Legal

Privacy Policy

Last updated 28 September 2026.

Hosto answers messages on behalf of local businesses. To do that it has to read the messages customers send and pass them to an AI provider. This page says exactly what that means.

Who we are

Hosto is operated by the owner of hosto.online, contactable at npaulp@proton.me. A business that connects its account is our customer; the people who message that business are the ones whose data we handle on the business's behalf.

What we collect

  • Messages you send to a connected business. The text of the message, the time it was sent, and the account-scoped identifier Instagram or Facebook gives us for the sender. We do not receive your email address, your phone number, or your password.
  • Replies the assistant sends back, kept with the conversation so the business can see what was said in its name.
  • Business information the client enters — prices, hours, location, policies — which is what the assistant answers from.
  • An access token per connected account, issued by Meta, stored encrypted, and used only to receive and send that account's messages.

Where messages go

To generate a reply, the text of your message and recent messages in the same thread are sent to an AI provider — Google (Gemini) or OpenAI, depending on the business's configuration — along with the business's own information. Those providers process the request and return an answer. We do not sell data, and we do not use conversations to train any model of our own.

Some businesses connect their own system so the assistant can look something up for you — the status of an order, for example. When you ask for that, the details you give for the lookup (such as an order number and the mobile number on it) are sent to that business's system, and what it answers is used in the reply. The business decides what its system will tell you, and it only answers when the details match its own records.

Speaking instead of typing

Some businesses turn on a microphone button in their web chatbox. If you use it, your browser — not us — turns what you say into text, and most browsers do that by sending the audio to their maker (Google for Chrome, Apple for Safari) under that company's own privacy policy. We never receive the recording and we never store it. What reaches us is the transcribed text, treated exactly like a message you typed. Replies are read aloud by a voice already installed on your device. The microphone opens only when you tap it and closes again after one message, and typing instead avoids all of it.

How long we keep it

Conversations are kept while the business's account is active, because the thread is the business's record of what was promised to a customer. Delete a conversation and its messages go with it. If a business disconnects its account, we disable it and destroy the stored token immediately.

Sandbox chats on this website are different: they live in server memory for the session only, are never written to the database, and disappear when the process restarts.

Your choices

You can ask us to delete everything we hold about you — see how to request deletion below, or email npaulp@proton.me. Removing the app from your Instagram or Facebook settings also tells us to disconnect, which we act on automatically.

Security

Traffic is served over HTTPS. Access tokens are encrypted at rest. Requests from Meta are cryptographically verified before we act on them, so a message claiming to come from Instagram cannot reach the assistant unless Instagram signed it.

Changes

If this policy changes materially we will update the date at the top. This is a prototype service and its scope may change as it develops.