StayPilot blog

Who sees your guest messages when an AI answers them?

September 23, 2026 · hosting · trust

Three parties, and the list is short on purpose: you and the people you've given a role in your account; the AI model's API, for the seconds it takes to draft a reply; and nobody else. Guest messages are not training material, not shared between customers, and not sold or passed to a data broker. That is the answer in one breath. The rest of this post walks the path a message actually takes, names who can read it at each step, and — because "trust us" is not an answer — points at where each claim is written down.

The path a message takes

A guest writes to you through the booking platform, the same as always. StayPilot reads the message, pulls the relevant details from your listing knowledge — the wifi name, the checkout time, the parking rule — and drafts a reply. The drafting itself happens through Anthropic's API: the message and the listing context go out, a draft comes back, and that is the whole excursion. Anthropic does not train models on API traffic, and StayPilot does not train models on your data either. Your guest's "is the pool heated?" improves no one's model. It gets answered, logged in your account, and that's it.

Who can read it inside your account

Access is scoped by role, and the scopes are narrow. You see everything. A cleaner you've added sees their turnovers, not your guest conversations. A vendor sees the job they were assigned. And the boundary between customers is structural, not policy: every account's data is isolated at the database layer, so another host on StayPilot cannot see your messages any more than they could see your inbox. There is no shared pool of conversations, no "anonymized insights" product built on your guests' words.

What gets logged — and why that's for you, not us

Every AI reply is written to a log you can read in your dashboard: the confidence score it gave itself, the policy that decided whether it was sent, drafted, or escalated, and what happened next. The decision and its record are written together, so the audit trail cannot quietly diverge from what actually happened. This matters for the trust question in both directions — nothing happens behind your back, and when a guest asks "who told you that?", you can point at the exact reply and the exact source. New accounts start in draft mode, so early on, every one of those logged replies is one you personally pressed send on.

What happens to the messages if you leave

They leave with you. Your listing knowledge, message history, and house rules were yours before StayPilot and stay yours after: ask, and you get everything you put in, in standard formats, and we delete our copy on request. A vendor that makes leaving expensive is telling you something about how it thinks about your data while you're still there.

Don't take the blog post's word for it

Everything above is written down where it is inconvenient to walk back. The trust page answers the ten governance questions a buyer should put to any AI vendor — data ownership, logging, the off switch, who's accountable — and the legal agreements are public, in full, before you sign anything. If you're evaluating any AI tool that talks to your guests, ours included, read those two pages first and walk away from any vendor that won't show you theirs. Guests trust you with arrival times, phone numbers, and the occasional overshared reason for the trip; whether or not they ever notice an AI is involved, that trust is yours to protect.

The quickest way to see the boundary working is to stand inside it: paste your listing into the demo and watch the replies draw only on what you gave it. What you put in is all it knows — which is exactly the point.

See what StayPilot would say to your guests.

Paste your listing, get answers from its real details. Free 7-day preview, no card.