Privacy Policy
Last updated September 2026
Who we are
ZimalAI is operated by [LEGAL ENTITY NAME], [ADDRESS]. Questions about this policy or your data: [PRIVACY CONTACT EMAIL].
What we collect
- Account data. Your email address and, if you sign in with Google, your name and profile picture.
- Profile data you give us. Business name, industry, target audience, and goals.
- Content you upload. Documents, URLs, notes, and transcripts you add to your Knowledge Vault, plus the numerical representations (embeddings) we derive from them.
- Connected platform data. If you connect an account, read-only metadata about your own posts and their performance.
How we use it
To analyse your content, generate drafts in your voice, produce your Content Strength Score, and operate and secure the service. We do not sell your data, and we do not use your content to train foundation models.
Google user data and Limited Use
ZimalAI's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
- We request read-only YouTube scopes. We never upload, edit, or delete your videos, and never post on your behalf.
- Google user data is used solely to provide the content analysis and scoring features you asked for.
- We do not transfer Google user data to third parties except as needed to provide the service, comply with law, or as part of a merger with your notice.
- We do not use Google user data for advertising, and no humans read it except with your explicit consent, for security, or where required by law.
Sub-processors
We share the minimum necessary data with: Supabase (database, auth, file storage), Vercel (hosting), Anthropic (content generation and analysis), OpenAI (embeddings), and Tavily (web research). Each processes data only on our instructions.
Retention and deletion
We keep your data while your account is open. Delete an individual Vault item at any time and it is removed along with its embeddings. Disconnect a platform and we delete the stored access tokens. Email [PRIVACY CONTACT EMAIL] to delete your account and we will erase your data within 30 days.
Your rights
Depending on where you live you may have rights to access, correct, export, or delete your personal data, and to object to processing. Contact [PRIVACY CONTACT EMAIL] and we will respond within 30 days.
Security
Data is encrypted in transit and at rest. OAuth tokens are stored in a table that application users cannot read; only our backend can access them.
Changes
If we make a material change we will notify you by email before it takes effect.