Privacy
Privacy policy.
Last updated 2026-07-14 · Version 2.2
ZephyrHQ helps you see the benefits your accounts — such as credit cards, memberships, carriers, and insurers — already provide, and monitors your connected email inbox for time-sensitive events such as flight changes, closing return windows, unusual bills, and denied refunds.
To provide these features, we need to know which accounts you hold and, if you connect your email, to read the confirmations and notices those accounts send you. This policy explains what information we collect, how we use it, what we do not collect, and the choices available to you.
This Privacy Policy applies to your use of ZephyrHQ and should be read together with our Terms of Service. If you have questions about it, contact us at privacy@myzephyrhq.com.
Summary
- We store what you have, not what you do. We store the accounts you add and the information we extract from your email (such as a trip, a bill, or a promotional code), not a log of your activity.
- Your email stays in Gmail. We access it read-only, keep the information we extract, and hold the original message only briefly before deleting it. Gmail remains your permanent copy.
- No third-party trackers in our applications or on our site.
- We don't sell your personal information.
- We don't use your data to train AI models — our own or our providers'.
- Deletion is permanent. When you delete your account, your data is removed, including from backups. You can export your data at any time.
- We're a US company and are subject to US legal process (see Jurisdiction and legal process below).
What we collect
Everything in this list is tied to your account and used to operate the product. We do not maintain a separate marketing or analytics collection outside this list. The "What we store" screen in your settings is a live version of this section.
Account identity
- Email address (your primary address — the one you sign in with and where we send account notices), how you sign in (Google or a passkey), internal user ID, and the date you created your account.
Why: so you can sign in and so we can associate your data with the correct account.
Your accounts — the ones you've told us about
- The list of accounts you've added (e.g. "Chase," "T-Mobile Go5G Plus," "NYPL," "UnitedHealthcare").
Why: we can't show your benefits without knowing your accounts.
Enrichment answers
- Your responses to per-account differentiator questions (e.g. "which Chase cards do you have?", "which T-Mobile plan?").
Why: benefits vary by tier and product. These answers let us surface accurate benefits instead of generic ones.
Email-derived records (only if you connect an inbox)
- You connect an email account through your provider's authorization. For Gmail — the only provider supported at launch — this is Google's OAuth, which grants us read-only access to your mail without sharing your password. When you first connect, we process your existing mail — how far back we reach depends on your plan, up to your entire history — and then new mail as it arrives, extracting structured records into a small set of categories: trips and events, purchases, bills, promotions, reading, personal mail, and background noise. Each record contains only the fields its category needs — a purchase record holds the merchant, item description, date, amount, the card used, and the return window; a trip record holds the airline or hotel, confirmation code, dates, and location.
- We keep the original message (body and attachments) in encrypted storage for a short window so we can re-process it if needed, then delete it automatically. We also keep the Gmail message ID to link you back to the message and re-fetch it. In the extracted records, product images are stored as a vendor link, not the file.
- For personal mail (messages from an individual rather than an automated sender), we store the sender, subject, and a short AI-generated summary so the app can indicate what is awaiting your attention. The message body follows the short-window storage described above.
- You can connect more than one inbox; the same rules apply to each.
- If we add other providers (such as Outlook, Yahoo, or iCloud), some may connect through a different method — for example, IMAP with an app-specific password rather than OAuth. Because that would change what we receive, we will update this policy, including the No credentials statement below, before we support it.
Why: this powers the trips, purchases, bills, promotions, reading, and personal surfaces: we reconstruct the useful information and leave the underlying mail in Gmail.
OAuth tokens
- The tokens that let us read your connected Gmail account(s) and, if you connect it, your calendar. Stored with field-level encryption; see How we protect it.
Why: without them, we can't read your inbox. We do not see or store your Google password. Our Gmail authorization is read-only on your mail content (see Google user data); it does not include permission to label, modify, delete, or send mail.
Calendar data (optional)
- If you connect your calendar, we read event titles, dates, and locations with read-only access to associate trips and events with what's already on your schedule. When you add something to your calendar from ZephyrHQ, it happens through your device's own calendar (a deep link or share sheet); we do not write to your calendar ourselves.
Why: so a flight confirmation and the matching calendar entry become one trip, not two. Reading live keeps the dates we show you current.
Intelligence feed history
- A history of the items we've surfaced to you (expiring credits, duplications we detected, enrollment gaps, trip disruptions, anomalous bills, refund denials, etc.), kept while your account is active.
