Skip to content

Privacy policy

This is a demonstration product, and this page is illustrative rather than a real privacy policy. Before operating zrdio commercially, replace it with a policy reviewed for the privacy laws that apply to you and your users.

What we store

  • Account data: your name, email address and a salted, memory-hard hash of your password. Never the password itself.
  • Workspace content: projects, generated site versions, scan reports and content you create.
  • Session data: a hashed session token, your browser's user-agent string and IP address, used for the signed-in devices list.
  • Usage data: counts of AI generations and scans, used for plan limits and shown to you on the billing page.

What we send to third parties

  • AI generation: when an API key is configured, your briefs and site content are sent to the AI provider to produce the output you requested. In simulation mode nothing leaves the server.
  • Payments: when Stripe is configured, billing details are handled by Stripe. Card numbers never touch our servers.
  • Scanning: scans fetch the URL you specify from our server. We send that site a normal HTTP request identifying our crawler.

What we do not do

We do not sell your data, run third-party advertising trackers, or read your generated content for any purpose other than serving it back to you.

Retention and deletion

Deleting a project permanently removes its versions, scans, findings and content. Deleting your account removes your user record, sessions and notifications. Invoices are retained as required by accounting law.

Cookies

One cookie: the session token that keeps you signed in. It is HttpOnly, SameSite=Lax and, in production, Secure. There are no tracking cookies, which is why there is no cookie banner.