Before you let software talk to your guests, you deserve straight answers about your data, the logs, and the off switch. Here are ours, in the open. If another vendor can't answer the first three, walk away.
You do. All of it.
Your listing knowledge, guest conversations, house rules, and message history belong to you, not us. Every tenant's data is isolated at the database layer, so no other customer can ever see yours. If you leave, ask and we hand you everything you put in, in standard formats, and delete our copy on request.
Every decision, in the same breath as the action.
Every AI reply carries its confidence score, the policy that decided its fate, and whether it was sent, drafted, or escalated. The decision and its record are written together, so an action and its audit trail cannot diverge. You can read the full log in your dashboard any time — nothing happens behind your back.
It starts off. You turn it on.
New accounts default to draft-only: the AI writes, you press send. Full autopilot is something you enable, per conversation, after the system has earned it — and you can drop back to draft-only or jump into any conversation instantly. There is no mode where you can't take the wheel.
Export, then delete. No hostage data.
When StayPilot stops being useful to you, you take your knowledge base and message history with you and we delete the rest on request. Your institutional knowledge — the wifi quirks, the vendor list, the guest history — was yours before us and stays yours after.
Your data is never training material.
Replies are generated through Anthropic's API, which does not train models on API traffic. We don't train on your data either. Inside your account, access is scoped by role: owners see their properties, cleaners see their turnovers, vendors see their jobs. Nobody sees more than their job requires.
Anywhere it's your call, you press send.
Refunds, safety issues, legal matters, and money disputes always route to you — that's policy, not configuration. Spending above your threshold waits for your approval. And any message category you reserved for yourself during onboarding, like the personal welcome message, comes to you with a draft ready instead of being sent.
It says so, and holds the message.
Every reply self-reports a confidence score. Below the bar, the message is held as a draft for your review instead of sent — the system would rather ask than guess. Anything that misfires lands in an exception queue with the context and a recommended action, and you can step into the conversation and correct course immediately.
Standard APIs and webhooks. No middleware you don't control.
Channels connect over ordinary webhooks and APIs — SMS via Twilio, channel managers via their webhook APIs, payments via Stripe. There's no proprietary bridge you have to rent, and disconnecting an integration is a settings change, not a support ticket.
A subscription plus metered AI you can watch.
The subscription price is on the pricing page. AI usage runs on a prepaid balance debited at actual measured usage per reply, and you can see every debit. No surprise compute bill, no per-seat games, and walking away costs nothing but the goodbye.
A named human. Jack. The founder.
StayPilot is founder-run, and the founder answers the email. If the system does something wrong in front of your guest, you have a person, not a ticket queue — hello@staypilot.work reaches someone who can actually fix it and who reviews what the AI did that week.