What data this covers
Zavi is a B2B software platform that gives a company operator a team of AI agents that read that operator's own business data. The data we hold about you falls into two groups:
- Account data. Your email, name, optional company name, and the records of agent runs performed for your workspace.
- Connected-account data. Data we retrieved on your behalf from a third-party account you connected — for example Meta (Facebook and Instagram) ad performance, Google Ads campaign performance, Slack messages, or GitHub repository contents — plus the OAuth access token for that connection, which is held encrypted in Supabase Vault and never exposed to your browser.
Revoking access to a connected account
Revoking access stops Zavi reading anything further from that account. It takes effect immediately and you can do it yourself, without contacting us.
- Meta (Facebook and Instagram) — from inside Zavi. Go to Settings in your Zavi workspace, find the Meta Ads connector, open its ⋯ menu and choose Disconnect. The stored access token is deleted immediately and the
performance-marketeragent stops reading your ad account at once. You can reconnect at any time. - Meta — from Facebook instead. If you would rather revoke from Meta's side, open Facebook Settings → Apps and Websites, find Zavi, and choose Remove. Facebook notifies us at that moment and our stored token for your ad account stops working. Your Zavi workspace will then show the Meta Ads connector as needing to be reconnected.
- Google Ads or Google Analytics. Open your Google account permissions, find Zavi, and choose Remove access.
- Slack. A workspace admin can remove the Zavi app from the workspace in Slack's Manage apps settings.
- GitHub. Uninstall the Zavi GitHub App from your organisation or account in GitHub's Applications settings.
Revoking access stops future reads. It does not, on its own, erase what we already stored — for that, make a deletion request below.
Requesting deletion of stored data
Email support@zaviagent.com from the address on your Zavi account, with the subject Data deletion request. Tell us whether you want:
- One connection deleted — name it (for example “Meta Ads”) and we delete the stored token and the data we retrieved from it, leaving the rest of your workspace intact; or
- Your whole account deleted — we delete your account, your workspace's stored data, and every connected-account token we hold.
We acknowledge the request within 5 business days and complete the deletion within 30 days, except for records we are legally required to retain (for example, tax-related billing records for up to 7 years). We will email you to confirm when it is done. There is no charge, and you do not need an active subscription to make a request.
If you can no longer sign in to Zavi — for example you removed the app on Facebook and never had a separate Zavi login — email us from the address you signed up with and name the ad account or workspace, and we will locate and delete the records without requiring you to sign back in.
What happens to your data in the meantime
Data we hold is stored in AWS us-west-1 (Northern California), encrypted at rest and in transit, and isolated per workspace by row-level security in Postgres. We do not sell it, we do not share it beyond the sub-processors listed in our Privacy Policy, and we do not use it to train any foundation model. Agent run telemetry is deleted on a rolling 12-month basis whether or not you make a request.
Other privacy rights
Depending on where you live you may also have the right to access, correct, or port your data, and to object to or restrict processing. Those rights, and how to exercise them, are described in our Privacy Policy. Use the same email address for any of them.
Contact
Zavi · San Francisco, California · support@zaviagent.com. See also our Privacy Policy and Terms of Service.