The short version
Most people want to know these points first. Each one links to the section that covers it in full.
- Every Zyflow workspace runs on Free today. Paid plans aren’t on sale yet, and nothing is charged. See section 2.
- Free has no time limit and needs no card. See section 6.
- Your content is yours. Export your records, documents and history any time, on every plan. See section 5.
- An AI app you connect acts as you: in the one workspace you approved, with your role, and every change it makes is labeled with its name. You’re responsible for what it does, and you can disconnect it at any time. See section 3.
- Your AI app’s calls to Zyflow are never billed on any plan, and there are no AI credits. See section 2.
- Reaching a plan limit never deletes anything. You can’t add more of what’s full until you make room. See section 4.
- Deleting a workspace or an account is immediate and permanent. See section 5.
- Zyflow runs no AI model and doesn’t train one on your data. See section 5.
- Don’t store regulated data, such as health records or government ID numbers, and don’t use Zyflow to break the law or harm others. See section 3.
- We’ll email workspace owners before these terms change in ways that matter. See section 9.
This summary helps you read the terms. If it and the numbered sections ever differ, the numbered sections apply.
1. Service and accounts
Zyflow is a hosted CRM for you and your AI apps, and each person needs their own login.
What Zyflow is
Zyflow is a hosted service with three parts: a web app for people, a Zyflow link (an MCP server) that your AI apps connect to, and a REST API for scripts and forms. Zyflow runs no AI of its own. Your AI app does the talking; Zyflow keeps the record.
- Zyflow is in English only. Your own AI can draft messages in your customer’s language.
- The one-file local bridge, for AI apps that can only start local servers, is MIT-licensed, and that license covers the bridge only. The rest of Zyflow isn’t open source, and self-hosting isn’t offered.
Words we use in these terms
- Workspace: one business in Zyflow, with its own customers, files, documents, plan and people.
- Owner, admin and member: the three roles a person can have in a workspace, described below.
- People: everyone who can sign in to the workspace, including pending invitations. AI apps, API keys and AI agents never count as people.
- Records: contacts, companies and deals. Notes, calls, memories, follow-ups, files, invoices and quotes don’t count, and neither does anything in the trash. Importing contacts with a company column also creates those companies, so a sheet can use more records than it has rows.
- Your content: everything you, your team, your AI apps and your API keys put in a workspace, including files and documents.
- AI app: Claude, ChatGPT, Cursor or any other app that supports MCP, once you’ve signed in and approved it for a workspace.
- API key: a named key that lets a script or form reach one workspace through the REST API or the Zyflow link.
- You: you, and the business you use Zyflow for. We and us: Zyflow CRM.
Who can use Zyflow
Zyflow is made for running a business: owners, their teams and the consultants who set up tools for them. If you create a workspace for a business, you confirm you’re allowed to accept these terms for it.
Your account and sign-in
You can sign in with an email and password, an emailed sign-in link, or Google. You’re responsible for what happens under your account.
- Keep your sign-in details safe. If you think someone else has used your account, change your password, remove AI apps and API keys you don’t recognize on the Connect page, and tell us at [SECURITY EMAIL].
- Each person uses their own login. Zyflow labels each change with the person who made it, so with a shared login, History can’t show who did what.
- Zyflow doesn’t hold security certifications such as SOC 2 or ISO 27001 today, and doesn’t offer two-factor sign-in or SSO yet.
Workspaces, roles and people
Every workspace has exactly one owner, who is responsible for it.
- Owner: can do everything, including deleting the workspace.
- Admin: manages settings, the team and every record, and can change the plan.
- Member: works with every record, but can’t change settings.
Every member, and every member’s AI, can see and edit every customer. There are no per-person permissions yet.
- Ownership can be transferred in Settings > Team, and the old owner becomes an admin. If you set up a workspace for a client, transfer ownership to them when you hand it over. From then on, they decide who has access.
- One login can own up to 10 workspaces.
- Each invitation works once, for one email address, and expires after 7 days.
2. Plans, reservations and future billing terms
Every workspace is on Free today, you can reserve a paid plan for later, and nothing is charged.
Today: every workspace is on Free
Paid plans aren’t on sale yet. Every workspace starts on Free, and nothing is charged until you start a paid plan. Reserve Solo, Team or Pro to get the founding price when they open. Plan limits are on our pricing page and our limits page.
Reserving a paid plan
Until paid plans open, an owner or admin can choose a paid plan in Settings > Plan and usage, and we record that as a reservation. A reservation is free and commits you to nothing. We’ll email you when paid plans open, and nothing is charged unless you then start a paid plan.
What every plan includes
Every feature we offer today is on every plan. Plans differ in how much they hold, such as people, records, file storage and history. New features may come with their own price.
Your AI app’s calls to Zyflow, through MCP or the REST API, are never billed on any plan, and there are no AI credits. Short burst limits stop runaway scripts. Your AI app’s own subscription and usage limits still apply.
Prices and the founding price
- Free: $0, for 1 person and 5,000 records.
- Solo: $12 a month, or $120 a year, for up to 3 people and 10,000 records.
- Team: $30 a month, or $300 a year, for up to 10 people and 50,000 records.
