Privacy Policy

Privacy Policy.

Last updated 2026-09-22. Privacy questions: support@zaviagent.com.

1.What we collect

We collect the minimum needed to operate Zavi for you:

  • Account information. Email, name, and optional company name when you sign up.
  • Authentication identifiers. OAuth subject IDs from GitHub or Google when you choose those sign-in methods. We do not receive your password.
  • Connector data. When you connect Slack, GitHub, or another integration, we receive the data those connectors are scoped to read. We store OAuth tokens in Supabase Vault and never expose them to the client browser.
  • Content you send to agents. Your messages, the files and images you attach, and the connector data an agent reads to answer you. To generate a response, this content is sent to the foundation model providers listed in our sub-processors page, and may pass through our model gateway in transit. Those providers process it to return a response and are contractually barred from using it to train their models.
  • Usage telemetry. Public funnel page views, whitelisted product events, agent run IDs, run latency, and cost. Our own telemetry pipeline does not record raw model inputs, raw model outputs, prompts, or user content — internal agent telemetry is whitelisted to { tool_name, ms, code, iter }. That is a statement about telemetry specifically, not about the Service as a whole: the content you send to an agent does reach model providers, as described directly above.
  • Cookies. First-party session cookies set by Supabase Auth to keep you signed in, and first-party analytics storage used by PostHog and Mixpanel, which you can turn off at any time in the cookie banner. We do not use advertising cookies, and we do not run advertising or session-replay trackers on our site. Our cookie policy lists every cookie and storage key by name. You can change your choice at any time from the “Cookie preferences” control in the footer or on your account page, and you can ask us to delete analytics data associated with you by emailing support@zaviagent.com.

2.Why we collect it

We use the data above to (a) operate the Service, (b) generate agent outputs you requested, (c) keep you signed in, (d) bill you if you are on a paid plan, and (e) communicate service-related notices. We do not sell your data and we do not use it to train any foundation model.

3.How we share it

We share data with our sub-processors to operate the Service. Each one is contractually limited to processing your data on our behalf, for a stated purpose. The complete, current list — what each vendor is for, which ones are engaged only if you use a particular feature, and how we announce changes — is on our sub-processors page. It is part of this policy.

Separately, integrations you connect yourself (Slack, GitHub, Google, Meta and the others listed on that page) receive data at your direction, under the scopes you approve. Disconnecting one ends our access.

We do not share your data with any other third party except (i) at your direction, (ii) to comply with a valid legal demand, or (iii) to protect our or others' rights or safety. We do not sell your data.

4.Where your data lives

All production data is hosted in AWS us-west-1 (Northern California). Data is encrypted at rest by Supabase and AWS, and encrypted in transit over TLS 1.2+. We do not offer EU residency at this time; if that's a requirement for you, contact us.

5.How long we keep it

We keep each category of data only as long as it is needed for the purpose it was collected for:

  • Account information and connector tokens — for as long as your account is active.
  • Your messages, agent runs and the content attached to them — for as long as your account is active, unless you delete them sooner.
  • Indexed Slack messages — 90 days, then deleted on a rolling basis.
  • Meeting recordings — deleted after transcription; if processing or that deletion fails, the recording can remain with our vendor. Transcripts and the notes distilled from them are kept for as long as your account is active.
  • Usage telemetry and agent run metrics — for as long as your account is active.
  • Billing and tax records — up to 7 years, because we are required to keep them.

If you delete your account, it is deactivated straight away. To have the above erased, email support@zaviagent.com and we will delete it, except records we are legally required to retain.

6.If something goes wrong

If we discover a breach of security that compromises your personal data, we will notify you and any regulator that must be told, without undue delay and within the deadlines the applicable law sets. The notice will tell you what happened, what data was involved, and what we are doing about it. Customers on a signed Data Processing Addendum receive notice on the timeline set out in that agreement.

7.Your rights

Depending on your jurisdiction, you may have the right to access, correct, port, or delete the personal data we hold about you, and to object to or restrict certain processing. To exercise any right, email support@zaviagent.com. We acknowledge requests within 10 business days and respond within 45 days, which we may extend once by a further 45 days where the request is complex — we will tell you if we need to. We may need to verify your identity before acting on a request for access, deletion or correction. You may use an authorised agent, who must provide proof that you permitted them to act for you. If we decline a request, you may appeal by replying to our response; we will give you a written decision on the appeal. If you are in California, see the California section below. If you are in the EU or UK, see the EU / UK section.

