Legal
Leto Privacy Notice
Last updated: 8 April 2026
1. Who we are
Leto is an AI guest messaging service provided by LetGrow (“we”, “us”, “our”). We are the data controller for the personal data processed through the Leto service.
Contact: hello@letgrow.co.uk
2. What data we collect
From hosts (our customers)
- Name, email address, phone number
- Property details (name, address, amenities, house rules)
- Account credentials (password hash, authentication tokens)
- Alert preferences (email, WhatsApp number)
- Payment information (processed by Stripe, not stored by us)
From guests (via Airbnb/Booking.com messaging)
- Guest name and email address (as provided by the booking platform)
- Message content (text of guest messages and responses)
- Booking details (check-in/out dates, number of guests, booking source)
Data we generate
- AI-generated responses and confidence scores
- Complaint detection classifications and severity ratings
- Question pattern analytics (aggregated, non-personal)
- Text embeddings (numerical representations of knowledge base entries for semantic search)
3. How we use your data
| Purpose | Lawful basis |
|---|---|
| Responding to guest messages on behalf of the host | Contract performance (Art 6(1)(b)) |
| Detecting and classifying complaints | Contract performance |
| Sending escalation alerts to hosts | Contract performance |
| Building property knowledge base for accurate responses | Contract performance |
| Analysing question patterns and generating insights | Legitimate interest (Art 6(1)(f)) |
| Suggesting guidebook updates based on recurring questions | Legitimate interest |
| Offering upsells to guests (late checkout, etc.) | Soft opt-in (PECR) — existing customer, similar services |
| Guest vetting and risk scoring (advisory only) | Legitimate interest with safeguards |
4. AI processing
Leto uses artificial intelligence to process guest messages and generate responses. Specifically:
- Claude (by Anthropic) — analyses messages, detects complaints, and generates responses using the host’s property knowledge base
- OpenAI — generates text embeddings (numerical representations) for semantic search of the knowledge base. Message content is not stored by OpenAI.
AI transparency: Leto responds on behalf of the host using their name and tone of voice. While we do not actively state that responses are AI-generated in each message, we disclose in this notice that AI assists in the messaging process. Hosts can configure Leto to identify itself as an assistant if they prefer.
No automated decisions with legal effects: Where Leto provides guest vetting or risk scoring, this is advisory only. The host always makes the final decision on whether to accept or decline a booking. Guests have the right to request human review of any automated assessment under Article 22 of UK GDPR.
5. Third-party processors
| Processor | Purpose | Location |
|---|---|---|
| Beds24 | Channel manager — reads and sends messages via Airbnb/Booking.com APIs | EU |
| Anthropic (Claude) | AI message generation and complaint detection | US (adequate safeguards) |
| OpenAI | Text embedding generation for semantic search | US (adequate safeguards) |
| Supabase | Database hosting and file storage | EU (eu-west-2) |
| Vercel | Application hosting | US/EU (adequate safeguards) |
| Brevo | Email delivery for host alerts | EU |
| Stripe | Payment processing for subscriptions | US/EU (PCI DSS compliant) |
6. Data retention
| Data type | Retention period | Reason |
|---|---|---|
| Guest messages | Duration of stay + 60 days | Airbnb dispute resolution window |
| Escalation records | Duration of stay + 90 days | Complaint resolution and audit trail |
| Question pattern analytics | 12 months (anonymised) | Service improvement |
| Host account data | Duration of subscription + 30 days | Service provision |
| Financial/billing records | 6 years | HMRC requirements |
| Property knowledge base | Duration of subscription | Service provision |
When retention periods expire, data is permanently deleted or anonymised.
7. Your rights (hosts)
Under UK GDPR, you have the right to:
- Access — request a copy of your personal data
- Rectification — correct inaccurate data
- Erasure — request deletion of your data
- Portability — receive your data in a portable format
- Object — object to processing based on legitimate interest
- Restrict processing — request we limit how we use your data
To exercise any of these rights, email hello@letgrow.co.uk. We will respond within 30 days.
8. Guest rights
Guests whose messages are processed by Leto have the same rights as listed above. Guests can contact us at hello@letgrow.co.uk to exercise their rights.
If guest vetting/risk scoring is enabled, guests have the right to request human review of any automated assessment and to contest the decision.
9. Data security
- All data is encrypted in transit (TLS/HTTPS) and at rest
- Authentication tokens are cryptographically generated and time-limited
- Passwords are hashed using scrypt with random salts
- Access is restricted by role-based authentication
- Each host can only access their own properties and data
- Guest message data is never used to train AI models
10. Cookies and tracking
The Leto dashboard uses essential cookies only (authentication tokens stored in localStorage). We do not use advertising or tracking cookies within the Leto dashboard. The LetGrow marketing website uses Google Analytics — see our main privacy policy for details.
11. Changes to this notice
We may update this privacy notice from time to time. Material changes will be communicated to hosts via email. The “last updated” date at the top of this page will always reflect the most recent version.
12. Complaints
If you are unhappy with how we handle your data, you can contact us at hello@letgrow.co.uk. You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO) at ico.org.uk.