Why: so your feed has continuity, so you can scroll back, and so we don't re-surface the same item repeatedly.
Preferences and state
- Notification preferences (per-category critical-alert toggles, per-sender mutes), custom categories you've defined, snooze timestamps, your plan/subscription status, and — for the extension — which state each known account site is in for you (tracked, or not tracking).
Why: to honor your settings, and so the extension knows whether to prompt you or stay silent when you visit a site.
Local cache (in your browser)
- A copy of your accounts, active benefits, and held promotion codes stored in
chrome.storageon your own device.
Why: so the extension can surface benefits and enter a held code at checkout quickly, and continue working if our backend is unavailable. This cache resides in your browser; we do not access it except through normal sync.
Device and push data (mobile app)
- Device type, OS version, and a push notification token if you enable notifications, lock screen widgets, or Live Activities.
Why: so time-sensitive alerts — flight cancelled, autopay failed, return window closing — can reach you.
Basic operational logs
- De-identified, aggregated usage signals (e.g. "the extension popup was opened," "a feed item was clicked") with no personal content attached.
- Security and operational logs, which can include IP addresses and request details, used to run and protect the service.
Why: to keep the service running and detect abuse. See the Cookies and tracking section for more.
What we do NOT collect
- No credentials. We do not ask for, receive, or store passwords, PINs, or two-factor codes for any third-party site. ZephyrHQ does not log into your bank, your carrier, your insurer, or anything else on your behalf. Email and calendar access happens through OAuth — your email provider holds your password, not us.
- No bank or card connections. We don't connect to your bank or card issuer, and we don't pull data directly from any financial institution. What we know comes from what you've told us, from public benefit documentation, and from the bills and receipts in the email you've chosen to connect — which do include amounts and balances (see Gray areas below).
- No browsing history. We don't build a log of the sites you visit. The extension only reacts when you're on a site that's on our curated list of known account sites — and even then, we don't store a timestamped log of those visits.
- No page content. When you're on a merchant site, we detect that you're there and surface relevant benefits or held codes. We don't scrape the page, read form fields, or capture what's in your cart.
- No cookie contents. The extension checks whether a session cookie exists on a known site to determine if you're logged in. We do not read the cookie's value or transmit it.
- Device permissions only when a feature needs them. We don't use your contacts, address book, or microphone. If a feature you use ever needs your camera (for example, to photograph a receipt) or your location, your device will ask you first, and we'll use it only for that feature.
- No name, phone number, or mailing address at signup. Email is all we ask for. If you use Google sign-in, we receive the email address associated with that account and nothing else.
- No full card numbers. We do not ask you to enter a card number. When we detect the last four digits in a receipt, we ask you to identify the card; that is all we store.
- No passwords, no Facebook auth. You sign in with Google or with a passkey — we don't use passwords, and we don't support Facebook login.
Gray areas — disclosed explicitly
The following practices sit near the edges of the statements above, and we describe them explicitly.
- Email-derived purchase and bill amounts. We have no connection to your bank, so we do not pull your transactions. But if you connect your inbox, the records we extract from receipts and bills include dollar amounts (and, for bills, balances), merchants, and the card you used — spending data sourced from your email rather than your bank. We retain it because the product cannot flag a closing return window or an unusual bill without it. You retain control: any record can be deleted individually.
- We read the full message to extract from it. Classifying a message and extracting its fields requires our systems (including AI models) to read the entire message, not only its headers. We keep the raw message only briefly, then delete it (see What we collect and Retention); the extracted records are kept longer, and Gmail remains your permanent copy.
- People who email you. Personal-mail records can include the names and email addresses of people who write to you — people who are not ZephyrHQ users and have not agreed to this policy. We hold only what arrived in your inbox (sender, subject, a summary), we use it only to show you your own mail, and it is deleted with the record, the inbox connection, or your account.
Google user data — Limited Use
ZephyrHQ's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In plain language:
- We use Gmail and Calendar data only to provide the features you see in ZephyrHQ — not for advertising, not for sale, and not to train generalized AI models.
- We do not transfer your Google data, or the records we derive from it, to anyone except the service providers that process it on our behalf to deliver those features (under contracts that bind them to these same restrictions), for security purposes, or to comply with law. If ZephyrHQ is ever part of a merger, acquisition, or sale of assets, we will not transfer your Google user data as part of that transaction without your explicit prior consent.
- We never use your Google data — or anything we derive from it — to determine credit-worthiness or for lending, and we do not transfer or sell it to advertising platforms, data brokers, or information resellers.
