The short version
Here is this privacy policy in eight lines. The sections below give the detail, with each limit next to its promise.
- Zyflow runs no AI model. Your AI app gets what it asks for in the one workspace you approved, and its provider handles that under its own terms.
- How Zyflow makes money: from paid plans, once they open.1 No ads, no data sales, no AI upsell.
- We store your account, and what you, your team and your AI apps put into your workspace: customers, deals, notes, files, invoices and quotes, plus a history of every change.
- Zyflow receives only what your AI app sends in its tool calls, not the rest of your chat. Our tool-call log keeps which tool ran, not what was in it, for 90 days.
- Deleted records and files stay in the trash for 30 days, then they’re removed. Deleting a workspace or your account is immediate and permanent.
- No analytics, advertising or tracking cookies. The app uses sign-in cookies to keep you logged in.
- A hosting provider and an email provider process data for us, and Google does if you choose Google sign-in. Each is named on our subprocessors page.
- Export your records, documents and history any time, on every plan.2
Who this policy covers
This policy covers the Zyflow website, the Zyflow app and the emails Zyflow sends. Zyflow CRM, [REGISTERED ADDRESS], provides all three. Zyflow handles two kinds of data, and a different party decides about each.
- Your account data. Your name, email address, sign-in details, sessions and settings. Zyflow CRM decides how this data is used, as this policy describes.
- Workspace data. The customers, deals, notes, files and documents your business keeps in Zyflow. Your business decides what goes in and why. Zyflow stores it and works with it only to run the service for you.
This policy doesn’t cover your AI apps, such as Claude or ChatGPT, which have their own privacy policies, or Google, if you use Google sign-in. Using Zyflow is also covered by our terms of service.
What we store
Zyflow stores two kinds of data. Account data is about you: your name, email address, sign-in details, sessions and settings. Workspace data is what you, your team and your AI apps put into Zyflow: customers, deals, notes, facts, follow-ups, money owed, files, invoices and quotes, plus a history of every change and who made it.
| What | Examples | Why | How long |
|---|---|---|---|
| Your account | Name, email address, whether it’s confirmed, a profile picture if Google provides one, your job title in each workspace | To give you an account and contact you about it | Until you delete your account |
| Sign-in and sessions | Your password, if you set one. Sign-in links, stored as hashes. For each signed-in device, the IP address and browser it signed in from. If you use Google sign-in, the link to your Google account | To sign you in, keep you signed in and let you sign out other devices | See how long we keep data |
| Business profile and Notes for your AI | Business name, logo and address, up to 5 emails and 5 phones, payment instructions, tax registration numbers you add, and Notes for your AI (up to 2,000 characters) | To print on your documents and brief your AI apps | While the workspace exists |
| Customer records | Contacts with their emails, phones, WhatsApp numbers, birthdays, anniversaries and tags; companies; deals; calls and notes; facts about each customer; follow-ups; money owed | They’re your CRM | Until you delete them, then 30 days in the trash |
| Files and documents | Files you or your AI save; invoices, quotes and letters with their PDFs; templates | To keep paperwork with the customer | Until you delete them, then 30 days in the trash |
| History | For every change: the values of the changed fields before and after, a one-line summary, who made it, which app or API key, and when | To label each change and let you review it | Your plan’s history window |
| Team | Members’ names, email addresses, roles and job titles. Invitations: the invited email address and role, with the link stored as a hash | To run a shared workspace | While the person is a member. Invitation links work for 7 days |
| AI connections and API keys | Which apps you approved, for which workspace, and when each was last used. API key names. Tokens and keys, stored as hashes | To let apps and scripts act for you, and to show and revoke them | Until you disconnect or revoke them |
| Usage records | The tool-call log, and daily counts of tool calls, API calls and writes | To show the usage panel and apply plan limits | Log: 90 days. Daily counts: while the workspace exists |
| Paid-plan reservations | Workspace, plan, monthly or yearly, who asked and when1 | To email you when paid plans open | While the workspace exists |
What we don’t store
- Your conversations with your AI app. Zyflow receives only the tool calls your app sends.
- Card or bank details. Paid plans can’t be bought yet, so Zyflow collects no payment details.
- Copies of the emails we send. Email goes out through our email provider, and Zyflow keeps no copy.
- Your inbox, calendar, calls or WhatsApp. Zyflow doesn’t connect to them, so it holds only what you, your team or your AI save.
- Records of how you use the app. The app runs no analytics or tracking scripts.
