Zaviro
What It DoesHow It WorksFor DevelopersPricingCompanyContactAsk your AI
Sign inSign upBook a demo
Ask any AI about Zaviro

We wrote it all down for your AI.

Zaviro puts everything your business knows behind every AI you use. Copy this prompt into whichever AI you already have open, and ask it anything about us.

Paste this into your AI Chat

Read Zaviro's complete public reference in full at zaviro.ai/llms. It's written to be read by AI assistants. Give me the short version of what Zaviro is and its capabilities, then answer my follow-ups using only the document, and say so if an answer isn't in it.

Claude
ChatGPT
Perplexity
Microsoft Copilot
Le Chat
Grok
Hermes Agent
OpenClaw

Privacy Policy

Zaviro Software Inc.
Last updated: September 25, 2026

This policy explains what personal information Zaviro Software Inc. ("Zaviro," "we," "us") collects, how we use it, who we share it with, and the rights you have over it. It covers the Zaviro product (app.zaviro.ai and api.zaviro.ai) and the zaviro.ai website.

We run a knowledge-base service for businesses: our customers connect their own systems (email, files, business tools), Zaviro builds a knowledge base from them, and the customer's own AI tools read from it. Because of that design, this policy distinguishes two very different kinds of data, and our role differs for each:

  • Customer Content — the documents, emails, and records our customers connect or upload, and everything we derive from them. This content routinely contains personal information about people who are not Zaviro users (for example, the people our customer corresponds with by email, or contacts in their CRM). For Customer Content, we act as a processor / service provider on our customer's instructions. The customer decides what is connected and is responsible for having the right to connect it.
  • Account, Billing, and Usage Data — information about you as a Zaviro user (your account, your subscription, your use of the service). For this data, we act as the controller.

1. Information we collect

Account data (you provide it): name, email address, password (stored only as a salted hash — PBKDF2-SHA256), phone number, country, timezone, optional profile picture, company details (name, legal name, address, contact email, website, industry, tax ID, registration number, logo). Consent to our Terms is recorded (timestamp and terms version).

Security and session data (generated as you use the service): sign-in records; per-session device and browser labels, IP address, and, where enabled, approximate city/country derived from the IP using a local geolocation database (no lookup service receives your IP); a per-account security activity log (sign-ins, password and email changes, two-factor changes, passkey and session events, exports, team changes) including IP address and browser identifier; two-factor authentication data (authenticator-app secrets stored encrypted; passkey public keys and metadata — passkeys never give us biometric data; where SMS two-factor is offered and you enable it, one-time codes exist only as short-lived hashes); email-change and verification records.

Billing data: subscription plan, seat counts, credit balances and transactions, invoices. Payment card details never touch our servers — cards are entered only on Stripe's hosted pages, and we store Stripe's reference identifiers, not card numbers.

Usage and telemetry data: activity events (which tools and features were used, when, by which account) — in deployed environments the content of queries and tool arguments is redacted at write time into irreversible hashes; credit-usage records; transactional email records (what we sent you and whether it bounced); error reports (aggressively scrubbed — see Sentry in §6).

Team data: invitations you send (invitee email and optional name), roles and capability grants, referral records (the referred person's email and status).

Support data: what you send through the in-app support form (subject, message), together with your account context.

Website forms (zaviro.ai): what you submit on the marketing website, where no account is involved — the contact form (name, email address, optional phone number and company, your message, and your acceptance of our Terms), the waitlist form (email address), and the early-access form (name, email address, optional company, team size, and what you would use Zaviro for). Webflow, which hosts the website, stores these submissions for us (§6, §12).

Customer Content (your business connects it): files you upload; email subjects, bodies, and attachments from mailboxes you connect or from messages your team forwards to your organization's Zaviro forwarding addresses; files from drives you connect; records from business systems you connect; notes and documents your AI tools push in; and everything we derive from that content (extracted text, summaries, entities, relationships, structured facts, search embeddings). We periodically fetch your own public website, only to keep our one-line summary of what your business does current (never if you have written that summary yourself) — we do not crawl the web.

Product analytics: where enabled, the app sends pseudonymous usage events to our analytics provider (§6) — which pages and features are used, tied to an account identifier and role, never to your name or email, and never containing Customer Content. You can opt out any time in Settings → Privacy & Security.

What we deliberately do not collect: there are no advertising trackers, no session-recording tools, and no third-party fonts or CDNs in the app. We do not collect biometric data. We do not scan or moderate the substance of Customer Content beyond malware/spam screening on inbound email and file-type validation.

