Privacy

Privacy Policy

We want ExpatGuideAI to be useful while treating user information with care. This page describes what the current public-beta architecture processes and why.

Last updated: 10 September 2026

What this policy covers

This policy explains the data handling of the ExpatGuideAI website, mobile experience and public beta chat. ExpatGuideAI is an independent product and is not a Thai government agency, law firm or immigration authority.

Account information

If you create an account, we process the account identifier and email address provided through our authentication service. We also keep the minimum product records needed for your plan, entitlement status and daily usage limits.

Account data is used to keep access and usage consistent across supported ExpatGuideAI experiences. We do not sell account information or use it for targeted advertising.

Information you provide

When you use chat, the text you submit and the recent conversation context needed to answer it are sent to our server. Depending on the workflow, you may also provide case details such as travel timing, nationality, visa purpose, document details or checklist progress.

We use the information you provide to deliver the ExpatGuideAI feature you are using, improve service reliability and maintain your requested product experience. We aim to collect and retain only what is reasonably needed for those purposes.

AI processing

ExpatGuideAI uses the Google Gemini API for some classification, language and general-answer tasks, and the OpenAI API for background generation of reusable source-backed Answer Memory responses. For supported source-backed topics, the user-facing response may be produced directly from reviewed product rules and official sources without waiting for an AI model call.

For the public beta, our Gemini use is on a billing-enabled paid API project. Google states that paid-tier Gemini API content is not used to improve its products unless the project owner separately chooses to share data. OpenAI states that API inputs and outputs are not used to train or improve its models by default unless the customer opts in to data sharing.

AI processing may occur outside Thailand. Provider retention and security practices are governed by the provider's applicable service terms and configuration. We do not intentionally submit user chats to optional shared training datasets.

Browser and app storage

  • Conversation state and temporary interface state may be stored in sessionStorage so the current browser session can continue the conversation.
  • On the current mobile beta, case progress, saved answers and user-created reminders are stored locally on the device in localStorage. These items are not currently synchronized across devices or accounts.
  • Local reminder records include the reminder title, due date and selected lead time. In an installed native app, the operating system may also store the scheduled local notification after you grant notification permission. ExpatGuideAI does not need a third-party push-notification server to deliver these local reminders.
  • Functional cookies may be used to remember language preferences and to keep a stable guest usage identity for daily beta limits. On experiences where ExpatGuideAI custom traffic analytics are enabled, the same server-derived guest quota key may also be used as the subject key for short-lived analytics so we do not create a second persistent visitor identifier.
  • For traffic measurement on the website and supported non-iOS experiences, the current browser/app session may store bounded first-touch categories such as organic search, campaign, referral or direct/unknown, plus a bounded campaign/referrer category and platform category. Raw referrer URLs and arbitrary UTM text are discarded rather than stored as analytics data.
  • Questions typed into the home-page ask box are transferred to chat through sessionStorage rather than being placed in the URL.
  • During the current beta, signed-in mobile/PWA sessions store authentication session tokens in localStorage so the session can be refreshed. We do not put those tokens into analytics or application logs.

Analytics

On the website and supported non-iOS experiences, we use Vercel Analytics and a small first-party traffic measurement layer to understand whether real users are finding and using ExpatGuideAI. For admitted chat requests, we may record bounded categories for acquisition source, campaign/referrer type, platform, signed-in versus guest use, coarse two-letter country code supplied by our hosting edge, and an audience category such as internal, likely tester, likely reviewer or unknown when there is explicit trusted evidence.

The native iOS app does not use ExpatGuideAI's custom traffic analytics. We rely instead on aggregate App Store Connect acquisition and usage analytics supplied by Apple from users who have chosen to share diagnostics and usage information with developers. ExpatGuideAI does not show a separate analytics-consent or App Tracking Transparency prompt for this purpose and does not use cross-app tracking or targeted advertising.

We do not infer reviewer/tester status from device type, IP address, country, store timing or user agent. Trusted tester/reviewer markers are short-lived cohort-level markers and do not contain a person identifier or grant product privileges. Conflicting, expired, malformed or forged markers are treated as unknown.

Our custom traffic analytics do not store raw IP addresses, raw user agents, full referrer URLs, arbitrary UTM values, raw question text, answers, email addresses, authentication tokens, conversation/session IDs or the private quota email-HMAC key. This analytics rule is separate from the limited coverage-gap quality records described below. Existing Vercel custom chat events remain limited to bounded product dimensions such as locale, turn type, response type/mode, latency and bounded traffic categories where enabled. We do not use ExpatGuideAI analytics for targeted advertising.

Custom analytics writes happen only after a chat request passes the quota gate. They are best-effort and run separately so an analytics outage does not block chat, alter quotas or change entitlements. Coverage is compared against quota-admission counts so missing analytics writes can be detected rather than silently treated as real traffic loss.