Emails we send you
Zyflow sends seven kinds of account email to you and your team: confirm your email, sign-in link, password reset, welcome, workspace invitation, import finished and the 8am email. If you reserve a paid plan, we’ll email you when paid plans open. There’s no newsletter and no marketing email. Zyflow sends nothing to your customers.
The 8am email lists your follow-ups, payments to chase and birthday wishes, so it carries customer names, amounts and invoice numbers.3 Each person can switch theirs off in Settings > Profile, under Morning digest.
What your AI apps receive, and under whose terms
When you connect an AI app, you sign in and approve one workspace. The app then receives what it asks for through Zyflow’s tools in that workspace, such as customer records, facts, follow-ups, money owed, file links and your Notes for your AI. Zyflow receives only what the app sends in its tool calls, not the rest of your chat. The app’s provider, such as Anthropic or OpenAI, handles that data under its own terms.
A tool call is one request from your AI app to Zyflow, such as “find Maya Chen” or “log this call and set a follow-up for Friday.”
Sent when an app connects
- Your Notes for your AI (about 1,500 characters) and the “About this business” text from your business profile.
- Your workspace’s date format, currency and today’s date.
Sent when the app asks
- Customer records, facts, deals, calls and notes, follow-ups, money owed, documents and change history, from the approved workspace only.
- The contents of files your AI opens: images up to 5 MB and text files up to 1 MB.
- Links to files and PDFs. Each works for 7 days, anyone holding it can open it, and links can’t be revoked one at a time.
- Your teammates’ names, email addresses, roles and job titles, so your AI knows who’s who.
Never sent
- Your password. Signing in works like “Sign in with Google”: you approve in your browser, and the app gets a token.
- Anything from another workspace.
- Control of billing, members or API keys. Each app acts with its person’s role and can’t change those.
Disconnecting an app on the Connect page revokes its access and every token it holds, at once. Your teammates’ AI apps can see what your teammates can see.
Two small things leave Zyflow during sign-in. For an app that publishes a public description, Zyflow fetches it from the app’s own site to show the app’s name. For an app Zyflow has no built-in logo for, the consent screen loads the logo from the address the app supplies, so that site can see your IP address.
What happens to data after your AI app reads it is up to that app and your settings there. Set its data controls as you would for any chat. See how data moves between your AI app and Zyflow.
Tool-call logs: tool names, not contents, kept 90 days
Each time an AI app calls a Zyflow tool, Zyflow logs the tool’s name, the app, the person it acts for, whether it worked, any error code, how long it took and when. It doesn’t log what your AI asked for or what Zyflow sent back. The log powers the usage panel on the Connect page and is deleted after 90 days.
There’s one exception. If your AI app sends a retry key with a change, Zyflow keeps that call’s result and a fingerprint of the request for 24 hours, so a repeated call gets the first result back instead of saving twice. Then both are deleted.
Zyflow also keeps daily counts of tool calls, API calls and writes for each workspace, for as long as the workspace exists. Calls through the REST API aren’t in the tool-call log; any change they make is in History, like every other change. None of these records is used for billing.
Zyflow’s server doesn’t log each request, and its logs redact passwords, tokens, cookies, email addresses and phone numbers. [HOSTING LOGS: what the hosting provider’s own logs keep, and for how long]
How long we keep data
Deleted records and files stay in Zyflow’s trash for 30 days on every plan, then are removed for good, including file contents. Tool-call logs are deleted after 90 days. How long change history is kept depends on your plan, as below. Deleting a workspace or your account is immediate and permanent. Backups are kept for [BACKUP RETENTION], so deleted data can remain in backups until then.
| Data | Kept for |
|---|---|
| Records, files and folders in the trash | 30 days, then removed for good by an hourly job, including file contents. You can empty the Files trash sooner |
| Change history | See the line under this table |
| Tool-call log | 90 days |
| Results kept for retries | 24 hours |
| Sign-in links and password-reset links | 15 minutes and 1 hour |
| Sessions, with IP address and browser | A session ends 30 days after you last used Zyflow on that device, or when you log out |
| AI-app tokens | Access tokens last 60 minutes and refresh tokens 90 days. Their records are deleted 7 days after the refresh token expires, and unused sign-in codes a day after they expire. Disconnecting revokes tokens at once |
| Markers that an 8am email was sent | 7 days |
| Finished background jobs | 3 days |
| An uploaded import file | Cleared when the import finishes |
| Import summaries (counts and up to 200 row errors), daily usage counts, paid-plan reservations | While the workspace exists |
| Your account | Until you delete it |
| A workspace or account you delete | Removed at once, permanently |
| Backups | [BACKUP FREQUENCY AND RETENTION] |
| Hosting and network logs | [WHAT THEY HOLD AND FOR HOW LONG] |
Change history: Free shows the last 30 days of history, and paid plans show up to 3 years. While paid plans aren’t on sale, we don’t remove any history.1
See the history window for each plan, and how history and undo work.