- Our employees, contractors, and any successor in interest are bound to handle Google user data under these same requirements.
- Humans at ZephyrHQ do not read your email data except with your affirmative agreement to view specific messages (for example, a support request you initiate), for security purposes (such as investigating abuse), or as required by law.
- What we can do with your Gmail: read your mail. That is the full extent of the authorization — read-only access to your messages.
- What we cannot do with your Gmail: we do not label, modify, delete, or send mail from your Gmail account. We did not request — and do not hold — permission to do any of those things.
- Calendar is read-only. We read it to keep dates current; we do not write to it (see What we collect).
- We do not send email on your behalf. Our Gmail authorization does not include permission to send, and we do not send mail from your account.
- Organizing your Gmail in place is a future add-on. Labeling or archiving mail within Gmail would require additional permission. It is not part of launch; if we add it, it will be opt-in and separately disclosed.
How we protect it
Encryption at rest. Data is encrypted at rest using AWS KMS (customer-managed keys).
Encryption in transit. We use TLS for connections between your device, our servers, and our infrastructure providers, with modern cipher suites. We intend to enable HSTS preload for our production domain at launch.
Field-level encryption for high-sensitivity fields. OAuth tokens are encrypted at the application layer, on top of the at-rest encryption, and can be decrypted only by the specific service that needs them, through scoped key access.
No blanket "zero-access" claim. Some services claim they cannot read any user data; we cannot make that claim — our rules engine reads your account information to determine applicable benefits, and our extraction pipeline reads incoming mail to produce records. The highest-sensitivity fields receive the field-level protection described above; for other data we rely on the remaining controls in this section — access restrictions, logging, and minimal collection.
No PII in URLs. User IDs, email addresses, and account names do not appear in URL paths or query strings. This reduces the risk of leakage through referrer headers, browser history, and server access logs.
We keep personal data out of logs. Our logging is built to strip personal information before it's stored, and we don't use a third-party error-reporting service that would transmit your data off our systems.
Security and operational logs. To run and protect the service, our systems keep security and operational logs that can include IP addresses and request details. We retain them for as long as we need them for security and to meet our legal obligations, and we don't use them to profile you or track your activity for any other purpose.
Internal access controls. Access to user data is restricted to a small number of engineers on a need-to-know basis, logged, and audited. We do not access user data for product research or analytics.
Passwordless sign-in. You sign in with Google or a passkey — a phishing-resistant credential that stays on your device — so there is no password to steal, phish, or reuse. You can add an authenticator app (TOTP) as an additional factor. These options are available on every plan.
Step-up verification for sensitive actions. Even on a signed-in device, actions like deleting your account, changing the email you sign in with, removing a mailbox, or changing your security settings require a fresh proof of identity. Changing the email you sign in with also signs you out everywhere, so every device re-authenticates against the new address.
Sign-in monitoring. We watch for risky sign-ins — a new device or location, impossible travel, known-bad networks, or a password that has turned up in a known breach — and may challenge them or alert your primary email.
Retention
- Raw messages: the original message (body and attachments) is kept in encrypted storage for a short period, then automatically deleted. It exists only so we can re-process recent mail; Gmail remains your permanent copy.
- Extracted records: kept for a period that depends on the record's type — for example, financial records up to about a year, promotions about 30 days (or until the offer expires), and most others about 90 days by default — then automatically deleted.
- Deleting an email in Gmail does not delete our record. The product retains the extracted fact — the receipt, the trip, the bill — rather than mirroring your inbox. To remove a record from ZephyrHQ, remove it in the app.
- Removed records: when you delete a record (or disconnect the inbox it came from), it — along with any raw message we still hold for it — is removed from your live view immediately and purged from our live systems within roughly 7 days (encrypted backups age out on our backup-retention window).
- Deleted account: hard-deleted from live systems immediately, and purged from backups within our backup-retention window.
- Security and operational logs: kept as long as needed for security and to meet legal obligations.
- Intelligence feed history: deleted with your account.
Hard delete, not soft delete. When you delete your account, your account and its data are destroyed, not flagged as deleted and retained. Any copies in our encrypted backups age out on our backup-retention window.
Who can see your data
ZephyrHQ employees and contractors, in limited cases. Engineers with production access may access user data when required for support, debugging, or security investigation. Each access is logged. We do not access user data for product research or analytics. If you contact support and we need to look at your account to assist you, we will tell you.
