1. Who we are
Anny AI, Inc., a Delaware corporation, provides Anny at www.anny.ai. This policy describes how we collect, use, share, and retain information when you visit the website, create an account, use the application, call our APIs, or connect an assistant through the MCP server.
Anny AI, Inc. is the controller of the personal information described in this policy.
Contact: hi@ask.anny.ai.
2. Information we collect
We collect:
- Account details: name, email, and a password or a Google or Microsoft sign-in.
- Workspace data: organization, roles, hotels, competitor sets, schedules, reports, API keys, and the operating data you enter.
- Billing records in Stripe. Card numbers are handled by Stripe; we store only the card brand and last four digits.
- Product analytics, request logs, and, in the signed-in application, session recordings.
- Emails we send you and messages you send to Ask Anny.
- MCP OAuth identity, the tool calls an assistant makes, and the results we return. We do not collect the rest of your chat with the assistant.
- Optional setup assistance inputs you confirm before we save them, such as a hotel identity.
3. How we use it
We use this information to provide and secure the service, run the rate shops and Event Intelligence you authorize, bill and send receipts, send reports and invitations, understand product use, respond to support, and comply with law.
We do not sell personal information. We do not use your workspace data or MCP tool content to train foundation models, and we do not share it with anyone for that purpose.
If you are in the EEA or the UK, we rely on these legal bases:
- A contract with you, to create your account, provide the service, run the shops you schedule, and bill you.
- Our legitimate interests, to keep the service secure, understand how it is used, and improve it, weighed against your privacy.
- A legal obligation, to keep billing and tax records.
- Your consent, where we ask for it. You can withdraw it at any time.
4. Storage
Workspace and account data live in PostgreSQL hosted by Neon. Raw rate-provider responses are stored in private Amazon S3. The application is hosted on Vercel. We use HTTPS in transit.
5. Sharing
We share information with service providers that help us operate, and only as needed for that work:
- Vercel for hosting and site analytics.
- Neon for the database.
- Amazon Web Services for object storage, email delivery, and delivery events.
- Stripe for payments.
- PostHog for product analytics, error tracking, and session recordings in the signed-in application.
- Google or Microsoft if you choose those sign-in methods.
- Google Maps to turn a hotel address into coordinates and to draw the map in a report.
- Cal.com if you book a demo, which receives the name, email, and time you enter.
- A hotel-rate data provider that returns published market rates for the hotels and stay dates we request. We send hotel identifiers and stay parameters, not your name or email.
- Model providers through Vercel AI Gateway for optional setup assistance, Help Center search embeddings, and Event Intelligence research. Event research sends the hotel name and address, its coordinates, the dates being searched, and any description you enter, and it uses provider web search. Traced generations use privacy mode, so prompts and model output are not sent to our analytics provider.
6. Assistants you connect
When you connect Claude or another MCP client, that assistant receives the tool results needed to answer you, under your workspace permissions. We do not send Anny data to an assistant provider except through those tool calls. You can disconnect the assistant from the app or from the assistant's connector settings.
7. Cookies
Essential cookies keep you signed in and remember language. PostHog sets analytics cookies. Session recordings run only in the signed-in application, and fields we mark sensitive, such as passwords and pasted keys, are excluded from them. An embedded map or the demo scheduler can set its own cookies when you use it.
8. Retention
We keep account and workspace data while the workspace is active. Rate-shop evidence and raw provider payloads are retained for history and audit and do not expire automatically. Billing records follow Stripe and tax requirements. Email hi@ask.anny.ai to request deletion. Product analytics, request logs, and session recordings are kept for a limited period set in our analytics provider and are then deleted. Support messages are kept while we need them for support history. We may retain limited records when law or security requires it.
9. Your choices and rights
You can update profile and workspace settings in the app, disconnect an assistant, and cancel a paid plan. You can also email us to access, correct, or delete personal information. Browser controls can limit analytics cookies; essential cookies are required to sign in.
If you are in the EEA or the UK, you can also ask for a copy of your personal information, have it corrected or deleted, restrict or object to how we use it, and withdraw consent you gave. Email hi@ask.anny.ai and we will answer within one month. You can also complain to your national data protection authority.
10. Children
Anny is a business service. It is not directed at children.
11. International
We operate from the United States. If you use the service from another country, you understand information is processed in the United States.
12. Changes
We will update this page when our practices change. The date at the top is the current version.
13. Contact
Privacy questions: hi@ask.anny.ai.