Privacy Policy

Last updated 9 August 2026

How Zealoop handles personal data — both the data of the people who use our dashboard, and the data of your customers that flows through the agent.

Two kinds of data, two different roles

This distinction runs through the whole document, so it comes first. Zealoop handles personal data in two capacities:

Data we collect as a controller

WhatWhyBasis
Name and email addressTo create and secure your account, and to contact you about the servicePerformance of a contract
Password hashTo authenticate you. We store a scrypt hash and never the password itselfPerformance of a contract
Google or GitHub account identifiersIf you choose to sign in with a provider, we receive your verified email address and display namePerformance of a contract
Workspace and billing detailsTo operate your subscriptionPerformance of a contract
Product usage and diagnosticsTo keep the service reliable and to understand which features are usedLegitimate interests

What we do not collect

We do not buy personal data, we do not sell it, and we do not use your customers’ conversations to train models — ours or anyone else’s.

Data we process on your behalf

When you operate a workspace, the following flows through our systems as a processor. The categories are determined by what you choose to configure:

You decide what goes into a workspace. If you upload a column you would not want quoted back in a support reply, the agent may quote it back in a support reply — see Tables.

Model providers

Generating an answer requires sending the customer’s question and the retrieved context to a large language model provider. This is inherent to the service and cannot be switched off while the agent is in use. Current providers are listed on the Subprocessors page.

We use providers under terms that prohibit training on data submitted through the API. If you have a jurisdictional constraint on where inference may happen, raise it before you deploy — it affects which providers we can use for your workspace.

Retention

DataRetained
Account recordsFor the life of the account, then deleted within 30 days of closure
Conversations and tracesFor as long as the workspace exists, unless you delete them sooner
Knowledge chunksUntil the source is deleted or re-synced; deletion removes the chunks in the same operation
Table rowsUntil you delete the row or the table
BackupsRolling, and overwritten within 35 days
Security and access logs12 months

Deleting a workspace deletes its knowledge, tables, conversations, traces and action history. Backups age out on the cycle above; we do not selectively restore a deleted record into an existing backup.

Security

Passwords are stored as scrypt hashes. Widget secrets and action credentials are encrypted at rest with AES-256-GCM. Session cookies are HttpOnly and, in production, Secure. Transport is TLS throughout. Every workspace is isolated at the query level, and a token issued for one workspace is rejected against another. More detail on the Security page.

International transfers

Our infrastructure and our subprocessors may process data outside your country of residence. Where personal data leaves the EEA or the UK, transfers rely on the European Commission’s Standard Contractual Clauses and the UK Addendum, as applicable.

Your rights

Depending on where you live, you may have the right to access, correct, delete, port or restrict the processing of your personal data, and to object to processing based on legitimate interests. You can exercise most of these directly in the dashboard; for anything else, write to privacy@zealoop.com.

If you are one of our customers’ customers — you spoke to an agent on somebody’s website — your request belongs with that company, not with us. They decide what is collected and how long it is kept. We will forward a request we receive by mistake, and assist that company in answering it.

Cookies

The dashboard sets a session cookie so you stay signed in, and a short-lived state cookie during a Google or GitHub sign-in to protect the redirect against cross-site request forgery. Both are strictly necessary. This marketing site sets no advertising or cross-site tracking cookies.

Children

The service is not directed at children and we do not knowingly collect personal data from anyone under 16. If you believe a child has provided us data, contact us and we will delete it.

Changes

We will post any change here and update the date at the top. For a change that materially reduces your rights, we will give notice by email to workspace owners before it takes effect.

Contact

privacy@zealoop.com for anything in this policy. For a data protection matter you believe we have handled badly, you also have the right to complain to your local supervisory authority.