Deleting a workspace is immediate and permanent. There’s no grace period, so export first.
Cookies and analytics
Zyflow’s website sets no analytics or advertising cookies, runs no tracking scripts and hosts its own demo videos. The Zyflow app uses sign-in cookies to keep you logged in and stores display preferences, such as a collapsed menu, in your browser. The app loads no analytics or third-party scripts.
The sign-in cookie, zyflow.session_token, is strictly necessary. Only the app’s own address sets it, scripts on the page can’t read it, and it ends 30 days after you last used Zyflow on that device, or when you log out.
The app keeps these preferences in your browser’s own storage, and they don’t leave your device: whether the menu is collapsed, list or grid view in Files, whether AI pop-ups show on this device, the Today rows you dismissed that day, light or dark theme, and whether documents are switched on for each workspace. It also keeps a one-minute marker that lets an open tab reload once after an update.
If you choose Google sign-in, Google’s own pages set Google’s cookies, under Google’s terms.
Because nothing else is set, the site shows no cookie banner. If we ever add analytics or embedded content from another company, we’ll update this policy and the subprocessors page first, publish a cookie page and ask for your consent.
Who can see your data
Inside your workspace, your teammates and the AI apps they connect can see your customer records. Outside it, the people who run Zyflow can reach its database to operate the service, and our providers process data for us. Beyond them, data goes only where this list says.
- Your teammates. Every member, and every member’s AI, can see and edit every customer. There are no per-person permissions yet. Owners and admins also manage settings and the team; members can’t.
- AI apps that you and your teammates connect. Each gets what it asks for in the approved workspace, within its person’s role. Its provider handles that under its own terms.
- Anyone holding a link. File and PDF links work for 7 days for whoever has them.
- The people who run Zyflow. They can access its database to operate and secure the service. We look at what’s inside a workspace only when you ask for help, to investigate a security or abuse problem, or when the law requires it. The admin console they use shows totals (users, workspaces, records and AI calls), each workspace’s name, country, plan and counts, and the list of paid-plan reservations with names and email addresses. It doesn’t show your records. [LAWYER and FOUNDER: approve this commitment word for word]
- Our providers. The hosting and email providers in the next section.
- Authorities. We disclose data when the law requires it, and we tell the affected workspace owner first unless the law forbids it.
- If Zyflow is sold or merged, your data moves with the service, and this policy keeps applying until you’re told otherwise.
Who processes data for us
Zyflow uses a small number of companies to run the service: a hosting provider that stores and serves your workspace, and an email provider that delivers sign-in links, invitations and the 8am email. Google is involved only if you choose Google sign-in. Each one is listed on our subprocessors page with what it handles and where.
| Purpose | What they handle | Who and where |
|---|---|---|
| Hosting | Your account, your workspaces, files and backups | Named on the subprocessors page |
| Email delivery | Names and email addresses, sign-in links, invitations and the contents of the 8am email | Named on the subprocessors page |
| Google sign-in, only if you choose it | Your sign-in with Google | Google, under its own privacy policy |
AI apps aren’t on this list. You connect them yourself, under their own terms, so they aren’t Zyflow’s subprocessors. See the full list of subprocessors.
Where your data is stored
Zyflow runs on [HOSTING PROVIDER] in [REGION]. Files are stored [FILE STORAGE]. Backups run [BACKUP FREQUENCY] and are kept for [BACKUP RETENTION]. There’s no choice of where your data is stored yet.
Your requests
You can export your workspace, delete a workspace or your account, disconnect an AI app, revoke an API key and switch off the 8am email yourself, in Settings and on the Connect page. For anything else, such as a copy of your account data, a correction or help with a deletion, email [SUPPORT EMAIL] with the subject “Privacy request”.
Do it yourself
You can export or delete your Zyflow data yourself, on every plan. Export from Settings > Import and export.2 Delete your account in Settings > Profile; owners delete a workspace in Settings > General. Deletion is immediate and permanent.
- Export. Any member can export, and so can any API key, including a read-only one. See what an export contains.
- Correct your details. Change your name, job title and password in Settings > Profile.
- Delete a record or a file. It moves to the trash for 30 days, then it’s removed. You can empty the Files trash sooner.
- Delete your account. Type DELETE to confirm. If you own a workspace other people use, transfer it first in Settings > Team. Workspaces only you own are deleted with your account. What you added to a team’s workspace stays with that workspace, no longer linked to you.
