Legal
Airlyn Privacy Policy
Version 1.0 · Effective August 28, 2026
Airlyn Privacy Policy
How Airlyn handles information about visitors, customers, and people represented in customer content
Company: AIRLYN.AI LLC, an Ohio limited liability company
Version: 1.0
Effective date: August 28, 2026
Contact: [email protected]
Mail: P.O. Box 142, Hamersville, Ohio 45130, United States
Plain-language summary: Airlyn uses account, property, calendar, media, guidebook, billing, security, and website-analytics information to provide an AI marketing and guest-guidebook service. Hosts control what they upload and publish. Published guidebooks are public to anyone with the link or QR code.
1. Scope
This Privacy Policy explains how AIRLYN.AI LLC, an Ohio limited liability company doing business as Airlyn (“Airlyn,” “we,” “us,” or “our”), collects, uses, discloses, retains, and protects personal information through https://www.airlyn.ai/, the Airlyn application, public guest guidebooks, waitlist and support channels, APIs, Model Context Protocol connections, OAuth and connected applications, and related services (collectively, the “Service”).
It applies to marketing-site and waitlist visitors; customers, organization members, and authorized API or connected-app users; public-guidebook visitors; and people whose information a customer places in calendar feeds, reviews, uploads, reports, prompts, media, or guidebooks even if those people never create an Airlyn account.
This Policy does not govern a customer’s independent privacy practices, a third-party website reached through a link, or a connected application after it receives data under the access the customer authorized.
2. Airlyn’s role
Airlyn generally determines why and how it processes account, authentication, website-analytics, waitlist, billing, security, support, and business-administration information. For that information, Airlyn acts as a controller or business under applicable privacy law.
When a host uploads or connects information about guests, reviewers, property owners, contractors, employees, or other people so Airlyn can provide requested features, Airlyn generally processes that information on the host’s instructions as a service provider or processor. The host is responsible for providing required notices, establishing a lawful basis, respecting individual rights, and having permission to submit the information.
3. Information we collect
3.1 Account and organization information
We collect email address, internal user and organization identifiers, Stytch member and organization identifiers, Google sign-in identity, account status and type, account creation time, organization membership, administrative status, listing limits, feature permissions, session version, password-reset timestamps, and records of policy acceptance. The current Airlyn user record does not require a profile name, phone number, or profile photograph.
3.2 Billing and usage information
We collect Stripe customer, checkout, subscription, invoice, payment, charge, price, refund, dispute, and event identifiers; purchase type and status; amount and currency; subscription quantity; billing-operation metadata; AI allowance, token and cost information; extra-credit balances when offered; and storage usage. Stripe receives billing contact email and Airlyn account or organization identifiers. Airlyn does not receive or store full payment-card numbers, card-verification codes, or raw bank credentials entered in Stripe Checkout or the Stripe Customer Portal.
3.3 Listing, property, and business information
We collect listing and property names, full address, titles, descriptions, summaries, property and room type, check-in and checkout times, prices, fees, minimum stay, occupancy capacity, bedrooms, beds, bathrooms, amenities, house rules, quiet hours, booking-window and average-daily-rate information, marketing settings, listing health information, social and marketing URLs, and Airbnb, Vrbo, Booking.com, Expedia, self-booking, iCal, and similar URLs.
3.4 Calendar and potential guest information
When a customer supplies an iCal or similar feed URL, Airlyn may collect event UID, recurrence information, start and end dates, all-day status, summary, description, status, sequence, derived booking timestamps, reservation or block classification, availability, occupancy metrics, and content hashes. A feed’s summary or description may contain guest names, reservation-platform identifiers, owner names, maintenance information, or other personal information even though Airlyn does not maintain a dedicated guest-name field.
Calendar-feed URLs can operate like bearer credentials. We store the URL supplied by the customer and periodically retrieve the feed from its host. Airbnb, Vrbo, Hospitable, or another calendar host is a source selected by the customer; it is not necessarily an Airlyn service provider.
3.5 Uploads, media, reports, and prompts
We collect images, videos, documents, PDFs, CSV files, screenshots, review exports, advertising reports, occupancy or performance reports, filenames, file type and size, storage location, upload time, captions, descriptions, quality assessments, tags, prompt history, editing instructions, and generated or edited derivatives.
Customers may place faces, license plates, home interiors, addresses, guest communications, reviews, names, contact information, access details, or other personal or confidential information in these materials. Customers should minimize personal information and avoid regulated or sensitive data that is not necessary for the requested feature.
