HostelHound policies

Privacy Policy

This policy explains what HostelHound uses to provide price tracking, accounts, and the optional MCP connection for ChatGPT and other approved clients.

Last updated September 16, 2026

Information we use

You can browse HostelHound's public price calendars and city pages without an account. When you create an account or use account features, we use your verified email address, a secure session, and the saved follows, alerts, or trips you choose to keep. We use this information to provide the feature you asked for and to protect account ownership.

HostelHound's price data comes from accommodation listings and is stored in US dollars for comparison. Your currency choice changes display formatting; it does not change the source price data.

MCP and OAuth connections

The optional HostelHound MCP connector is a delegated connection started by ChatGPT. An OAuth consent screen explains the access requested before a connection is completed. The catalog:read capability allows destination, hostel, price, forecast, and itinerary-quote or validation lookups. The trips:prepare capability allows an expiring, unsaved trip-preparation preview for browser review. Static clients represent these capabilities as delegated OAuth scopes; consent-claim clients select Search or Search and prepare trips and bind that choice to a signed local grant. It does not book, purchase, or share a trip.

Depending on the client flow, standard OAuth scopes such as openid, email, and offline_access may also be requested for identity and reconnect behavior. WorkOS provides the OAuth authorization and token service for this optional connection.

To complete the connection, HostelHound sends WorkOS only the minimum identity details needed for the handoff: an opaque provider authorization reference, a stable account identifier, and your normalized, verified email address. HostelHound does not store ChatGPT access or refresh tokens, and MCP requests do not use your website cookie.

Retention and deletion

OAuth authorization transactions are short-lived and expire after about ten minutes. Expired transactions cannot be used to authenticate and are removed by bounded cleanup; cleanup timing is best effort. OAuth access and refresh tokens are not retained by HostelHound.

A disconnected connection's limited status history is eligible for deletion after seven days, but cleanup is best effort and the record may remain until a later opportunistic cleanup run. We retain account and price data only as needed to provide the service, keep it secure, and meet operational or legal requirements.

If you request account deletion, HostelHound revokes your web sessions and local MCP access before processing deletion. Provider-side identity deletion may require a retry; Ko-fi billing is separate and must be canceled there.

Revoking access

To disconnect a current connection, sign in and use Connectors. Local MCP access is revoked immediately, even if an external OAuth token has not expired. You can also revoke the provider's OAuth consent in ChatGPT or its authorization settings. Reconnecting starts a new authorization flow in ChatGPT.

For privacy questions or a data request, email [email protected]. Please do not include access tokens, authorization codes, passwords, or session cookies.

Questions

See the Terms of Service for the service rules, or visit Support & contact for the expected support path.