- Delete a workspace. Owners type the workspace’s exact name to confirm.
- Disconnect an AI app or revoke an API key. On the Connect page.
- Switch off the 8am email. In Settings > Profile, under Morning digest.
Ask us
Email [SUPPORT EMAIL] with the subject “Privacy request” and tell us what you need: a copy of your account data, a correction you can’t make yourself, or help deleting something. We may ask you to confirm the request from the email address on your account before we act on it.
Depending on where you live, you may have the right to see, correct, delete or get a copy of your personal data, to object to or limit how it’s used, and to complain to your local data protection authority.
If your details are in someone else’s workspace
If your details are in a business’s Zyflow workspace, that business decides what’s kept about you. Contact them first. If you can’t reach them, email [SUPPORT EMAIL] and we’ll pass your request to the workspace owner.
What deletion can’t reach
Deleting a contact moves it to the trash for 30 days. After that:
- its change history, including the details recorded in each change, stays for your plan’s history window (while paid plans aren’t on sale, we don’t remove any history);
- deals, notes, facts, follow-ups and files that were linked to it are kept, no longer linked, until you delete them;
- issued invoices keep the details printed on them;
- copies outside Zyflow, such as exports, downloaded PDFs and your AI app’s chats, aren’t affected;
- backups keep it until they expire.
Zyflow has no tool yet that finds and erases everything about one person in one step. If you need that, email us and we’ll help by hand.
Security, in brief
AI apps sign in with OAuth 2.1 with PKCE and refresh-token rotation. Keys and tokens Zyflow issues are stored only as hashes, and Zyflow’s logs redact personal data such as email addresses and phone numbers. Zyflow doesn’t add its own encryption to your records and files; encryption at rest depends on our hosting provider.
Zyflow doesn’t offer a data processing agreement (DPA) or a choice of where your data is stored yet. Zyflow doesn’t hold security certifications such as SOC 2 or ISO 27001 today, and doesn’t offer two-factor sign-in or SSO yet. The security page lists what Zyflow doesn’t offer yet.
Children
Zyflow is for businesses and isn’t meant for children. You must be at least [MINIMUM AGE, SET BY THE LAWYER] to create an account. If you think a child has given us personal data, email [SUPPORT EMAIL] and we’ll delete it.
Changes to this policy
When we change this policy, we update the date at the top of this page and add a line to the change log below. If a change affects what we store, who processes it or how long we keep it, we’ll email workspace owners [NOTICE PERIOD] before it takes effect.
| Date | What changed |
|---|---|
| [PUBLISH DATE] | First version of this policy |
Contact
To ask about this policy or make a privacy request, email [SUPPORT EMAIL] with the subject “Privacy request”. Zyflow is provided by Zyflow CRM, [REGISTERED ADDRESS]. To report a security issue, email [SECURITY EMAIL].
Common questions
Does Zyflow see my conversations with Claude or ChatGPT?
No. Zyflow receives only what your AI app sends in its tool calls, such as “find Maya Chen”, not the rest of your chat. Its tool-call log records which tool ran, not what was in it, and is deleted after 90 days.
Does Zyflow use my data to train AI?
Zyflow runs no AI model and doesn’t train one on your data. Zyflow receives only what your AI app sends in its tool calls, not the rest of your chat. What your AI app does with what it reads is covered by your AI provider’s terms.
Does Zyflow sell my data or show ads?
No. How Zyflow makes money: from paid plans, once they open.1 No ads, no data sales, no AI upsell. A hosting provider and an email provider process data to run the service, and they’re named on the subprocessors page.
How long does Zyflow keep data I delete?
Deleted records and files stay in the trash for 30 days, then they’re removed for good, including file contents. Deleting a workspace or your account is immediate and permanent. Backups keep deleted data for up to [BACKUP RETENTION].
If I delete a contact, is everything about them gone?
Not everything. After 30 days in the trash the contact is removed, but its change history stays for your plan’s history window, and linked deals, notes and files stay, no longer linked. Issued invoices, exports and your AI app’s chats keep their copies.
Where is my data stored, and is it backed up?
Zyflow runs on [HOSTING PROVIDER] in [REGION], and backups run [BACKUP FREQUENCY] and are kept for [BACKUP RETENTION]. There’s no choice of where your data is stored yet.
Does Zyflow offer a DPA?
Not yet. Zyflow doesn’t offer a data processing agreement or a choice of where your data is stored. If your contracts require a DPA, Zyflow isn’t a fit yet. See what Zyflow doesn’t offer yet.