Who we are, and the two roles we play
The Aikebom platform is provided by a sole trader (empresário em nome individual) registered in Portugal (“Aikebom”, “we”). Contact: hello@aikebom.com.
For this website (including the book-a-demo form), Aikebom is the data controller. For a deployed concierge, the client — the event organiser or the hotel — is the controller of their guests’ data, and Aikebom processes it on their behalf under a data-processing agreement (available on request).
What a concierge session stores
No account, no sign-up. Using a concierge creates an anonymous session (an HMAC-signed, httpOnly cookie) holding: the conversation history (including transcripts of voice conversations), the trip preferences you mention (dates, interests, dietary needs), and any itinerary you build. That is what lets you leave and pick up where you stopped.
A hotel or resort concierge is normally not open to the public: by default it opens only for the property’s own guests, who arrive on a verified link the property issues at check-in. That is a door, not a login — there is still no account and no password, and the session it creates is the anonymous one described above.
Two optional additions exist when a client enables them: a verified guest link (a signed link carrying, at most, your booking reference, your name, your room or seat, and a guest tier if the property uses one — so the concierge can greet you and route requests; delivered individually to you, expiring with the stay), and reservation data pushed by the property’s management system (booking dates, room number, moves, and the contact details it holds for you — email address, phone number, language) so answers stay current.
Where a property switches on the check-in welcome, that link is emailed to you as you check in, to the address its booking system holds — and, where the property has also told us it collects WhatsApp consent at check-in, a short greeting goes to the number that system holds. The two carry different things, deliberately: the email carries your first name and the link, while the WhatsApp greeting is a fixed message carrying your first name. Neither carries anything you have written. You can stop the WhatsApp messages by replying STOP, and you can ask us to stop the emails at any time.
How long we keep it — two models, both automatic
Events have one published cut-off for everyone: shortly after the event ends (by default about two weeks after the final day), every session — conversations, profiles, itineraries — is deleted automatically.
Hotels & resorts delete per guest, on the guest’s own clock, triggered by inactivity: once you stop using the concierge, your data is deleted about a week after your last message — and never lives more than 45 days past it, whatever happens. A known checkout date only ever protects a still-in-house guest from early deletion; it is never what triggers deletion. Nothing is kept for the life of the property.
What checkout does do is close the door: access to the concierge ends shortly after your checkout day. That is a separate and much shorter clock than deletion, and it is what guarantees the inactivity clock actually starts — so a guest who has left cannot keep a session alive indefinitely simply by carrying on the conversation.
Both schedules are enforced by Aikebom in the engine itself — they are not settings a client can quietly extend. After deletion, only anonymised, aggregate usage statistics remain in our systems (counts and costs, never conversation content or personal data) — what reached the providers listed under Sub-processors below follows their retention terms, not this schedule — plus, if you asked us to stop messaging you, a one-way hashed record of that request, kept for no other purpose than to keep honouring it. Deleting a session also disables any itinerary share links it created.
Voice
Voice conversations are processed in real time: audio is streamed for transcription and replies are synthesized as speech. We do not store the audio. The text transcript joins your conversation history and follows the same retention as chat, above.
What we don't do
No advertising or tracking cookies, no profiling for ads, no selling or renting data — ever. Nothing one client’s guests teach the concierge is used for another client. We do not train any model on your data ourselves, and the providers that see your conversation text to generate a reply — OpenAI and Anthropic, and the Vercel AI Gateway that routes to them — are used under terms that exclude training on the content we send. The other providers listed under Sub-processors operate under their own terms, and we don’t make that commitment on their behalf.
Cookies
Strictly functional only: the anonymous concierge session cookie, an admin session cookie for staff who log in, and a language-preference cookie on this website. No third-party or advertising cookies — which is why you don’t see a consent banner.
This website's demo form
If you book a demo or join the early-access list, we store what you submit (email, and whatever else you choose to fill in) and use it solely to respond — including a confirmation email. Write to us and we’ll delete it.
Sub-processors
Running the service means using specialised providers. Each receives the minimum the feature needs:
| Provider | Purpose | What reaches it |
|---|---|---|
| Vercel | Application hosting | All application traffic |
| Vercel AI Gateway | Language-model request routing | Conversation text and replies, in transit to the language model |
| Supabase | Database | Session, conversation and itinerary data |
| OpenAI | Language model (API) | Conversation text and the trip details you share (including dietary or mobility needs), to generate replies; and, where a property enables it, your name and room |
| Anthropic | Language model (API) — document summarization & transcription always, and reply generation while in use | Uploaded knowledge documents and URLs, submitted by organisers; and, while Anthropic models generate replies, the same conversation and trip details described for OpenAI above |
| Voyage AI | Search embeddings | Uploaded documents and search queries |
| Deepgram | Speech-to-text (voice) | Live voice audio, transcribed in real time |
| Cartesia | Text-to-speech (voice) | Reply text, synthesized in real time |
| Hetzner | Self-hosted voice infrastructure | Live voice call streams |
| Google Maps Platform | Places, routes, transit | Place names and locations from queries |
| Perplexity | Web search | Search queries derived from your questions, which can include trip details you mentioned such as dietary or mobility needs |
| SearchApi.io | Venue ratings | Venue names being looked up |
| OpenWeatherMap / Open-Meteo | Weather and conditions | Coordinates only |
| Meta (WhatsApp Business Platform) | Guest messaging channel | Your WhatsApp number and the messages exchanged; where a property runs guest notifications, the type and status of a request you made; and where it runs the check-in welcome and has told us it collects WhatsApp consent at check-in, a welcome sent to the number its booking system holds, carrying your first name and the language it is written in |
| Upstash | Rate limiting | Anonymous request counters |
| Resend | Transactional email | Lead-form details you submit to us; where a property runs guest notifications, the guest email address its booking system sent us together with the type and status of a request they made; and where it runs the check-in welcome, that same address with the guest’s first name and their personal entry link, which itself carries the booking reference, full name and room described above |
Reply generation moved from Anthropic to OpenAI on 24 August 2026: OpenAI generates the concierge’s replies today. Anthropic stays named above for two separate reasons — it processes uploaded documents either way, and it remains the fallback we can move reply generation back to, either entirely or for spoken replies alone. Both stay named for as long as either can be the one generating your replies.
Some providers process data outside the EU (notably in the United States) under their standard contractual clauses. Queries sent to search and mapping providers carry the content needed to answer, which can include trip details you mentioned. Each provider above keeps what we send it under its own retention terms, on its own clock: the deletion schedule above governs our systems, and we don’t claim it reaches inside theirs.
Your rights
Under the GDPR you can request access, correction, deletion, restriction or portability of your data, and complain to a supervisory authority (in Portugal, the CNPD). For a deployed concierge, the event or property you used it at is the controller — you can go to them or directly to us at hello@aikebom.com and we’ll handle or route it. Since sessions are anonymous, we may ask you for the session’s device or share-link details to locate the right data.
Changes
We’ll update this page as the service evolves; material changes move the date below. Last updated: 10 September 2026.