- Pro: $90 a month, or $900 a year, for up to 30 people and 250,000 records.
Prices in US$. Each price covers the whole workspace, not each person.
Founding price: reserve a paid plan before paid plans open, start it on yearly billing within 30 days of opening, and pay 20% less than the yearly price. That’s Solo $96, Team $240 or Pro $720 a year ($8, $20 or $60 a month). The price holds for 24 months from your first payment, as long as you stay subscribed. If a plan’s limits rise during that time, you get them, and yours won’t be lowered. Monthly billing is always at the list price.
3. Acceptable use, including AI apps and API keys
Use Zyflow lawfully and fairly, and treat every AI app and API key you connect as acting for you.
Using Zyflow fairly
Don’t use Zyflow to break the law or to harm the service or other people. In particular:
- Don’t store anything illegal, or details about people that you have no right to hold and use.
- Don’t upload malware, or content written to attack Zyflow, other workspaces or other people’s AI apps, such as hidden instructions meant to hijack an AI app.
- Don’t create extra accounts or workspaces to get around plan limits.
- Don’t overload, scrape or probe Zyflow beyond what the documented API allows. Found a security issue? Contact us.
We may suspend access for misuse, as section 8 explains.
Data you shouldn’t store
Don’t store health records, government ID numbers, payment card numbers or other regulated data in Zyflow. Zyflow doesn’t hold security certifications such as SOC 2 or ISO 27001. If a law where you work requires special safeguards for some kind of data, keep that data out of Zyflow.
Your AI apps act for you
You’re responsible for what an AI app you connect does in Zyflow, as with anything done under your account. An AI app acts as you, with your role, in the one workspace you approved. Every change it makes is labeled with the app’s name. AI changes to records, files and documents can be undone within your plan’s history window. You can disconnect an app at any time.
- An AI app never gets more than your role, and it can’t touch billing, members or API keys.
- AI apps can only move things to the trash. Issued invoices can only be voided, not deleted. Bulk changes preview first and stop at 200 records.
- Zyflow doesn’t check the facts your AI writes. It labels them, so you can review them.
- Zyflow has built-in defenses against prompt injection: hidden characters are stripped, and file text reaches your AI labeled as customer data, not instructions. These are mitigations, not guarantees.
- Disconnect an app on the Connect page, and its access ends right away. Members can disconnect their own apps; owners and admins can disconnect anyone’s.
- Your AI app’s own plan and terms decide what it can do in Zyflow and what happens to what it reads. Which AI plans work?
See what your AI can and can’t touch.
API keys
API keys let scripts and forms reach one workspace. You’re responsible for keeping your keys secret and for what anyone does with them.
- Each key is named, shown once and stored only as a hash. It acts with the role of the person who created it, and it never reaches account, team or billing settings.
- Keys don’t expire. Revoke keys you no longer use on the Connect page. Any member can create a key, and can see and revoke anyone’s.
- A read-only key can still export the workspace, so guard it like any other key.
- Unlike AI apps, API keys can permanently delete files that are already in the trash.
- Never put a key in a web page’s code, where anyone who opens the page could copy it. Use keys from a server or a script.
Rate limits and fair use
Short burst limits stop abuse and runaway scripts. They’re the same on every plan, and they never add to a bill: a request over the limit is refused with a note saying when to try again. We don’t publish the figures, because they can change.
What Zyflow doesn’t do for you
Zyflow sends nothing to your customers. Your AI drafts; you press send.
Zyflow records payments; it doesn’t collect them. There are no card payment links.
Zyflow works out totals, tax and numbering. Unit prices come from what you or your AI enter; there’s no price list.
You’re responsible for the invoices, quotes and letters you send, including their prices, tax and wording, and for your own tax and accounting.
4. Over-limit policy
Reaching a plan limit never deletes anything.
Everything stays readable and editable, your AI can still read it, and export still works. You can’t add more of what’s full until you make room: new contacts, companies or deals, uploads, or invitations. To free storage, empty the trash.
| Limit | What happens |
|---|---|
| Records | New contacts, companies and deals are refused. Reading, editing and export still work |
| Storage | New uploads are refused. Files stay viewable and downloadable |
| People | New invitations are refused |
| API keys, custom fields, pipelines | No new ones until there’s room |
Nothing is deleted for being over a limit, but the normal 30-day trash still empties. Records in the trash don’t count toward your records limit, but files in the trash count toward storage until they leave the trash. If storage is full, a new invoice still saves, but its PDF can’t be filed until there’s space.
5. Your data, export and deletion
Your content is yours, you can export it any time, and when you delete it, it’s gone.
Your content is yours
The customer records, files and documents you and your AI apps put in Zyflow are yours. We store and process them to run the service for you. Export your records, documents and history any time, on every plan.
How Zyflow makes money: from paid plans, once they open. No ads, no data sales, no AI upsell.
What your AI apps receive
Your AI app receives only what it asks Zyflow for, plus your Notes for your AI when it connects, from the one workspace you approved. Anything that reaches your AI app is handled under your AI provider’s terms, so set its data controls as you would for any chat.
