Privacy Policy
Last updated 9 August 2026
How Zealoop handles personal data — both the data of the people who use our dashboard, and the data of your customers that flows through the agent.
Two kinds of data, two different roles
This distinction runs through the whole document, so it comes first. Zealoop handles personal data in two capacities:
- As a controller, for the people who sign up and use our dashboard — your name, email, and how you use the product.
- As a processor, for the customer data you put into a workspace and the conversations your visitors have with the agent. That data is yours. We process it on your instructions to provide the service, and for nothing else. Those instructions are set out in the Data Processing Addendum.
Data we collect as a controller
| What | Why | Basis |
|---|---|---|
| Name and email address | To create and secure your account, and to contact you about the service | Performance of a contract |
| Password hash | To authenticate you. We store a scrypt hash and never the password itself | Performance of a contract |
| Google or GitHub account identifiers | If you choose to sign in with a provider, we receive your verified email address and display name | Performance of a contract |
| Workspace and billing details | To operate your subscription | Performance of a contract |
| Product usage and diagnostics | To keep the service reliable and to understand which features are used | Legitimate interests |
What we do not collect
We do not buy personal data, we do not sell it, and we do not use your customers’ conversations to train models — ours or anyone else’s.
Data we process on your behalf
When you operate a workspace, the following flows through our systems as a processor. The categories are determined by what you choose to configure:
- Knowledge sources — the pages, files and snippets you add, and the chunks and embeddings derived from them.
- Tables — the customer records you upload, keyed on the identity column you nominate.
- Conversations — messages between your visitors and the agent, replies from your team, and the end-user identifiers attached to them.
- Traces — the per-turn record of retrieval, model calls, token counts and outcomes. Traces contain the customer’s query text.
- Action calls — the requests made to endpoints you configure and the responses they return.
You decide what goes into a workspace. If you upload a column you would not want quoted back in a support reply, the agent may quote it back in a support reply — see Tables.
Model providers
Generating an answer requires sending the customer’s question and the retrieved context to a large language model provider. This is inherent to the service and cannot be switched off while the agent is in use. Current providers are listed on the Subprocessors page.
We use providers under terms that prohibit training on data submitted through the API. If you have a jurisdictional constraint on where inference may happen, raise it before you deploy — it affects which providers we can use for your workspace.
Retention
| Data | Retained |
|---|---|
| Account records | For the life of the account, then deleted within 30 days of closure |
| Conversations and traces | For as long as the workspace exists, unless you delete them sooner |
| Knowledge chunks | Until the source is deleted or re-synced; deletion removes the chunks in the same operation |
| Table rows | Until you delete the row or the table |
| Backups | Rolling, and overwritten within 35 days |
| Security and access logs | 12 months |
Deleting a workspace deletes its knowledge, tables, conversations, traces and action history. Backups age out on the cycle above; we do not selectively restore a deleted record into an existing backup.
Security
Passwords are stored as scrypt hashes. Widget secrets and action credentials are encrypted at rest with AES-256-GCM. Session cookies are HttpOnly and, in production, Secure. Transport is TLS throughout. Every workspace is isolated at the query level, and a token issued for one workspace is rejected against another. More detail on the Security page.
International transfers
Our infrastructure and our subprocessors may process data outside your country of residence. Where personal data leaves the EEA or the UK, transfers rely on the European Commission’s Standard Contractual Clauses and the UK Addendum, as applicable.
Your rights
Depending on where you live, you may have the right to access, correct, delete, port or restrict the processing of your personal data, and to object to processing based on legitimate interests. You can exercise most of these directly in the dashboard; for anything else, write to privacy@zealoop.com.
If you are one of our customers’ customers — you spoke to an agent on somebody’s website — your request belongs with that company, not with us. They decide what is collected and how long it is kept. We will forward a request we receive by mistake, and assist that company in answering it.
Cookies
The dashboard sets a session cookie so you stay signed in, and a short-lived state cookie during a Google or GitHub sign-in to protect the redirect against cross-site request forgery. Both are strictly necessary. This marketing site sets no advertising or cross-site tracking cookies.
Children
The service is not directed at children and we do not knowingly collect personal data from anyone under 16. If you believe a child has provided us data, contact us and we will delete it.
Changes
We will post any change here and update the date at the top. For a change that materially reduces your rights, we will give notice by email to workspace owners before it takes effect.
Contact
privacy@zealoop.com for anything in this policy. For a data protection matter you believe we have handled badly, you also have the right to complain to your local supervisory authority.