Infrastructure providers. We run on Amazon Web Services (AWS). Data flows through AWS's systems to be stored, processed, and served back to you. AWS acts as a data processor, not a controller — they can't use your data for their own purposes. We don't use any third-party SaaS vendor that gets bulk access to user data.
AI processing providers. Some extraction and summarization features use AI models. Where a third-party model provider is involved, content is processed transiently to perform the specific task, under contracts that prohibit the provider from retaining your data or using it to train their models. We will list our subprocessors on a public page before launch.
Payment processor. Paid plans are billed through a payment processor (likely Stripe, or Apple if you subscribe in the iOS app). They receive the information needed to bill you — payment method details, the amount, billing address. ZephyrHQ doesn't store your credit card number. The payment processor's handling of that data is governed by their own privacy policy.
No advertisers. No data brokers. No marketing partners. We don't share, sell, rent, license, or otherwise provide your data to any company for advertising, marketing, or data-resale purposes, including in de-identified form. We have no contracts or pipelines built to enable it.
Legal process. If we receive a valid legal request from US authorities (subpoena, court order, search warrant), we may be legally compelled to produce user data. We will:
- Push back on overbroad or improper requests through our legal counsel.
- Produce the narrowest possible response that complies with the order.
- Notify affected users whenever we are legally permitted to do so.
- Not build capabilities specifically to enable bulk surveillance.
We cannot promise that we will never comply with a court order; no US company can. We do commit to resisting requests that go beyond what the law requires.
AI and your data
We use AI in two distinct ways, described below.
1. Building the rules engine (internal, does not involve your data). To tell you what a given card includes, we first turn the card's benefit guide into structured data. We use large language models internally to parse public benefit documentation — card terms PDFs, issuer benefit guides, publicly available pages — into structured records, which are reviewed by a person against the source before they ship to users. Your data is not involved in this process — it uses public documents, not your information.
2. Email understanding (involves your connected mail, transiently). If you connect an inbox, AI models classify each message and extract the structured fields described above. For personal mail, AI writes the short summary you see in the app. The model reads the full message to produce the record and does not retain it; the source message itself is kept briefly in encrypted storage (see Retention), then deleted.
We don't use your personal data to train AI models — our own or the third-party models we use, whose agreements prohibit training on your data. If this ever changed, we would ask for your explicit consent and update this policy first, rather than introduce it without notice.
AI output can be wrong. Summaries, extracted fields, and anomaly explanations are machine-generated and can contain mistakes. We design the product to link you back to the source — the Gmail message, the issuer's posted benefit terms, the carrier's published policy — so you can verify before you act.
Your controls
See what we store. The "What we store" screen in settings is a live inventory of exactly what ZephyrHQ holds for your account.
Export your data. At any time, you can download a complete export of everything ZephyrHQ has associated with your account — your accounts, enrichment answers, email-derived records, feed history, settings — in a structured format (JSON). Available from your settings.
Delete your account. From your settings — "Delete account & forget me." We delete your account and its data immediately, and the copies in our backups are purged within our backup-retention window. After that, the data cannot be recovered.
Disconnect an inbox. One tap revokes our access to a connected email account and removes the records we extracted from it (purged within ~7 days). Your mail in Gmail is unaffected.
Delete any record. Every extracted record — a purchase, a bill, a trip — can be removed individually with one click, and is purged within ~7 days. Because we keep our own copy of the extracted information, deleting the original email in Gmail will not remove it here; remove it in the app. "Keep, don't track" removes an item from your active feed without deleting it.
Manage your devices and sessions. On a device you mark as trusted, you stay signed in — like your mail app does; on a device you don't trust, you sign in each time. You can see every device that's stayed signed in and sign any of them out remotely.
Recover your account. We don't use passwords, so there is nothing to reset. If you sign in with Google and lose access to that Google account, use Google's own account recovery to regain access; if you lose a passkey, you can enroll a new one once signed in. We do not bypass your security to restore access. (This concerns regaining access to a live account; deleted data, by contrast, is unrecoverable.)
Notification controls. We do not send advertising. We may send account, service, and re-engagement notifications (for example, a reminder to finish signing up). Critical-alert pushes can be toggled per category (trips, purchases, bills, events, personal) and muted per sender or vendor.
Per-site disable (extension). You can tell the extension to stay entirely quiet on a given site. ZephyrHQ also maintains a default blocklist for sensitive site categories (banking login pages, health portals, etc.) — you can add to it.