3.6 Marketing, AI, and generated information
We collect and create marketing profiles, ideal-guest profiles, audiences and interests, strategies, fill dates, events, attractions, experiences, titles, descriptions, image analysis, social and advertising drafts, email drafts, recommendations, prompts, outputs, provider and model information, token counts, cost estimates, pricing status, raw usage metadata, and error information. Generated output may be stored both in the applicable feature record and in AI usage logs.
3.7 Guidebook information
We collect guidebook title, language, publication status, public token, QR code, header image, welcome content, Wi-Fi information, check-in and checkout instructions, house rules, booking instructions, contact name, phone number, email, SMS preference, custom sections, attached media, and information about restaurants, shopping, attractions, events, experiences, hospitals, urgent care, pharmacies, police, and fire services.
Guidebook contact fields are entered separately by the host and are not automatically copied from the Airlyn account record.
3.8 Technical, authentication, and security information
We collect session and authentication information, IP address, truncated user-agent string, route, authentication event, timestamp, local user ID where known, partially redacted email, request and correlation identifiers, API-key metadata and scopes, API-key usage time, OAuth client and consent information, MCP member identifiers, rate-limit identifiers, task and queue metadata, error messages, stack traces, infrastructure health data, and related audit information.
DigitalOcean and other infrastructure providers may also record request time, path, response information, IP address, user agent, task identifiers, errors, provider identifiers, and public-guidebook tokens embedded in URLs, depending on production logging settings.
3.9 Waitlist, support, and communications
We collect an email address and timestamp when a person joins the waitlist. If a person contacts support, we collect the message, contact information, attachments, account context, and the records needed to investigate and respond. Postmark may process staff operational alerts; Stytch currently handles authentication-related email such as password recovery.
3.10 Website and guidebook visitor information
The public landing page uses Google Analytics 4, currently associated with measurement ID G-NQMTN4DQ0Q, to collect page URL and title, referrer, browser and device information, session or visit identifiers, cookie information, interaction and measurement events, and IP-derived approximate location as configured. Google Analytics is not currently loaded by the public-guidebook template.
Airlyn does not currently maintain a dedicated guidebook visitor profile, click history, advertising identifier, or guest-engagement database. Ordinary application and infrastructure logs may nevertheless record a guidebook visitor’s IP address, user agent, request path, token URL, and time.
4. Sources of information
We receive information directly from customers and visitors; automatically from browsers, devices, cookies, sessions, logs, and use of the Service; from Stytch and Google sign-in; from Stripe; from customer-selected calendar, listing, public-web, and connected-app sources; from authorized API and MCP clients; from public websites and search results; from AI providers; and from administrators or support interactions.
5. How we use information
We use information to authenticate users and manage organizations; provide listings, calendars, uploads, AI generation, marketing planning, guidebooks, APIs, connected applications, downloads, and storage; bill subscriptions and credits; measure allowances and costs; publish content at a host’s direction; send authentication, support, and operational communications; administer the waitlist; provide customer support; prevent fraud, abuse, and unauthorized access; rate-limit and secure the Service; diagnose errors; reconcile billing and durable operations; maintain infrastructure; analyze the public landing page; comply with law; enforce agreements; and protect Airlyn, customers, guests, and others.
Airlyn may create aggregated or deidentified statistics that do not reasonably identify a person and use them for operations, capacity planning, security, product improvement, and business analysis. Airlyn will not attempt to reidentify information it has deidentified except to test whether deidentification measures work or as permitted by law.
6. When and with whom we disclose information
We disclose information only as reasonably necessary for the purposes described in this Policy, at a customer’s direction, in a business transfer, or as required or permitted by law.
Authentication and identity providers. Stytch processes sign-in, sessions, authentication email, OAuth consent, and connected applications. Google processes Google sign-in identity.
Payment providers. Stripe processes payment methods, Checkout, subscriptions, invoices, refunds, disputes, fraud screening, receipts, and the Customer Portal.
AI and search providers. OpenAI and Google Gemini process prompts, listing context, media, files, generated output, and related technical data for requested AI features. Gemini grounding may provide generated search queries and context to Google Search.
Hosting and infrastructure. DigitalOcean provides App Platform, managed PostgreSQL, Redis or Valkey, and Spaces storage. Airlyn’s resources are currently configured in the nyc3 region, subject to production verification. Browser-loaded content-delivery providers, including the Bootstrap CDN when used, may receive ordinary request information such as IP address, user agent, referrer, and requested asset.
Analytics. Google Analytics processes landing-page visit and device information as configured.
Communications. Postmark may process staff operational alerts and related delivery information. Other communications may be handled by Stytch or the recipient’s email provider.
Customer-authorized recipients. API clients, MCP clients, OAuth connected applications, organization members, guidebook visitors, and people to whom a customer sends a download, public link, or output receive information within the access or publication the customer authorizes.
