Legal

Leto Privacy Notice

Last updated: 8 April 2026

1. Who we are

Leto is an AI guest messaging service provided by LetGrow (“we”, “us”, “our”). We are the data controller for the personal data processed through the Leto service.

Contact: hello@letgrow.co.uk

2. What data we collect

From hosts (our customers)

  • Name, email address, phone number
  • Property details (name, address, amenities, house rules)
  • Account credentials (password hash, authentication tokens)
  • Alert preferences (email, WhatsApp number)
  • Payment information (processed by Stripe, not stored by us)

From guests (via Airbnb/Booking.com messaging)

  • Guest name and email address (as provided by the booking platform)
  • Message content (text of guest messages and responses)
  • Booking details (check-in/out dates, number of guests, booking source)

Data we generate

  • AI-generated responses and confidence scores
  • Complaint detection classifications and severity ratings
  • Question pattern analytics (aggregated, non-personal)
  • Text embeddings (numerical representations of knowledge base entries for semantic search)

3. How we use your data

PurposeLawful basis
Responding to guest messages on behalf of the hostContract performance (Art 6(1)(b))
Detecting and classifying complaintsContract performance
Sending escalation alerts to hostsContract performance
Building property knowledge base for accurate responsesContract performance
Analysing question patterns and generating insightsLegitimate interest (Art 6(1)(f))
Suggesting guidebook updates based on recurring questionsLegitimate interest
Offering upsells to guests (late checkout, etc.)Soft opt-in (PECR) — existing customer, similar services
Guest vetting and risk scoring (advisory only)Legitimate interest with safeguards

4. AI processing

Leto uses artificial intelligence to process guest messages and generate responses. Specifically:

  • Claude (by Anthropic) — analyses messages, detects complaints, and generates responses using the host’s property knowledge base
  • OpenAI — generates text embeddings (numerical representations) for semantic search of the knowledge base. Message content is not stored by OpenAI.

AI transparency: Leto responds on behalf of the host using their name and tone of voice. While we do not actively state that responses are AI-generated in each message, we disclose in this notice that AI assists in the messaging process. Hosts can configure Leto to identify itself as an assistant if they prefer.

No automated decisions with legal effects: Where Leto provides guest vetting or risk scoring, this is advisory only. The host always makes the final decision on whether to accept or decline a booking. Guests have the right to request human review of any automated assessment under Article 22 of UK GDPR.

5. Third-party processors

ProcessorPurposeLocation
Beds24Channel manager — reads and sends messages via Airbnb/Booking.com APIsEU
Anthropic (Claude)AI message generation and complaint detectionUS (adequate safeguards)
OpenAIText embedding generation for semantic searchUS (adequate safeguards)
SupabaseDatabase hosting and file storageEU (eu-west-2)
VercelApplication hostingUS/EU (adequate safeguards)
BrevoEmail delivery for host alertsEU
StripePayment processing for subscriptionsUS/EU (PCI DSS compliant)

6. Data retention

Data typeRetention periodReason
Guest messagesDuration of stay + 60 daysAirbnb dispute resolution window
Escalation recordsDuration of stay + 90 daysComplaint resolution and audit trail
Question pattern analytics12 months (anonymised)Service improvement
Host account dataDuration of subscription + 30 daysService provision
Financial/billing records6 yearsHMRC requirements
Property knowledge baseDuration of subscriptionService provision

When retention periods expire, data is permanently deleted or anonymised.

7. Your rights (hosts)

Under UK GDPR, you have the right to:

  • Access — request a copy of your personal data
  • Rectification — correct inaccurate data
  • Erasure — request deletion of your data
  • Portability — receive your data in a portable format
  • Object — object to processing based on legitimate interest
  • Restrict processing — request we limit how we use your data

To exercise any of these rights, email hello@letgrow.co.uk. We will respond within 30 days.

8. Guest rights

Guests whose messages are processed by Leto have the same rights as listed above. Guests can contact us at hello@letgrow.co.uk to exercise their rights.

If guest vetting/risk scoring is enabled, guests have the right to request human review of any automated assessment and to contest the decision.

9. Data security

  • All data is encrypted in transit (TLS/HTTPS) and at rest
  • Authentication tokens are cryptographically generated and time-limited
  • Passwords are hashed using scrypt with random salts
  • Access is restricted by role-based authentication
  • Each host can only access their own properties and data
  • Guest message data is never used to train AI models

10. Cookies and tracking

The Leto dashboard uses essential cookies only (authentication tokens stored in localStorage). We do not use advertising or tracking cookies within the Leto dashboard. The LetGrow marketing website uses Google Analytics — see our main privacy policy for details.

11. Changes to this notice

We may update this privacy notice from time to time. Material changes will be communicated to hosts via email. The “last updated” date at the top of this page will always reflect the most recent version.

12. Complaints

If you are unhappy with how we handle your data, you can contact us at hello@letgrow.co.uk. You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO) at ico.org.uk.