Security at Paco
Paco reads your hotel's mailbox and reports. Here is how it protects them, in plain words. Your data is hosted in Germany, the logins to your mailbox and software are encrypted, every customer is kept apart from the others, and Paco sends nothing outside the limits you have set.
Where your data lives
Paco's servers are in Germany, in the European Union.
Hosted in Germany
The database, the documents and mail run on servers rented from Hetzner Online, in its Falkenstein data centre in Germany.
A backup copy every night
Every night a copy is sent off the server, to Backblaze. It is stored encrypted and locked for 30 days: during that time nobody can delete it, not even us. Restoring from that copy has been tested.
Your documents read in Europe
The AI that reads your reports is provided by Mistral AI, in France. For a hotel in the EU, the chat assistant runs on Mistral too; for a hotel outside the EU, it uses Claude (Anthropic, US) by default. Your data is not used to train their models.
The full list, stated plainly
Every company that handles data for Paco, including the few outside the European Union, is named in the privacy policy.
Your mailbox and your software
The access you give Paco is the most valuable thing it holds. It is treated that way.
Encrypted before they are stored
The passwords and access tokens for your mailbox, the connections to your hotel software, and personal data such as phone numbers are encrypted before they enter the database. A copy of the database on its own reveals none of them.
Two separate keys
The key that protects your logins is not the key that protects personal data. One lost key never opens both.
A separate service for your logins, being rolled out
We are moving the logins to your mailbox and software into a small isolated service, the only one able to open them. The part of Paco that reads incoming mail will no longer hold them. It is being switched on in stages.
You can cut it off at any time
Disconnecting a mailbox deletes the stored access, and Paco stops reading it.
A person decides what goes out
A letter to an outside company leaves only when someone at the hotel approved that copy, when the manager asked for it in chat, or as a kind of letter whose exact wording the manager approved once. Every send leaves a receipt naming who allowed it. Paco never deletes an email from your mailbox.
Every customer, kept apart
Paco is one service for every hotel that uses it. None sees what belongs to another.
Your data answers only to you
Each read of a customer's data is limited to that customer's organisation. An automated check blocks any new code that forgets, unless the exception is written down with its reason (our own support console, for example).
Files opened in isolation
Files you upload, or that Paco finds in an email, are opened in an isolated process that holds no passwords and no keys.
Who can get in
The fewer the doors, the less there is to guard.
Passwords are never readable
They are stored in a form that cannot be reversed. Nobody at Paco can read yours.
Guessing does not work
After five failed attempts on one account within five minutes, or ten from one connection, Paco refuses further attempts for a while.
Encrypted connections only
Everything goes over HTTPS, and browsers are told never to connect to Paco without it.
Our own team faces a second check
The console Paco's team uses to help customers requires a password and a code from an authenticator app, checked on the server for every request.
Two people on the servers
Only the two founders can reach the production servers, with a personal key: password login is switched off there. Every read of the files that hold the server's secrets is recorded.
Checked from outside
We do not rely on our own opinion alone.
Verified by Google for Gmail access
Before an app may read Gmail, Google requires an independent security assessment. Paco's was carried out in September 2026, and Google approved Paco's Gmail access in October 2026. It is repeated every year.
Attacked on purpose, then fixed
In September 2026 we ran automated attack tests against the live site, signed in as a customer, fixed every real problem they found, and ran them again to confirm.
Error reports without your data
When something breaks, the report we receive has passwords, keys and personal data removed.
Your data stays yours
You can take everything with you, and erase it.
Download everything
In Settings › Account, "Download my data" gives you a copy of your data in a common format.
Delete your account
"Delete my account" closes the account. The data is then deleted or anonymised within 12 months, backups included as they expire.
Told if something goes wrong
If a data breach affects you, we tell you without undue delay, with what you need to report it to the authority.
Report a vulnerability
Found a security problem in Paco? Write to contact@pacoapp.io with "Security" in the subject, what you found and how to reproduce it. Please do not access, change or delete anyone else's data while testing, and give us time to fix it before you talk about it publicly. These details are also in the standard security.txt file.
Key facts
| Hosting | Hetzner Online, Falkenstein, Germany (European Union) |
|---|---|
| Backups | Nightly, off the server (Backblaze), encrypted, locked for 30 days, restore tested |
| Encryption in transit | HTTPS only |
| Encryption of stored data | Mailbox and software logins, personal data; two separate keys |
| Customer separation | Reads limited to the customer's organisation, checked automatically |
| Outgoing email | Only in the ways the hotel allowed, with a receipt for every send |
| Paco team access | Console behind a password and an authenticator code; servers reachable by key by the two founders only |
| Independent assessment | Independent assessment done in September 2026; Gmail access approved by Google in October 2026, renewed every year |
| Report a vulnerability | contact@pacoapp.io |
| Publisher | Vesper Holdings SAS, Marseille, France |
Common questions
Where is my data stored?
In Germany, with Hetzner Online. The nightly backup copy is encrypted and kept with Backblaze. The full list of sub-processors, with their countries, is in the privacy policy.
Can Paco send email from my mailbox on its own?
Paco drafts the letter. It leaves only if you approved that copy, asked for it in chat for an overdue check, or approved that kind of letter's exact wording once. Every send leaves a receipt.
Are my documents used to train an AI?
No. Your data is not used to train the models of the AI providers Paco uses.
What happens to my data if I leave?
You can download everything, then delete your account. The data is deleted or anonymised within 12 months, backups included.
How do I report a security problem?
Write to contact@pacoapp.io with "Security" in the subject.