Professional, legal, and safety recipients. We may disclose information to contractors, auditors, insurers, accountants, lawyers, security investigators, law enforcement, regulators, courts, or affected parties when reasonably necessary to operate the business, protect rights or safety, investigate wrongdoing, respond to lawful process, or comply with law.
Business transfers. Information may be disclosed or transferred in connection with financing, due diligence, merger, reorganization, sale, acquisition, bankruptcy, or transfer of assets, subject to applicable privacy obligations.
7. Artificial-intelligence processing
Airlyn may send property addresses and descriptions, media, calendar-derived context, reviews, reports, prompts, guidebook information, marketing profiles, and existing outputs to OpenAI or Google Gemini to provide requested features. Airlyn does not operate a separate general-purpose model-training pipeline using Customer Content. Additional user responsibilities and AI limitations appear in the Airlyn AI Usage & Disclosure Policy.
Airlyn uses provider API or business services and account settings intended for commercial use. Provider-side use, retention, and deletion depend on the service, feature, contract, safety requirements, and account configuration. OpenAI states that API data is not used to train or improve its models unless the API customer opts in, and that limited retention may apply for abuse monitoring or application state.
Google states that prompts, files, and responses submitted through eligible paid Gemini API services are not used to improve its products, although limited logging or retention may apply for safety, legal, grounding, debugging, or service purposes. Airlyn does not intend to use unpaid AI services for confidential Customer Content. Provider terms and Airlyn’s account configuration control the provider-side treatment.
Provider terms, models, tools, configurations, and retention practices can change. Airlyn’s provider accounts and settings, rather than this Policy alone, determine the exact provider-side controls. Customers should not submit information that is unnecessary for the feature or that they are not authorized to provide.
8. Public guidebooks and other public content
A guidebook starts unpublished unless the Service states otherwise. When a host publishes it, anyone who has or obtains its opaque token URL or QR code can view it without logging in. Public information may include property context, Wi-Fi details, check-in and checkout instructions, house rules, contact information, media, links, and recommendations.
Public token URLs can appear in browser history, messages, copied links, infrastructure logs, screenshots, caches, printed copies, or downloads. Search and AI crawler instructions are voluntary and are not access controls. Revoking or deleting a guidebook stops future access through Airlyn as designed but cannot erase copies already made by other people or systems.
Private customer media is intended to use private storage with time-limited signed access. Media intentionally included in an active public guidebook is made available through the guidebook’s public sharing mechanism. A person possessing a valid signed URL may access the object until the URL expires.
9. Cookies, session storage, and analytics
Airlyn uses essential technologies for Flask sessions, remember-me functions, CSRF and OAuth state, Stytch session JWTs, security, authentication, rate limiting, and user-requested functionality. The application may use sessionStorage to remember temporary interface state, such as whether an image-quality panel should remain expanded during navigation.
The public landing page uses Google Analytics cookies or similar identifiers for statistical measurement, and those technologies may activate when the landing page loads. Public guidebooks do not currently load Google Analytics. Visitors can limit analytics through browser privacy controls, cookie blocking, or Google’s available opt-out tools. Airlyn may disable analytics or add consent and preference controls as required for particular regions or as the Service changes.
10. Sale, sharing, advertising, and browser signals
Airlyn does not sell personal information for monetary consideration and does not operate a data-broker or cross-context behavioral advertising business. Airlyn uses Google Analytics for measurement, and some privacy laws may define certain analytics disclosures as “sharing” even when no money changes hands. Where required, Airlyn will provide an applicable opt-out or consent choice.
Because there is no universally accepted technical standard for legacy Do Not Track signals, Airlyn does not currently respond to them automatically. Airlyn does not currently represent that it automatically recognizes Global Privacy Control. A person may contact [email protected] to exercise an applicable opt-out right, and Airlyn will implement browser-signal recognition if and when applicable law requires it for Airlyn’s operations.
11. Retention and deletion
We retain account, organization, listing, calendar, media, guidebook, generated, and support information while needed to provide the Service and for a reasonable period afterward for account closure, security, billing, disputes, legal obligations, and deletion processing.
Hosts can permanently delete a listing. Listing deletion removes its active database graph and public guidebook availability and schedules related storage and billing operations. Storage deletion can be asynchronous. Certain payment, authentication, administrative, error, API, security, and audit records may remain after a listing or account identifier is removed or detached.
Account deletion is currently support-mediated and may require deletion of all listings first. The local process does not necessarily delete records held independently by Stripe, Stytch, OpenAI, Google, Postmark, infrastructure backups, public recipients, API or MCP clients, or other third parties. We will request or perform provider-side deletion where required, technically available, and consistent with legal, security, payment, and recordkeeping obligations.