Snooze (extension). A temporary mute for the extension's proactive prompts. It does not affect data handling; it only silences the prompt.
Cookies and tracking
First-party only. ZephyrHQ uses cookies only for things the product structurally requires — session cookies to keep you logged in, and a small set of preference cookies. We don't set marketing or advertising cookies.
No third-party trackers. We don't embed Google Analytics, Mixpanel, Segment, Facebook Pixel, Hotjar, Intercom trackers, or other third-party analytics, advertising, session-replay, or attribution tools in our marketing site, web app, mobile app, or extension.
Analytics stays first-party. We don't use third-party analytics. Any product-usage measurement we do (things like landing-page views, extension installs, or feature engagement) uses a self-hosted, first-party tool on our own infrastructure, at an aggregate level that isn't tied to individual users.
No cross-site tracking. We don't track you across other sites, and we don't receive information about which ad or referral brought you to us.
Children
ZephyrHQ is intended only for adults 18 and older. We don't direct the product to minors, we don't knowingly collect data from anyone under 18 (including anyone under 13), and we don't design features for them. If you believe a minor has created an account, contact us at the address below and we'll delete it.
Your privacy rights (US state laws)
Depending on where you live, you may have rights under your state's comprehensive consumer privacy law. As of the last update of this policy, those states include California (CCPA/CPRA), Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and a growing number of others. The exact rights and procedures vary by state, but we extend the substance of the rights below to all users regardless of where they live (see Your controls). This section is the formal statement of those rights.
The rights. Subject to your state's law and its exceptions, you may:
- Know and access — confirm whether we process your personal information and obtain the categories we collect, the sources, the purposes, the categories we disclose to, and a copy of the information itself. The What we collect and Who can see your data sections are that disclosure; the self-serve export in settings is the fastest way to get your copy.
- Correct — ask us to fix inaccurate personal information.
- Delete — ask us to delete your personal information, subject to legal exceptions. The self-serve account delete is the fastest path.
- Obtain a portable copy — receive your data in a portable, machine-readable format (the export is JSON).
- Opt out of sale, targeted advertising, and certain profiling — see our practices immediately below.
Our practices on the opt-out rights. ZephyrHQ does not sell personal information, does not share it for cross-context behavioral advertising or targeted advertising, and does not use it for profiling that produces legal or similarly significant effects about you. Because we don't do these things, for most users there is nothing to opt out of. Where required by state law, we honor browser-based opt-out preference signals such as Global Privacy Control (GPC).
Sensitive information (consent-based). Several states require your consent before a business processes "sensitive" categories of personal information; California instead gives you a right to limit its use. Because we read your connected email, the records we create can include sensitive information — most notably the contents of your communications, and at times health, financial-account, or precise-location details. We process sensitive information only to provide the features you have asked for, and we do not sell it, use it for advertising, or use it to train AI models. Connecting an inbox — after the plain-language explanation we show you at that step — is how you consent to this processing, and you can withdraw that consent at any time by disconnecting the inbox or deleting the records. See Health and other sensitive information below.
How to exercise your rights. Use the self-serve controls in settings (export, delete, disconnect) — the fastest path — or email privacy@myzephyrhq.com with "Privacy Request" in the subject line. We will respond within the timeframe your state's law requires (generally 45 days, extendable once by a further 45 days with notice). We do not charge for a request unless it is excessive or repetitive, as permitted by law.
Verification and authorized agents. We may need to verify your identity before we act on a request, using information already associated with your account. You may use an authorized agent to submit a request; we may require proof of the agent's authorization and, where permitted, verification of your own identity.
Appeals. If we deny your request, you may appeal by replying to our decision or emailing privacy@myzephyrhq.com with "Privacy Appeal" in the subject line. We will respond with our decision and the reasons for it within the period your state's law requires. If we deny the appeal and your state provides a way to contact its Attorney General, we will tell you how.
Non-discrimination. We won't deny you service, charge you a different price, or provide a different quality of service because you exercised any of these rights.