Coverage-gap quality review

When ExpatGuideAI deterministically identifies that it could not answer or verify the current question usefully, we may retain the failed question immediately asked so the product team can diagnose missing coverage. Before storage, we deterministically scrub obvious secret-like values such as explicit passwords, bearer or authentication tokens and API keys. We store only that failed last-user question for this purpose, not the full conversation history.

A coverage-gap record may also contain a one-way question fingerprint, a compact redacted sample, the server-controlled response mode and failure reason, limited diagnostic flags, timestamps, an occurrence count, triage status and an optional resolution note. The record does not contain an email address, raw IP address, account or user ID, guest ID or cookie identifier as identity fields. These records are used for product-quality triage, not targeted advertising or optional model-training data sharing.

AI response reports

You can report an AI response inside the website or mobile app. A report includes the reason you choose, any optional details you add, the reported response, the question immediately before it when available, the interface language and the server-controlled response type. If you are signed in and account verification is available, the report may also be associated with your account identifier.

We use reports to review potentially offensive, harmful, incorrect or misleading responses and to improve safety and reliability. Rate limiting uses a one-way derived reporter key; raw network addresses and raw guest cookie values are not stored with the report. Reports are not used for targeted advertising or optional model-training data sharing.

Security, abuse prevention and cost controls

To enforce fair-use limits and protect the service, ExpatGuideAI uses server-side derived identifiers for guest, account and network-level abuse controls. Raw guest identifiers and raw network addresses are not stored in the anonymous daily usage table. For signed-in daily quota protection, a verified email address is normalized and converted inside the database into a keyed one-way HMAC identity; the raw email is not stored in that quota identity.

The account quota identity exists only to keep a same-day usage limit from being reset by deleting and recreating an account. Detached quota rows are not used to restore historical account data and are removed when they are no longer needed for the daily abuse-control flow.

The service also records limited operational data such as request identifiers, request status, token counts and estimated AI cost for reliability and budget control. Access to operational systems is restricted and internal database or raw knowledge-debug endpoints are not exposed publicly.

Source-backed Answer Memory

For supported source-backed topics, ExpatGuideAI may store a reusable generated answer together with canonical topic parameters and source-version fingerprints. Raw user text is not used as the Answer Memory key. On a cache miss, the user can receive the source-backed deterministic response first while a reusable answer is generated separately in the background for later matching questions.

Before a reusable source-backed answer is stored or served, the system checks its cited evidence identifiers and source-version fingerprints. If the underlying reviewed source version changes, the previous reusable answer is not treated as current.

Retention and account deletion

Browser sessionStorage is controlled by the browser session. Device-local case progress, saved answers and reminders remain on that device until you remove them, clear site/app data or uninstall the app. Server-side operational records, coverage-gap quality records, AI response reports and reusable source-backed-answer records are kept only as needed for service operation, product-quality and safety review, security, source-version integrity, reliability and cost control.

Subject-linked custom traffic analytics are retained for up to 30 days and then removed. We may retain longer-lived daily aggregate totals that no longer contain an account ID or guest subject key. Signed-in account deletion immediately removes account-linked traffic attribution/activity rows through database deletion rules; non-identifying aggregate totals are not reconstructed into personal history.

A signed-in user can start permanent account deletion from the Account screen. Deleting the account removes the authentication account and linked ExpatGuideAI profile, entitlement and account-associated personal records. To prevent deletion and immediate recreation from resetting a daily fair-use limit, the current day's chat count may remain temporarily under a keyed one-way quota identity that does not store the raw email address. It is used only for abuse prevention and is not restored as historical account data. Coverage-gap quality records are not linked to the account or guest identity in their persistence model. Device-local case progress, saved answers and reminders can also be removed by clearing the app's local data. You can visit /delete-account for deletion instructions if you cannot access the app.

Your choices and requests

Where a browser or app webview exposes Global Privacy Control or Do Not Track, ExpatGuideAI disables its custom traffic analytics for that experience while leaving functional quota, security and service processing in place. Native iOS custom traffic analytics are disabled regardless of these browser signals.

You can remove saved answers, cases and reminders from their product screens, or clear site/app data to remove locally stored information. You may contact us to ask a privacy question or request deletion or correction of information that we can reasonably identify and are legally required to act on.

Children

ExpatGuideAI is designed for adults managing Thailand travel, residency, work, family or property matters. It is not directed to children.

Changes to this policy

We may update this policy as the beta, providers and data flows change. Material changes will be reflected on this page with a new last-updated date.

Support

Questions or privacy requests

If you have a question about privacy or how ExpatGuideAI handles your information, contact us at hello@expatguideai.com.

Email ExpatGuideAI