What this policy covers
This policy explains the data handling of the ExpatGuideAI website, mobile experience and public beta chat. ExpatGuideAI is an independent product and is not a Thai government agency, law firm or immigration authority.
Privacy
We want ExpatGuideAI to be useful while treating user information with care. This page describes what the current public-beta architecture processes and why.
Last updated: 10 September 2026
This policy explains the data handling of the ExpatGuideAI website, mobile experience and public beta chat. ExpatGuideAI is an independent product and is not a Thai government agency, law firm or immigration authority.
If you create an account, we process the account identifier and email address provided through our authentication service. We also keep the minimum product records needed for your plan, entitlement status and daily usage limits.
Account data is used to keep access and usage consistent across supported ExpatGuideAI experiences. We do not sell account information or use it for targeted advertising.
When you use chat, the text you submit and the recent conversation context needed to answer it are sent to our server. Depending on the workflow, you may also provide case details such as travel timing, nationality, visa purpose, document details or checklist progress.
We use the information you provide to deliver the ExpatGuideAI feature you are using, improve service reliability and maintain your requested product experience. We aim to collect and retain only what is reasonably needed for those purposes.
ExpatGuideAI uses the Google Gemini API for some classification, language and general-answer tasks, and the OpenAI API for background generation of reusable source-backed Answer Memory responses. For supported source-backed topics, the user-facing response may be produced directly from reviewed product rules and official sources without waiting for an AI model call.
For the public beta, our Gemini use is on a billing-enabled paid API project. Google states that paid-tier Gemini API content is not used to improve its products unless the project owner separately chooses to share data. OpenAI states that API inputs and outputs are not used to train or improve its models by default unless the customer opts in to data sharing.
AI processing may occur outside Thailand. Provider retention and security practices are governed by the provider's applicable service terms and configuration. We do not intentionally submit user chats to optional shared training datasets.
On the website and supported non-iOS experiences, we use Vercel Analytics and a small first-party traffic measurement layer to understand whether real users are finding and using ExpatGuideAI. For admitted chat requests, we may record bounded categories for acquisition source, campaign/referrer type, platform, signed-in versus guest use, coarse two-letter country code supplied by our hosting edge, and an audience category such as internal, likely tester, likely reviewer or unknown when there is explicit trusted evidence.
The native iOS app does not use ExpatGuideAI's custom traffic analytics. We rely instead on aggregate App Store Connect acquisition and usage analytics supplied by Apple from users who have chosen to share diagnostics and usage information with developers. ExpatGuideAI does not show a separate analytics-consent or App Tracking Transparency prompt for this purpose and does not use cross-app tracking or targeted advertising.
We do not infer reviewer/tester status from device type, IP address, country, store timing or user agent. Trusted tester/reviewer markers are short-lived cohort-level markers and do not contain a person identifier or grant product privileges. Conflicting, expired, malformed or forged markers are treated as unknown.
Our custom traffic analytics do not store raw IP addresses, raw user agents, full referrer URLs, arbitrary UTM values, raw question text, answers, email addresses, authentication tokens, conversation/session IDs or the private quota email-HMAC key. This analytics rule is separate from the limited coverage-gap quality records described below. Existing Vercel custom chat events remain limited to bounded product dimensions such as locale, turn type, response type/mode, latency and bounded traffic categories where enabled. We do not use ExpatGuideAI analytics for targeted advertising.
Custom analytics writes happen only after a chat request passes the quota gate. They are best-effort and run separately so an analytics outage does not block chat, alter quotas or change entitlements. Coverage is compared against quota-admission counts so missing analytics writes can be detected rather than silently treated as real traffic loss.
When ExpatGuideAI deterministically identifies that it could not answer or verify the current question usefully, we may retain the failed question immediately asked so the product team can diagnose missing coverage. Before storage, we deterministically scrub obvious secret-like values such as explicit passwords, bearer or authentication tokens and API keys. We store only that failed last-user question for this purpose, not the full conversation history.
