Privacy Policy
Effective date: August 25, 2026
This Policy explains how Zaovra handles information when you visit the website, sign in, purchase a membership, or use the desktop app. It distinguishes BYOK traffic from Zaovra-managed model access so you can understand where your data goes.
1. Information we collect
- Account data: account identifiers, verified email address, sign-in provider, and workspace membership.
- Billing data: plan, subscription status, transaction identifiers, invoice records, and limited payment-method metadata such as type and last four digits. Stripe handles full payment credentials.
- Service data: app version, device and network diagnostics, feature usage, model and token usage, errors, and security events.
- Support data: messages and files you choose to send when requesting help.
- AI request data: prompts, relevant workspace context, tool results, and model output when needed to perform a request.
2. BYOK data flow
BYOK credentials are configured in the desktop app and are not entered on the Zaovra website. BYOK model requests are sent using the provider connection you choose and are subject to that provider’s privacy and retention terms. A Zaovra account is still required to use the desktop app, but BYOK does not require a paid membership or consume managed model allowance.
3. Managed model data flow
When you use a paid membership’s managed model access, Zaovra processes and routes the request to the model provider selected by the live service configuration. Request content is transmitted only as needed to return the requested result. We also record operational and usage metadata needed to apply your plan, prevent abuse, diagnose failures, and maintain billing records. Upstream providers may process request content under their applicable data terms.
4. How we use information
We use information to authenticate accounts, operate desktop and managed model features, process and reconcile subscriptions, provide support, secure the Service, prevent fraud and abuse, diagnose errors, meet legal obligations, and communicate material service or policy changes. We do not sell personal information. We do not use private source code or prompt content to train public AI models without your explicit consent.
5. Service providers
We disclose only the information necessary to providers that support authentication, payment processing, infrastructure, monitoring, support, and managed AI inference. Stripe processes payments. GitHub or Google processes sign-in when you choose that provider. Each provider processes data under its own terms and our applicable agreement with it.
6. Retention
Account and subscription records are retained while your account is active and as needed for security, dispute resolution, tax, accounting, and legal obligations. Operational logs are retained only for the period needed for reliability and security. Support messages are retained while the request is active and for a reasonable follow-up period. Provider-side retention for BYOK and managed inference is governed by the provider terms applicable to that request.
7. Security
We use access controls, encrypted transport, environment-separated credentials, and restricted internal access appropriate to the information processed. No system is completely secure; please report suspected account or credential compromise promptly.
8. Your choices and rights
You may request access, correction, export, or deletion of personal information, subject to identity verification and legal retention duties. You may cancel a membership through the billing portal and may stop provider processing by removing a BYOK connection from the desktop app.
9. Children
The Service is not directed to children under 13, and we do not knowingly collect their personal information.
10. Policy changes
Material changes will be announced through the website, account, or email before they take effect where required.
11. Contact
Privacy, account, and data-rights requests: support@zaovra.com.