Legal
Privacy Policy
This Privacy Notice explains what zy.ai collects, why we collect it, and the choices you have. It is written for real people: clear enough to read, careful enough to protect both you and the service.
1. Overview
zy.ai (also referred to as “we”, “us”, or “the Service”) provides a multi-model AI chat product at zyai.org, including the web app and optional connected channels such as Telegram when enabled.
By creating an account or using the Service, you acknowledge this Privacy Notice and our Terms of Service.
We do not sell your personal data. We do not sell, rent, or trade your queries, prompts, or conversation content to advertisers. We do not use private chats to build third-party advertising profiles. We use data to run the product, keep it secure, bill correctly, and improve reliability.
This notice covers the consumer and self-serve product. If you use a separately contracted enterprise arrangement, additional terms in that agreement may apply.
2. What we collect
We collect only what we need to operate the Service. Categories include:
Account information
- Email address and password (passwords are stored hashed, not in plain text)
- Name or profile details you choose to provide
- Google account identifiers if you sign in with Google
- Plan type (Free, Pro, Ultra) and related billing status
Content you submit
- Messages, prompts, and chat history
- Files you upload (documents, code, images, and similar)
- Voice inputs when you use voice features
- Code submitted to /scan or scan tools
- Feedback you send us
Usage and technical data
- Approximate usage counts and rate limit counters for your plan
- Device and browser type, IP address, and basic request logs
- Error reports and security related signals (abuse, fraud, attacks)
- Theme preference and similar UI settings stored on your device
Payments
Card payments are processed by Lemon Squeezy. Crypto payments may be processed by Cryptomus. We receive confirmation of payment, plan, and transaction references. We do not store full card numbers on our servers.
Optional channels
If you use Telegram with zy.ai, we may store a link between your Telegram ID and your zy.ai account, plus messages you send through that channel, so the product works the same way as on the web.
3. How we use data
We use personal data to:
- Provide the Service: run chat, models, history, scan, account features
- Authenticate you: sign in, sessions, password reset, email verification
- Bill and manage plans: upgrades, renewals, support for payment issues
- Keep the Service safe: rate limits, abuse prevention, fraud checks, security monitoring
- Communicate with you: service emails (verification, resets, important notices)
- Improve reliability: understand failures, fix bugs, capacity planning (aggregated or de identified where practical)
- Comply with law: respond to valid legal requests where required
We do not use your private chats for third party advertising profiles.
4. AI processing (important)
When you chat or use AI features, the content you send is processed by language model providers so we can return a response. That means prompts, attachments you include, and related context may leave our infrastructure and be handled by those providers under their terms and privacy practices.
Providers may include, depending on the model you select and our routing, services such as OpenRouter, OpenAI, Anthropic, Google, Groq, Mistral, Hugging Face, and similar vendors we configure over time.
Training: We do not sell your chats as a dataset. We do not train our own public foundation models on your private conversations. Upstream model providers have their own policies about logging and training. Where a provider offers a zero retention or no training option for API traffic, we aim to use enterprise appropriate settings when available. You should still assume that anything you type could be processed by a third party system.
Rule based /scan analysis runs on our side without calling a model for the scan itself. Results may still be stored with your account so you can reopen them.
6. Storage and security
Account data, chat history, and related records are stored using hosting and infrastructure providers we control or contract with.
We use industry standard measures such as HTTPS, hashed passwords, access controls, and rate limiting. No online service is perfectly secure. You are responsible for keeping your password and devices safe.
If we become aware of a breach that affects your personal data in a material way, we will take steps required by applicable law, which may include notifying you and relevant authorities.
7. Cookies and local storage
We use a small set of first-party cookies and browser storage so the product works. We do not run third-party advertising cookies or pixels on the core chat product for cross-site profiling.
| Category | Examples | Purpose | Required? |
|---|---|---|---|
| Essential / security | Auth session token, CSRF / request integrity where used | Sign-in, keep you logged in, protect accounts | Yes — product cannot work without them |
| Preferences | Theme (light/dark), language, model last used, UI layout flags | Remember your settings on this device | Functional; can be cleared in the browser or via in-app preferences |
| Product operation | Dismissed onboarding, tool toggles, temporary drafts on device | Avoid repeating the same prompts; keep tools as you left them | Functional |
| Infrastructure | CDN / edge security cookies from our host (e.g. Cloudflare) | Delivery, DDoS and bot protection | Technical; set by infrastructure |
We do not use advertising cookies on the core product to track you across other websites for ads. If that ever changes, we will update this notice and, where the law requires it, ask for consent before non-essential tracking.
You can clear site data in your browser (that may sign you out). In the app, open Settings → Privacy → Cookie preferences to control optional preference storage (theme, language, last model). Essential cookies stay on for login and security. Clearing storage does not delete chat history stored on your account; use account tools or contact us for that.
7A. Your privacy choices
- Account & history: sign in, review chats, delete sessions or request account deletion.
- Training / improvement: where the product offers a toggle for using data to improve services, you can change it in Settings (see in-app Privacy / data controls).
- Cookies & local storage: essential items stay on for security and login. Optional preference storage is controlled in Settings → Privacy → Cookie preferences; we do not force optional ad cookies.
- Marketing email: we send service mail (verify, reset, billing). Marketing mail only if we offer it and you can unsubscribe.
- Access / export / delete: contact us (below). We verify identity before acting.
8. Retention
- Account: kept while your account is active
- Chats and files: kept so you can reopen history, unless you delete them or close your account (subject to backups and legal holds)
- Billing records: kept as long as needed for accounting, tax, and dispute resolution
- Logs: kept for a limited period for security and debugging, then deleted or aggregated
When you delete content or request account deletion, we remove or de identify data from active systems within a reasonable time. Residual copies in backups may expire on a backup cycle.
9. Your rights and choices
Depending on where you live, you may have rights to:
- Access the personal data we hold about you
- Correct inaccurate data
- Delete your account or certain data
- Export a copy of data you provided (where feasible)
- Object to or restrict certain processing
- Withdraw consent where processing is based on consent
You can update some information in Settings. For deletion or a full access request, contact us (see below). We may need to verify your identity before acting. We will respond within a reasonable period and as required by applicable law.
If you are in the EEA/UK, our legal bases for processing typically include: contract (to provide the Service), legitimate interests (security, improvement, fraud prevention), consent (where required), and legal obligation.
If you are in California or another region with similar laws, you may have rights to know, delete, and opt out of “sale” or “sharing” of personal information. We do not sell personal information as commonly defined for ad tech. We do not use sensitive data for cross context behavioral advertising.
10. Children
The Service is not directed to children under 13 (or the minimum age required in your country). We do not knowingly collect personal data from children under that age. If you believe a child has created an account, contact us and we will delete it.
11. International transfers
We and our processors may process data in the United States, the European Economic Area, and other countries where our infrastructure and model providers operate. Where required, we rely on appropriate safeguards such as standard contractual clauses or equivalent mechanisms used by our providers.
12. Changes to this policy
We may update this Privacy Policy when the product or the law changes. The “Effective date” at the top will change. Material changes may be announced in the app or by email when appropriate. Continued use after the effective date means you accept the updated policy, unless applicable law requires another step.
13. Contact
Questions about privacy, access, or deletion:
zy.ai
Website: https://zyai.org
Privacy requests: use the in app support options, or email the address published on the site / in Settings when available.
If you are not satisfied with our response and live in a region with a data protection authority, you may lodge a complaint with that authority.
This page is a product privacy policy, not personalized legal advice. If you process regulated data (health, finance, government secrets), check your own compliance duties before using any online AI tool.