Zyverna

Privacy Policy

Effective date: 2026-10-07 · Last updated: 2026-10-07

This Privacy Policy explains how Zyverna, Inc. ("Zyverna", "we", "us") collects, uses, discloses and protects personal data when you visit https://zyverna.com, use the Zyverna application, agent features or API (the "Service"), or otherwise interact with us.

We are the controller of personal data about visitors, account holders and billing contacts. When you upload code, files or other content to the Service, we act as a processor on your behalf for any personal data contained in that content, under our Data Processing Addendum.

Summary: We collect what we need to run the Service and bill you. We never sell personal data or use your content to train models. You can access, export or delete your data at any time. Contact [email protected] with questions.

1. Personal data we collect

1.1 Data you provide

CategoryExamplesPurpose
Account dataname, email address, password hash, avatar, organization name, roleCreate and secure your account, communicate with you
Billing databilling name and address, VAT/GST ID, currency, last four digits and brand of card, transaction historyProcess payments, issue invoices, prevent fraud, comply with tax law
Customer Contentprompts, code, files, repository metadata, agent instructions, outputsProvide the Service (as processor)
Communicationssupport tickets, emails, survey responses, feedbackRespond to you, improve the Service
Preferencesselected models, currency, notification and cookie settingsPersonalize your experience

Full payment card numbers are collected directly by our payment processor, Stripe, and never touch our servers.

1.2 Data collected automatically

CategoryExamplesPurpose
Usage datafeatures used, model and token counts, credit consumption, agent run metadata, API endpoint and status codesBilling, abuse prevention, product analytics
Device and log dataIP address, browser type and version, operating system, language, referring URL, timestamps, crash reportsSecurity, debugging, legal compliance
Cookies and similar technologiessession identifiers, consent state, analytics identifiersSee our Cookie Policy

1.3 Data from third parties

If you sign in with Google, GitHub, Microsoft or another identity provider, we receive your name, email and profile picture from that provider. Our payment processor provides us with payment status, risk signals and dispute information. We may receive company information from business data providers for sales and compliance purposes.

2. How we use personal data

We use personal data to:

  • provide, operate, maintain and secure the Service;
  • authenticate you and manage your account and organization;
  • process payments, calculate taxes, issue invoices and manage credits;
  • deliver AI functionality by transmitting your prompts and context to model providers;
  • monitor usage, enforce limits and detect, prevent and investigate fraud, abuse and security incidents;
  • provide customer support and respond to your requests;
  • send transactional messages (receipts, security alerts, service changes) and, with your consent where required, product news and marketing;
  • analyze and improve the Service, develop new features and perform research using aggregated or de-identified data;
  • comply with legal obligations, including tax, accounting, sanctions and law-enforcement requests; and
  • establish, exercise or defend legal claims.

We do not use Customer Content to train or fine-tune machine learning models, and we contractually prohibit our model providers from doing so.

Where the GDPR, UK GDPR or Swiss FADP applies, we rely on the following legal bases:

  • Performance of a contract (Art. 6(1)(b)) — account, billing, providing the Service.
  • Legitimate interests (Art. 6(1)(f)) — security, fraud prevention, analytics, improving the Service, B2B marketing; we balance these interests against your rights.
  • Consent (Art. 6(1)(a)) — non-essential cookies, marketing emails to consumers; you may withdraw consent at any time.
  • Legal obligation (Art. 6(1)(c)) — tax, accounting, responding to lawful requests.

4. How we share personal data

We share personal data only as described below. We do not sell personal data and do not share it for cross-context behavioral advertising.

  • Service providers (subprocessors). Cloud hosting, model inference, payment processing, email delivery, analytics, customer support and error monitoring providers, acting on our instructions under written contracts. The current list is on our Subprocessors page.
  • Model providers. Prompts and context are transmitted to third-party model providers to generate output. Providers are contractually bound to process this data only to provide the service to us, not to train on it, and (where Privacy Mode is enabled) to retain nothing after the response is returned.
  • Payment processor. Stripe processes payments as an independent controller for certain activities (e.g., fraud prevention). See Stripe's Privacy Policy.
  • Organization administrators. If you use the Service through a Business or Scale account, your administrators can access your account information, usage data and workspace content.
  • Legal and safety. When required by law, subpoena or court order, or when we believe disclosure is necessary to protect rights, safety or property, enforce our terms, or investigate fraud or security issues.
  • Business transfers. In connection with a merger, acquisition, financing or sale of assets, subject to confidentiality and this Policy.
  • With your direction. When you integrate third-party services or ask us to share data.

