Privacy Policy
What we collect, what we deliberately do not, and who else touches it.
Cimyah is operated by Compass Tech Labs LLC. This policy covers two different groups of people, and the difference matters: the hosts who have accounts with us, and the guests who open a guide.
The short version for guests: we measure how guides are used, not who used them.
Guests: what happens when you open a guide
If you are staying somewhere and your host sent you a link, you have no account with us and we are not trying to identify you.
When you open a guide we record what was used, so your host can see which parts of their guide people actually read. Each event holds:
- Which property's guide it was.
- The time.
- What kind of event it was — the guide opening, a page opening, a link being followed, a code being copied, the map opening, a language being switched.
- Which page or item it concerned.
- How the guide was reached — a QR code, a link, and so on.
- The language shown.
- A random session id that groups one visit's events together.
That is the complete list.
What we deliberately do not do:
- No cookies. We do not set any.
- No advertising, no analytics from other companies, no tracking pixels, no fingerprinting.
- We do not store your IP address. The table these events live in has no column that could hold one.
- We do not store your device type, browser or operating system.
- We do not ask for, or hold, your name, email, or phone number.
The session id is generated fresh in your browser at the start of each visit and kept in session storage, which your browser throws away when you close the tab. It is not linked to you, not linked to your other visits, and not linked to any other property's guide. There is nothing in it, or beside it, that could identify you.
One thing we want to be straight about: every request on the internet carries an IP address, and the companies that deliver this page to you — our hosting and database providers, and the map provider if you open a map — process yours transiently in order to serve it and to defend against abuse. We do not receive it into our own records, and we do not keep it. We would rather say that than claim something tidier and less true.
Guests: your host, not us
The content of a guide is written by your host, and the usage figures above are shown to your host. For that information, your host decides what is collected and why; we process it on their instructions. If you want a guide's information corrected or removed, ask your host. If you would rather we help you reach them, write to hello@cimyah.com.
Hosts: what we hold about you
If you have an account, we hold:
- Your email address. Sign-in is by emailed link, so the address is the account.
- Your account name, plan, and the limits that go with it.
- Everything you write into your guides and your places list, including photographs you upload.
- Your door codes, gate codes and wi-fi passwords, encrypted.
- The usage figures for your own guides, as described above.
- A record of which legal documents you accepted, at which version, when, and from which IP address.
- If you send us a bug report or feedback: your message, the page you were on, any screenshot you attach, and your browser's user-agent string.
- If you subscribe: a customer record with our payment processor. We never see or hold your card number.
Note the asymmetry, because it is deliberate. We record an IP address for you, once, at the moment you accept these documents — that is what makes an acceptance evidence rather than an assertion. We record none for your guests, ever.
If you write to us, or redeem a code
The contact form is open to anyone, with or without an account. When you use it we keep your message and the details you put in it, together with your IP address and your browser's user-agent string. Those last two are there to stop the form being used to send bulk mail through us — they are a rate limit, not a profile, and they are not shown to hosts or joined to anything else.
Redeeming a code records the IP address the attempt came from, for the same reason and no other: it is what stops a code being guessed at scale.
Door codes and passwords
Credentials are treated differently from everything else you write. They are encrypted before they are stored, they are kept out of the guide document itself and referenced from it, and they are never sent to any AI provider.
A published guide only reveals them according to the settings you chose — behind a stay link, if that is what you set up. What no system can do is protect a code from a link you shared with someone.
Why we hold it
To run the service you asked for, to bill you if you are on a paid plan, to show you how your guides are being used, to answer you when you write to us, to keep the service working and secure, and to meet our legal obligations. We do not sell personal information, and we do not share it for advertising.
Who else touches it
We use other companies to run the service. Each one only receives what it needs:
- Supabase — database, sign-in, and file storage. Holds your account and guide content.
- Vercel — hosting. Serves the application and your guides.
- Anthropic — AI drafting, translation and photo descriptions. Receives the property details and text you ask it to work on. Never receives your saved credentials.
- Google Places — finding nearby venues. Receives a location to search around. We store nothing from it beyond a place identifier.
- MapTiler — maps shown in a guide, when a MapTiler key is configured.
- CARTO — the fallback basemap, used when no MapTiler key is configured. Like any map provider it receives the map tiles your browser asks for, which is the area you are looking at.
- Resend — sending email, such as team invitations.
- Sentry — error reporting, so we find out when something breaks.
- Stripe — payments. Handles card details directly; we never receive them.
These providers operate in the United States and elsewhere. Where personal data of people in the EEA or the UK is transferred, we rely on the providers' standard contractual clauses.
How long we keep it
Account and guide content: for as long as your account exists, and then deleted. Guest usage events: the daily totals your analytics are built from are kept for as long as the property exists and are deleted with it; the individual event rows behind those totals are deleted after 400 days, which is long enough to compare a season against the same season a year earlier and no longer than that. Legal acceptance records and billing records: kept as long as we may need them to defend a claim or meet a tax or accounting obligation. Bug reports and messages sent through the contact form: kept until resolved and for a reasonable period afterwards.
Published web addresses are never reissued, even after deletion, because printed QR codes outlive accounts and a recycled address would point someone's kitchen sticker at a stranger's guide.
Your rights
Depending on where you live, you may have the right to see what we hold about you, to have it corrected, to have it deleted, to object to some processing, and to receive a copy in a portable form. Write to hello@cimyah.com and we will act on it.
If you are a guest, most of these requests concern your host rather than us, and we will help you reach them.
Children
The service is not for children. We do not knowingly collect personal information from anyone under 13. Accounts require an adult.
Security
Every table in our database enforces row-level access rules, so one account's data is unreachable from another. Credentials are encrypted at rest. Published guides ask search engines not to index them. Payment card details never reach our servers.
No system is perfect. If you find a security problem, please tell us at hello@cimyah.com before telling anyone else.
Changes
We may update this policy. When the substance changes we publish a new dated version and ask account holders to accept it at their next sign-in. This policy is governed by the laws of the Commonwealth of Massachusetts, United States.
Questions: hello@cimyah.com.