Privacy

Privacy policy.

Last updated 2026-07-14 · Version 2.2

ZephyrHQ helps you see the benefits your accounts — such as credit cards, memberships, carriers, and insurers — already provide, and monitors your connected email inbox for time-sensitive events such as flight changes, closing return windows, unusual bills, and denied refunds.

To provide these features, we need to know which accounts you hold and, if you connect your email, to read the confirmations and notices those accounts send you. This policy explains what information we collect, how we use it, what we do not collect, and the choices available to you.

This Privacy Policy applies to your use of ZephyrHQ and should be read together with our Terms of Service. If you have questions about it, contact us at privacy@myzephyrhq.com.


Summary

What we collect

Everything in this list is tied to your account and used to operate the product. We do not maintain a separate marketing or analytics collection outside this list. The "What we store" screen in your settings is a live version of this section.

Account identity

Why: so you can sign in and so we can associate your data with the correct account.

Your accounts — the ones you've told us about

Why: we can't show your benefits without knowing your accounts.

Enrichment answers

Why: benefits vary by tier and product. These answers let us surface accurate benefits instead of generic ones.

Email-derived records (only if you connect an inbox)

Why: this powers the trips, purchases, bills, promotions, reading, and personal surfaces: we reconstruct the useful information and leave the underlying mail in Gmail.

OAuth tokens

Why: without them, we can't read your inbox. We do not see or store your Google password. Our Gmail authorization is read-only on your mail content (see Google user data); it does not include permission to label, modify, delete, or send mail.

Calendar data (optional)

Why: so a flight confirmation and the matching calendar entry become one trip, not two. Reading live keeps the dates we show you current.

Intelligence feed history

Why: so your feed has continuity, so you can scroll back, and so we don't re-surface the same item repeatedly.

Preferences and state

Why: to honor your settings, and so the extension knows whether to prompt you or stay silent when you visit a site.

Local cache (in your browser)

Why: so the extension can surface benefits and enter a held code at checkout quickly, and continue working if our backend is unavailable. This cache resides in your browser; we do not access it except through normal sync.

Device and push data (mobile app)

Why: so time-sensitive alerts — flight cancelled, autopay failed, return window closing — can reach you.

Basic operational logs

Why: to keep the service running and detect abuse. See the Cookies and tracking section for more.

What we do NOT collect

Gray areas — disclosed explicitly

The following practices sit near the edges of the statements above, and we describe them explicitly.

Google user data — Limited Use

ZephyrHQ's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In plain language:

How we protect it

Encryption at rest. Data is encrypted at rest using AWS KMS (customer-managed keys).

Encryption in transit. We use TLS for connections between your device, our servers, and our infrastructure providers, with modern cipher suites. We intend to enable HSTS preload for our production domain at launch.

Field-level encryption for high-sensitivity fields. OAuth tokens are encrypted at the application layer, on top of the at-rest encryption, and can be decrypted only by the specific service that needs them, through scoped key access.

No blanket "zero-access" claim. Some services claim they cannot read any user data; we cannot make that claim — our rules engine reads your account information to determine applicable benefits, and our extraction pipeline reads incoming mail to produce records. The highest-sensitivity fields receive the field-level protection described above; for other data we rely on the remaining controls in this section — access restrictions, logging, and minimal collection.

No PII in URLs. User IDs, email addresses, and account names do not appear in URL paths or query strings. This reduces the risk of leakage through referrer headers, browser history, and server access logs.

We keep personal data out of logs. Our logging is built to strip personal information before it's stored, and we don't use a third-party error-reporting service that would transmit your data off our systems.

Security and operational logs. To run and protect the service, our systems keep security and operational logs that can include IP addresses and request details. We retain them for as long as we need them for security and to meet our legal obligations, and we don't use them to profile you or track your activity for any other purpose.

Internal access controls. Access to user data is restricted to a small number of engineers on a need-to-know basis, logged, and audited. We do not access user data for product research or analytics.