2. Where data comes from

Directly from you (registration, settings, uploads, the contact form); automatically as you use the service (sessions, security events, usage); from sources you connect — Gmail, Outlook, Google Drive, Dropbox, OneDrive/SharePoint and HubSpot under read-only access you approve on the provider's own consent screen; Notion under an integration token you create in your own Notion workspace and share specific pages with. Zaviro only ever reads from a connected source; from your team (an admin inviting you); from Google, if you choose "Sign in with Google" (we receive only your email, its verified status, and your name — never a Google password or access to Google content through the sign-in); and through our API and MCP surfaces when your business's tools push content in.

3. Our role for Customer Content

For Customer Content, the customer organization is the controller and Zaviro is a processor/service provider. In plain terms:

  • We process Customer Content only to provide the service: extract, organize, index, retrieve, and serve it back to the customer's own authorized tools and users.
  • We do not sell it, advertise with it, or use it to train AI models (§5).
  • People whose personal information appears inside Customer Content (for example, a customer's correspondents) should direct privacy requests to the business that connected the data — that business is the controller. We assist that business in fulfilling such requests as its processor.
  • Our Data Processing Agreement covers this processing for every business customer (incorporated by reference into our Terms of Service; a countersigned copy is available for Enterprise customers).
  • One adjacent audience: if a customer runs a public chatbot grounded in documents they chose to publish (see the Terms), visitors' questions to that chatbot are processed to serve those published documents and are not logged; notice to those visitors is the customer's site's responsibility.

4. What we use data for, and why

Purpose
Data
Legal basis (GDPR)
Provide the service: build and serve the knowledge base (Customer Content)
Customer Content
Processed as processor on the customer's documented instructions; the customer, as controller, is responsible for the legal basis
Provide the service: accounts, workspaces, access
Account data
Contract
Authentication and account security (sessions, 2FA, security log, new-device alerts)
Account, security, session data
Contract; legitimate interests (protecting accounts)
Billing and subscription management
Account, billing data
Contract; legal obligation (tax/financial records)
Transactional email (verification, security alerts, billing, product alerts and digests you can tune)
Account data, notification preferences
Contract; legitimate interests
Service protection (rate limiting, abuse and fraud prevention, spend controls)
Usage, session, billing data
Legitimate interests
Error monitoring and service improvement
Scrubbed telemetry
Legitimate interests
Support
Support data, account context
Contract; legitimate interests
Legal compliance and dispute records
Billing, audit, tombstone records (§9)
Legal obligation; legitimate interests

We do not use your data for advertising. We do not profile you. No decisions producing legal or similarly significant effects are made about anyone automatically — Zaviro retrieves and cites; it does not decide.

5. AI processing — and what we never do with your data

Zaviro uses external AI providers to read, understand, and index Customer Content. Exactly three providers can receive content, each under commercial API terms that exclude training on customer data:

  • Anthropic (US) — language-model processing for document understanding, knowledge-graph extraction, and serving. May retain API inputs/outputs up to 30 days for trust-and-safety purposes, then deletes them, unless a zero-data-retention arrangement is in effect.
  • OpenAI (US) — search embeddings, and full processing as an automatic fallback when Anthropic is temporarily unavailable (so OpenAI can receive complete document content, including scanned-page images, on those occasions). We assert the no-storage option on every completion call; the embeddings endpoint offers no equivalent, so embedding inputs fall under OpenAI's standard retention; API data is excluded from training by default and retained up to 30 days for abuse monitoring unless zero-data-retention is in effect.
  • Voyage AI (US) — search re-ranking (receives the query and candidate text passages to rank them; not used for training under Voyage's API terms; retained per those terms).

This roster is enforced in our codebase: adding a content-touching provider without a recorded data-handling entry fails our build.

Zaviro never uses your data to train AI models. Zaviro also never generates content: your own AI tools do the answering, under your accounts and your control — what those tools do with retrieved content is governed by their terms, not ours.

