HornostAI
Legal

Privacy Policy

Last updated: September 25, 2026  ·  Effective: June 29, 2026

This Privacy Policy explains how HornostAI (“HornostAI”, “we”, “us”) collects, uses, shares, and protects personal data when you visit hornostai.com or interact with our AI assistant on the messaging channels of the businesses that use our service. We are committed to processing personal data lawfully, fairly, and transparently.

1. Who we are & our role

HornostAI provides an AI agent that helps online businesses communicate with their customers across Instagram, Telegram, WhatsApp, Viber, Facebook Messenger, email and an embeddable web widget, take orders, arrange shipping, and accept payments — all managed from a secure console.

2. Information we collect

2.1 Conversation data

Messages you send and receive on the business’s channels — Instagram Direct, Telegram, WhatsApp, Viber, Facebook Messenger, email or the web widget — including any voice notes or images you share, so that the AI agent can respond and assist you.

2.2 Order & contact data

Name, phone number, delivery city and post office/branch, and order contents needed to fulfil a purchase.

2.3 Payment data

We do not store card details. Payments are processed by third-party payment providers; we receive only the payment status.

2.4 Technical & usage data

Basic server logs (e.g. IP address, browser type, timestamps) used for security, diagnostics, and abuse prevention. Security events — such as sign-ups, too many requests from one address, or attempts to misuse the demo chat — are kept in a security log for 90 days (entries about the demo chat for 30 days). If you use the HornostAI console, we also record the IP address and browser of each sign-in to your account, so you can review them on your account’s security page and spot access you do not recognise; this sign-in history is kept for 90 days and deleted with your account. This website does not use advertising trackers.

2.5 Website analytics

We use Umami, a cookieless analytics service, to see aggregate statistics on how this website is used, such as which pages are visited and which buttons are clicked. It does not identify individual visitors.

2.6 Advertising cookies (only with your consent)

If you click “Allow” in the cookie banner, we load the Meta Pixel, which sets cookies so we can measure our Meta ads and show them to people who may find HornostAI useful. It records which pages you visit and actions such as clicking the sign-up button. Nothing is loaded if you decline or ignore the banner, and you can change your choice at any time via “Cookie settings” at the bottom of the home page.

2.7 Demo chat on this website

If you chat with the demo agent on hornostai.com, we store the messages you send and the answers you receive, so we can see what visitors ask and improve the product. To protect the demo from abuse and attacks, we also store your IP address, browser (user agent) and the page you came from. The IP address, browser and referring page are deleted after 30 days; after that only an anonymised identifier derived from the IP remains. We may block an IP address that is used to attack or misuse the demo. Please do not type sensitive details there — it is a product demo, not a support channel. The conversations themselves are deleted after 180 days.

3. How we use personal data

4. Legal bases for processing (GDPR)

Where the GDPR applies, we rely on the following legal bases under Article 6:

5. Sharing & sub-processors

We share personal data only with service providers necessary to operate the service, and only to the extent required:

We may also disclose data where required by law. We do not sell your personal data.

6. Google user data (Google Calendar integration)

A business that uses HornostAI may connect its own Google Calendar so that appointments booked through our assistant appear in the calendar that business already uses. Connecting is optional, is started by the business owner from our console, and is authorised through Google’s own consent screen. This section states exactly how HornostAI handles data obtained through Google APIs.

6.1 What Google user data we access

We request two scopes, and only these two:

We do not read the contents of existing calendar events, do not enumerate the user’s other calendars, and do not access any other Google service or Google Account data.

6.2 How we use it

Google user data is never used for advertising, profiling, or credit and lending decisions.

6.3 What we share

We do not sell Google user data and we do not transfer it to any third party. In particular, it is not shared with the AI providers listed in section 5: availability is calculated on our own servers, and the AI model receives only the resulting list of free start times — a list that is also shaped by the business’s working hours and its own bookings — never the calendar data itself.

6.4 How we protect it

6.5 Retention and deletion

6.6 Limited Use

HornostAI’s use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

6.7 AI and machine learning

Google user data is not used to develop, improve, or train any AI or machine-learning model, and is not transferred to any third-party service for that purpose. HornostAI uses third-party AI providers to generate replies in customer conversations; those providers do not train their models on data submitted through their APIs, and as described in 6.3 they do not receive Google user data.

7. International data transfers

Some providers are located outside your country (including the United States). Where personal data is transferred internationally, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses or an adequacy decision, as applicable.

8. Data retention

Demo-chat IP addresses, browser details and referring pages (2.7) are deleted after 30 days, and the conversations after 180 days. Otherwise we retain personal data only for as long as necessary for the purposes described above and to comply with legal obligations, after which it is deleted or anonymised. Retention periods depend on the type of data and the applicable legal requirements.

9. Security

We apply appropriate technical and organisational measures to protect personal data, including encryption in transit (HTTPS), restricted access, and secure storage of secrets. No method of transmission or storage is completely secure, but we work to protect your data on an ongoing basis.

10. Your rights

Subject to applicable law, you may have the right to:

If you are a California resident, you may also have rights under the CCPA/CPRA, including the right to know, delete, and opt out of the “sale” or “sharing” of personal information (we do not sell personal information), and the right not to be discriminated against for exercising your rights.

To exercise any of these rights, contact us at privacy@hornostai.com or via Instagram Direct @hornost.ai. We will respond within the time frame required by applicable law.

11. Businesses and customers in Canada

This section applies when a business that uses HornostAI is based in Canada, or when you are a customer in Canada talking to such a business. It describes how we work; it is not legal advice to that business.

11.1 Our role under PIPEDA

Under Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA), the business you talk to is responsible for your personal information. HornostAI is a service provider to that business: we process conversation, booking and order data only to provide the service to it, under its instructions, and we protect it as described in this Policy.

11.2 Commercial messages (CASL)

Messages the assistant sends to customers are sent on behalf of the business, from the business’s own accounts. Under Canada’s Anti-Spam Legislation (CASL), the business is responsible for having the customer’s consent to receive commercial messages from it, such as promotions and broadcasts.

11.3 Where data is processed and who processes it

Personal information of Canadian businesses and their customers is processed outside Canada. Our database (Supabase) and our application servers (Railway) are located in the European Union. Some of the providers below process data in other countries, including the United States. The providers involved are the ones already named in sections 5 and 6:

Nova Poshta and the Ukrainian payment providers named in section 5 are not used for businesses based in Canada.

12. Children’s privacy

Our service is not directed to children under 16, and we do not knowingly collect their personal data. If you believe a child has provided us with personal data, please contact us and we will delete it.

13. Cookies

We use only the cookies and browser storage listed below. Advertising cookies are set only after you allow them in the cookie banner.

Website analytics (2.5) uses no cookies. To change your choice, use “Cookie settings” at the bottom of the home page; declining after accepting deletes the Meta cookies.

14. Changes to this Policy

We may update this Policy from time to time. The current version is always available on this page with the “Last updated” date above. Material changes will be highlighted where appropriate.

15. Contact

For any privacy questions or requests, contact us at privacy@hornostai.com or on Instagram @hornost.ai.