sensitive, reach the team directly.
Contact us