6. Who else we share data with (subprocessors)

  • Amazon Web Services — hosting. All Customer Content and account data is stored in Canada. AWS also delivers our transactional email (SES).
  • Stripe (US) — payments. Receives the billing contact's name and email; card details go directly to Stripe and never touch our servers.
  • Anthropic, OpenAI, Voyage AI (US) — AI processing, as in §5.
  • Twilio (US) — SMS delivery, only where SMS two-factor authentication is offered and you enable it (receives your phone number and the one-time code message).
  • Webflow (US) — hosting for the zaviro.ai marketing website; it stores the submissions from the website's forms (§1) on our behalf.
  • Sentry (US) — error monitoring. Configured to never receive request bodies, stack-frame variables, auth headers, or your email; users appear as numeric IDs.
  • PostHog (US) — product analytics, where enabled: pseudonymous usage events only (account identifier and role — no names, no emails, no Customer Content; autocapture and session recording are off), with a per-user opt-out in Settings.

We do not sell personal information and we do not share it for cross-context behavioral advertising. We disclose data if required by law, and in a corporate transaction your data would remain protected under this policy. Providers of systems you connect as sources (Google, Microsoft, Dropbox, HubSpot, Notion) are not our subprocessors — they are your existing services, and data flows from them to us under read-only access you grant and can revoke at any time, at the provider or in Zaviro.

Our Data Processing Agreement carries the authorized subprocessor list for Customer Content and commits to 30 days' notice of changes.

7. International data location

Primary storage for Customer Content and account data is Canada. Customer Content leaves Canada only for the AI processing described in §5, where the US-based providers may temporarily retain it as §5 states; account, billing, and telemetry data flows to the US-based service providers in §6 as described there. Where GDPR or UK GDPR applies, transfers to these providers are protected by the contractual safeguards in each provider's data-processing terms, including standard contractual clauses where required and, where the provider is certified, the EU-US Data Privacy Framework.

8. Security

Zaviro is built so that privacy is architecture, not policy:

  • Read-only connections: every source connection uses read-only access; Zaviro cannot modify, send, or delete anything in your systems.
  • Tenant isolation in the build: each customer's data is isolated structurally; our build fails if code queries customer data without tenant scoping.
  • Personal stays personal: each user's personal knowledge base is invisible to everyone else, including the organization's owner. There is no admin override, and no API key can read personal data.
  • Encryption: TLS for all data in transit; encryption at rest, including field-level application encryption of document text, email bodies, summaries, and derived descriptions, so a raw database dump yields ciphertext; OAuth tokens encrypted; API keys and issued tokens stored only as hashes.
  • Access controls: the substance of Customer Content — document text, email bodies and subjects, and derived summaries and descriptions — is excluded from our internal administration tools; limited operational metadata (such as document names and message senders) remains visible to authorized staff for support and troubleshooting. Operator access is limited to authorized personnel for operating and supporting the service, under access controls; staff administrative access requires two-factor authentication; activity telemetry is content-redacted at rest in deployed environments.
  • Account security for you: two-factor authentication (authenticator app, passkeys, and, where offered, SMS), organization-wide 2FA enforcement, session management, a security activity log, and re-authentication for destructive actions.
  • Breached-password check: when you set a password we check it against a public breached-password service using the first five characters of its hash only. The password itself never leaves Zaviro, and the service cannot learn which password was checked.

Honest limits: Zaviro is access-control-private, not zero-knowledge — the service must process text to index and serve it, so encryption at rest protects storage, not a claim that we are technically unable to process your data. Zaviro is not yet independently certified (no SOC 2 or ISO 27001); our controls are designed to support SOC 2, GDPR, and PIPEDA obligations.

If a breach creates a real risk of significant harm, we will notify affected customers without undue delay and report to the appropriate authorities as required by applicable law (including Canada's OPC and, where GDPR applies, the competent supervisory authority within the required timelines). Our internal breach procedure — containment, assessment, the notification commitments above, and record-keeping — is maintained in our incident-response runbook.