California specifics (CCPA/CPRA). For California residents, the categories of personal information we collect map to the statutory categories as follows:
| CCPA category | Do we collect it? | Examples |
|---|---|---|
| Identifiers | Yes | email address, internal user ID, IP address (security only) |
| Customer records / commercial information | Yes | accounts you've added, purchases, bills, benefits |
| Internet or network activity | Limited | de-identified product usage signals; extension per-site state |
| Geolocation | No precise geolocation | (approximate, from IP, for security only) |
| Audio/visual, biometric | No | — |
| Professional, education, protected classifications | No | not intentionally collected |
| Contents of communications | Yes (sensitive) | the records we extract from your connected email |
| Sensitive personal information | Yes | contents of communications; financial-account details (e.g. card last four, amounts); health details that appear incidentally |
| Inferences | Limited | benefit and account recommendations |
We collect this information from you and from the accounts and mailboxes you connect; we use it for the business purposes described in What we collect (the Why notes) and AI and your data; we disclose it only to the service providers described in Who can see your data; and we do not sell or share it. You have the right to limit our use of sensitive personal information to the purposes permitted by law — we already limit it to providing the service. We do not offer financial incentives for personal information, and we do not disclose personal information to third parties for their own direct marketing ("Shine the Light").
If you're outside the United States. ZephyrHQ is offered only in the United States at this time. When we expand to other markets, we will add the terms those markets require (for example, GDPR / UK GDPR legal bases, transfer mechanisms, and additional data-subject rights).
Health and other sensitive information
Because ZephyrHQ reads your connected email, health or other sensitive information can pass through it. The following explains what that does and does not entail.
We are not a healthcare provider, and HIPAA does not govern our relationship with you. ZephyrHQ is not a HIPAA "covered entity" or "business associate," and connecting your email does not create a HIPAA relationship. (If we later offer a product that operates in a HIPAA context — for example, helping you appeal a health-insurance denial — we will provide the appropriate notices and agreements for that product at that time. This policy does not cover such a product.)
Sensitive information may appear in your email, and we handle it narrowly. In practice, providers and insurers usually route health details through their own secure portals rather than email, so incidental exposure is limited, though not eliminated, and you may forward sensitive information yourself. When health, financial, or other sensitive details do appear, we process them only to provide the features you've asked for. We do not sell them, use them for advertising, or use them to train AI models.
State consumer-health-data laws. A few states — notably Washington (My Health My Data Act), Nevada, and Connecticut — regulate "consumer health data" broadly, even outside HIPAA. Where these laws apply to you, we commit to: obtaining your consent before collecting consumer health data beyond what is necessary to provide a feature you've requested; not selling consumer health data without your separate, valid authorization; honoring your rights to access, delete, and withdraw consent; and not using geofencing around healthcare facilities (we don't collect precise location at all). Washington residents: where the My Health My Data Act requires it, we will provide additional detail in a separate Consumer Health Data Privacy Policy.
What you can do. You control this data: remove any individual record with one tap, disconnect a mailbox that carries sensitive mail, or decline to connect a sensitive inbox.
Jurisdiction and legal process
ZephyrHQ is a US-based company. Our infrastructure is in the United States, our employees are in the United States, and we're subject to US law.
What this means for you:
- US law enforcement can compel disclosure of user data through legal process (subpoena, court order, warrant). We can't opt out of that by writing a privacy policy.
- We're subject to US surveillance laws, including provisions that can, in narrow circumstances, compel providers to produce data or assist investigations under gag orders.
- We are not based in a jurisdiction with stronger constitutional data-privacy protections, such as Switzerland or Iceland.
What we do about it:
- We collect as little data as we can, we keep raw mail only briefly (encrypted) before deleting it, and Gmail remains your permanent copy. A court can only compel us to produce data we actually hold.
- We push back on overbroad or improper requests through counsel.
- We notify affected users whenever we're legally allowed to.
- We don't build backdoors, bulk-surveillance capabilities, or government-specific access mechanisms.
- We'll publish a transparency report once we have sufficient operating history to do so.
Changes to this policy
We'll update this policy when something material changes. When we do:
- We'll update the "Last updated" date and version at the top.
- We'll send an email to every active user before the change takes effect, describing what's changing in plain language.
- We'll keep a public changelog of past versions so you can see what changed and when.
- Core protections (no third-party trackers, no data sale, no personal data used for AI training, encryption of stored data, hard delete) won't be weakened without a version change and clear notice to you.
How to contact us
- General privacy questions: privacy@myzephyrhq.com
- Data access, export, or deletion requests: privacy@myzephyrhq.com (but the fastest path is the self-serve controls in your settings)
- Security vulnerability disclosures: security@myzephyrhq.com
- Legal process: legal@myzephyrhq.com
We aim to respond to privacy inquiries within 5 business days.
This document is a pre-launch draft undergoing legal review and will be finalized before ZephyrHQ is made generally available.