Hosted connector

Effective September 29, 2026

If you connect an AI assistant to Gazdura’s hosted connector, the assistant sends Gazdura the tool request needed to answer you. Depending on what you ask and what you choose to share, that request may include your question and trip details (for example loyalty tier or carrier, travel dates and route, traveler count, and preferences you provide).

Purpose. Gazdura processes each hosted request to confirm who is making the request and that they are allowed to make it, produce and return the tool answer to your assistant, and handle necessary operational needs when a request fails. Gazdura’s policy is not to sell personal information from a hosted tool request, and not to use the request’s question or trip details for advertising or traveler-level profiling. Gazdura may use limited operational measurements needed to run and improve the connector, such as counts of request outcomes or response times, only if those measurements are actually collected and disclosed. Gazdura does not currently claim to collect its own request counts, response times, or error rates for the connector beyond Cloudflare’s Free-plan dashboards. Request content is not used for ads or profiling. Platform operators listed below may still process technical traffic or website error metadata under their own systems, as described below where known.

Who helps run this. Cloudflare runs the hosted Gazdura connector. Supabase provides sign-in and authorization (Gazdura checks your authorization before answering). Netlify hosts the product website and related server functions. Sentry may receive error reports from the product website when configured. Your AI assistant’s conversation and tool transcript are handled under that assistant’s own privacy policy.

Application retention. Gazdura’s hosted connector is designed not to keep an application copy of your question or trip request payload after the answer is returned. That does not mean other systems keep nothing: Cloudflare, Supabase, Netlify, Sentry, and your assistant provider may process or retain technical data under their own systems, as described below where known.

Authorization data (Supabase). Supabase handles sign-in and records sign-in and session data for this project. In our current settings and records, session records include an IP address and browser details (user agent). Sign-in service logs can include your IP address. Security audit events include browser details. The IP address on those events was often empty. An access token expires after one hour. A refresh token can be used again within a 10-second window. That reuse is allowed. It is not blocked. Detection of compromised refresh tokens is turned on. No session time limit is set, and no inactivity timeout is set. These token and session settings are security controls, not a schedule for deleting data. Database backups are taken daily and kept for 7 days. Point-in-time recovery is not enabled. Gazdura does not promise a specific deletion window for sign-in session or audit records beyond what Supabase’s settings and documentation provide for this project.

Product website logs (Netlify). gazdura.com runs on Netlify Pro. Function logs are kept for 7 days. When we checked our Netlify team settings, log forwarding (Log Drains) was not set up. That feature needs Netlify’s Enterprise plan. Files saved with each deploy have their own retention period. They do not replace the 7-day retention of the function logs above.

Errors (Sentry). Error monitoring is set up for the Gazdura website. There is no separate error-monitoring project for the hosted connector, and this notice does not claim that hosted connector failures are reported to Sentry. Error reports from the website may go to Sentry. After Sentry receives a report, its data scrubbing is on: default scrubbers are on, the setting that prevents storing IP addresses is on, and email is listed as an extra sensitive field. That IP setting is a setting, not a promise that a report never includes an IP address. On our current plan, error reports are kept for 30 days. Gazdura may also remove sensitive text before a report leaves your browser. Scrubbing reduces risk but is not a guarantee: a report can still contain leftover error or message text, and we do not claim that error reports never contain an email address or IP address.

Edge and platform data (Cloudflare). gazdura.com uses Cloudflare’s Free plan. In Cloudflare’s dashboard we can view website traffic analytics for periods of up to 30 days, and security events for the last 24 hours. Those are separate sets of data. That is what the dashboard shows, not a general promise about when Cloudflare deletes data. Our Free-plan view did not show a list of log-export (Logpush) jobs, so we could not tell from that view whether any export is running.

Your choices. To request access or deletion of data Gazdura controls, contact legal@gazdura.com. Your assistant may retain the conversation under its own policy.

This notice covers only the hosted Gazdura connector as it works today. Anything that is not live yet is not covered here and is not promised.