A coverage-gap record may also contain a one-way question fingerprint, a compact redacted sample, the server-controlled response mode and failure reason, limited diagnostic flags, timestamps, an occurrence count, triage status and an optional resolution note. The record does not contain an email address, raw IP address, account or user ID, guest ID or cookie identifier as identity fields. These records are used for product-quality triage, not targeted advertising or optional model-training data sharing.
You can report an AI response inside the website or mobile app. A report includes the reason you choose, any optional details you add, the reported response, the question immediately before it when available, the interface language and the server-controlled response type. If you are signed in and account verification is available, the report may also be associated with your account identifier.
We use reports to review potentially offensive, harmful, incorrect or misleading responses and to improve safety and reliability. Rate limiting uses a one-way derived reporter key; raw network addresses and raw guest cookie values are not stored with the report. Reports are not used for targeted advertising or optional model-training data sharing.
To enforce fair-use limits and protect the service, ExpatGuideAI uses server-side derived identifiers for guest, account and network-level abuse controls. Raw guest identifiers and raw network addresses are not stored in the anonymous daily usage table. For signed-in daily quota protection, a verified email address is normalized and converted inside the database into a keyed one-way HMAC identity; the raw email is not stored in that quota identity.
The account quota identity exists only to keep a same-day usage limit from being reset by deleting and recreating an account. Detached quota rows are not used to restore historical account data and are removed when they are no longer needed for the daily abuse-control flow.
The service also records limited operational data such as request identifiers, request status, token counts and estimated AI cost for reliability and budget control. Access to operational systems is restricted and internal database or raw knowledge-debug endpoints are not exposed publicly.
For supported source-backed topics, ExpatGuideAI may store a reusable generated answer together with canonical topic parameters and source-version fingerprints. Raw user text is not used as the Answer Memory key. On a cache miss, the user can receive the source-backed deterministic response first while a reusable answer is generated separately in the background for later matching questions.
Before a reusable source-backed answer is stored or served, the system checks its cited evidence identifiers and source-version fingerprints. If the underlying reviewed source version changes, the previous reusable answer is not treated as current.
Browser sessionStorage is controlled by the browser session. Device-local case progress, saved answers and reminders remain on that device until you remove them, clear site/app data or uninstall the app. Server-side operational records, coverage-gap quality records, AI response reports and reusable source-backed-answer records are kept only as needed for service operation, product-quality and safety review, security, source-version integrity, reliability and cost control.
Subject-linked custom traffic analytics are retained for up to 30 days and then removed. We may retain longer-lived daily aggregate totals that no longer contain an account ID or guest subject key. Signed-in account deletion immediately removes account-linked traffic attribution/activity rows through database deletion rules; non-identifying aggregate totals are not reconstructed into personal history.
A signed-in user can start permanent account deletion from the Account screen. Deleting the account removes the authentication account and linked ExpatGuideAI profile, entitlement and account-associated personal records. To prevent deletion and immediate recreation from resetting a daily fair-use limit, the current day's chat count may remain temporarily under a keyed one-way quota identity that does not store the raw email address. It is used only for abuse prevention and is not restored as historical account data. Coverage-gap quality records are not linked to the account or guest identity in their persistence model. Device-local case progress, saved answers and reminders can also be removed by clearing the app's local data. You can visit /delete-account for deletion instructions if you cannot access the app.
Where a browser or app webview exposes Global Privacy Control or Do Not Track, ExpatGuideAI disables its custom traffic analytics for that experience while leaving functional quota, security and service processing in place. Native iOS custom traffic analytics are disabled regardless of these browser signals.
You can remove saved answers, cases and reminders from their product screens, or clear site/app data to remove locally stored information. You may contact us to ask a privacy question or request deletion or correction of information that we can reasonably identify and are legally required to act on.
ExpatGuideAI is designed for adults managing Thailand travel, residency, work, family or property matters. It is not directed to children.
We may update this policy as the beta, providers and data flows change. Material changes will be reflected on this page with a new last-updated date.
Support
If you have a question about privacy or how ExpatGuideAI handles your information, contact us at hello@expatguideai.com.
Email ExpatGuideAI