5. International transfers

We are based in the United States and process data in the US and other countries where our subprocessors operate. Where we transfer personal data from the EEA, UK or Switzerland, we rely on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum), adequacy decisions where available (including the EU-US Data Privacy Framework for certified recipients), and supplementary measures such as encryption. You may request a copy of the relevant safeguards at [email protected].

6. Data retention

DataRetention
Account dataLife of the account plus 30 days, then deleted or anonymized
Customer Content (workspaces, chats)Until you delete it or close your account; export available for 30 days after closure, then deleted within 30 days
Prompts sent to model providersNot retained by us beyond the session unless you save the conversation; provider retention is 0 days in Privacy Mode and up to 30 days for abuse monitoring otherwise
Billing records and invoices7 years, as required by tax and accounting law
Usage and security logs12 months (aggregated analytics may be kept longer)
Support communications3 years after the ticket closes
Marketing consent recordsDuration of consent plus 3 years

Backups are encrypted and purged on a rolling 35-day schedule.

7. Security

We use encryption in transit (TLS 1.2+) and at rest (AES-256), role-based access controls, least-privilege principles, audit logging, secrets management, vulnerability scanning, secure software development practices and regular third-party penetration testing. Employee access to Customer Content is restricted to what is necessary for support and operations, is logged, and requires your permission except where required for security or by law. Details are on our Security page. No system is perfectly secure; please report concerns to [email protected].

8. Your rights and choices

Depending on where you live, you may have the right to:

  • access the personal data we hold about you and receive a copy;
  • correct inaccurate or incomplete data;
  • delete your data ("right to be forgotten");
  • port your data to another service in a machine-readable format;
  • restrict or object to certain processing, including direct marketing;
  • withdraw consent at any time without affecting prior processing;
  • opt out of "sale", "sharing" or targeted advertising (we do not engage in these);
  • not be discriminated against for exercising your rights; and
  • lodge a complaint with a supervisory authority.

You can exercise most rights directly in account settings (export, delete account, manage emails) or by emailing [email protected]. We will verify your identity and respond within 30 days (45 days for California residents), extendable where permitted. Authorized agents may submit requests on your behalf with proof of authorization.

8.1 EEA, UK and Switzerland

You may complain to your local data protection authority. Our representative details for Art. 27 GDPR and UK GDPR, once appointed, will be listed here. Until then, contact [email protected].

8.2 California (CCPA/CPRA)

In the preceding 12 months we collected the categories of personal information listed in Section 1 for the purposes in Section 2 and disclosed them to the categories of recipients in Section 4. We do not sell or share personal information, and we have no actual knowledge of selling or sharing data of consumers under 16. We do not use or disclose sensitive personal information for purposes other than those permitted by the CPRA. You have the rights to know, delete, correct, and to limit use of sensitive information, as well as the right to non-discrimination. Submit requests at [email protected] or via account settings.

8.3 Canada (PIPEDA and provincial laws)

We collect, use and disclose personal information with consent, except where permitted by law. You may withdraw consent subject to legal or contractual restrictions, and you may access and challenge the accuracy of your information. You may complain to the Office of the Privacy Commissioner of Canada.

8.4 Other jurisdictions

Residents of Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana and other US states with comprehensive privacy laws, and residents of Australia, Brazil, Japan, Singapore and other countries, may have comparable rights. We honor requests from all users regardless of location to the extent practicable.

9. Marketing communications

You can unsubscribe from marketing emails using the link in each email or in account settings. We will continue to send transactional messages necessary to operate the Service.

10. Do Not Track and Global Privacy Control

We honor Global Privacy Control (GPC) signals as an opt-out of non-essential cookies where legally required. We do not currently respond to "Do Not Track" browser signals because there is no industry standard.

11. Children

The Service is not directed to children under 16 and we do not knowingly collect personal data from them. If you believe a child has provided us personal data, contact [email protected] and we will delete it.

The Service may link to or integrate with third-party websites and services (e.g., GitHub, identity providers). Their privacy practices are governed by their own policies.

13. Changes to this Policy

We will post updates here and revise the "Last updated" date. For material changes we will notify you by email or in-product at least 30 days before they take effect, where required.

14. Contact us

Data Controller: Zyverna, Inc., [Registered Agent Address — provided by Stripe Atlas], Wilmington, DE 19801, United States Privacy inquiries: [email protected] Data Protection contact: [email protected] Security: [email protected]

This document is provided by Zyverna, Inc.. Previous versions are available on request at [email protected].