Last updated: September 13, 2026
Account information: When you create an account, we collect your email address, display name, age, and sex (for personalization). We also store authentication credentials (passkey public keys, password hashes) and session tokens.
Payment data: When you subscribe to a paid plan, we process payment through Flutterwave. We store transaction references, card tokens (last 4 digits, brand), and invoice metadata. We do NOT store your full card number, CVV, or PIN.
Usage data: We track document activity (uploads, edits, exports, template usage), AI call counts, email send counts, function invocation counts, storage usage, and bandwidth usage — all tied to your account for quota enforcement and billing.
Device and connection data: IP address (hashed for analytics, stored raw for 24 hours for security), browser user-agent, device type, screen resolution, and approximate geolocation (country-level, derived from IP). Used for rate limiting, fraud detection, and security logging.
Audit logs: We maintain audit logs of significant account actions (storage uploads/deletes, AI calls, email sends, API key creation, account changes) for 90 days. These logs include timestamps, action types, and IP addresses.
Support communications: If you contact us via email or WhatsApp, we retain those communications for quality and training purposes.
We do NOT:
For users in the European Economic Area (EEA), our legal basis for processing your personal data is:
Your data is stored on Cloudflare's global infrastructure:
For extended storage (when R2 capacity is exceeded), data may be replicated to:
All extended storage backends receive AES-GCM encrypted data. You never know which backend holds your data, and the encryption key is never shared with the backend provider.
At rest: All data is encrypted using AES-GCM (Advanced Encryption Standard with Galois/Counter Mode). Each account has a unique Data Encryption Key (DEK) derived from a platform master key using HKDF-SHA256. The DEK is never stored alongside the data it encrypts.
In transit: All network communication uses TLS 1.3 with strong cipher suites. HSTS is enforced. No plaintext protocols are used.
Authentication: Passkeys use WebAuthn (FIDO2) with hardware-backed key storage. Password hashes use bcrypt with a work factor of 12. Session tokens are SHA-256 hashed before storage.
Key rotation: The platform master key can be rotated without re-encrypting existing data. DEKs are derived deterministically, so rotation does not affect previously stored data.
When you use AI-powered features, your Content is transmitted to third-party AI providers for processing. Each provider is engaged under their own terms:
We transmit only the minimum data necessary for the AI request (typically the cropped image region or the specific text to edit). We do NOT transmit your account information, payment details, or other unrelated data to AI providers.
You can opt out of AI processing by not using AI-powered features. The Platform remains fully functional without AI — you can upload, edit, and export documents manually.
When you use the Email Service, the following data is processed:
Resend is our email delivery partner. Their privacy policy is available at resend.com/privacy. Resend may use email metadata for abuse detection and service improvement.
When you execute code through the Functions runtime, the following data is processed:
Function code is executed in a sandboxed environment with limited access to platform internals. Your function code cannot access other users' data, the platform's encryption keys, or internal APIs.
The Platform uses local storage (not cookies) for:
Local storage data is stored in your browser and is NOT sent to our servers unless you explicitly perform an action (upload, save, export). Clearing your browser's local storage will sign you out and reset your editor state.
No tracking cookies are used. No Google Analytics, no Facebook Pixel, no Hotjar, no Mixpanel, no Segment. We do not track your behavior across other websites.
We use server-side analytics only, derived from our own audit logs and usage counters. This includes:
We do NOT use client-side tracking, behavioral analytics, heatmaps, session recordings, or A/B testing tools. We do NOT fingerprint your browser or device for advertising purposes.
| Data Type | Retention Period |
|---|---|
| Account data | While account is active + 30 days post-termination |
| Uploaded files | Until user deletes them or account is terminated |
| AI conversation history | Until user deletes the session |
| Audit logs | 90 days |
| Payment records | 7 years (required by Nigerian tax law) |
| Email metadata | 30 days |
| Function execution logs | 24 hours |
| Security logs (IP addresses) | 24 hours (raw), 90 days (hashed) |
| Support communications | 2 years |
We do NOT sell, rent, or share your personal data with third parties for marketing or advertising purposes. We share data only in the following circumstances:
The following third-party services process your data as part of providing the Platform:
| Provider | Purpose | Data Processed |
|---|---|---|
| Cloudflare | Infrastructure | All data (encrypted at rest) |
| Flutterwave | Payments | Email, amount, card token, BVN |
| Resend | Email delivery | Email content, sender/recipient addresses |
| NVIDIA | AI vision | Image regions, text prompts |
| Google (Gemini) | AI processing | Images, text prompts |
| Groq | AI text | Text prompts, document context |
| Z.ai | AI text | Text prompts |
| Telegram | Extended storage | Encrypted file chunks only |
Depending on your jurisdiction, you may have the following rights regarding your personal data:
To exercise these rights, contact us at zylink.corp@gmail.com. We will respond within 30 days. For account deletion, use the "Delete Account" button in your dashboard settings — this is immediate and irreversible.
We comply with the Nigeria Data Protection Regulation (NDPR) 2019 and the Nigeria Data Protection Act 2023. Our Data Protection Officer (DPO) can be contacted at zylink.corp@gmail.com.
Under the NDPR, you have the right to:
We comply with the EU General Data Protection Regulation (GDPR) for users in the European Economic Area. We act as a data controller for account data and as a data processor for Content you upload.
If you are a business subject to GDPR and use the Platform to process personal data of your customers, you are the data controller and we are your data processor. We process personal data on your behalf only in accordance with your instructions (as transmitted through the Platform's APIs).
International data transfers from the EEA to non-adequate countries are carried out using Standard Contractual Clauses (SCCs) approved by the European Commission.
We comply with the California Consumer Privacy Act (CCPA) for users in California. Under the CCPA, you have the right to:
To exercise these rights, submit a request to zylink.corp@gmail.com with the subject line "CCPA Request".
The Platform is not directed to children under 16. We do not knowingly collect personal data from children under 16. If you become aware that a child under 16 has provided us with personal data, please contact us at zylink.corp@gmail.com, and we will delete the data immediately.
If we discover that we have collected personal data from a child under 16 without parental consent, we will delete that data as soon as possible.
Your data is stored on Cloudflare's global network and may be processed in countries other than your own, including but not limited to the United States, the European Union, and Singapore. By using the Platform, you consent to the transfer of your data to these countries.
We ensure that international transfers comply with applicable data protection laws through:
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify:
You can delete your account at any time from the dashboard settings. Account deletion is permanent and irreversible. Upon deletion:
The Platform may contain links to third-party services and websites (Flutterwave, Resend, Cloudflare, NVIDIA, Google, Groq, Z.ai). These links are provided for your convenience. We are not responsible for the content or privacy practices of these third-party sites. We encourage you to review their privacy policies separately.
We may update this Privacy Policy at any time. We will notify you of material changes via email at least 14 days before the changes take effect. Material changes include modifications to:
Non-material changes (typo fixes, clarifications, formatting) may be made without notice. The "Last updated" date at the top of this page reflects the most recent revision.
Continued use of the Platform after changes constitutes acceptance of the updated Privacy Policy. If you do not agree, you may delete your account.
For privacy questions, data requests, or to exercise your rights, contact us:
We will respond to all privacy-related inquiries within 30 days.