Waitlist information is retained until it is no longer reasonably needed for access invitations and related communications or until a valid deletion request is completed, subject to legal or security needs. Backup, log, and provider copies expire according to applicable operational schedules and provider terms.
When fixed retention periods are not stated, we consider the account relationship, purpose, sensitivity, legal requirements, security and dispute needs, provider limitations, and whether information can be deidentified.
12. Security
Airlyn uses administrative, technical, and organizational safeguards designed for the nature of the information processed. Measures include encrypted HTTPS transport; Secure, HTTP-only, SameSite cookies in production; organization and listing access checks; private media storage with signed access; hashed API keys; scoped API, OAuth, and MCP permissions; rate limiting; session invalidation; audit logging; provider authentication; and durable deletion operations.
No system is completely secure. Customers must protect credentials, calendar-feed URLs, public-guidebook links, and downloaded or connected-app copies, and must promptly report suspected unauthorized access to [email protected].
13. Your choices and privacy rights
Depending on where you live and subject to exceptions, you may have rights to request access to personal information, correction, deletion, portability, restriction, objection, withdrawal of consent, or information about disclosures. You may also have the right to appeal a denied request or complain to a privacy regulator.
To make a request, email [email protected] with the subject “Privacy Request” or write to the address below. Describe the request, the Airlyn account or guidebook involved, your relationship to the information, and the jurisdiction whose rights you are invoking. Do not send passwords, API keys, calendar URLs, payment-card numbers, door codes, or other secrets.
We may verify identity and authority before acting. If information came from an Airlyn customer and Airlyn processes it on that customer’s instructions, we may direct the request to the customer or assist the customer in responding. Authorized agents may be required to provide proof of authority.
Airlyn does not currently provide a one-click comprehensive privacy export or self-service account-delete button. Customers can view, correct, download, or delete many records within the Service, and Airlyn handles broader requests through support. We will not discriminate unlawfully because a person exercised an applicable privacy right.
14. United States state disclosures
If a United States state privacy law applies to Airlyn and to your information, you may have rights to know categories or specific information; confirm processing; obtain a copy; correct; delete; opt out of sale, targeted advertising, or certain profiling; limit certain sensitive-information uses; and appeal a decision. The categories collected, sources, purposes, recipients, and retention approach are described in this Policy.
Airlyn does not sell personal information for money. If Airlyn becomes legally required to provide a “Do Not Sell or Share My Personal Information” or “Your Privacy Choices” mechanism beyond the controls described here, Airlyn will implement it before engaging in the covered activity.
15. EEA, Switzerland, and United Kingdom information
When European data-protection law applies, Airlyn relies on contractual necessity to create and service an account and paid subscription; legitimate interests to secure, support, improve, and administer the Service; consent for nonessential analytics where required and available; and legal obligation for tax, accounting, fraud, dispute, and regulatory records. Airlyn may limit analytics, registration, or Service availability in a region when required compliance measures are not yet available.
People in these regions may have rights of access, rectification, erasure, restriction, portability, objection, withdrawal of consent, and complaint to a supervisory authority. Withdrawal does not affect processing already lawfully completed.
Airlyn is based in the United States. Information may be processed in the United States and other countries where Airlyn or its providers operate. Where required, Airlyn will use an applicable lawful transfer mechanism and supplemental safeguards. Provider-specific location and residency options may vary by service and account configuration.
AIRLYN.AI LLC is the contact for these requests at [email protected]. Airlyn has not appointed an EU or UK representative. Airlyn may limit active offering of the Service in a jurisdiction until any required representative, Data Processing Addendum, transfer mechanism, or related compliance arrangement is in place.
16. Children
The Service is for business users age 18 or older and is not directed to children. Airlyn does not knowingly create accounts for people under 18. Customer Content may incidentally depict or refer to children; the customer is responsible for having an appropriate right and avoiding unnecessary sensitive information. Contact [email protected] if you believe a child’s personal information was submitted improperly.
17. Third-party services and links
The Service contains links to listing platforms, social networks, local businesses, emergency resources, maps or directions, public sources, and customer-selected sites. Their privacy practices are governed by their policies. Airlyn is not responsible for a third party’s independent collection after you visit, authorize, or send information to it.
18. Changes to this Policy
We may update this Policy as the Service, providers, laws, or practices change. We will post the updated version and effective date. For material changes affecting account users, we will provide at least 15 days’ advance notice by email, in-product notice, or another reasonable method unless a shorter period is necessary for security, legal, provider, or emergency reasons. We may request renewed acknowledgment where appropriate.
19. Contact
AIRLYN.AI LLC
Attn: Privacy
P.O. Box 142
Hamersville, Ohio 45130
United States
[email protected]
https://www.airlyn.ai/