Privacy Policy
This Privacy Policy explains how Zamski collects, uses, and protects your data.
1. What we collect
When you use Zamski, we collect:
- Authentication: email, name, user ID, via Auth0 login.
- OAuth tokens: encrypted access tokens for platforms you connect.
- Workspace data: tickets, code, messages, and meeting transcripts from connected platforms.
- Usage data: how you use Zamski, for improving the product.
What we do not collect
- Browsing history outside connected platforms.
- Keyboard input outside Zamski.
- Personal files or documents.
- Credit card details, which are handled by Stripe if we charge in the future.
2. How we use it
We use your data to:
- Provide the service you signed up for.
- Improve our analysis using aggregated, anonymized data.
- Fix bugs and improve performance.
- Send you updates about the product. You can unsubscribe.
We do not sell your data. Ever.
3. Who we share with
We share your data only with services that help us run Zamski.
AI processing
Language model providers process your data to produce analysis. Current subprocessors are listed at our trust center.
Infrastructure
- AWS for hosting and storage, encrypted at rest and in transit.
- ArangoDB for our database, encrypted.
- Stripe for payment processing if and when we charge. We do not see your card details.
Connected platforms
When you connect a platform, we access data through its API in accordance with that platform’s privacy policy.
We never sell your data, share it with advertisers, give it to competitors, or use it for unrelated marketing.
4. How we protect your data
- Encryption: data is encrypted in transit and at rest.
- Access controls: your data is isolated by organization. You only see your own.
- OAuth security: tokens are encrypted and automatically refreshed.
- No raw passwords: we use Auth0 for authentication and never see your password.
Found a security issue? Email [email protected].
If there is a breach
If your data is compromised, we will email you within 72 hours with details and next steps.
5. Your responsibilities
Recording consent
If you connect tools that record or transcribe meetings, you are responsible for notifying all participants that transcription or recording is active, obtaining the consent required by the applicable law, and following your organization’s policies.
Workspace authorization
Make sure you have permission to connect your organization’s accounts to Zamski. We are not responsible if you connect accounts without proper authorization.
6. Your data, your control
How long we keep your data
We keep your data while you are using Zamski, plus a reasonable period after you disconnect platforms.
How to delete your data
- Disconnect a platform: revokes OAuth access immediately.
- Delete your account: email [email protected] and we will process it within 30 days.
- Download your data: email us and we will send it to you.
Your legal rights under GDPR and CCPA
If you are in the EU or California, you have additional rights:
- Access: get a copy of your data.
- Correct: fix inaccurate data.
- Delete: request deletion.
- Export: get your data in a portable format.
To exercise these rights, email [email protected]. We will respond within 30 days.
7. Questions
- Privacy: [email protected]
- Security: [email protected]
- Support: [email protected]