Maison Labs, Inc.
Updated Aug 26, 2026
Maison (“Maison,” “we,” “us,” or “our”) provides an AI hotel-concierge service that reads guest messages sent to a hotel's mailbox and drafts a concierge reply from that same mailbox. This Privacy Policy explains what data we collect, how we use it, how we store and protect it, who we share it with, and the choices and rights you have. It applies to the Maison service and website at https://maison.cx and is written to satisfy the Google API Services User Data Policy, including its Limited Use requirements (affirmed in Section 5).
Who our customer is. Our direct customer is the hotel/hospitality operator (“Operator”) that connects its mailbox to Maison. Guests correspond with the hotel by email; Maison processes those messages on the Operator's behalf. For data-protection purposes the Operator is the controller and Maison acts as its processor/service provider.
Legal entity. Maison is operated by Maison Labs, Inc.
| Scope | Access it grants | Why Maison needs it |
|---|---|---|
| gmail.modify | Read message bodies, threads, and history of the connected hotel mailbox, and modify message labels (read/unread state) | Read the inbound guest message to generate an accurate concierge reply, and mark a guest email as read only after the agent has replied — unanswered mail stays unread as the hotel staff's work queue. No deletion, no settings changes, no filters. |
| gmail.send | Send mail as the connected hotel mailbox | Send the concierge reply from the hotel's own mailbox. A separate grant from read. |
gmail.send allows sending only. Maison requests exactly these two scopes and no others; the only label operation performed under gmail.modify is marking an answered guest email as read. Maison never deletes mail, never changes mailbox settings, and never creates filters or forwarding rules.
Exactly what is accessed: message bodies/threads + mailbox history, and read/unread label state; the OAuth access + refresh tokens (stored encrypted, Section 3); only the single hotel mailbox the Operator connects — never any other Google account.
Use: read the inbound message (gmail.modify); draft the reply via Google Gemini through Maison's llm-service for stateless inference only (never used to train/fine-tune/improve any model, never for advertising, never sold); optional human review by the Operator before sending (their own mailbox, with their consent); send the reply (gmail.send / Microsoft Graph); mark the answered guest email as read (gmail.modify) — unanswered mail stays unread for hotel staff. Used only to provide/improve these user-facing features.
Store + secure: OAuth tokens encrypted at rest with AES-256-GCM in Postgres (client_channels), never logged; guest content processed transiently to make one reply (not a long-term archive on the inference path); active conversation state in DynamoDB auto-expires after 7 days; the durable conversation log (guest message + agent reply, reviewable by the hotel in its console) is retained for the duration of the Operator's service relationship; TLS in transit.
We do not sell data, do not use it for advertising, do not use it to train/fine-tune/improve any AI model. Subprocessors:
| Subprocessor | Purpose | Data involved |
|---|---|---|
| Gmail API + Gemini (stateless inference) | Mailbox content + OAuth tokens; guest content sent to Gemini for inference only | |
| Microsoft | Graph / Outlook access | Mailbox content + OAuth tokens (Outlook path) |
| AWS | Hosting + storage (Postgres, DynamoDB, S3) | Encrypted tokens, session logs |
No other third parties except to comply with law or in a merger/acquisition (with continued protection).
Maison's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements. Maison affirms:
Google user data is never used to train, fine-tune, or improve any generalized or non-personalized AI/ML model. All inference is stateless, solely to generate the reply.
Disconnecting a mailbox (any time) → Maison erases the stored tokens and revokes access. Account deletion → Maison purges associated data (request via support@maison.cx / engineering@maison.cx). Guest deletion requests go to the hotel (Operator), who may route to Maison at support@maison.cx.
Connection control (disconnect any time); human oversight (review before send); access/correction/deletion/restriction rights depending on location (contact support@maison.cx). No discrimination for exercising rights.
If we become aware of a security incident affecting Google user data or other personal data, we respond per applicable law and notify affected parties as required. Report concerns to security@maison.cx.
We may update this policy; material changes update the “Last updated” date with notice where appropriate.
Product: https://maison.cx · General/privacy/deletion: support@maison.cx · Engineering: engineering@maison.cx · Security: security@maison.cx