Passwordless sign-in. You sign in with Google or a passkey — a phishing-resistant credential that stays on your device — so there is no password to steal, phish, or reuse. You can add an authenticator app (TOTP) as an additional factor. These options are available on every plan.

Step-up verification for sensitive actions. Even on a signed-in device, actions like deleting your account, changing the email you sign in with, removing a mailbox, or changing your security settings require a fresh proof of identity. Changing the email you sign in with also signs you out everywhere, so every device re-authenticates against the new address.

Sign-in monitoring. We watch for risky sign-ins — a new device or location, impossible travel, known-bad networks, or a password that has turned up in a known breach — and may challenge them or alert your primary email.

Retention

Hard delete, not soft delete. When you delete your account, your account and its data are destroyed, not flagged as deleted and retained. Any copies in our encrypted backups age out on our backup-retention window.

Who can see your data

ZephyrHQ employees and contractors, in limited cases. Engineers with production access may access user data when required for support, debugging, or security investigation. Each access is logged. We do not access user data for product research or analytics. If you contact support and we need to look at your account to assist you, we will tell you.

Infrastructure providers. We run on Amazon Web Services (AWS). Data flows through AWS's systems to be stored, processed, and served back to you. AWS acts as a data processor, not a controller — they can't use your data for their own purposes. We don't use any third-party SaaS vendor that gets bulk access to user data.

AI processing providers. Some extraction and summarization features use AI models. Where a third-party model provider is involved, content is processed transiently to perform the specific task, under contracts that prohibit the provider from retaining your data or using it to train their models. We will list our subprocessors on a public page before launch.

Payment processor. Paid plans are billed through a payment processor (likely Stripe, or Apple if you subscribe in the iOS app). They receive the information needed to bill you — payment method details, the amount, billing address. ZephyrHQ doesn't store your credit card number. The payment processor's handling of that data is governed by their own privacy policy.

No advertisers. No data brokers. No marketing partners. We don't share, sell, rent, license, or otherwise provide your data to any company for advertising, marketing, or data-resale purposes, including in de-identified form. We have no contracts or pipelines built to enable it.

Legal process. If we receive a valid legal request from US authorities (subpoena, court order, search warrant), we may be legally compelled to produce user data. We will:

We cannot promise that we will never comply with a court order; no US company can. We do commit to resisting requests that go beyond what the law requires.

AI and your data

We use AI in two distinct ways, described below.

1. Building the rules engine (internal, does not involve your data). To tell you what a given card includes, we first turn the card's benefit guide into structured data. We use large language models internally to parse public benefit documentation — card terms PDFs, issuer benefit guides, publicly available pages — into structured records, which are reviewed by a person against the source before they ship to users. Your data is not involved in this process — it uses public documents, not your information.

2. Email understanding (involves your connected mail, transiently). If you connect an inbox, AI models classify each message and extract the structured fields described above. For personal mail, AI writes the short summary you see in the app. The model reads the full message to produce the record and does not retain it; the source message itself is kept briefly in encrypted storage (see Retention), then deleted.

We don't use your personal data to train AI models — our own or the third-party models we use, whose agreements prohibit training on your data. If this ever changed, we would ask for your explicit consent and update this policy first, rather than introduce it without notice.

AI output can be wrong. Summaries, extracted fields, and anomaly explanations are machine-generated and can contain mistakes. We design the product to link you back to the source — the Gmail message, the issuer's posted benefit terms, the carrier's published policy — so you can verify before you act.

Your controls

See what we store. The "What we store" screen in settings is a live inventory of exactly what ZephyrHQ holds for your account.

Export your data. At any time, you can download a complete export of everything ZephyrHQ has associated with your account — your accounts, enrichment answers, email-derived records, feed history, settings — in a structured format (JSON). Available from your settings.

Delete your account. From your settings — "Delete account & forget me." We delete your account and its data immediately, and the copies in our backups are purged within our backup-retention window. After that, the data cannot be recovered.

Disconnect an inbox. One tap revokes our access to a connected email account and removes the records we extracted from it (purged within ~7 days). Your mail in Gmail is unaffected.