Zyflow runs no AI model and doesn’t train one on your data. Zyflow receives only what your AI app sends in its tool calls, not the rest of your chat. What your AI app does with what it reads is covered by your AI provider’s terms.
We keep a log of each tool call (each request your AI app makes to Zyflow) for 90 days. It records which tool ran, for which app and person, whether it worked and how long it took, but not what was in it.
Export any time
You can export your workspace any time, on every plan, in Settings > Import and export or through the API with any key. Any member can export, and so can a read-only key.
Export gives you six CSV files, or one JSON file with your records, documents, change history (up to 100,000 changes) and links to every file. File contents download separately from Files. See the export formats.
The trash and undo
Deleted records and files go to the trash, and you can restore them for 30 days. After that, they’re removed for good.
Undo works within your plan’s history window: 30 days on Free, up to 3 years on paid plans. Deleted items can be restored for 30 days on every plan. Settings changes, such as pipelines, custom fields and tag renames, are logged but can’t be undone.
Files deleted for good from the trash can’t be restored, and neither can a deleted workspace or account. How long we keep change history is set out in our privacy policy.
Deleting a workspace or your account
Deleting a workspace is immediate and permanent. Only the owner can delete a workspace, in Settings > General, by typing its exact name. Every record, file and document in it is removed.
Deleting your account, in Settings > Profile by typing DELETE, also deletes the workspaces only you use. If you own a workspace other people use, you need to transfer it in Settings > Team before you can delete your account. To keep a copy, export before you delete.
[BACKUPS: what happens to backup copies after a deletion, and how long they last, once the hosting facts are confirmed]
Personal data
Our privacy policy explains how we handle personal data, and our subprocessors page lists the companies that help us run Zyflow. When you store details about your customers and contacts, you decide what goes in, and we process those details for you to run the service.
Zyflow’s operators have technical access to the database that holds workspaces.
6. Free plan promise
Free has no time limit and needs no card.
Free covers one person and every feature we offer today, within the limits on our pricing page. Nothing is charged on Free.
7. Support and availability
Help comes from the docs and by email, and we don’t promise response times or uptime.
Start with the docs. For sign-in, connection or data problems, email [SUPPORT EMAIL].
We don’t promise response times or a particular uptime. Zyflow can sometimes be slow or unavailable, for example during maintenance or an outage.
Zyflow doesn’t send you scheduled exports, so export your workspace regularly if you want your own copy.
8. Suspension, ending and if Zyflow shuts down
You can leave at any time, and we may suspend access for misuse, security or legal reasons.
Leaving
You can stop using Zyflow at any time. Export your workspace, then delete it or your account, as section 5 explains. Nothing is charged today, so there’s no payment to stop.
Suspension
We may suspend or limit an account, a workspace, an AI app connection or an API key to stop misuse of the kinds in section 3, to protect the service or other people, or when the law requires it. Where we can, we’ll tell you first and give you a chance to export.
If Zyflow shuts down
We can’t promise Zyflow will run forever, which is why export works any time, on every plan.
9. Changes and notice
When these terms change, we update the date at the top, and we email workspace owners before changes that matter.
- We may update these terms as Zyflow changes, for example when paid plans open.
- For changes that matter, we’ll email every workspace owner at least [NOTICE PERIOD] before they take effect.
- Small changes, such as fixing a typo or making a sentence clearer, take effect when we post them.
- If you don’t agree with a change, you can export your data and stop using Zyflow before it takes effect.
Every version is listed at the end of this page, with its date and what changed.
10. Legal terms
These are the standard legal clauses, each with a plain sentence first.
Warranties
We build Zyflow carefully, but it can have bugs and outages, and the AI apps you connect can write things that are wrong.
Limitation of liability
Our responsibility for losses is limited, as far as the law allows.
Indemnity
If someone brings a claim against us because of your content or how you used Zyflow, you’re responsible for that claim.
Intellectual property and feedback
Zyflow’s software, name and design belong to Zyflow CRM, and your content stays yours. If you send us ideas or feedback, we may use them freely. The bridge’s MIT license covers the bridge file only.
Third-party services
AI apps, Google sign-in and other services you use with Zyflow are run by other companies under their own terms, and we aren’t responsible for them. Zyflow isn’t affiliated with or endorsed by the companies that make the AI apps it works with.
Governing law and disputes
If something goes wrong, please email us at [SUPPORT EMAIL] first, so we can try to fix it.
Consumer rights
If you’re a consumer, for example in the EU, the UK or Australia, you keep the rights your local law gives you, and nothing in these terms takes them away.
General
These terms are the whole agreement between you and us about Zyflow.
11. Contact
Questions about these terms go to [SUPPORT EMAIL].
Company: Zyflow CRM
Postal address: [POSTAL ADDRESS]
Questions about these terms, and support: [SUPPORT EMAIL]
Security issues: [SECURITY EMAIL]
Privacy requests: see our privacy policy
For anything else, contact us.
Versions
These terms and our privacy policy go together.
Free plan. No card.
- Version 1 · Effective [EFFECTIVE DATE]: first published version.
Add one line per change, newest first, and never delete old lines.
© 2026 Zyflow CRM. All rights reserved.