9. How long we keep data

Data
Retention
Customer Content
For the life of the document/account. Deleting a document removes the stored original and subtracts its contribution from derived knowledge.
Organization deletion
30-day recovery window, then permanent deletion of the organization, its users, content, and stored files. Unused prepaid subscription time is refunded automatically.
Removed team member
Personal-scope data sealed at removal, permanently deleted 30 days later (reactivation within the window restores it).
Expired trial (no payment method)
Retained for 90 days after trial end, then deleted.
Unpaid accounts
Access reduces on a published ladder (§7 of the Terms); data becomes eligible for deletion 90 days after payment failure.
Voluntarily canceled subscriptions
Access continues to period end; the account is retained so you can return or delete it. You can delete your organization at any time (30-day window as above).
Activity telemetry, security events, transactional-email records
365 days by default; the retention period is configurable per organization under an Enterprise agreement. Email-delivery records include the recipient address and the details each email was generated from.
In-app support messages
Retained as transactional-email records (365 days).
Website form submissions (contact, waitlist, early access)
Stored by Webflow for up to 12 months, then deleted. When we reply, the exchange continues by email and is kept as transactional-email records (365 days).
Invitations and referral records
Invitation records live with your organization. Referral records — including the referred person's email address — are retained for financial audit and fraud prevention, and survive account deletion.
Notifications
Read notifications are cleared after 7 days and unread ones after 90; cleared notifications are deleted 30 days after clearing.
Billing and financial records
Retained in content-free form for as long as tax, accounting, and dispute obligations require, and at least seven years.
Deletion records
Minimal records of deletions — including the organization's name, the email addresses of the owner and the person who requested deletion, and refund references — are retained indefinitely for audit, fraud-prevention, and legal purposes; they contain no Customer Content.
Backups
Database backups retain deleted data for up to 30 days. Deleted files are removed from primary storage immediately; residual storage-version copies expire within ~35 days.

A small set of operational records survives organization deletion for the remainder of its retention window, as rows above note: email-delivery records, security-audit entries with identifying details stripped at deletion, billing and financial records, referral records tied to issued credits, and the deletion record itself.

10. Your rights

Wherever you are, you can: access your data, correct it, export it, delete it, and complain to a supervisory authority. Concretely, in the product today:

  • Access/export: Settings → Privacy & Security → data export produces a machine-readable archive of your account data (profile, preferences, security posture, sessions, invitations, activity). Your uploaded documents remain accessible and individually downloadable in the app; connections are read-only, so your originals were never moved out of your own systems.
  • Correction: account details are self-serve editable; knowledge-base corrections are a product feature.
  • Deletion: delete individual documents anytime; delete your account by leaving an organization; an owner can delete the whole organization (30-day recovery window, then permanent).
  • Consent withdrawal: disconnect any connected source at any time (in Zaviro or at the provider); optionally delete already-imported email content on disconnect.

European Economic Area / UK (GDPR): rights of access, rectification, erasure, restriction, portability, and objection; where processing rests on consent you may withdraw it; you may lodge a complaint with your supervisory authority.

Canada (PIPEDA and substantially similar provincial laws, including Alberta's PIPA and Quebec's Law 25): rights to access and correct your personal information and to withdraw consent subject to legal or contractual restrictions; complaints may be directed to the Office of the Privacy Commissioner of Canada or your provincial commissioner.

California (CCPA/CPRA): rights to know, access, correct, delete, and to opt out of sale or sharing — we do not sell or share personal information, and we do not use or disclose sensitive personal information beyond what is necessary to provide the service. We will not discriminate against you for exercising your rights. Requests are honored within the statutory window (45 days, extendable once). You may use an authorized agent; we will verify requests against your account.

To exercise any right, use the in-product tools above or contact support@zaviro.ai. If your personal information appears inside a business's Customer Content, direct your request to that business (the controller); we support them as their processor.

11. Age

Zaviro is a business product. It is not directed to, and may not be used by, anyone under 18 or the age of majority in their jurisdiction.

12. Website, cookies, and tracking

The Zaviro app uses only the storage necessary to keep you signed in and remember your settings; it contains no advertising cookies. In-app product analytics is limited to the pseudonymous usage events described in §1, with the per-user opt-out in Settings → Privacy & Security. The zaviro.ai marketing website is hosted on Webflow, which processes the forms you submit there (the contact, waitlist, and early-access forms — see §1) on our behalf and sets its own cookies necessary to serve the site.

13. Changes to this policy

We will post changes here and update the date above; for material changes we will notify you by email or in the product before they take effect. Each version of our terms and this policy is versioned, and your acceptance is recorded against the version you accepted.

14. Contact

The Privacy Officer, Zaviro Software Inc. — support@zaviro.ai, or the contact form at zaviro.ai. Security vulnerability reports: security@zaviro.ai.

Have questions?
Every message gets read and answered.
Contact us
Your AI brings the intelligence.
Zaviro brings your business.
start with zaviro
Start for freeBook a demo
Have questions? We’ll get you answers.
Main Pages
HomeWhat It DoesHow It WorksFor DevelopersPricingCompanyContact
Resources
Blog
Social links
LinkedIn
Zaviro
© 2026 Zaviro Software Inc. All rights reserved.
Terms of ServicePrivacy PolicyData Processing Agreement