8.Children

Zavi is a B2B service for adults. You must be at least 18 to hold an account, as required by our Terms of Service. We do not knowingly collect data from anyone under 18. If we learn that we have, we will delete the account and the associated personal data promptly.

9.Security

We follow defense-in-depth practices: per-tenant row-level security in Postgres, Vault-stored OAuth tokens, no service-role credentials in the browser bundle (CI enforced), and prod secrets in AWS Secrets Manager with least-privilege IAM. For more, see our Security page. If you believe you've found a vulnerability, please report it to support@zaviagent.com.

10.International transfers

If you access the Service from outside the United States, you understand that your data will be processed in the United States. When we transfer personal data from the EU/UK to the U.S., we rely on Standard Contractual Clauses with our sub-processors.

11.California (CCPA / CPRA)

California residents have the right to know what categories of personal information we collect, the categories of sources, the business purposes, and the categories of third parties with whom we share it. That is described in the collection, purpose and sharing sections above, together with our sub-processors page. The categories we collect are identifiers, commercial information, internet and network activity, user content, and — because we hold the OAuth tokens you grant us — account access credentials, which California treats as sensitive personal information. We use those tokens only to operate the connectors you authorised, which is a use that does not trigger the right to limit. We do not sell personal information and we do not share it for cross-context behavioural advertising, so we do not offer a “Do Not Sell or Share” link; should that ever change, we will honour opt-out preference signals including Global Privacy Control. You can request access, deletion, correction or portability by emailing support@zaviagent.com, and we will not discriminate against you for exercising any of these rights.

12.EU / UK (GDPR)

If you are in the EU or UK, your lawful bases for processing are: (a) performance of a contract (to operate the Service), (b) legitimate interests (to improve and secure the Service), and (c) consent where we explicitly ask for it (e.g., marketing emails). You have the right to lodge a complaint with your local supervisory authority.

13.Meeting recording and transcription

If you turn on the Zavi Notetaker, a bot joins the meetings you schedule it for on Zoom, Google Meet or Microsoft Teams, and transcribes them so your agents can use what was decided. We use Recall.ai to operate the bot.

  • The bot announces itself. It joins under a visible name and posts a message stating that it is recording and transcribing. That message cannot be removed.
  • The recording is deleted after transcription. We keep the derived transcript and the notes distilled from it, and the recording is deleted at our vendor as well. If processing or that deletion fails, the recording can remain with our vendor.
  • It joins only meetings you send it to. That is the meeting link and times you set in workspace settings, or a meeting someone in your workspace asks it to join now.
  • Getting consent is your responsibility. Several U.S. states, including California, Florida, Illinois, Pennsylvania and Washington, require every participant to consent before a call is recorded. We give you the announcement and the controls; you are the one in the room. Do not use the Notetaker where you do not have every participant's consent.
  • Turning it off. Disable the Notetaker in workspace settings and it stops joining. To have stored transcripts and notes deleted, see Data deletion.

14.Slack workspace content

If you connect Slack and grant message scopes, we index messages the Zavi bot receives so your agents can answer questions about what your team has already discussed. This covers public channels the bot has been invited to, private channels it has been invited to, direct messages with the bot, and group DMs it is a member of. It does not cover conversations the bot is not part of.

  • Sensitive values are stripped before storage. Every string in an incoming Slack event is run through a redactor before the row is written — email addresses, phone numbers, U.S. Social Security numbers, credit-card numbers, and authentication tokens and API keys.
  • Slack's own visibility rules are enforced. An agent only surfaces content from conversations the person asking is a member of.
  • Retention is 90 days. Indexed messages older than 90 days are deleted on a rolling basis by a daily job.
  • Deletions follow through. Deleting a message in Slack deletes the indexed row and any note distilled from it. Editing re-runs the redactor. Uninstalling the Slack app purges the workspace.
  • You can switch indexing off. Uninstall the Zavi Slack app, or email support@zaviagent.com and we will turn indexing off. Either stops new writes and purges the indexed content along with any notes distilled from it. It also covers your colleagues: this content includes messages written by other people in your workspace, so you are responsible for telling your team that Zavi is connected.

