Privacy Policy
Last updated 2026-09-10
This policy explains what personal data Zetra, Inc. collects through Zetra, why, and what your options are. It covers two different groups of people: workspace users (you, if you have a Zetra account) and end users (the people who chat with an agent you've deployed).
1. Data we collect from workspace users
- Account data: name, email address, and a hashed password (or a Google account identifier if you sign up with Google — we never see your Google password).
- Workspace content: the documents, website content, text snippets, and Q&A pairs you upload to train an agent; agent instructions and settings; any third-party credentials you enter to connect an integration.
- Usage data: IP address and timestamps recorded on security-relevant actions (login, invites, API key changes) for audit purposes; general request logs kept by our hosting infrastructure.
- Payment data: if you subscribe to a paid plan, billing is handled by our payment processor (see Subprocessors) — we don't store your card number ourselves.
2. Data we collect from end users of your agent
When someone chats with an agent you've deployed, we process their messages in order to generate a response, and store the conversation so you can review it. If your agent has a lead-capture form enabled, we store whatever the visitor submits (typically name, email, and/or phone number). This data belongs to you as the workspace owner — we process it on your behalf, not for our own purposes.
3. How we use data
- To operate the Service: generating agent responses, running the retrieval pipeline, sending notifications you've configured (webhooks, Slack, email).
- To secure the Service: detecting abuse, enforcing rate limits, investigating security incidents.
- To communicate with you: service updates, security notices, and (only if you opt in) product updates.
- We do not sell personal data, and we do not use your workspace content to train AI models we operate ourselves.
4. Third parties we share data with
Generating an AI response requires sending relevant parts of your content to the AI model provider your agent is configured to use. If you connect an integration (Slack, Zendesk, WhatsApp, Shopify, etc.), data flows to that third party using credentials you provide, under that third party's own terms. The full, current list is on our Subprocessors page.
5. Data retention and deletion
Workspace content is retained until you delete it. You can delete an individual agent, or delete all conversations for an agent, at any time from that agent's Settings — this is immediate and permanent. There is currently no fully self-service "delete my entire account" flow; email [email protected] to request full account and workspace deletion, and we'll confirm once it's done.
6. Your rights
Depending on where you're located, you may have rights to access, correct, export, or delete your personal data, and to object to certain processing. [Placeholder — requires legal counsel] The specific legal basis and rights framework (GDPR, CCPA, or another regime) depends on where Zetra, Inc. operates and where its users are located — counsel should confirm which applies and finalize the exact language. To exercise any of these rights, contact [email protected].
7. Cookies
We use a single essential, httpOnly session cookie to keep you signed in — it's not used for advertising or cross-site tracking, and it's not readable by client-side scripts. We don't currently use analytics or advertising cookies on the marketing site.
8. Changes to this policy
If we make material changes to this policy, we'll update the "Last updated" date above and, where required, notify you directly.
9. Contact
Questions about this policy can be sent to [email protected] or via our contact page.