01Who we are#
ZYRO is operated by Zyro LLC, a Florida limited liability company, at 3105 N 22nd St, Tampa, Florida 33605, United States.
For our website, sign-up and our own sales and support contacts, Zyro LLC is the controller of your personal information. When a customer organization uses ZYRO, the content it puts into the Service is processed on that customer’s behalf and under its instructions. If you use ZYRO through your employer or another organization, that organization controls that content, and you should direct requests about it to them first.
02Information we collect#
Information you give us
- Account details: your name, email address, and the security settings you choose, such as multi-factor authentication. Passwords are stored only as salted hashes.
- Organization and workspace data: organization and workspace names, the people you invite, and their roles.
- Project content: project briefs, uploaded documents, code you connect as evidence, clarifications, comments, edits and approvals, and the discovery outputs, artifacts and tasks produced from them.
- Billing data: your plan, billing email, the billing name, address and tax IDs you add, and invoice history. Card payments are handled by Stripe. We receive limited card details from Stripe, such as the brand, the last four digits and the expiry date, but never the full card number.
- Enquiries and support: what you send us through our contact form or by email, including your name, work email, company, role, team size and message.
Information collected automatically
- Usage data: which features are used, AI credit consumption, and the activity recorded in your organization’s audit ledger, such as generations, edits and approvals.
- Security logs: sign-ins, session activity and security events, including the IP address and browser user agent involved. For contact form submissions we store only a one-way hash of the IP address, used for rate limiting and abuse prevention.
Information from third parties
When you connect GitHub or Linear, we receive the information needed for the integration to work, such as account and repository or team identifiers. Stripe tells us about payment events.
03How we use information#
We use personal information to:
- provide, maintain and support the Service, including running discovery and generating output;
- authenticate users, keep accounts secure, and detect and prevent fraud and abuse;
- process payments, manage subscriptions and credits, and send invoices and receipts;
- send service messages, such as sign-in codes, invitations, security alerts and billing notices;
- respond to enquiries and support requests;
- understand how the Service is used so we can fix problems and improve it; and
- meet our legal obligations and enforce our terms.
We do not sell personal information, and we do not use it for third-party advertising.
04Legal bases for processing#
Where laws such as the EU or UK General Data Protection Regulation apply, we rely on these legal bases:
- Contract: to provide the Service you or your organization signed up for.
- Legitimate interests: to secure the Service, prevent abuse, respond to enquiries and improve the product, where those interests are not overridden by your rights.
- Legal obligation: to keep billing and tax records and to respond to lawful requests.
- Consent: where we ask for it. You can withdraw consent at any time.
05How we share information#
We share personal information with service providers (sub-processors) that help us run ZYRO, under contracts that limit their use of it to providing their services to us. By category, they are:
- Cloud hosting and storage, which runs the application, database and file storage.
- AI model providers, which process project content to generate the output you ask for.
- Payments: Stripe, for subscriptions, credit packs, invoices and card handling.
- Email delivery, for sign-in codes, invitations and other service messages.
- Bot protection, used on sign-up to stop automated account creation.
- GitHub and Linear, only when your organization connects them, to send the tasks and issues you choose to hand off.
We may also share information within your organization (for example, other members can see project activity according to their roles), when the law requires it, to protect the rights, safety and security of our users or the public, or as part of a merger, acquisition or sale of assets, in which case this policy continues to apply to the information transferred.
06International transfers#
ZYRO is operated from the United States, and personal information is processed in the United States. If you use ZYRO from outside the United States, your information will be transferred there, where data protection laws may differ from those where you live. Where the law requires it, we use appropriate safeguards for these transfers, such as the European Commission’s Standard Contractual Clauses.
07Retention, export and deletion#
We keep personal information for as long as an account is active and as needed to provide the Service, then for as long as necessary to meet legal, tax and accounting obligations, resolve disputes and enforce our agreements.
- Organization administrators can export their organization’s or a workspace’s data from the Service at any time. Export downloads stay available for 14 days.
- Administrators can request deletion of an organization or workspace. A deletion request is scheduled seven days ahead so it can be cancelled if it was made in error, and is then carried out unless a legal hold applies.
- Organization audit records are append-only by design, and some information may persist in backups and logs for a limited period after deletion.
- We keep contact form enquiries for as long as needed to respond and follow up.
08Security#
We protect information with measures that include:
- role-based access control, with Owner, Admin, Architect, Reviewer, Developer and Viewer roles;
- tenant isolation, so each organization and workspace sees only its own data;
- an organization audit ledger and a history of security events;
- multi-factor authentication for user accounts;
- encryption of customer secrets, such as integration credentials, before they are stored; and
- tenant data export and deletion.
No system is perfectly secure, and we cannot guarantee the security of information. If we learn of a breach that affects your personal information, we will notify you as the law requires. Read more on our security page.
09Your rights#
Depending on where you live, you may have the right to:
- access the personal information we hold about you and receive a copy of it;
- correct information that is inaccurate or incomplete;
- have your information deleted;
- receive your information in a portable, machine-readable format;
- object to or restrict certain processing; and
- withdraw consent where processing is based on consent.
To make a request, email hello@usezyro.ai or use our contact form. We will verify your identity before acting on a request, and respond within the time the law requires. If your information is held on behalf of an organization that uses ZYRO, we may refer your request to that organization. You also have the right to complain to your local data protection authority.
10California privacy rights#
If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act, gives you rights over your personal information.
- Right to know: the categories and specific pieces of personal information we have collected about you, where it came from, why we collected it, and who we disclosed it to. The categories we collect are identifiers (such as name, email and IP address), commercial information (such as plans and purchases), internet activity (such as usage and security logs), professional information (such as company and role), and the content you provide.
- Right to delete and to correct personal information, subject to legal exceptions.
- Right to opt out of sale or sharing. We do not sell personal information or share it for cross-context behavioral advertising, and have not done so in the past 12 months.
- Sensitive information. We use account credentials only to provide and secure the Service, and do not use sensitive personal information to infer characteristics about you.
- Non-discrimination. We will not treat you differently for exercising these rights.
You or an authorized agent can make a request by emailing hello@usezyro.ai. We will verify the request before responding.
11Cookies#
We use only essential cookies: the session cookies that keep you signed in and protect your account. We do not use advertising cookies, and we do not use third-party tracking or analytics cookies. Because essential cookies are needed for the Service to work, they cannot be switched off while you are signed in, but you can delete them in your browser at any time.
12Children#
ZYRO is a business product and is not directed at anyone under 16. We do not knowingly collect personal information from children under 16. If you believe a child has given us personal information, contact us and we will delete it.
13Changes to this policy#
We may update this policy as the Service and the law change. The “Last updated” date at the top of this page shows when it last changed. If a change is material, we will tell you by email or in the Service before it takes effect.
14Contact us#
Questions or requests about privacy can be sent to:
Zyro LLC
3105 N 22nd St, Tampa, Florida 33605, United States
hello@usezyro.ai
You can also reach us through our contact form.