16.Meta (Facebook and Instagram) Ads data

If you connect your Meta ad account, the Zavi performance-marketer agent uses the Meta Marketing API on your behalf under the ads_read and ads_management permissions you grant at the Facebook consent dialog. We read ad-account structure and performance data (campaigns, ad sets, ads, budgets, and metrics such as impressions, clicks, conversions, spend, CPA, and ROAS) to generate recommendations. We write changes back to Meta — budget shifts, campaign and ad-set status — only after you explicitly approve the specific change. We do not read your Facebook profile, friends, messages, or any personal content, and we do not request permissions beyond the ads scopes above. Meta data is stored in AWS us-west-1, encrypted at rest and in transit; the Meta OAuth access token is held in Supabase Vault and never exposed to the browser. We use this data solely to operate the performance-marketer agent for you, we do not sell or share it beyond the sub-processors above, and we do not use it to train any foundation model. Disconnecting the integration in Zavi, or removing Zavi from your Facebook Apps and Websites settings, revokes our access. See Data deletion for how to have the stored data removed.

17.Zavi Chrome extension

The Zavi Chrome extension is a side panel for your Zavi account. You ask about the browser tab you are looking at, and Zavi answers in the panel. This section describes the extension specifically. Everything else on this page applies to it as well.

  • When a screenshot is taken. Only when you press Send in the panel, and every time you press Send, including follow-up messages. There is no preview step. The extension does not capture anything when you open the panel, switch tabs, or load a page.
  • What we receive with each message. A screenshot of the visible part of the tab you are on (scaled down to at most 1568 pixels on its longest side), the tab’s web address with the query string and fragment removed, and the tab title. If a page cannot be captured, for example Chrome’s own pages or the Chrome Web Store, we receive your message as text only and the panel tells you so.
  • A screenshot is not filtered. It shows whatever was visible in the tab, which can include names, messages from other people, figures, or anything else on screen. We do not blank out parts of it. Only press Send on a tab you are comfortable sharing with your Zavi account.
  • What Zavi does with it. Zavi uses the screenshot, address and title to answer your message and, if you ask, to carry out the request through the tools connected to your Zavi account, the same as Zavi chat on the web or on your phone. Actions your account requires approval for are shown in the panel for you to approve or reject. The extension itself never clicks, types, fills in forms, or navigates on any page.
  • Agreement first. Before the first screenshot is sent, the extension asks you to agree to this section. Chrome may also ask whether Zavi can capture pages. Until you agree, no screenshot is sent.
  • What we store, and where. The screenshot is stored with your message in your own Zavi account, the same way an image you paste into Zavi chat is stored, in AWS us-west-1, encrypted at rest and in transit. The address and title are stored with the message. Page content is never written into our internal operational telemetry.
  • Who can see it. Zavi staff supporting your account, and Zavi’s own review of answer quality, which is how we find and fix answers that were wrong. That is what the agreement asks you to agree to. Nobody else sees it.
  • What we do not do with it. We do not sell it. We do not transfer it to advertising platforms, data brokers, or anyone who resells information. We do not use it for advertising of any kind. We do not use it to train any foundation model. We do not use it for credit or lending decisions. Our use of information received from the Chrome extension follows the Chrome Web Store User Data Policy, including its Limited Use requirements.
  • Changing your mind. Open settings in the Zavi side panel and turn page reading off. The extension stops sending screenshots, and the screenshots it already sent for you are deleted. You can also remove Zavi’s site access from Chrome’s extension settings, or remove the extension. To ask us to delete everything, see Data deletion.

18.Deleting your data

You can ask us to delete the data we hold about you at any time, including data we obtained from a connected third-party account such as Meta or Google. Disconnecting a connector revokes our access immediately; deleting your Zavi account removes stored account and connector data within 30 days, except records we are legally required to retain. Full step-by-step instructions, including what to do if you no longer have access to your Zavi account, are on our Data deletion page.

19.Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be communicated by email or in-product notice at least 14 days before they take effect.

20.Contact

Zavi Labs, Inc. is the controller of the personal data described in this policy. San Francisco, California. Contact support@zaviagent.com with any privacy question, or to exercise any of the rights described above.