This policy explains what personal information Zaviro Software Inc. ("Zaviro," "we," "us") collects, how we use it, who we share it with, and the rights you have over it. It covers the Zaviro product (app.zaviro.ai and api.zaviro.ai) and the zaviro.ai website.
We run a knowledge-base service for businesses: our customers connect their own systems (email, files, business tools), Zaviro builds a knowledge base from them, and the customer's own AI tools read from it. Because of that design, this policy distinguishes two very different kinds of data, and our role differs for each:
Account data (you provide it): name, email address, password (stored only as a salted hash — PBKDF2-SHA256), phone number, country, timezone, optional profile picture, company details (name, legal name, address, contact email, website, industry, tax ID, registration number, logo). Consent to our Terms is recorded (timestamp and terms version).
Security and session data (generated as you use the service): sign-in records; per-session device and browser labels, IP address, and, where enabled, approximate city/country derived from the IP using a local geolocation database (no lookup service receives your IP); a per-account security activity log (sign-ins, password and email changes, two-factor changes, passkey and session events, exports, team changes) including IP address and browser identifier; two-factor authentication data (authenticator-app secrets stored encrypted; passkey public keys and metadata — passkeys never give us biometric data; where SMS two-factor is offered and you enable it, one-time codes exist only as short-lived hashes); email-change and verification records.
Billing data: subscription plan, seat counts, credit balances and transactions, invoices. Payment card details never touch our servers — cards are entered only on Stripe's hosted pages, and we store Stripe's reference identifiers, not card numbers.
Usage and telemetry data: activity events (which tools and features were used, when, by which account) — in deployed environments the content of queries and tool arguments is redacted at write time into irreversible hashes; credit-usage records; transactional email records (what we sent you and whether it bounced); error reports (aggressively scrubbed — see Sentry in §6).
Team data: invitations you send (invitee email and optional name), roles and capability grants, referral records (the referred person's email and status).
Support data: what you send through the in-app support form (subject, message), together with your account context.
Website forms (zaviro.ai): what you submit on the marketing website, where no account is involved — the contact form (name, email address, optional phone number and company, your message, and your acceptance of our Terms), the waitlist form (email address), and the early-access form (name, email address, optional company, team size, and what you would use Zaviro for). Webflow, which hosts the website, stores these submissions for us (§6, §12).
Customer Content (your business connects it): files you upload; email subjects, bodies, and attachments from mailboxes you connect or from messages your team forwards to your organization's Zaviro forwarding addresses; files from drives you connect; records from business systems you connect; notes and documents your AI tools push in; and everything we derive from that content (extracted text, summaries, entities, relationships, structured facts, search embeddings). We periodically fetch your own public website, only to keep our one-line summary of what your business does current (never if you have written that summary yourself) — we do not crawl the web.
Product analytics: where enabled, the app sends pseudonymous usage events to our analytics provider (§6) — which pages and features are used, tied to an account identifier and role, never to your name or email, and never containing Customer Content. You can opt out any time in Settings → Privacy & Security.
What we deliberately do not collect: there are no advertising trackers, no session-recording tools, and no third-party fonts or CDNs in the app. We do not collect biometric data. We do not scan or moderate the substance of Customer Content beyond malware/spam screening on inbound email and file-type validation.
Directly from you (registration, settings, uploads, the contact form); automatically as you use the service (sessions, security events, usage); from sources you connect — Gmail, Outlook, Google Drive, Dropbox, OneDrive/SharePoint and HubSpot under read-only access you approve on the provider's own consent screen; Notion under an integration token you create in your own Notion workspace and share specific pages with. Zaviro only ever reads from a connected source; from your team (an admin inviting you); from Google, if you choose "Sign in with Google" (we receive only your email, its verified status, and your name — never a Google password or access to Google content through the sign-in); and through our API and MCP surfaces when your business's tools push content in.
For Customer Content, the customer organization is the controller and Zaviro is a processor/service provider. In plain terms:
We do not use your data for advertising. We do not profile you. No decisions producing legal or similarly significant effects are made about anyone automatically — Zaviro retrieves and cites; it does not decide.
