1. Introduction
This Privacy Policy describes how Zero Computer Company ("z0.ai," "we," "us," or "our") collects, uses, and discloses information about you when you use our AI agent platform and related services (collectively, the "Services"). By using the Services, you agree to the collection and use of information in accordance with this policy.
2. Information We Collect
2.1 Account Information
When you create an account, we collect account identifiers such as email address, display name, authentication identity, tenant and workspace memberships, invitations, roles, and browser session metadata.
2.2 Connected Services and Secrets
You may connect third-party services such as Slack, Composio-managed tools, model providers, approved outbound destinations, and memory providers. We process connection identifiers, installation metadata, credential references, and related configuration so the Services can route work, inject allowed context, and execute approved actions.
2.3 Workspace, Prompt, Run, and Artifact Data
We store customer-managed agent instructions, conversation inputs and replies, prepared prompt packages, included and dropped context metadata, tool calls, approval decisions, denials, run status, retry and checkpoint records, sandbox snapshot artifacts, and other execution records needed to operate and inspect agent runs.
2.4 Usage Data
We collect usage and billing data including credit balances, reservations, settlements, rate-card usage, run compute, model token accounting, Composio tool-call charges, billing account status, subscription plan, and related ledger metadata.
2.5 Analytics and Cookies
We use cookies for authentication and session management. We may use service logs and privacy-focused analytics to understand aggregate usage patterns, debug failures, and secure the Services. We do not use third-party tracking or advertising cookies.
2.6 Billing Information (Paid Plans)
If you subscribe to a paid tier, we and Stripe process billing metadata including name, email, subscription status, plan code, payment method metadata, customer ID, checkout session, invoice history, and webhook events. We do not store full payment card numbers in our systems.
3. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve the Services
- Authenticate users and manage accounts
- Create tenants, workspaces, agents, Slack routes, and integration bindings
- Prepare prompts, execute runs, preserve checkpoints, and inspect failures
- Admit runs against budgets and settle credit usage
- Run connected workflows
- Send service-related communications (outages, updates, security alerts)
- Respond to support requests and customer inquiries
- Prevent fraud and abuse
- Comply with legal obligations
We do not train foundation models on customer data or sell customer information.
4. Data Sharing and Subprocessors
4.1 Hosting and Infrastructure Providers
We use hosting and infrastructure providers to operate the Services, including control-plane APIs, databases, runner backends, artifacts, logs, and network services. These providers process data only as needed to provide their infrastructure services to us.
4.2 Payment Processing (Stripe)
We use Stripe, Inc.(United States) as a payment processor and subprocessor for paid plans. Stripe processes payment and billing information on our behalf under its own privacy and security standards. Review Stripe's Privacy Policy.
4.3 CDN and Edge Infrastructure
We may use CDN, traffic security, and network edge services to deliver and protect the Services.
4.4 AI Model Providers
When you use AI models through the Services, prompts and model responses are sent to the model provider used by the configured runtime, such as Anthropic or OpenAI. Each provider has its own data policies. Review their policies before use:
We are not responsible for how AI model providers handle your data under their own policies. You are responsible for reviewing and accepting each provider's terms before use.
4.5 Other Disclosures
We may disclose your information if required by law, to protect our rights, prevent fraud, or comply with legal processes (subpoenas, court orders, etc.).
5. Data Retention
We retain account, tenant, workspace, run, artifact, usage, billing, integration, and audit records for as long as needed to provide the Services, satisfy legal obligations, resolve disputes, maintain security, and enforce agreements.
When a tenant admin or workspace admin deletes a tenant or workspace, the affected records enter a 30-day soft-delete state. During that window the records are hidden from all customer-facing access paths but remain in our encrypted-at-rest databases so core records can be restored by support if the customer changes their mind. Restored Slack app access and channel routes may require reauthorization or reconfiguration, and generated apps may need to be recreated or redeployed. After 30 days, an automated process hard-deletes the records and the associated runtime volumes. Tenant deletion also immediately attempts tenant-level Slack OAuth token revocation; workspace deletion disables workspace Slack routes and installation records.
6. Security
We implement industry-standard security measures including:
- Tenant and workspace authorization checks
- Brokered model egress for sandboxed Codex and Claude runs
- Approved-destination controls for outbound network access
- Policy evaluation and approval flows for mutating tool actions
- Secret handling for connected services and runtime credentials
- Encryption in transit (TLS 1.2+)
- Durable audit, run, approval, usage, checkpoint, and snapshot records
However, no system is 100% secure. You are responsible for securing your account credentials and connected service access.
7. Your Rights
You may request access, correction, deletion, or export of your personal data. Additional rights may apply based on your jurisdiction (including GDPR and CCPA):
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate data
- Deletion: Request deletion of your account and data
- Portability: Export applicable data
- Objection: Object to certain data processing
- Restriction: Restrict processing of your data
To exercise these rights, contact us at privacy@z0.ai.
8. International Transfers
We and our service providers may process information in countries other than where you reside. Where required, we rely on appropriate transfer mechanisms for international data transfers.
9. Children's Privacy
The Services are not intended for users under 18 years of age. We do not knowingly collect personal information from children. If you believe we have collected information from a child, contact us immediately.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or through the Services. The "Last updated" date at the top reflects the most recent version. Continued use of the Services after changes constitutes acceptance of the updated policy.
11. Contact Us
If you have questions about this Privacy Policy or our data practices, contact us at privacy@z0.ai.