Privacy Policy
Last updated: September 25, 2026 · Effective: June 29, 2026
This Privacy Policy explains how HornostAI (“HornostAI”, “we”, “us”) collects, uses, shares, and protects personal data when you visit hornostai.com or interact with our AI assistant on the messaging channels of the businesses that use our service. We are committed to processing personal data lawfully, fairly, and transparently.
1. Who we are & our role
HornostAI provides an AI agent that helps online businesses communicate with their customers across Instagram, Telegram, WhatsApp, Viber, Facebook Messenger, email and an embeddable web widget, take orders, arrange shipping, and accept payments — all managed from a secure console.
- For visitors to this website, HornostAI acts as the data controller.
- For end-customer conversations handled on behalf of a business that uses our platform, that business is the controller and HornostAI acts as a data processor, processing data under that business’s instructions.
2. Information we collect
2.1 Conversation data
Messages you send and receive on the business’s channels — Instagram Direct, Telegram, WhatsApp, Viber, Facebook Messenger, email or the web widget — including any voice notes or images you share, so that the AI agent can respond and assist you.
2.2 Order & contact data
Name, phone number, delivery city and post office/branch, and order contents needed to fulfil a purchase.
2.3 Payment data
We do not store card details. Payments are processed by third-party payment providers; we receive only the payment status.
2.4 Technical & usage data
Basic server logs (e.g. IP address, browser type, timestamps) used for security, diagnostics, and abuse prevention. Security events — such as sign-ups, too many requests from one address, or attempts to misuse the demo chat — are kept in a security log for 90 days (entries about the demo chat for 30 days). If you use the HornostAI console, we also record the IP address and browser of each sign-in to your account, so you can review them on your account’s security page and spot access you do not recognise; this sign-in history is kept for 90 days and deleted with your account. This website does not use advertising trackers.
2.5 Website analytics
We use Umami, a cookieless analytics service, to see aggregate statistics on how this website is used, such as which pages are visited and which buttons are clicked. It does not identify individual visitors.
2.6 Advertising cookies (only with your consent)
If you click “Allow” in the cookie banner, we load the Meta Pixel, which sets cookies so we can measure our Meta ads and show them to people who may find HornostAI useful. It records which pages you visit and actions such as clicking the sign-up button. Nothing is loaded if you decline or ignore the banner, and you can change your choice at any time via “Cookie settings” at the bottom of the home page.
2.7 Demo chat on this website
If you chat with the demo agent on hornostai.com, we store the messages you send and the answers you receive, so we can see what visitors ask and improve the product. To protect the demo from abuse and attacks, we also store your IP address, browser (user agent) and the page you came from. The IP address, browser and referring page are deleted after 30 days; after that only an anonymised identifier derived from the IP remains. We may block an IP address that is used to attack or misuse the demo. Please do not type sensitive details there — it is a product demo, not a support channel. The conversations themselves are deleted after 180 days.
3. How we use personal data
- to respond to enquiries and hold conversations across messaging channels;
- to create, process, and fulfil orders (shipping and payment);
- to send service messages related to your order;
- to operate, secure, maintain, and improve our service;
- to comply with legal obligations and enforce our terms.
4. Legal bases for processing (GDPR)
Where the GDPR applies, we rely on the following legal bases under Article 6:
- Performance of a contract — to handle your enquiry and complete your order;
- Legitimate interests — to secure and improve the service, understand how the website is used (analytics), and prevent abuse and attacks, including recording and blocking the IP addresses used against the demo chat (balanced against your rights);
- Legal obligation — to meet accounting, tax, and other statutory requirements;
- Consent — for advertising cookies (2.6) and wherever else specifically requested; you may withdraw consent at any time.
5. Sharing & sub-processors
We share personal data only with service providers necessary to operate the service, and only to the extent required:
- Meta Platforms, Inc. (Instagram, WhatsApp, Facebook Messenger), Telegram and Viber — messaging delivery;
- Meta Platforms Ireland Ltd. — advertising measurement via the Meta Pixel, only with your consent (see 2.6);
- Resend — sending and receiving email for the email channel;
- Nova Poshta — creating and tracking shipments;
- Payment providers (e.g. Monobank, LiqPay) — processing online payments;
- Hosting & infrastructure (e.g. Railway, Supabase) — running the service and storing data;
- AI providers (e.g. Anthropic for responses, Groq for voice-note transcription) — generating and understanding messages;
- Umami Software, Inc. — cookieless website analytics (see 2.5).
We may also disclose data where required by law. We do not sell your personal data.
6. Google user data (Google Calendar integration)
A business that uses HornostAI may connect its own Google Calendar so that appointments booked through our assistant appear in the calendar that business already uses. Connecting is optional, is started by the business owner from our console, and is authorised through Google’s own consent screen. This section states exactly how HornostAI handles data obtained through Google APIs.
6.1 What Google user data we access
We request two scopes, and only these two:
- .../auth/calendar.freebusy — busy time ranges (start and end times) on the connected calendar. This returns availability only: no event titles, descriptions, locations, attendees, or any other event content.
- .../auth/calendar.events — used to create an event for a booking made through HornostAI, and to delete that same event if the booking is cancelled.
We do not read the contents of existing calendar events, do not enumerate the user’s other calendars, and do not access any other Google service or Google Account data.
6.2 How we use it
- Busy time ranges are read at the moment a customer asks about availability, and are used to remove already-occupied times from the slots we offer. They are used in memory to compute that answer and are not stored.
- Event creation and deletion keep the owner’s calendar in step with the bookings made through the assistant.
Google user data is never used for advertising, profiling, or credit and lending decisions.
