Privacy Policy

Privacy Policy.

Last updated 2026-08-07. Privacy questions: support@zaviagent.com.

1.What we collect

We collect the minimum needed to operate Zavi for you:

  • Account information. Email, name, and optional company name when you sign up.
  • Authentication identifiers. OAuth subject IDs from GitHub or Google when you choose those sign-in methods. We do not receive your password.
  • Connector data. When you connect Slack, GitHub, or another integration, we receive the data those connectors are scoped to read. We store OAuth tokens in Supabase Vault and never expose them to the client browser.
  • Usage telemetry. Public funnel page views, whitelisted product events, agent run IDs, run latency, and cost. We do NOT capture raw model inputs, raw model outputs, prompts, or any user content in our telemetry pipeline. Internal agent telemetry is whitelisted to { tool_name, ms, code, iter }.
  • Cookies. First-party session cookies set by Supabase Auth and first-party analytics storage used by PostHog when analytics is enabled. We do not use advertising cookies.

2.Why we collect it

We use the data above to (a) operate the Service, (b) generate agent outputs you requested, (c) keep you signed in, (d) bill you if you are on a paid plan, and (e) communicate service-related notices. We do not sell your data and we do not use it to train any foundation model.

3.How we share it

We share data with the sub-processors listed below to operate the Service. Each sub-processor is contractually limited to processing your data on our behalf for the stated purpose. We do not share your data with any other third party except (i) at your direction, (ii) to comply with a valid legal demand, or (iii) to protect our or others' rights or safety.

Sub-processorPurpose
AnthropicFoundation model provider — Claude API for agent inference
SupabasePostgres database + auth + Vault for OAuth tokens
AWSHosting (Amplify for web, EC2 for backend, Secrets Manager for prod secrets) — us-west-1 only
InngestBackground job orchestration for agent runs
PostHogProduct analytics for public funnel page views and whitelisted product events
SlackOptional — operator can connect their workspace via OAuth
GitHubOptional — operator can install our GitHub App on their repos
GoogleOptional — operator can connect their Google Ads account; we use the Google Ads API to read campaign performance and apply changes the operator approves
MetaOptional — operator can connect their Meta (Facebook + Instagram) ad account; we use the Meta Marketing API to read campaign performance and apply changes the operator approves

4.Where your data lives

All production data is hosted in AWS us-west-1 (Northern California). Data is encrypted at rest by Supabase and AWS, and encrypted in transit over TLS 1.2+. We do not offer EU residency at this time; if that's a requirement for you, contact us.

5.How long we keep it

We retain account data for as long as your account is active. If you delete your account, we delete account data within 30 days, except where we are required to keep specific records by law (for example, tax-related billing records for up to 7 years). Agent run telemetry is retained for 12 months and then deleted on a rolling basis.

6.Your rights

Depending on your jurisdiction, you may have the right to access, correct, port, or delete the personal data we hold about you, and to object to or restrict certain processing. To exercise any right, email support@zaviagent.com. We will respond within 30 days. If you are in California, you can read more about your rights under the CCPA in Section 10 below. If you are in the EU/UK, your GDPR rights are described in Section 11.

7.Children

Zavi is a B2B service not intended for use by children under 13 (or 16 where local law sets a higher threshold). We do not knowingly collect data from children. If we learn that we have collected such data, we will delete it promptly.

8.Security

We follow defense-in-depth practices: per-tenant row-level security in Postgres, Vault-stored OAuth tokens, no service-role credentials in the browser bundle (CI enforced), and prod secrets in AWS Secrets Manager with least-privilege IAM. For more, see our Security page. If you believe you've found a vulnerability, please report it to support@zaviagent.com.

9.International transfers

If you access the Service from outside the United States, you understand that your data will be processed in the United States. When we transfer personal data from the EU/UK to the U.S., we rely on Standard Contractual Clauses with our sub-processors.

10.California (CCPA / CPRA)

California residents have the right to know what categories of personal information we collect, the categories of sources, the business purposes, and the categories of third parties with whom we share it. All of that is described in Sections 1–3 above. You can request access, deletion, or correction by emailing support@zaviagent.com. We do not sell personal information or share it for cross-context behavioral advertising.

11.EU / UK (GDPR)

If you are in the EU or UK, your lawful bases for processing are: (a) performance of a contract (to operate the Service), (b) legitimate interests (to improve and secure the Service), and (c) consent where we explicitly ask for it (e.g., marketing emails). You have the right to lodge a complaint with your local supervisory authority.

13.Meta (Facebook and Instagram) Ads data

If you connect your Meta ad account, the Zavi performance-marketer agent uses the Meta Marketing API on your behalf under the ads_read and ads_management permissions you grant at the Facebook consent dialog. We read ad-account structure and performance data (campaigns, ad sets, ads, budgets, and metrics such as impressions, clicks, conversions, spend, CPA, and ROAS) to generate recommendations. We write changes back to Meta — budget shifts, campaign and ad-set status — only after you explicitly approve the specific change. We do not read your Facebook profile, friends, messages, or any personal content, and we do not request permissions beyond the ads scopes above. Meta data is stored in AWS us-west-1, encrypted at rest and in transit; the Meta OAuth access token is held in Supabase Vault and never exposed to the browser. We use this data solely to operate the performance-marketer agent for you, we do not sell or share it beyond the sub-processors above, and we do not use it to train any foundation model. Disconnecting the integration in Zavi, or removing Zavi from your Facebook Apps and Websites settings, revokes our access. See Data deletion for how to have the stored data removed.

14.Deleting your data

You can ask us to delete the data we hold about you at any time, including data we obtained from a connected third-party account such as Meta or Google. Disconnecting a connector revokes our access immediately; deleting your Zavi account removes stored account and connector data within 30 days, except records we are legally required to retain. Full step-by-step instructions, including what to do if you no longer have access to your Zavi account, are on our Data deletion page.

15.Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be communicated by email or in-product notice at least 14 days before they take effect.

16.Contact

Zavi · San Francisco, California · Contact support@zaviagent.com.