Zaviro uses external AI providers to read, understand, and index Customer Content. Exactly three providers can receive content, each under commercial API terms that exclude training on customer data:
This roster is enforced in our codebase: adding a content-touching provider without a recorded data-handling entry fails our build.
Zaviro never uses your data to train AI models. Zaviro also never generates content: your own AI tools do the answering, under your accounts and your control — what those tools do with retrieved content is governed by their terms, not ours.
We do not sell personal information and we do not share it for cross-context behavioral advertising. We disclose data if required by law, and in a corporate transaction your data would remain protected under this policy. Providers of systems you connect as sources (Google, Microsoft, Dropbox, HubSpot, Notion) are not our subprocessors — they are your existing services, and data flows from them to us under read-only access you grant and can revoke at any time, at the provider or in Zaviro.
Our Data Processing Agreement carries the authorized subprocessor list for Customer Content and commits to 30 days' notice of changes.
Primary storage for Customer Content and account data is Canada. Customer Content leaves Canada only for the AI processing described in §5, where the US-based providers may temporarily retain it as §5 states; account, billing, and telemetry data flows to the US-based service providers in §6 as described there. Where GDPR or UK GDPR applies, transfers to these providers are protected by the contractual safeguards in each provider's data-processing terms, including standard contractual clauses where required and, where the provider is certified, the EU-US Data Privacy Framework.
Zaviro is built so that privacy is architecture, not policy:
Honest limits: Zaviro is access-control-private, not zero-knowledge — the service must process text to index and serve it, so encryption at rest protects storage, not a claim that we are technically unable to process your data. Zaviro is not yet independently certified (no SOC 2 or ISO 27001); our controls are designed to support SOC 2, GDPR, and PIPEDA obligations.
If a breach creates a real risk of significant harm, we will notify affected customers without undue delay and report to the appropriate authorities as required by applicable law (including Canada's OPC and, where GDPR applies, the competent supervisory authority within the required timelines). Our internal breach procedure — containment, assessment, the notification commitments above, and record-keeping — is maintained in our incident-response runbook.
A small set of operational records survives organization deletion for the remainder of its retention window, as rows above note: email-delivery records, security-audit entries with identifying details stripped at deletion, billing and financial records, referral records tied to issued credits, and the deletion record itself.
Wherever you are, you can: access your data, correct it, export it, delete it, and complain to a supervisory authority. Concretely, in the product today:
European Economic Area / UK (GDPR): rights of access, rectification, erasure, restriction, portability, and objection; where processing rests on consent you may withdraw it; you may lodge a complaint with your supervisory authority.
Canada (PIPEDA and substantially similar provincial laws, including Alberta's PIPA and Quebec's Law 25): rights to access and correct your personal information and to withdraw consent subject to legal or contractual restrictions; complaints may be directed to the Office of the Privacy Commissioner of Canada or your provincial commissioner.
California (CCPA/CPRA): rights to know, access, correct, delete, and to opt out of sale or sharing — we do not sell or share personal information, and we do not use or disclose sensitive personal information beyond what is necessary to provide the service. We will not discriminate against you for exercising your rights. Requests are honored within the statutory window (45 days, extendable once). You may use an authorized agent; we will verify requests against your account.
To exercise any right, use the in-product tools above or contact support@zaviro.ai. If your personal information appears inside a business's Customer Content, direct your request to that business (the controller); we support them as their processor.
Zaviro is a business product. It is not directed to, and may not be used by, anyone under 18 or the age of majority in their jurisdiction.
The Zaviro app uses only the storage necessary to keep you signed in and remember your settings; it contains no advertising cookies. In-app product analytics is limited to the pseudonymous usage events described in §1, with the per-user opt-out in Settings → Privacy & Security. The zaviro.ai marketing website is hosted on Webflow, which processes the forms you submit there (the contact, waitlist, and early-access forms — see §1) on our behalf and sets its own cookies necessary to serve the site.
We will post changes here and update the date above; for material changes we will notify you by email or in the product before they take effect. Each version of our terms and this policy is versioned, and your acceptance is recorded against the version you accepted.
The Privacy Officer, Zaviro Software Inc. — support@zaviro.ai, or the contact form at zaviro.ai. Security vulnerability reports: security@zaviro.ai.