6.3 What we share
We do not sell Google user data and we do not transfer it to any third party. In particular, it is not shared with the AI providers listed in section 5: availability is calculated on our own servers, and the AI model receives only the resulting list of free start times — a list that is also shaped by the business’s working hours and its own bookings — never the calendar data itself.
6.4 How we protect it
- the Google refresh token is encrypted at rest, is never written to logs, and is never returned by our API;
- all traffic to and from Google APIs is over HTTPS;
- data is isolated per business — every query is scoped to a single business account;
- access to production systems is restricted to authorised personnel.
6.5 Retention and deletion
- the refresh token is kept only while the calendar is connected: when the owner disconnects, we revoke the token with Google and delete our copy;
- the identifier of an event we created is stored alongside the corresponding booking so that we can delete that event later, and is removed together with the booking;
- busy time ranges are not retained at all;
- an owner can disconnect at any time in the HornostAI console, and can additionally revoke access at myaccount.google.com/permissions;
- deletion can also be requested at privacy@hornostai.com.
6.6 Limited Use
6.7 AI and machine learning
Google user data is not used to develop, improve, or train any AI or machine-learning model, and is not transferred to any third-party service for that purpose. HornostAI uses third-party AI providers to generate replies in customer conversations; those providers do not train their models on data submitted through their APIs, and as described in 6.3 they do not receive Google user data.
7. International data transfers
Some providers are located outside your country (including the United States). Where personal data is transferred internationally, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses or an adequacy decision, as applicable.
8. Data retention
Demo-chat IP addresses, browser details and referring pages (2.7) are deleted after 30 days, and the conversations after 180 days. Otherwise we retain personal data only for as long as necessary for the purposes described above and to comply with legal obligations, after which it is deleted or anonymised. Retention periods depend on the type of data and the applicable legal requirements.
9. Security
We apply appropriate technical and organisational measures to protect personal data, including encryption in transit (HTTPS), restricted access, and secure storage of secrets. No method of transmission or storage is completely secure, but we work to protect your data on an ongoing basis.
10. Your rights
Subject to applicable law, you may have the right to:
- access the personal data we hold about you;
- rectify inaccurate or incomplete data;
- erase your data (“right to be forgotten”);
- restrict or object to processing;
- data portability — receive your data in a portable format;
- withdraw consent at any time, without affecting prior processing;
- lodge a complaint with your local data protection authority.
If you are a California resident, you may also have rights under the CCPA/CPRA, including the right to know, delete, and opt out of the “sale” or “sharing” of personal information (we do not sell personal information), and the right not to be discriminated against for exercising your rights.
11. Businesses and customers in Canada
This section applies when a business that uses HornostAI is based in Canada, or when you are a customer in Canada talking to such a business. It describes how we work; it is not legal advice to that business.
11.1 Our role under PIPEDA
Under Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA), the business you talk to is responsible for your personal information. HornostAI is a service provider to that business: we process conversation, booking and order data only to provide the service to it, under its instructions, and we protect it as described in this Policy.
- Access and correction. To see or correct the personal information a business holds about you, contact that business. The business can export or delete it in the HornostAI console, and we help it answer your request. You can also write to privacy@hornostai.com, and we will pass your request to the business.
- Complaints. If you are not satisfied with the answer, you can contact the Office of the Privacy Commissioner of Canada.
11.2 Commercial messages (CASL)
Messages the assistant sends to customers are sent on behalf of the business, from the business’s own accounts. Under Canada’s Anti-Spam Legislation (CASL), the business is responsible for having the customer’s consent to receive commercial messages from it, such as promotions and broadcasts.
- Besides replying to a customer’s own messages, the assistant sends reminders about bookings the customer made, and the automated follow-ups the business switches on.
- If a customer asks in the chat to stop receiving messages (for example, “unsubscribe” or “stop messaging me”), the assistant records it and does not start further automated follow-ups to that customer. Replies to messages the customer sends later are not affected.
- Broadcasts are started by the business, which decides who receives them and must not send them to customers who have unsubscribed.
11.3 Where data is processed and who processes it
Personal information of Canadian businesses and their customers is processed outside Canada. Our database (Supabase) and our application servers (Railway) are located in the European Union. Some of the providers below process data in other countries, including the United States. The providers involved are the ones already named in sections 5 and 6:
- Supabase — database and storage (EU);
- Railway — application hosting (EU);
- Anthropic — generating the assistant’s replies;
- Groq — transcribing voice notes;
- Meta Platforms, Inc. (Instagram, WhatsApp, Facebook Messenger) and Telegram — delivering messages on the channels the business connects;
- Resend — the email channel;
- Google — Google Calendar, only if the business connects it (see section 6);
- Umami Software, Inc. — cookieless analytics for this website.
Nova Poshta and the Ukrainian payment providers named in section 5 are not used for businesses based in Canada.
12. Children’s privacy
Our service is not directed to children under 16, and we do not knowingly collect their personal data. If you believe a child has provided us with personal data, please contact us and we will delete it.
13. Cookies
We use only the cookies and browser storage listed below. Advertising cookies are set only after you allow them in the cookie banner.
- hornost_consent (HornostAI, strictly necessary) — remembers your cookie choice across hornostai.com and console.hornostai.com; 180 days.
- Language choice (HornostAI, browser local storage, strictly necessary) — opens the site in the language you picked; until you clear it.
- _fbp, _fbc (Meta, advertising, only with consent) — measure ad performance and attribute visits to Meta ads; up to 90 days.
Website analytics (2.5) uses no cookies. To change your choice, use “Cookie settings” at the bottom of the home page; declining after accepting deletes the Meta cookies.
14. Changes to this Policy
We may update this Policy from time to time. The current version is always available on this page with the “Last updated” date above. Material changes will be highlighted where appropriate.
15. Contact
For any privacy questions or requests, contact us at privacy@hornostai.com or on Instagram @hornost.ai.