Delete any record. Every extracted record — a purchase, a bill, a trip — can be removed individually with one click, and is purged within ~7 days. Because we keep our own copy of the extracted information, deleting the original email in Gmail will not remove it here; remove it in the app. "Keep, don't track" removes an item from your active feed without deleting it.

Manage your devices and sessions. On a device you mark as trusted, you stay signed in — like your mail app does; on a device you don't trust, you sign in each time. You can see every device that's stayed signed in and sign any of them out remotely.

Recover your account. We don't use passwords, so there is nothing to reset. If you sign in with Google and lose access to that Google account, use Google's own account recovery to regain access; if you lose a passkey, you can enroll a new one once signed in. We do not bypass your security to restore access. (This concerns regaining access to a live account; deleted data, by contrast, is unrecoverable.)

Notification controls. We do not send advertising. We may send account, service, and re-engagement notifications (for example, a reminder to finish signing up). Critical-alert pushes can be toggled per category (trips, purchases, bills, events, personal) and muted per sender or vendor.

Per-site disable (extension). You can tell the extension to stay entirely quiet on a given site. ZephyrHQ also maintains a default blocklist for sensitive site categories (banking login pages, health portals, etc.) — you can add to it.

Snooze (extension). A temporary mute for the extension's proactive prompts. It does not affect data handling; it only silences the prompt.

Cookies and tracking

First-party only. ZephyrHQ uses cookies only for things the product structurally requires — session cookies to keep you logged in, and a small set of preference cookies. We don't set marketing or advertising cookies.

No third-party trackers. We don't embed Google Analytics, Mixpanel, Segment, Facebook Pixel, Hotjar, Intercom trackers, or other third-party analytics, advertising, session-replay, or attribution tools in our marketing site, web app, mobile app, or extension.

Analytics stays first-party. We don't use third-party analytics. Any product-usage measurement we do (things like landing-page views, extension installs, or feature engagement) uses a self-hosted, first-party tool on our own infrastructure, at an aggregate level that isn't tied to individual users.

No cross-site tracking. We don't track you across other sites, and we don't receive information about which ad or referral brought you to us.

Children

ZephyrHQ is intended only for adults 18 and older. We don't direct the product to minors, we don't knowingly collect data from anyone under 18 (including anyone under 13), and we don't design features for them. If you believe a minor has created an account, contact us at the address below and we'll delete it.

Your privacy rights (US state laws)

Depending on where you live, you may have rights under your state's comprehensive consumer privacy law. As of the last update of this policy, those states include California (CCPA/CPRA), Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and a growing number of others. The exact rights and procedures vary by state, but we extend the substance of the rights below to all users regardless of where they live (see Your controls). This section is the formal statement of those rights.

The rights. Subject to your state's law and its exceptions, you may:

Our practices on the opt-out rights. ZephyrHQ does not sell personal information, does not share it for cross-context behavioral advertising or targeted advertising, and does not use it for profiling that produces legal or similarly significant effects about you. Because we don't do these things, for most users there is nothing to opt out of. Where required by state law, we honor browser-based opt-out preference signals such as Global Privacy Control (GPC).

Sensitive information (consent-based). Several states require your consent before a business processes "sensitive" categories of personal information; California instead gives you a right to limit its use. Because we read your connected email, the records we create can include sensitive information — most notably the contents of your communications, and at times health, financial-account, or precise-location details. We process sensitive information only to provide the features you have asked for, and we do not sell it, use it for advertising, or use it to train AI models. Connecting an inbox — after the plain-language explanation we show you at that step — is how you consent to this processing, and you can withdraw that consent at any time by disconnecting the inbox or deleting the records. See Health and other sensitive information below.

How to exercise your rights. Use the self-serve controls in settings (export, delete, disconnect) — the fastest path — or email privacy@myzephyrhq.com with "Privacy Request" in the subject line. We will respond within the timeframe your state's law requires (generally 45 days, extendable once by a further 45 days with notice). We do not charge for a request unless it is excessive or repetitive, as permitted by law.

Verification and authorized agents. We may need to verify your identity before we act on a request, using information already associated with your account. You may use an authorized agent to submit a request; we may require proof of the agent's authorization and, where permitted, verification of your own identity.

Appeals. If we deny your request, you may appeal by replying to our decision or emailing privacy@myzephyrhq.com with "Privacy Appeal" in the subject line. We will respond with our decision and the reasons for it within the period your state's law requires. If we deny the appeal and your state provides a way to contact its Attorney General, we will tell you how.

Non-discrimination. We won't deny you service, charge you a different price, or provide a different quality of service because you exercised any of these rights.

California specifics (CCPA/CPRA). For California residents, the categories of personal information we collect map to the statutory categories as follows:

CCPA category Do we collect it? Examples
IdentifiersYesemail address, internal user ID, IP address (security only)
Customer records / commercial informationYesaccounts you've added, purchases, bills, benefits
Internet or network activityLimitedde-identified product usage signals; extension per-site state
GeolocationNo precise geolocation(approximate, from IP, for security only)
Audio/visual, biometricNo
Professional, education, protected classificationsNonot intentionally collected
Contents of communicationsYes (sensitive)the records we extract from your connected email
Sensitive personal informationYescontents of communications; financial-account details (e.g. card last four, amounts); health details that appear incidentally
InferencesLimitedbenefit and account recommendations

We collect this information from you and from the accounts and mailboxes you connect; we use it for the business purposes described in What we collect (the Why notes) and AI and your data; we disclose it only to the service providers described in Who can see your data; and we do not sell or share it. You have the right to limit our use of sensitive personal information to the purposes permitted by law — we already limit it to providing the service. We do not offer financial incentives for personal information, and we do not disclose personal information to third parties for their own direct marketing ("Shine the Light").

If you're outside the United States. ZephyrHQ is offered only in the United States at this time. When we expand to other markets, we will add the terms those markets require (for example, GDPR / UK GDPR legal bases, transfer mechanisms, and additional data-subject rights).

Health and other sensitive information

Because ZephyrHQ reads your connected email, health or other sensitive information can pass through it. The following explains what that does and does not entail.

We are not a healthcare provider, and HIPAA does not govern our relationship with you. ZephyrHQ is not a HIPAA "covered entity" or "business associate," and connecting your email does not create a HIPAA relationship. (If we later offer a product that operates in a HIPAA context — for example, helping you appeal a health-insurance denial — we will provide the appropriate notices and agreements for that product at that time. This policy does not cover such a product.)

Sensitive information may appear in your email, and we handle it narrowly. In practice, providers and insurers usually route health details through their own secure portals rather than email, so incidental exposure is limited, though not eliminated, and you may forward sensitive information yourself. When health, financial, or other sensitive details do appear, we process them only to provide the features you've asked for. We do not sell them, use them for advertising, or use them to train AI models.

State consumer-health-data laws. A few states — notably Washington (My Health My Data Act), Nevada, and Connecticut — regulate "consumer health data" broadly, even outside HIPAA. Where these laws apply to you, we commit to: obtaining your consent before collecting consumer health data beyond what is necessary to provide a feature you've requested; not selling consumer health data without your separate, valid authorization; honoring your rights to access, delete, and withdraw consent; and not using geofencing around healthcare facilities (we don't collect precise location at all). Washington residents: where the My Health My Data Act requires it, we will provide additional detail in a separate Consumer Health Data Privacy Policy.

What you can do. You control this data: remove any individual record with one tap, disconnect a mailbox that carries sensitive mail, or decline to connect a sensitive inbox.

Jurisdiction and legal process

ZephyrHQ is a US-based company. Our infrastructure is in the United States, our employees are in the United States, and we're subject to US law.

What this means for you:

What we do about it:

Changes to this policy

We'll update this policy when something material changes. When we do:

How to contact us

We aim to respond to privacy inquiries within 5 business days.


This document is a pre-launch draft undergoing legal review and will be finalized before ZephyrHQ is made generally available.